Stránka 1 z 2

Fakepolice

Napsal: 16 led 2014 14:35
od karelfritz
Dobrý den, naskytl se mi problém, který už se mým přátelům stal. Při spuštění prohlížeče mi naskočí stránka, kdy jsem informován, že můj počítač byl zablokovaný policií a mám uhradit pokutu do 12 hodin. Proto bych vás chtěl požádat o radu, je mi jasné, že se jedná o vir a s policií to nemá co společného, spíš bych chtěl vědět jak se viru zbavit. Předem mockrát děkuju za odpověď. S pozdravem, Karel Fritz


Logfile of random's system information tool 1.09 (written by random/random)
Run by Kuba at 2014-01-16 14:20:57
Microsoft Windows 8
System drive C: has 847 GB (93%) free of 912 GB
Total RAM: 3962 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:21:01, on 16. 1. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\windows\SysWOW64\WScript.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Kuba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbar.dll
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O3 - Toolbar: VideoDownloadConverter - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [WeatherBlink EPM Support] "C:\PROGRA~2\WEATHE~2\bar\1.bin\gcmedint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [WeatherBlink Browser Plugin Loader 64] C:\Program Files (x86)\WeatherBlink\bar\1.bin\gcbrmon64.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [VideoDownloadConverter EPM Support] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zmedint.exe" T8EPMSUP.DLL,S
O4 - HKLM\..\Run: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [VideoDownloadConverter_4z Browser Plugin Loader] C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
O4 - HKLM\..\Run: [VideoDownloadConverter_4z Browser Plugin Loader 64] C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [mswrmcviSrv] "C:\windows\system32\mswrmcvi.vbe" msqmrljg msiknm
O4 - HKCU\..\Run: [NextLive] C:\windows\SysWOW64\rundll32.exe "C:\Users\Kuba\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: Distributed Computing Experiment (DCE) - Unknown owner - C:\Program Files\DCE\dce.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\windows\system32\SAsrv.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VideoDownloadConverterService (VideoDownloadConverter_4zService) - COMPANYVERS_NAME - C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: WeatherBlinkService - COMPANYVERS_NAME - C:\PROGRA~2\WEATHE~2\bar\1.bin\gcbarsvc.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 12700 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
C:\windows\system32\CxAudMsg64.exe
"C:\Program Files\DCE\dce.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe"
"C:\Program Files\Elantech\ETDService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe"
C:\windows\SysWOW64\SAsrv.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
C:\PROGRA~2\WEATHE~2\bar\1.bin\gcbarsvc.exe
"C:\Program Files\Windows Defender\MsMpEng.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b570f252-de4e-47eb-913f-ff3b5b1f3e70 -SystemEventPortName:HostProcess-14558824-e812-41f4-a7e1-04fadb76d351 -IoCancelEventPortName:HostProcess-785bb561-430e-43d1-b84c-f4bd72bd8cbd -NonStateChangingEventPortName:HostProcess-572de231-02a0-4890-8962-ee3c5ed3d488 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:9c9fa14e-1a39-4350-96dc-cb8f11550a35 -DeviceGroupId:WudfDefaultDevicePool
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe" KMPProcess
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
atieclxx
taskhostex.exe
"C:\Program Files\Elantech\ETDCtrl.exe"
C:\windows\Explorer.EXE
ClassicStartMenu.exe -startup
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\AppIntegrator64.exe"
"C:\Windows\SysWOW64\rundll32.exe" "C:\Users\Kuba\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\WeatherBlink\bar\1.bin\gcbrmon64.exe"
"C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe"
"C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\windows\System32\WScript.exe" "C:\Windows\System32\mswrmcvi.vbe" msqmrljg msiknm
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
taskeng.exe {A00B19C7-5147-4076-A532-E883389ED915}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4636.0.2120470780\1497321580" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.3114 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4636.2.2108694256\1644761943" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4636.3.1034838163\1662655088" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4636.4.716798438\1443027380" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4636.5.977134739\1620865014" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4636.6.601534525\820738586" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4636.7.288287939\74634534" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="4636.8.1095724140\829709765" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="4636.9.109696228\575320869" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group1 pct:25 stable:r4 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="4636.10.1219349524\1023740941" /prefetch:673131151
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe24_ Global\UsGthrCtrlFltPipeMssGthrPipe24 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
C:\windows\system32\wbem\wmiprvse.exe
"C:\windows\system32\NOTEPAD.EXE" C:\rsit\info.txt
"C:\Users\Kuba\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin]
"Description"=VideoDownloadConverter Plugin
"Path"=C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin]
"Description"=VideoDownloadConverter_ScriptHelper Plugin
"Path"=C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WeatherBlink.com/Plugin]
"Description"=WeatherBlink Plugin
"Path"=C:\Program Files (x86)\WeatherBlink\bar\1.bin\NPgcStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\
4zffxtbr@VideoDownloadConverter_4z.com
gcffxtbr@WeatherBlink.com
{746505DC-0E21-4667-97F8-72EA6BCF5EEF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-20 774144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro64.dll [2014-01-13 516456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2013-10-20 460288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]
Toolbar BHO - C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbar.dll [2013-12-13 859720]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-20 627712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro.dll [2014-01-13 429416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]
Search Assistant BHO - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll [2013-12-13 140360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2013-10-20 386048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-20 774144]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-20 627712]
{48586425-6bb7-4f51-8dc6-38c88e3ebb58} - VideoDownloadConverter - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll [2013-12-13 859720]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-04-24 172016]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-04-24 399856]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-04-24 442352]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-02-04 899680]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2013-03-05 1647616]
"RtsFT"=C:\windows\RTFTrack.exe [2013-04-24 6339656]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-08-17 17097200]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-08-17 193008]
"VideoDownloadConverter Home Page Guard 64 bit"=C:\PROGRA~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe [2013-12-13 485448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2013-01-25 131712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"=C:\windows\SysWOW64\rundll32.exe [2012-07-26 48640]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-04-25 642816]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"WeatherBlink EPM Support"=C:\PROGRA~2\WEATHE~2\bar\1.bin\gcmedint.exe [2013-12-12 12872]
"WeatherBlink Browser Plugin Loader 64"=C:\Program Files (x86)\WeatherBlink\bar\1.bin\gcbrmon64.exe [2013-12-12 71752]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"VideoDownloadConverter EPM Support"=C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zmedint.exe [2013-12-13 12872]
"VideoDownloadConverter Search Scope Monitor"=C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe [2013-12-13 55368]
"VideoDownloadConverter_4z Browser Plugin Loader"=C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe [2013-12-13 61512]
"VideoDownloadConverter_4z Browser Plugin Loader 64"=C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe [2013-12-13 71752]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"mobilegeni daemon"=C:\Program Files (x86)\Mobogenie\DaemonProcess.exe []
"mswrmcviSrv"=C:\windows\system32\mswrmcvi.vbe msqmrljg msiknm []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2013-01-25 131712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-04-18 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-01-16 14:19:41 ----D---- C:\rsit
2014-01-16 14:19:41 ----D---- C:\Program Files\trend micro
2014-01-16 13:13:07 ----D---- C:\Program Files (x86)\Creative
2014-01-16 13:13:07 ----A---- C:\windows\SYSWOW64\eax.dll
2014-01-11 01:04:56 ----AS---- C:\windows\SYSWOW64\nircmdc.exe
2014-01-11 00:54:34 ----D---- C:\Program Files (x86)\Anvisoft
2014-01-11 00:45:13 ----RA---- C:\windows\SYSWOW64\MafiaSetup.exe
2014-01-11 00:45:11 ----A---- C:\windows\IsUninst.exe
2014-01-11 00:42:10 ----D---- C:\Program Files\Mafia
2014-01-11 00:41:59 ----RA---- C:\Users\Kuba\AppData\Roaming\MafiaSetup.exe
2014-01-10 19:13:31 ----D---- C:\Users\Kuba\AppData\Roaming\BSplayer Pro
2014-01-10 19:13:31 ----D---- C:\Users\Kuba\AppData\Roaming\BSplayer
2014-01-10 19:13:23 ----D---- C:\Program Files (x86)\Webteh
2014-01-10 19:12:55 ----D---- C:\Users\Kuba\AppData\Roaming\AVG
2014-01-10 19:12:40 ----D---- C:\ProgramData\AVG
2014-01-10 19:12:38 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-01-10 19:11:54 ----D---- C:\Users\Kuba\AppData\Roaming\OpenCandy
2014-01-10 03:13:07 ----D---- C:\Program Files (x86)\VideoPlayerV3
2014-01-09 21:31:52 ----D---- C:\BMW M3 Challenge
2014-01-09 14:32:46 ----D---- C:\Program Files (x86)\XMoto
2014-01-09 03:13:05 ----D---- C:\Program Files (x86)\WebexpEnhancedV1
2014-01-06 21:24:45 ----D---- C:\Users\Kuba\AppData\Roaming\Skype
2014-01-06 21:24:38 ----RD---- C:\Program Files (x86)\Skype
2014-01-06 21:24:34 ----D---- C:\ProgramData\Skype
2014-01-06 21:21:58 ----D---- C:\Program Files (x86)\Counter-Strike 1.6 Non-Steam
2013-12-28 12:42:31 ----D---- C:\Program Files (x86)\MyPC Backup
2013-12-25 22:09:05 ----D---- C:\Program Files (x86)\SecretSauce
2013-12-25 22:08:31 ----D---- C:\Program Files (x86)\TornTV.com
2013-12-25 22:03:09 ----D---- C:\Users\Kuba\AppData\Roaming\deluge
2013-12-25 22:02:22 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-12-25 22:02:22 ----A---- C:\windows\system32\d3d11.dll
2013-12-25 22:02:08 ----A---- C:\windows\SYSWOW64\esent.dll
2013-12-25 22:02:08 ----A---- C:\windows\system32\esent.dll
2013-12-25 22:02:00 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-12-25 22:02:00 ----A---- C:\windows\system32\WMPhoto.dll
2013-12-25 22:01:59 ----A---- C:\windows\system32\twinui.dll
2013-12-25 22:01:58 ----A---- C:\windows\SYSWOW64\twinui.dll
2013-12-25 22:01:57 ----A---- C:\windows\SYSWOW64\authui.dll
2013-12-25 22:01:57 ----A---- C:\windows\system32\authui.dll
2013-12-25 22:00:21 ----D---- C:\Program Files (x86)\Seznam.cz
2013-12-25 21:59:30 ----D---- C:\Users\Kuba\AppData\Roaming\Seznam.cz
2013-12-25 21:59:29 ----D---- C:\Users\Kuba\AppData\Roaming\newnext.me
2013-12-25 21:57:43 ----A---- C:\windows\SYSWOW64\msieftp.dll
2013-12-25 21:57:43 ----A---- C:\windows\system32\msieftp.dll
2013-12-25 19:25:40 ----D---- C:\Program Files (x86)\SysPlayer
2013-12-25 19:23:17 ----D---- C:\ProgramData\ShopperPro
2013-12-25 19:23:14 ----D---- C:\Program Files (x86)\ShopperPro
2013-12-25 19:22:36 ----D---- C:\Program Files\DCE
2013-12-25 19:21:07 ----D---- C:\Users\Kuba\AppData\Roaming\uTorrent
2013-12-25 19:15:32 ----D---- C:\Program Files (x86)\Google
2013-12-25 19:03:35 ----D---- C:\Users\Kuba\AppData\Roaming\TuneUp Software
2013-12-25 19:03:18 ----HD---- C:\$AVG
2013-12-25 19:03:18 ----D---- C:\ProgramData\AVG2014
2013-12-25 19:00:47 ----HD---- C:\ProgramData\Common Files
2013-12-25 19:00:47 ----D---- C:\ProgramData\MFAData
2013-12-25 11:25:03 ----D---- C:\windows\system32\MRT
2013-12-25 11:25:02 ----A---- C:\windows\system32\MRT.exe
2013-12-25 10:46:37 ----A---- C:\windows\SYSWOW64\rp.dll
2013-12-25 10:17:21 ----D---- C:\Users\Kuba\AppData\Roaming\GoobZo
2013-12-25 10:13:55 ----D---- C:\Users\Kuba\AppData\Roaming\2K Sports
2013-12-25 09:32:39 ----A---- C:\windows\SYSWOW64\xactengine2_5.dll
2013-12-25 09:32:39 ----A---- C:\windows\system32\xactengine2_5.dll
2013-12-25 09:32:38 ----A---- C:\windows\SYSWOW64\d3dx10.dll
2013-12-25 09:32:38 ----A---- C:\windows\system32\d3dx10.dll
2013-12-25 09:32:36 ----A---- C:\windows\SYSWOW64\d3dx9_32.dll
2013-12-25 09:32:36 ----A---- C:\windows\system32\d3dx9_32.dll
2013-12-25 09:32:31 ----A---- C:\windows\SYSWOW64\xactengine2_4.dll
2013-12-25 09:32:31 ----A---- C:\windows\SYSWOW64\x3daudio1_1.dll
2013-12-25 09:32:31 ----A---- C:\windows\system32\xactengine2_4.dll
2013-12-25 09:32:31 ----A---- C:\windows\system32\x3daudio1_1.dll
2013-12-25 09:32:30 ----A---- C:\windows\SYSWOW64\xinput1_3.dll
2013-12-25 09:32:30 ----A---- C:\windows\system32\xinput1_3.dll
2013-12-25 09:32:29 ----A---- C:\windows\SYSWOW64\d3dx9_31.dll
2013-12-25 09:32:29 ----A---- C:\windows\system32\d3dx9_31.dll
2013-12-25 09:32:28 ----A---- C:\windows\SYSWOW64\xinput1_2.dll
2013-12-25 09:32:28 ----A---- C:\windows\SYSWOW64\xactengine2_3.dll
2013-12-25 09:32:28 ----A---- C:\windows\system32\xinput1_2.dll
2013-12-25 09:32:28 ----A---- C:\windows\system32\xactengine2_3.dll
2013-12-25 09:32:26 ----A---- C:\windows\SYSWOW64\xactengine2_2.dll
2013-12-25 09:32:26 ----A---- C:\windows\system32\xactengine2_2.dll
2013-12-25 09:32:24 ----A---- C:\windows\SYSWOW64\xinput1_1.dll
2013-12-25 09:32:24 ----A---- C:\windows\system32\xinput1_1.dll
2013-12-25 09:32:22 ----A---- C:\windows\SYSWOW64\xactengine2_1.dll
2013-12-25 09:32:22 ----A---- C:\windows\system32\xactengine2_1.dll
2013-12-25 09:31:57 ----A---- C:\windows\SYSWOW64\d3dx9_30.dll
2013-12-25 09:31:57 ----A---- C:\windows\system32\d3dx9_30.dll
2013-12-25 09:31:56 ----A---- C:\windows\SYSWOW64\xactengine2_0.dll
2013-12-25 09:31:56 ----A---- C:\windows\SYSWOW64\x3daudio1_0.dll
2013-12-25 09:31:56 ----A---- C:\windows\system32\xactengine2_0.dll
2013-12-25 09:31:56 ----A---- C:\windows\system32\x3daudio1_0.dll
2013-12-25 09:31:54 ----A---- C:\windows\SYSWOW64\d3dx9_29.dll
2013-12-25 09:31:54 ----A---- C:\windows\system32\d3dx9_29.dll
2013-12-25 09:31:52 ----A---- C:\windows\SYSWOW64\d3dx9_28.dll
2013-12-25 09:31:52 ----A---- C:\windows\system32\d3dx9_28.dll
2013-12-25 09:31:50 ----A---- C:\windows\SYSWOW64\d3dx9_27.dll
2013-12-25 09:31:50 ----A---- C:\windows\system32\d3dx9_27.dll
2013-12-25 09:31:49 ----A---- C:\windows\SYSWOW64\d3dx9_26.dll
2013-12-25 09:31:49 ----A---- C:\windows\SYSWOW64\d3dx9_25.dll
2013-12-25 09:31:49 ----A---- C:\windows\system32\d3dx9_26.dll
2013-12-25 09:31:49 ----A---- C:\windows\system32\d3dx9_25.dll
2013-12-25 09:31:47 ----A---- C:\windows\SYSWOW64\d3dx9_24.dll
2013-12-25 09:31:47 ----A---- C:\windows\system32\d3dx9_24.dll
2013-12-24 22:38:48 ----A---- C:\windows\system32\dwmcore.dll
2013-12-24 22:38:47 ----A---- C:\windows\SYSWOW64\explorer.exe
2013-12-24 22:38:47 ----A---- C:\windows\SYSWOW64\dwmcore.dll
2013-12-24 22:38:47 ----A---- C:\windows\system32\ntoskrnl.exe
2013-12-24 22:38:47 ----A---- C:\windows\explorer.exe
2013-12-24 22:38:43 ----A---- C:\windows\system32\samsrv.dll
2013-12-24 22:38:42 ----A---- C:\windows\SYSWOW64\mfcore.dll
2013-12-24 22:38:42 ----A---- C:\windows\system32\mfcore.dll
2013-12-24 22:38:42 ----A---- C:\windows\system32\drivers\volsnap.sys
2013-12-24 22:38:41 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-12-24 22:38:41 ----A---- C:\windows\system32\winload.exe
2013-12-24 22:38:40 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-12-24 22:38:40 ----A---- C:\windows\SYSWOW64\mscms.dll
2013-12-24 22:38:40 ----A---- C:\windows\system32\winresume.exe
2013-12-24 22:38:40 ----A---- C:\windows\system32\vds.exe
2013-12-24 22:38:40 ----A---- C:\windows\system32\mscms.dll
2013-12-24 22:38:40 ----A---- C:\windows\system32\mfasfsrcsnk.dll
2013-12-24 22:38:40 ----A---- C:\windows\system32\audiosrv.dll
2013-12-24 22:38:39 ----A---- C:\windows\system32\samlib.dll
2013-12-24 22:38:38 ----A---- C:\windows\SYSWOW64\mfasfsrcsnk.dll
2013-12-24 22:38:38 ----A---- C:\windows\system32\MbaeParserTask.exe
2013-12-24 22:38:38 ----A---- C:\windows\system32\DeviceSetupManager.dll
2013-12-24 22:38:37 ----A---- C:\windows\SYSWOW64\samlib.dll
2013-12-24 22:38:37 ----A---- C:\windows\system32\vdsutil.dll
2013-12-24 22:38:36 ----A---- C:\windows\system32\drivers\BthAvrcpTg.sys
2013-12-24 22:38:30 ----A---- C:\windows\system32\drivers\ndis.sys
2013-12-24 22:34:38 ----A---- C:\windows\system32\shell32.dll
2013-12-24 22:34:35 ----A---- C:\windows\SYSWOW64\shell32.dll
2013-12-24 22:34:33 ----A---- C:\windows\SYSWOW64\msctf.dll
2013-12-24 22:34:33 ----A---- C:\windows\system32\msctf.dll
2013-12-24 22:34:31 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-12-24 22:34:27 ----A---- C:\windows\SYSWOW64\shdocvw.dll
2013-12-24 22:34:27 ----A---- C:\windows\SYSWOW64\SettingSync.dll
2013-12-24 22:34:27 ----A---- C:\windows\SYSWOW64\mbsmsapi.dll
2013-12-24 22:34:27 ----A---- C:\windows\system32\shdocvw.dll
2013-12-24 22:34:27 ----A---- C:\windows\system32\SettingSync.dll
2013-12-24 22:34:27 ----A---- C:\windows\system32\mbsmsapi.dll
2013-12-24 22:34:26 ----A---- C:\windows\system32\SettingSyncInfo.dll
2013-12-24 22:33:54 ----A---- C:\windows\SYSWOW64\wdc.dll
2013-12-24 22:33:54 ----A---- C:\windows\system32\wvc.dll
2013-12-24 22:33:54 ----A---- C:\windows\system32\wdc.dll
2013-12-24 22:33:53 ----A---- C:\windows\SYSWOW64\wvc.dll
2013-12-24 22:29:33 ----A---- C:\windows\system32\drivers\dtsoftbus01.sys
2013-12-24 22:29:30 ----D---- C:\Users\Kuba\AppData\Roaming\DAEMON Tools Lite
2013-12-24 22:29:26 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-12-24 22:28:32 ----D---- C:\ProgramData\DAEMON Tools Lite
2013-12-24 22:21:22 ----D---- C:\Program Files\Hry

======List of files/folders modified in the last 1 month======

2014-01-16 14:20:35 ----D---- C:\Users\Kuba\AppData\Roaming\ClassicShell
2014-01-16 14:19:49 ----D---- C:\windows\Prefetch
2014-01-16 14:19:41 ----RD---- C:\Program Files
2014-01-16 13:13:13 ----AD---- C:\Windows
2014-01-16 13:13:07 ----RD---- C:\Program Files (x86)
2014-01-16 13:13:07 ----D---- C:\windows\SysWOW64
2014-01-16 13:04:20 ----D---- C:\windows\system32\sru
2014-01-15 23:10:06 ----D---- C:\windows\Temp
2014-01-15 22:43:10 ----D---- C:\windows\system32\config
2014-01-15 20:50:21 ----D---- C:\windows\CbsTemp
2014-01-15 20:50:19 ----D---- C:\windows\WinSxS
2014-01-15 19:42:44 ----SHD---- C:\System Volume Information
2014-01-15 11:16:14 ----D---- C:\Users\Kuba\AppData\Roaming\vlc
2014-01-15 11:13:01 ----AD---- C:\windows\System32
2014-01-15 11:13:01 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-01-15 11:13:00 ----D---- C:\windows\Inf
2014-01-15 08:53:12 ----D---- C:\windows\system32\NDF
2014-01-15 07:50:36 ----D---- C:\windows\Microsoft.NET
2014-01-15 07:45:02 ----D---- C:\windows\system32\Tasks
2014-01-15 07:42:01 ----A---- C:\windows\SYSWOW64\log.txt
2014-01-11 01:10:21 ----D---- C:\windows\Tasks
2014-01-11 01:08:51 ----SHD---- C:\windows\Installer
2014-01-11 01:07:53 ----D---- C:\windows\system32\DriverStore
2014-01-11 01:07:53 ----D---- C:\windows\system32\Drivers
2014-01-11 00:47:04 ----HD---- C:\ProgramData
2014-01-09 09:02:07 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-01-09 03:13:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-01-08 22:12:02 ----D---- C:\windows\system32\drivers\UMDF
2014-01-06 21:24:40 ----D---- C:\Program Files (x86)\Common Files
2014-01-06 12:22:42 ----SD---- C:\Users\Kuba\AppData\Roaming\Microsoft
2014-01-06 05:30:08 ----D---- C:\windows\system32\catroot2
2014-01-04 23:51:58 ----AD---- C:\Users
2014-01-02 09:51:46 ----D---- C:\windows\system32\wdi
2014-01-01 21:09:06 ----D---- C:\windows\Logs
2013-12-29 21:02:17 ----D---- C:\ProgramData\Stardock
2013-12-28 23:45:45 ----RSD---- C:\windows\assembly
2013-12-27 16:42:22 ----D---- C:\windows\rescache
2013-12-27 10:07:08 ----D---- C:\windows\system32\catroot
2013-12-27 10:06:22 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-12-27 10:06:22 ----D---- C:\windows\system32\cs-CZ
2013-12-27 10:06:22 ----D---- C:\windows\system32\Boot
2013-12-27 10:06:22 ----D---- C:\Program Files\Common Files\microsoft shared
2013-12-27 10:06:16 ----D---- C:\windows\apppatch
2013-12-27 10:06:15 ----D---- C:\windows\SYSWOW64\en-US
2013-12-27 10:06:15 ----D---- C:\windows\system32\en-US
2013-12-27 10:06:14 ----RD---- C:\windows\ToastData
2013-12-27 10:06:14 ----D---- C:\windows\system32\SecureBootUpdates
2013-12-25 19:25:49 ----D---- C:\Program Files\Common Files\System
2013-12-25 19:08:15 ----HD---- C:\windows\ELAMBKUP
2013-12-25 11:19:42 ----AD---- C:\windows\system32\oobe
2013-12-25 09:32:42 ----SHD---- C:\$Recycle.Bin

Re: Fakepolice

Napsal: 16 led 2014 14:36
od karelfritz
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ACPI;@acpi.inf,%ACPI.SvcDesc%;Microsoft ACPI Driver; C:\windows\System32\drivers\ACPI.sys [2012-09-20 425192]
R0 acpiex;Microsoft ACPIEx Driver; C:\windows\System32\Drivers\acpiex.sys [2012-07-26 77040]
R0 amdkmpfd;@oem7.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\windows\System32\drivers\amdkmpfd.sys [2012-09-13 36520]
R0 CLFS;@%SystemRoot%\system32\drivers\clfs.sys,-100; C:\windows\System32\drivers\CLFS.sys [2012-07-26 361200]
R0 CNG;CNG; C:\windows\System32\Drivers\cng.sys [2012-10-11 562392]
R0 disk;@disk.inf,%disk_ServiceDesc%;Disk Driver; C:\windows\System32\drivers\disk.sys [2012-07-26 102640]
R0 FileInfo;@%SystemRoot%\system32\drivers\fileinfo.sys,-100; C:\windows\System32\drivers\fileinfo.sys [2012-07-26 71920]
R0 FltMgr;@%SystemRoot%\system32\drivers\fltmgr.sys,-10001; C:\windows\system32\drivers\fltmgr.sys [2012-07-26 374512]
R0 fvevol;@%SystemRoot%\system32\drivers\fvevol.sys,-100; C:\windows\System32\DRIVERS\fvevol.sys [2013-08-21 465240]
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2013-01-31 652784]
R0 KSecDD;KSecDD; C:\windows\System32\Drivers\ksecdd.sys [2012-09-20 100072]
R0 KSecPkg;KSecPkg; C:\windows\System32\Drivers\ksecpkg.sys [2012-10-11 172264]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2013-08-17 39008]
R0 mountmgr;@%SystemRoot%\system32\drivers\mountmgr.sys,-100; C:\windows\System32\drivers\mountmgr.sys [2012-07-26 93936]
R0 msisadrv;msisadrv; C:\windows\System32\drivers\msisadrv.sys [2012-07-26 17136]
R0 Mup;@%systemroot%\system32\drivers\mup.sys,-101; C:\windows\System32\Drivers\mup.sys [2012-07-26 83696]
R0 NDIS;@%SystemRoot%\system32\drivers\ndis.sys,-200; C:\windows\system32\drivers\ndis.sys [2013-06-16 997632]
R0 partmgr;@%SystemRoot%\system32\drivers\partmgr.sys,-100; C:\windows\System32\drivers\partmgr.sys [2013-01-10 91880]
R0 pci;@machine.inf,%pci_svcdesc%;PCI Bus Driver; C:\windows\System32\drivers\pci.sys [2012-07-26 234224]
R0 pcw;Performance Counters for Windows Driver; C:\windows\System32\drivers\pcw.sys [2012-07-26 52464]
R0 pdc;@%SystemRoot%\system32\drivers\pdc.sys,-100; C:\windows\system32\drivers\pdc.sys [2013-08-17 69864]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2012-07-26 217328]
R0 spaceport;@spaceport.inf,%Spaceport_ServiceDesc%;Storage Spaces Driver; C:\windows\System32\drivers\spaceport.sys [2013-10-05 285016]
R0 Tcpip;@%SystemRoot%\system32\tcpipcfg.dll,-50003; C:\windows\System32\drivers\tcpip.sys [2013-08-01 2233688]
R0 vdrvroot;@vdrvroot.inf,%vdrvroot_svcdesc%;Microsoft Virtual Drive Enumerator; C:\windows\System32\drivers\vdrvroot.sys [2012-07-26 36080]
R0 volmgr;@volmgr.inf,%volmgr_svcdesc%;Volume Manager Driver; C:\windows\System32\drivers\volmgr.sys [2012-07-26 83184]
R0 volmgrx;@%SystemRoot%\system32\drivers\volmgrx.sys,-100; C:\windows\System32\drivers\volmgrx.sys [2012-07-26 378608]
R0 volsnap;@volume.inf,%VolumeClassName%;Storage volumes; C:\windows\System32\drivers\volsnap.sys [2013-06-01 327936]
R0 Wdf01000;@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000; C:\windows\system32\drivers\Wdf01000.sys [2013-06-22 785624]
R0 WdFilter;@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-330; C:\windows\system32\drivers\WdFilter.sys [2013-07-01 247216]
R0 WFPLWFS;@%SystemRoot%\System32\drivers\wfplwfs.sys,-6000; C:\windows\system32\DRIVERS\wfplwfs.sys [2013-10-10 96600]
R1 AFD;@%systemroot%\system32\drivers\afd.sys,-1000; C:\windows\system32\drivers\afd.sys [2013-09-04 576512]
R1 BasicDisplay;BasicDisplay; C:\windows\System32\drivers\BasicDisplay.sys [2012-07-26 48640]
R1 BasicRender;BasicRender; C:\windows\System32\drivers\BasicRender.sys [2012-07-26 29696]
R1 Beep;Beep; C:\windows\system32\drivers\Beep.sys [2012-07-26 7680]
R1 cdrom;@cdrom.inf,%cdrom_ServiceDesc%;CD-ROM Driver; C:\windows\System32\drivers\cdrom.sys [2012-07-26 174080]
R1 Dfsc;@%systemroot%\system32\wkssvc.dll,-1008; C:\windows\System32\Drivers\dfsc.sys [2012-07-26 118784]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\windows\System32\drivers\discache.sys [2012-07-26 50688]
R1 dtsoftbus01;@oem65.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\windows\System32\drivers\dtsoftbus01.sys [2013-12-24 283064]
R1 Msfs;Msfs; C:\windows\system32\drivers\Msfs.sys [2012-07-26 26112]
R1 mssmbios;@mssmbios.inf,%mssmbios_svcdesc%;Microsoft System Management BIOS Driver; C:\windows\System32\drivers\mssmbios.sys [2012-07-26 37616]
R1 NetBIOS;@netnb.inf,%NetBIOS_Desc%;NetBIOS Interface; C:\windows\system32\DRIVERS\netbios.sys [2012-07-26 46080]
R1 NetBT;@%SystemRoot%\system32\drivers\netbt.sys,-2; C:\windows\System32\DRIVERS\netbt.sys [2012-07-26 331776]
R1 Npfs;Npfs; C:\windows\system32\drivers\Npfs.sys [2012-07-26 49152]
R1 npsvctrig;@npsvctrig.inf,%NPSVCTRIG.SvcDisplayName%;Named pipe service trigger provider; C:\windows\System32\drivers\npsvctrig.sys [2012-07-26 23552]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\windows\system32\drivers\nsiproxy.sys [2012-07-26 34304]
R1 Null;Null; C:\windows\system32\drivers\Null.sys [2012-07-26 5632]
R1 Psched;@%SystemRoot%\System32\drivers\pacer.sys,-101; C:\windows\system32\DRIVERS\pacer.sys [2012-07-26 145408]
R1 rdbss;@%systemroot%\system32\wkssvc.dll,-1000; C:\windows\system32\DRIVERS\rdbss.sys [2013-08-17 427520]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\windows\system32\DRIVERS\tdx.sys [2012-07-26 117248]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2012-07-26 64000]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\windows\system32\DRIVERS\wanarp.sys [2013-04-09 83456]
R2 lltdio;@%SystemRoot%\system32\lltdres.dll,-6; C:\windows\system32\DRIVERS\lltdio.sys [2012-07-26 60416]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\windows\system32\drivers\luafv.sys [2012-07-26 134144]
R2 NativeWifiP;@%SystemRoot%\System32\drivers\nwifi.sys,-101; C:\windows\system32\DRIVERS\nwifi.sys [2012-07-26 427520]
R2 Ndu;@%SystemRoot%\system32\drivers\Ndu.sys,-10001; C:\windows\system32\drivers\Ndu.sys [2012-07-26 97792]
R2 PEAUTH;PEAUTH; C:\windows\system32\drivers\peauth.sys [2013-04-09 805376]
R2 rspndr;@%SystemRoot%\system32\lltdres.dll,-5; C:\windows\system32\DRIVERS\rspndr.sys [2012-07-26 78848]
R2 secdrv;Security Driver; C:\windows\system32\drivers\secdrv.sys [2012-07-26 23040]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\windows\System32\drivers\tcpipreg.sys [2012-07-26 45056]
R3 ACPIVPC;@oem58.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\windows\System32\drivers\AcpiVpc.sys [2013-08-17 33560]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-04-25 11614208]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-04-25 578048]
R3 AthBTPort;@oem55.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2013-01-25 89168]
R3 athr;@oem12.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athw8x.sys [2013-03-25 3776000]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\windows\system32\DRIVERS\bowser.sys [2012-07-26 101888]
R3 BTATH_A2DP;@oem54.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2013-01-25 346192]
R3 btath_avdt;@oem54.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\windows\system32\drivers\btath_avdt.sys [2013-01-25 115280]
R3 BTATH_BUS;@oem51.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\windows\System32\drivers\btath_bus.sys [2013-01-25 34384]
R3 BTATH_HCRP;@oem57.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\windows\System32\drivers\btath_hcrp.sys [2013-01-25 179432]
R3 BTATH_LWFLT;@oem59.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2013-01-25 77464]
R3 BTATH_RCP;@oem61.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\windows\System32\drivers\btath_rcp.sys [2013-01-25 136424]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2013-01-25 581200]
R3 BthEnum;@tdibth.inf,%BthEnum.DisplayName%;Bluetooth Enumerator Service; C:\windows\System32\drivers\BthEnum.sys [2013-01-09 51712]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\windows\system32\DRIVERS\BthLEEnum.sys [2012-07-26 202752]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2012-07-26 119808]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2013-01-09 74752]
R3 CmBatt;@cmbatt.inf,%CmBatt.SvcDesc%;Microsoft ACPI Control Method Battery Driver; C:\windows\System32\drivers\CmBatt.sys [2012-07-26 25600]
R3 CnxtHdAudService;@oem11.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT64.sys [2013-03-05 1680992]
R3 CompositeBus;@CompositeBus.inf,%CompositeBus.SVCDESC%;Composite Bus Enumerator Driver; C:\windows\System32\drivers\CompositeBus.sys [2012-07-26 36352]
R3 condrv;Console Driver; C:\windows\System32\drivers\condrv.sys [2012-07-26 33792]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\windows\System32\drivers\dxgkrnl.sys [2013-09-19 1455448]
R3 ETD;@oem56.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\windows\system32\DRIVERS\ETD.sys [2013-02-27 355664]
R3 fastfat;FAT12/16/32 File System Driver; C:\windows\system32\drivers\fastfat.sys [2012-07-26 210672]
R3 HDAudBus;@hdaudbus.inf,%HDAudBus.SVCDESC%;Microsoft UAA Bus Driver for High Definition Audio; C:\windows\System32\drivers\HDAudBus.sys [2012-09-20 71168]
R3 HTTP;@%SystemRoot%\system32\drivers\http.sys,-1; C:\windows\system32\drivers\HTTP.sys [2013-08-17 861184]
R3 i8042prt;@msmouse.inf,%i8042prt.SvcDesc%;PS/2 Keyboard and Mouse Port Driver; C:\windows\System32\drivers\i8042prt.sys [2012-07-26 112640]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-04-18 5358784]
R3 IntcDAud;@oem6.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2013-04-22 342528]
R3 intelppm;@cpu.inf,%IntelPPM.SvcDesc%;Intel Processor Driver; C:\windows\System32\drivers\intelppm.sys [2012-11-06 89088]
R3 kbdclass;@keyboard.inf,%kbdclass.SvcDesc%;Keyboard Class Driver; C:\windows\System32\drivers\kbdclass.sys [2012-07-26 48368]
R3 kdnic;@kdnic.inf,%KdNic.Service.DispName%;Microsoft Kernel Debug Network Miniport (NDIS 6.20); C:\windows\system32\DRIVERS\kdnic.sys [2012-07-26 18432]
R3 ksthunk;Kernel Streaming Thunks; C:\windows\system32\drivers\ksthunk.sys [2012-07-26 21376]
R3 L1C;@oem9.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C63x64.sys [2013-04-03 129224]
R3 MEIx64;@oem3.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 monitor;@monitor.inf,%Monitor.SVCDESC%;Microsoft Monitor Class Function Driver Service; C:\windows\System32\drivers\monitor.sys [2013-03-01 30720]
R3 mouclass;@msmouse.inf,%mouclass.SvcDesc%;Mouse Class Driver; C:\windows\System32\drivers\mouclass.sys [2012-07-26 45808]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\windows\System32\drivers\mpsdrv.sys [2012-10-11 74752]
R3 mrxsmb;@%systemroot%\system32\wkssvc.dll,-1002; C:\windows\system32\DRIVERS\mrxsmb.sys [2013-08-17 370688]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\windows\system32\DRIVERS\mrxsmb10.sys [2012-07-26 279552]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\windows\system32\DRIVERS\mrxsmb20.sys [2013-08-17 215552]
R3 mshidumdf;@%SystemRoot%\system32\drivers\mshidumdf.sys,-100; C:\windows\System32\drivers\mshidumdf.sys [2012-07-26 10752]
R3 NdisTapi;@%systemroot%\system32\rascfg.dll,-32001; C:\windows\system32\DRIVERS\ndistapi.sys [2012-09-20 25088]
R3 Ndisuio;@ndisuio.inf,%NDISUIO_Desc%;NDIS Usermode I/O Protocol; C:\windows\system32\DRIVERS\ndisuio.sys [2012-07-26 58880]
R3 NdisWan;@%systemroot%\system32\rascfg.dll,-32002; C:\windows\system32\DRIVERS\ndiswan.sys [2012-07-26 174080]
R3 NDProxy;NDIS Proxy; C:\windows\system32\drivers\NDProxy.sys [2013-04-09 60416]
R3 Ntfs;Ntfs; C:\windows\system32\drivers\Ntfs.sys [2013-02-02 1933544]
R3 PptpMiniport;@%systemroot%\system32\rascfg.dll,-32006; C:\windows\system32\DRIVERS\raspptp.sys [2012-07-26 114176]
R3 RasAgileVpn;@netavpna.inf,%Svc-Mp-AgileVpn-DispName%;WAN Miniport (IKEv2); C:\windows\system32\DRIVERS\AgileVpn.sys [2012-07-26 68608]
R3 Rasl2tp;@%systemroot%\system32\rascfg.dll,-32005; C:\windows\system32\DRIVERS\rasl2tp.sys [2012-07-26 124928]
R3 RasPppoe;@%systemroot%\system32\rascfg.dll,-32007; C:\windows\system32\DRIVERS\raspppoe.sys [2012-07-26 81920]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\windows\system32\DRIVERS\rassstp.sys [2012-07-26 92672]
R3 rdpbus;@rdpbus.inf,%rdpbus_svcdesc%;Remote Desktop Device Redirector Bus Driver; C:\windows\System32\drivers\rdpbus.sys [2012-07-26 22528]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-10-12 27880]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\System32\drivers\rfcomm.sys [2013-03-01 156672]
R3 rtsuvc;@oem43.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\windows\system32\DRIVERS\rtsuvc.sys [2013-04-24 8243144]
R3 srv;@%systemroot%\system32\srvsvc.dll,-102; C:\windows\System32\DRIVERS\srv.sys [2012-07-26 416768]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\windows\System32\DRIVERS\srv2.sys [2013-04-09 623104]
R3 srvnet;srvnet; C:\windows\System32\DRIVERS\srvnet.sys [2013-04-09 247808]
R3 swenum;@swenum.inf,%SWENUM.SVCDESC%;Software Bus Driver; C:\windows\System32\drivers\swenum.sys [2012-07-26 13680]
R3 TPM;@tpm.inf,%TPM%;TPM; C:\windows\system32\drivers\tpm.sys [2013-08-10 151896]
R3 tunnel;@nettun.inf,%TUNNEL.Service.DisplayName%;Microsoft Tunnel Miniport Adapter Driver; C:\windows\system32\DRIVERS\tunnel.sys [2012-07-26 149504]
R3 UCX01000;USB Controller Extension; C:\windows\System32\drivers\ucx01000.sys [2013-07-02 213336]
R3 umbus;@umbus.inf,%umbus.SVCDESC%;UMBus Enumerator Driver; C:\windows\System32\drivers\umbus.sys [2012-07-26 48128]
R3 usbccgp;@usb.inf,%GenericParent.SvcDesc%;Microsoft USB Generic Parent Driver; C:\windows\System32\drivers\usbccgp.sys [2013-06-29 120832]
R3 usbehci;@usbport.inf,%EHCIMP.SvcDesc%;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\windows\System32\drivers\usbehci.sys [2013-07-01 79192]
R3 usbhub;@usbport.inf,%ROOTHUB.SvcDesc%;Ovladač standardního rozbočovače USB; C:\windows\System32\drivers\usbhub.sys [2013-07-01 623448]
R3 USBHUB3;@usbhub3.inf,%UsbHub3.SVCDESC%;SuperSpeed Hub; C:\windows\System32\drivers\UsbHub3.sys [2013-10-02 447320]
R3 USBXHCI;@usbxhci.inf,%PCI\CC_0C0330.DeviceDesc%;USB xHCI Compliant Host Controller; C:\windows\System32\drivers\USBXHCI.SYS [2013-07-02 337752]
R3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\windows\System32\drivers\vwifibus.sys [2012-07-26 24064]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2012-07-26 17920]
R4 cdfs;CD/DVD File System Reader; C:\windows\system32\DRIVERS\cdfs.sys [2012-07-26 108544]
S0 3ware;3ware; C:\windows\System32\drivers\3ware.sys [2012-07-26 106736]
S0 adp94xx;adp94xx; C:\windows\System32\drivers\adp94xx.sys [2012-07-26 492272]
S0 adpahci;adpahci; C:\windows\System32\drivers\adpahci.sys [2012-07-26 340720]
S0 adpu320;adpu320; C:\windows\System32\drivers\adpu320.sys [2012-07-26 184048]
S0 agp440;@machine.inf,%agp440_svcdesc%;Intel AGP Bus Filter; C:\windows\System32\drivers\agp440.sys [2012-07-26 63216]
S0 amdsata;amdsata; C:\windows\System32\drivers\amdsata.sys [2012-07-26 76016]
S0 amdsbs;amdsbs; C:\windows\System32\drivers\amdsbs.sys [2012-07-26 258288]
S0 amdxata;amdxata; C:\windows\System32\drivers\amdxata.sys [2012-07-26 26352]
S0 arc;arc; C:\windows\System32\drivers\arc.sys [2012-07-26 104688]
S0 arcsas;@arcsas.inf,%arcsas_ServiceName%;Adaptec SAS/SATA-II RAID Windows Inbox Miniport Driver; C:\windows\System32\drivers\arcsas.sys [2012-07-26 108272]
S0 atapi;@mshdc.inf,%idechannel.DeviceDesc%;IDE Channel; C:\windows\System32\drivers\atapi.sys [2012-07-26 25840]
S0 b06bdrv;@netbvbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II VBD; C:\windows\System32\drivers\bxvbda.sys [2012-09-20 533224]
S0 ebdrv;@netevbda.inf,%vbd_srv_desc%;Broadcom NetXtreme II 10 GigE VBD; C:\windows\System32\drivers\evbda.sys [2012-09-20 3265256]
S0 EhStorClass;@%SystemRoot%\system32\drivers\EhStorClass.sys,-100; C:\windows\System32\drivers\EhStorClass.sys [2012-07-26 81136]
S0 EhStorTcgDrv;@ehstortcgdrv.inf,%EhStorTcgDrv.Desc%;Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols; C:\windows\System32\drivers\EhStorTcgDrv.sys [2012-07-26 113904]
S0 gagp30kx;@machine.inf,%gagp30kx_svcdesc%;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\windows\System32\drivers\gagp30kx.sys [2012-07-26 66800]
S0 HpSAMD;HpSAMD; C:\windows\System32\drivers\HpSAMD.sys [2012-07-26 64752]
S0 hwpolicy;@%systemroot%\system32\drivers\hwpolicy.sys,-101; C:\windows\System32\drivers\hwpolicy.sys [2012-07-26 24816]
S0 iaStorV;@iastorv.inf,%*PNP0600.DeviceDesc%;Intel RAID Controller Windows 7; C:\windows\System32\drivers\iaStorV.sys [2012-07-26 411888]
S0 iirsp;iirsp; C:\windows\System32\drivers\iirsp.sys [2012-07-26 45296]
S0 intelide;intelide; C:\windows\System32\drivers\intelide.sys [2012-07-26 18672]
S0 isapnp;isapnp; C:\windows\System32\drivers\isapnp.sys [2012-07-26 22256]
S0 LSI_SAS;LSI_SAS; C:\windows\System32\drivers\lsi_sas.sys [2012-07-26 108784]
S0 LSI_SAS2;LSI_SAS2; C:\windows\System32\drivers\lsi_sas2.sys [2012-07-26 92400]
S0 LSI_SCSI;LSI_SCSI; C:\windows\System32\drivers\lsi_scsi.sys [2012-07-26 116976]
S0 LSI_SSS;LSI_SSS; C:\windows\System32\drivers\lsi_sss.sys [2012-07-26 81136]
S0 megasas;megasas; C:\windows\System32\drivers\megasas.sys [2012-07-26 51952]
S0 MegaSR;MegaSR; C:\windows\System32\drivers\MegaSR.sys [2012-07-26 353008]
S0 mvumis;mvumis; C:\windows\System32\drivers\mvumis.sys [2012-07-26 64240]
S0 nfrd960;nfrd960; C:\windows\System32\drivers\nfrd960.sys [2012-07-26 52464]
S0 nv_agp;@machine.inf,%agpnvidia_svcdesc%;NVIDIA nForce AGP Bus Filter; C:\windows\System32\drivers\nv_agp.sys [2012-07-26 125168]
S0 nvraid;nvraid; C:\windows\System32\drivers\nvraid.sys [2012-07-26 150256]
S0 nvstor;nvstor; C:\windows\System32\drivers\nvstor.sys [2012-07-26 168176]
S0 pciide;pciide; C:\windows\System32\drivers\pciide.sys [2012-07-26 14064]
S0 pcmcia;pcmcia; C:\windows\System32\drivers\pcmcia.sys [2012-07-26 237808]
S0 sbp2port;@sbp2.inf,%sbp2_ServiceDesc%;SBP-2 Transport/Protocol Bus Driver; C:\windows\System32\drivers\sbp2port.sys [2012-07-26 107760]
S0 SiSRaid2;SiSRaid2; C:\windows\System32\drivers\SiSRaid2.sys [2012-07-26 44784]
S0 SiSRaid4;SiSRaid4; C:\windows\System32\drivers\sisraid4.sys [2012-07-26 81648]
S0 stexstor;stexstor; C:\windows\System32\drivers\stexstor.sys [2012-07-26 30960]
S0 storahci;@mshdc.inf,%storahci_ServiceDescription%;Microsoft Standard SATA AHCI Driver; C:\windows\System32\drivers\storahci.sys [2013-03-02 77544]
S0 storflt;@%SystemRoot%\system32\vmstorfltres.dll,-1000; C:\windows\system32\DRIVERS\vmstorfl.sys [2012-07-26 45160]
S0 storvsc;storvsc; C:\windows\System32\drivers\storvsc.sys [2012-07-26 37992]
S0 uagp35;@machine.inf,%uagp35_svcdesc%;Microsoft AGPv3.5 Filter; C:\windows\System32\drivers\uagp35.sys [2012-07-26 65776]
S0 uliagpkx;@machine.inf,%uliagpkx_svcdesc%;Uli AGP Bus Filter; C:\windows\System32\drivers\uliagpkx.sys [2012-07-26 66800]
S0 viaide;viaide; C:\windows\System32\drivers\viaide.sys [2012-07-26 19184]
S0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\System32\drivers\vmbus.sys [2012-07-26 137832]
S0 vsmraid;vsmraid; C:\windows\System32\drivers\vsmraid.sys [2012-07-26 164080]
S0 VSTXRAID;@vstxraid.inf,%Driver.DeviceDesc%;VIA StorX Storage Controller Windows Driver; C:\windows\System32\drivers\vstxraid.sys [2012-07-26 322800]
S0 Wd;@wd.inf,%WdServiceDisplayName%;Microsoft Watchdog Timer Driver; C:\windows\System32\drivers\wd.sys [2012-07-26 23792]
S0 WdBoot;@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-390; C:\windows\system32\drivers\WdBoot.sys [2013-07-02 36288]
S1 dam;@%SystemRoot%\system32\drivers\dam.sys,-100; C:\windows\system32\drivers\dam.sys [2013-08-16 58200]
S3 1394ohci;@1394.inf,%PCI\CC_0C0010.DeviceDesc%;1394 OHCI Compliant Host Controller; C:\windows\System32\drivers\1394ohci.sys [2012-07-26 226304]
S3 acpipagr;@acpipagr.inf,%SvcDesc%;ACPI Processor Aggregator Driver; C:\windows\System32\drivers\acpipagr.sys [2012-07-26 10240]
S3 AcpiPmi;@acpipmi.inf,%AcpiPmi.SvcDesc%;ACPI Power Meter Driver; C:\windows\System32\drivers\acpipmi.sys [2012-07-26 12288]
S3 acpitime;@acpitime.inf,%AcpiTime.SvcDesc%;ACPI Wake Alarm Driver; C:\windows\System32\drivers\acpitime.sys [2012-07-26 10752]
S3 AmdK8;@cpu.inf,%AmdK8.SvcDesc%;AMD K8 Processor Driver; C:\windows\System32\drivers\amdk8.sys [2012-11-06 90624]
S3 AmdPPM;@cpu.inf,%AmdPPM.SvcDesc%;AMD Processor Driver; C:\windows\System32\drivers\amdppm.sys [2012-11-06 88064]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\windows\system32\drivers\appid.sys [2012-07-26 79360]
S3 AsyncMac;@%systemroot%\system32\rascfg.dll,-32000; C:\windows\system32\DRIVERS\asyncmac.sys [2012-07-26 26624]
S3 BthAvrcpTg;@bthaudhid.inf,%BthAvrcpTg_SvcDesc%;Bluetooth Audio/Video Remote Control HID; C:\windows\System32\drivers\BthAvrcpTg.sys [2013-06-01 37632]
S3 BthHFEnum;@bthhfenum.inf,%BthHFEnum.SVCDESC%;Bluetooth Hands-Free Audio and Call Control HID Enumerator; C:\windows\System32\drivers\bthhfenum.sys [2012-07-26 51200]
S3 bthhfhid;@bthaudhid.inf,%BthAudioHFHid.SVCDESC%;Bluetooth Hands-Free Call Control HID; C:\windows\System32\drivers\BthHFHid.sys [2012-11-27 29952]
S3 BTHMODEM;@bthspp.inf,%BthSerial.DisplayName%;Bluetooth Serial Communications Driver; C:\windows\System32\drivers\bthmodem.sys [2012-07-26 65536]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2013-03-01 1175040]
S3 circlass;@circlass.inf,%circlass.SVCDESC%;Consumer IR Devices; C:\windows\System32\drivers\circlass.sys [2012-07-26 45056]
S3 dmvsc;dmvsc; C:\windows\System32\drivers\dmvsc.sys [2012-07-26 33280]
S3 drmkaud;@wdmaudio.inf,%drmkaud.SvcDesc%;Microsoft Trusted Audio Drivers; C:\windows\system32\drivers\drmkaud.sys [2012-10-11 5632]
S3 e1iexpress;@net1ic64.inf,%E1IExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2012-06-02 333824]
S3 ErrDev;@errdev.inf,%ERRDEV.SvcDesc%;Microsoft Hardware Error Device Driver; C:\windows\System32\drivers\errdev.sys [2012-07-26 10240]
S3 exfat;exFAT File System Driver; C:\windows\system32\drivers\exfat.sys [2012-07-26 194560]
S3 fdc;@fdc.inf,%fdc_ServiceDesc%;Floppy Disk Controller Driver; C:\windows\System32\drivers\fdc.sys [2012-07-26 30720]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\windows\system32\drivers\filetrace.sys [2012-07-26 34816]
S3 flpydisk;@flpydisk.inf,%floppy_ServiceDesc%;Floppy Disk Driver; C:\windows\System32\drivers\flpydisk.sys [2012-07-26 24576]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\windows\System32\drivers\FsDepends.sys [2012-07-26 57584]
S3 FxPPM;@cpu.inf,%FxPPM.SvcDesc%;Power Framework Processor Driver; C:\windows\System32\drivers\fxppm.sys [2012-11-06 22528]
S3 gencounter;@wgencounter.inf,%GenCounter.SVCDESC%;Microsoft Hyper-V Generation Counter; C:\windows\System32\drivers\vmgencounter.sys [2012-07-26 12288]
S3 GPIOClx0101;Microsoft GPIO Class Extension Driver; C:\windows\System32\Drivers\msgpioclx.sys [2013-07-09 120144]
S3 HdAudAddService;@hdaudio.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2013-06-26 341504]
S3 HidBatt;@hidbatt.inf,%HidBatt.SvcDesc%;HID UPS Battery Driver; C:\windows\System32\drivers\HidBatt.sys [2012-07-26 27136]
S3 HidBth;@hidbth.inf,%HIDBTH.SvcDesc%;Microsoft Bluetooth HID Miniport; C:\windows\System32\drivers\hidbth.sys [2013-04-09 95744]
S3 hidi2c;@hidi2c.inf,%hidi2c.SVCDESC%;Microsoft I2C HID Miniport Driver; C:\windows\System32\drivers\hidi2c.sys [2012-11-20 39936]
S3 HidIr;@hidir.inf,%HIDIR.SvcDesc%;Microsoft Infrared HID Driver; C:\windows\System32\drivers\hidir.sys [2012-07-26 46080]
S3 HidUsb;@input.inf,%HID.SvcDesc%;Microsoft HID Class Driver; C:\windows\System32\drivers\hidusb.sys [2013-08-17 27648]
S3 hyperkbd;hyperkbd; C:\windows\System32\drivers\hyperkbd.sys [2012-07-26 11776]
S3 HyperVideo;HyperVideo; C:\windows\system32\DRIVERS\HyperVideo.sys [2012-07-26 24576]
S3 IpFilterDriver;@%systemroot%\system32\rascfg.dll,-32013; C:\windows\system32\DRIVERS\ipfltdrv.sys [2012-07-26 89088]
S3 IPMIDRV;IPMIDRV; C:\windows\System32\drivers\IPMIDrv.sys [2012-07-26 78336]
S3 IPNAT;IP Network Address Translator; C:\windows\System32\drivers\ipnat.sys [2012-07-26 145920]
S3 IRENUM;@%SystemRoot%\system32\drivers\irenum.sys,-100; C:\windows\system32\drivers\irenum.sys [2012-07-26 17920]
S3 iScsiPrt;@iscsi.inf,%iScsiPortName%;iScsiPort Driver; C:\windows\System32\drivers\msiscsi.sys [2012-11-06 277736]
S3 kbdhid;@keyboard.inf,%KBDHID.SvcDesc%;Keyboard HID Driver; C:\windows\System32\drivers\kbdhid.sys [2012-07-26 29184]
S3 Modem;Modem; C:\windows\system32\drivers\modem.sys [2012-07-26 40448]
S3 mouhid;@msmouse.inf,%MOUHID.SvcDesc%;Mouse HID Driver; C:\windows\System32\drivers\mouhid.sys [2013-03-02 26112]
S3 MRxDAV;@%systemroot%\system32\webclnt.dll,-104; C:\windows\system32\drivers\mrxdav.sys [2012-07-26 141312]
S3 MsBridge;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2012-07-26 129536]
S3 msgpiowin32;@msgpiowin32.inf,%GPIO.SvcDesc%;GPIO Buttons Driver; C:\windows\System32\drivers\msgpiowin32.sys [2013-01-10 28904]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\windows\System32\drivers\mshidkmdf.sys [2012-07-26 8704]
S3 MSKSSRV;@ksfilter.inf,%MSKSSRV.DeviceDesc%;Microsoft Streaming Service Proxy; C:\windows\system32\drivers\MSKSSRV.sys [2012-07-26 11008]
S3 MsLldp;@C:\Windows\system32\DRIVERS\mslldp.sys,-200; C:\windows\system32\DRIVERS\mslldp.sys [2012-07-26 68608]
S3 MSPCLOCK;@ksfilter.inf,%MSPCLOCK.DeviceDesc%;Microsoft Streaming Clock Proxy; C:\windows\system32\drivers\MSPCLOCK.sys [2012-07-26 7168]
S3 MSPQM;@ksfilter.inf,%MSPQM.DeviceDesc%;Microsoft Streaming Quality Manager Proxy; C:\windows\system32\drivers\MSPQM.sys [2012-07-26 6912]
S3 MsRPC;MsRPC; C:\windows\system32\drivers\MsRPC.sys [2012-07-26 390896]
S3 MSTEE;@ksfilter.inf,%MSTEE.DeviceDesc%;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2012-07-26 8192]
S3 MTConfig;@mtconfig.inf,%MTConfig.SVCDESC%;Microsoft Input Configuration Driver; C:\windows\System32\drivers\MTConfig.sys [2012-07-26 14848]
S3 NdisCap;@%SystemRoot%\System32\drivers\ndiscap.sys,-5000; C:\windows\system32\DRIVERS\ndiscap.sys [2012-07-26 46592]
S3 NdisImPlatform;@%SystemRoot%\System32\drivers\ndisimplatform.sys,-501; C:\windows\system32\DRIVERS\NdisImPlatform.sys [2012-07-26 126464]
S3 NDISWANLEGACY;@%systemroot%\system32\rascfg.dll,-32014; C:\windows\system32\DRIVERS\ndiswan.sys [2012-07-26 174080]
S3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys [2012-06-02 8604672]
S3 Parport;@msports.inf,%Parport.SVCDESC%;Parallel port driver; C:\windows\System32\drivers\parport.sys [2012-07-26 105984]
S3 Processor;@cpu.inf,%Processor.SvcDesc%;Processor Driver; C:\windows\System32\drivers\processr.sys [2012-11-06 87552]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\windows\system32\drivers\qwavedrv.sys [2012-07-26 46592]
S3 RasAcd;Remote Access Auto Connection Driver; C:\windows\System32\DRIVERS\rasacd.sys [2012-07-26 16384]
S3 RDPDR;@%SystemRoot%\System32\DRIVERS\rdpdr.sys,-100; C:\windows\System32\drivers\rdpdr.sys [2012-07-26 179712]
S3 RDPWD;RDP Winstation Driver; C:\windows\system32\drivers\RDPWD.sys [2012-07-26 208384]
S3 RSUSBVSTOR;@oem10.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2013-01-15 327240]
S3 s3cap;s3cap; C:\windows\System32\drivers\vms3cap.sys [2012-07-26 7168]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\windows\System32\DRIVERS\scfilter.sys [2012-07-26 36864]
S3 sdbus;sdbus; C:\windows\System32\drivers\sdbus.sys [2013-06-29 195416]
S3 sdstor;@sdstor.inf,%sdstor_ServiceDesc%;SD Storage Port Driver; C:\windows\System32\drivers\sdstor.sys [2012-10-11 56552]
S3 SerCx;Serial UART Support Library; C:\windows\system32\drivers\SerCx.sys [2012-07-26 62976]
S3 Serenum;@msports.inf,%Serenum.SVCDESC%;Serenum Filter Driver; C:\windows\System32\drivers\serenum.sys [2012-07-26 23040]
S3 Serial;@msports.inf,%Serial.SVCDESC%;Serial port driver; C:\windows\System32\drivers\serial.sys [2012-07-26 76800]
S3 sermouse;@msmouse.inf,%sermouse.SvcDesc%;Serial Mouse Driver; C:\windows\System32\drivers\sermouse.sys [2012-07-26 27136]
S3 sfloppy;@flpydisk.inf,%sfloppy_devdesc%;High-Capacity Floppy Disk Drive; C:\windows\System32\drivers\sfloppy.sys [2012-07-26 16896]
S3 SpbCx;Simple Peripheral Bus Support Library; C:\windows\system32\drivers\SpbCx.sys [2012-07-26 59392]
S3 TCPIP6;@netip6.inf,%MS_TCPIP6.TCPIP6.ServiceDescription%;Microsoft IPv6 Protocol Driver; C:\windows\system32\DRIVERS\tcpip.sys [2013-08-01 2233688]
S3 terminpt;@termmou.inf,%TermInpt.SVCDESC%;Microsoft Remote Desktop Input Driver; C:\windows\System32\drivers\terminpt.sys [2012-07-26 36592]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-07-26 57344]
S3 TsUsbGD;@tsgenericusbdriver.inf,%TsUsbGD.DeviceDesc.Generic%;Remote Desktop Generic USB Device; C:\windows\System32\drivers\TsUsbGD.sys [2012-07-26 30208]
S3 UASPStor;@uaspstor.inf,%UASPortName%;USB Attached SCSI (UAS) Driver; C:\windows\System32\drivers\uaspstor.sys [2012-07-26 97008]
S3 UmPass;@umpass.inf,%UmPass.SVCDESC%;Microsoft UMPass Driver; C:\windows\System32\drivers\umpass.sys [2012-07-26 11776]
S3 usbcir;@usbcir.inf,%usbcir.SVCDESC%;eHome Infrared Receiver (USBCIR); C:\windows\System32\drivers\usbcir.sys [2013-07-05 99328]
S3 usbohci;@usbport.inf,%OHCIMP.SvcDesc%;Microsoft USB Open Host Controller Miniport Driver; C:\windows\System32\drivers\usbohci.sys [2012-11-20 27136]
S3 usbprint;@usbprint.inf,%USBPRINT.SvcDesc%;Microsoft USB PRINTER Class; C:\windows\System32\drivers\usbprint.sys [2013-07-01 25600]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 USBSTOR;@usbstor.inf,%USBSTOR.SvcDesc%;USB Mass Storage Driver; C:\windows\System32\drivers\USBSTOR.SYS [2013-06-06 119040]
S3 usbuhci;@usbport.inf,%UHCIMP.SvcDesc%;Microsoft USB Universal Host Controller Miniport Driver; C:\windows\System32\drivers\usbuhci.sys [2013-06-29 32256]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-07-05 210560]
S3 VerifierExt;@%SystemRoot%\system32\drivers\VerifierExt.sys,-1000; C:\windows\system32\drivers\VerifierExt.sys [2012-07-26 106224]
S3 vhdmp;vhdmp; C:\windows\System32\drivers\vhdmp.sys [2013-03-02 495336]
S3 VMBusHID;VMBusHID; C:\windows\System32\drivers\VMBusHID.sys [2012-07-26 22144]
S3 vpci;@wvpci.inf,%vpci.SVCDESC%;Microsoft Hyper-V Virtual PCI Bus; C:\windows\System32\drivers\vpci.sys [2012-07-26 67824]
S3 WacomPen;@hiddigi.inf,%WacomPen.SVCDESC%;Wacom Serial Pen HID Driver; C:\windows\System32\drivers\wacompen.sys [2012-07-26 27008]
S3 Wanarp;@%systemroot%\system32\rascfg.dll,-32011; C:\windows\system32\DRIVERS\wanarp.sys [2013-04-09 83456]
S3 WIMMount;WIMMount; C:\windows\system32\drivers\wimmount.sys [2012-07-26 33520]
S4 udfs;udfs; C:\windows\system32\DRIVERS\udfs.sys [2013-06-26 321536]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-09-05 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-04-25 241152]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2013-01-25 227456]
R2 AudioEndpointBuilder;@%SystemRoot%\system32\AudioEndpointBuilder.dll,-204; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 Audiosrv;@%SystemRoot%\system32\audiosrv.dll,-200; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 BITS;@%SystemRoot%\system32\qmgr.dll,-1000; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 BrokerInfrastructure;@%windir%\system32\bisrv.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 CryptSvc;@%SystemRoot%\system32\cryptsvc.dll,-1001; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 CxAudMsg;@C:\windows\system32\CxAudMsg64.exe,-100; C:\windows\system32\CxAudMsg64.exe [2013-03-05 202400]
R2 DCE;Distributed Computing Experiment; C:\Program Files\DCE\dce.exe [2013-12-18 59392]
R2 DcomLaunch;@combase.dll,-5012; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 Dhcp;@%SystemRoot%\system32\dhcpcore.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 Dnscache;@%SystemRoot%\System32\dnsapi.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2013-02-25 92160]
R2 EventLog;@%SystemRoot%\system32\wevtsvc.dll,-200; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 EventSystem;@comres.dll,-2450; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 gpsvc;@gpapi.dll,-112; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-08-21 166720]
R2 LanmanServer;@%systemroot%\system32\srvsvc.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 LanmanWorkstation;@%systemroot%\system32\wkssvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 lmhosts;@%SystemRoot%\system32\lmhsvc.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-09-11 277792]
R2 LSM;@%windir%\system32\lsm.dll,-1001; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [2013-07-08 1922600]
R2 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 RpcSs;@combase.dll,-5010; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 SamSs;@%SystemRoot%\system32\samsrv.dll,-1; C:\windows\system32\lsass.exe [2012-09-20 35840]
R2 SAService;Conexant SmartAudio service; C:\windows\system32\SAsrv.exe []
R2 SENS;@%SystemRoot%\system32\Sens.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 ShellHWDetection;@%SystemRoot%\System32\shsvcs.dll,-12288; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 Schedule;@%SystemRoot%\system32\schedsvc.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
R2 Spooler;@%systemroot%\system32\spoolsv.exe,-1; C:\windows\System32\spoolsv.exe [2012-07-26 769024]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-19 142960]
R2 stisvc;@%SystemRoot%\system32\wiaservc.dll,-9; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 Themes;@%SystemRoot%\System32\themeservice.dll,-8192; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 TrkWks;@%SystemRoot%\system32\trkwks.dll,-1; C:\windows\System32\svchost.exe [2012-09-20 29696]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-09-11 365344]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService; C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe [2013-12-13 88648]
R2 Wcmsvc;@%SystemRoot%\System32\wcmsvc.dll,-4097; C:\windows\system32\svchost.exe [2012-09-20 29696]
R2 WeatherBlinkService;WeatherBlinkService; C:\PROGRA~2\WEATHE~2\bar\1.bin\gcbarsvc.exe [2013-12-12 88648]
R2 WinDefend;@%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310; C:\Program Files\Windows Defender\MsMpEng.exe [2013-07-02 16048]
R2 Winmgmt;@%Systemroot%\system32\wbem\wmisvc.dll,-205; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 DeviceAssociationService;@%SystemRoot%\system32\das.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 hidserv;@%SystemRoot%\System32\hidserv.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
R3 Netman;@%SystemRoot%\system32\netman.dll,-109; C:\windows\System32\svchost.exe [2012-09-20 29696]
R3 netprofm;@%SystemRoot%\system32\netprofmsvc.dll,-202; C:\windows\System32\svchost.exe [2012-09-20 29696]
R3 PlugPlay;@%SystemRoot%\system32\umpnpmgr.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 SSDPSRV;@%systemroot%\system32\ssdpsrv.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 SystemEventsBroker;@%windir%\system32\SystemEventsBrokerServer.dll,-1001; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 TimeBroker;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 upnphost;@%systemroot%\system32\upnphost.dll,-213; C:\windows\system32\svchost.exe [2012-09-20 29696]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\windows\System32\svchost.exe [2012-09-20 29696]
R3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\windows\System32\svchost.exe [2012-09-20 29696]
R3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\windows\system32\sppsvc.exe [2013-08-16 4917760]
S2 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\windows\servicing\TrustedInstaller.exe [2013-08-17 98304]
S3 ALG;@%SystemRoot%\system32\Alg.exe,-112; C:\windows\System32\alg.exe [2012-07-26 94208]
S3 AllUserInstallAgent;@%SystemRoot%\System32\AUInstallAgent.dll,-101; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 Browser;@%systemroot%\system32\browser.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 COMSysApp;@comres.dll,-947; C:\windows\system32\dllhost.exe [2012-07-26 10752]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-04-24 279024]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 DeviceInstall;@%SystemRoot%\system32\umpnpmgr.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 dot3svc;@%systemroot%\system32\dot3svc.dll,-1102; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 DsmSvc;@%SystemRoot%\system32\DeviceSetupManager.dll,-1000; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 Eaphost;@%systemroot%\system32\eapsvc.dll,-1; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\windows\System32\lsass.exe [2012-09-20 35840]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\windows\system32\fxssvc.exe [2012-07-26 669696]
S3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 fhsvc;@%systemroot%\system32\fhsvc.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2012-07-26 43616]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 116648]
S3 hkmsvc;@%SystemRoot%\system32\kmsvc.dll,-6; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 KeyIso;@keyiso.dll,-100; C:\windows\system32\lsass.exe [2012-09-20 35840]
S3 KtmRm;@comres.dll,-2946; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MSDTC;@comres.dll,-2797; C:\windows\System32\msdtc.exe [2012-07-26 144384]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 msiserver;@%SystemRoot%\system32\msimsg.dll,-27; C:\windows\system32\msiexec.exe [2012-07-26 124416]
S3 napagent;@%SystemRoot%\system32\qagentrt.dll,-6; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 NcaSvc;@%SystemRoot%\system32\ncasvc.dll,-3009; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 NcdAutoSetup;@%SystemRoot%\system32\NcdAutoSetup.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 Netlogon;@%SystemRoot%\System32\netlogon.dll,-102; C:\windows\system32\lsass.exe [2012-09-20 35840]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\windows\SysWow64\perfhost.exe [2012-07-26 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 PolicyAgent;@%SystemRoot%\System32\polstore.dll,-5010; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 PrintNotify;@C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll,-1; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 RasAuto;@%Systemroot%\system32\rasauto.dll,-200; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 RasMan;@%Systemroot%\system32\rasmans.dll,-200; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 RpcLocator;@%systemroot%\system32\Locator.exe,-2; C:\windows\system32\locator.exe [2012-07-26 9728]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 seclogon;@%SystemRoot%\system32\seclogon.dll,-7001; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 SharedAccess;@%SystemRoot%\system32\ipnathlp.dll,-106; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\windows\System32\snmptrap.exe [2012-07-26 14848]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 svsvc;@%SystemRoot%\system32\svsvc.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 swprv;@%SystemRoot%\System32\swprv.dll,-103; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 TapiSrv;@%SystemRoot%\system32\tapisrv.dll,-10100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 TermService;@%SystemRoot%\System32\termsrv.dll,-268; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\windows\system32\UI0Detect.exe [2012-07-26 40960]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\windows\system32\lsass.exe [2012-09-20 35840]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\windows\System32\vds.exe [2013-06-01 680960]
S3 vmickvpexchange;@%systemroot%\system32\vmicres.dll,-201; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 vmicrdv;@%systemroot%\system32\vmicres.dll,-601; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 vmicshutdown;@%systemroot%\system32\vmicres.dll,-301; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 vmictimesync;@%systemroot%\system32\vmicres.dll,-401; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 vmicvss;@%systemroot%\system32\vmicres.dll,-501; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 vmicheartbeat;@%systemroot%\system32\vmicres.dll,-101; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 VSS;@%systemroot%\system32\vssvc.exe,-102; C:\windows\system32\vssvc.exe [2013-08-17 1483776]
S3 W32Time;@%SystemRoot%\system32\w32time.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\windows\system32\wbengine.exe [2012-07-26 1616896]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 WebClient;@%systemroot%\system32\webclnt.dll,-100; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\windows\System32\svchost.exe [2012-09-20 29696]
S3 WiaRpc;@%SystemRoot%\system32\wiarpc.dll,-2; C:\windows\system32\svchost.exe [2012-09-20 29696]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\windows\System32\svchost.exe [2012-09-20 29696]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8201; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-12 139696]
S4 RemoteAccess;@%Systemroot%\system32\mprdim.dll,-200; C:\windows\System32\svchost.exe [2012-09-20 29696]
S4 RemoteRegistry;@regsvc.dll,-1; C:\windows\system32\svchost.exe [2012-09-20 29696]
S4 SCardSvr;@%SystemRoot%\System32\SCardSvr.dll,-1; C:\windows\system32\svchost.exe [2012-09-20 29696]

-----------------EOF-----------------

Re: Fakepolice

Napsal: 16 led 2014 17:49
od vyosek
Zdravim :)

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Fakepolice

Napsal: 23 led 2014 18:58
od karelfritz
Omlouvám se za pozdní reakci, ale po vaší informaci, kdy jste mě upozornil, že mi ty programy můžou zruinovat celý pc jsem raději počkal až budu s někým trošičku zkušený v informatice. V dalších příspěvcích vložím ty texty. Zároveň jsem vám chtěl mockrát poděkovat za vaší ochotu. S pozdravem, Fritz.

Re: Fakepolice

Napsal: 23 led 2014 18:58
od karelfritz
RKILL:

Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 01/23/2014 02:22:08 PM in x64 mode.
Windows Version: Windows 8

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 01/23/2014 02:22:48 PM
Execution time: 0 hours(s), 0 minute(s), and 39 seconds(s)

Re: Fakepolice

Napsal: 23 led 2014 18:59
od karelfritz
COMBO FIX: ComboFix 14-01-22.01 - Kuba . 01. 2014 14:29:15.1.4 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.3962.2014 [GMT 1:00]
Spuštěný z: c:\users\Kuba\Desktop\ComboFix.exe
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Torntv V7.0\ToRNtv v7.0-bho.dll
c:\program files (x86)\WeatherBlink
c:\program files (x86)\WeatherBlink\bar\1.bin\AppIntegrator64.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\AppIntegratorStub64.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\BOOTSTRAP.JS
c:\program files (x86)\WeatherBlink\bar\1.bin\CREXT.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\CrExtPgc.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\DPNMNGR.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\EXEMANAGER.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\FF-NativeMessagingDispatcher.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcauxstb.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcauxstb64.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbar.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbarsvc.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbprtct.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbrmon.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbrmon64.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbrstub.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbrstub64.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcdatact.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcdlghk.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcdlghk64.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcfeedmg.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcidle.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcieovr.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcmedint.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcmlbtn.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcPlugin.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcradio.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcregfft.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcreghk.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcregiet.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcscript.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcskin.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcskplay.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcSrcAs.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcSrchMn.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcsrchmr.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gctpinst.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gchighin.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gchkstub.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gchtmlmu.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gchttpct.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\Hpg64.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\CHROME.MANIFEST
c:\program files (x86)\WeatherBlink\bar\1.bin\chrome\gcffxtbr.jar
c:\program files (x86)\WeatherBlink\bar\1.bin\INSTALL.RDF
c:\program files (x86)\WeatherBlink\bar\1.bin\installKeys.js
c:\program files (x86)\WeatherBlink\bar\1.bin\LOGO.BMP
c:\program files (x86)\WeatherBlink\bar\1.bin\NPgcStub.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\T8EPMSUP.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\T8EXTEX.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\T8EXTPEX.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\T8HTML.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\T8RES.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\T8TICKER.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\UNIFIEDLOGGING.DLL
c:\program files (x86)\WeatherBlink\bar\1.bin\VERIFY.DLL
c:\program files (x86)\WeatherBlink\bar\gen1\COMMON.T8S
c:\program files (x86)\WeatherBlink\bar\IE9Mesg\COMMON.T8S
c:\program files (x86)\WeatherBlink\bar\Message\COMMON.T8S
c:\program files (x86)\WeatherBlink\bar\Settings\s_pid.dat
c:\program files (x86)\WebexpEnhancedV1
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\defaults\preferences\prefs.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\manifest.xml
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins.json
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\1_base.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\1000020_analytics.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\1000025_analyticsFront.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\1000030_mz.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\104_jollywallet_m.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\14_CrossriderUtils.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\16_FFAppAPIWrapper.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\17_jQuery.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\175_coolmirage_m.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\177_crossriderDashboard.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\182_openUrl.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\183_tabsWrapper.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\207_dbWrapper.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\21_debug.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\22_resources.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\28_initializer.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\4_jquery_1_7_1.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\47_resources_background.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\64_appApiMessage.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\72_appApiValidation.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\78_CrossriderInfo.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\91_monetizationLoader.js.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\plugins\98_omniCommands.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\userCode\background.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\extensionData\userCode\extension.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome.manifest
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\asyncDB.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\background.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\browserAction.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\contextMenu.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\dbManager.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\dom_bg.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\fileManager.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\firefox.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\firefoxNotifications.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\firefoxOmnibox.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\message.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\pageAction.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\request.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\tabs.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\webRequest.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\api\windowsMessagingHandler.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\background.html
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\baseObject.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\browser.xul
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\addressBarChangeObserver.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\console.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\consts.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\delegate.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\extensionDataStore.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\folderIOWrapper.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\httpObserver.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\IDBWrapper.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\installer.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\logFile.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\prefs.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\progressListenerObserver.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\registry.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\reloadObserver.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\reports.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\requestObject.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\searchSettings.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\uninstallObserver.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\updateManager.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\utils.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\core\xhr.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\dialog.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\main.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\options.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\options.xul
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\platformVersion.js
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\chrome\content\search_dialog.xul
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\install.rdf
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\locale\en-US\translations.dtd
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\button1.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\button2.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\button3.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\button4.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\button5.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\crossrider_statusbar.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\icon128.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\icon16.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\icon24.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\icon48.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\panelarrow-up.png
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\popup.html
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\skin.css
c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\00cf4073-9c0d-4c73-823c-9627a9ebda10@5ce0c315-7a90-4c46-8428-5c0df674cab0.com\skin\update.css
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_WeatherBlinkService
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-23 do 2014-01-23 )))))))))))))))))))))))))))))))
.
.
2014-01-22 18:39 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CC127D37-C9D9-4239-8B05-B7E1A51FA2BA}\mpengine.dll
2014-01-21 09:59 . 2014-01-21 09:59 -------- d-----w- c:\users\Kuba\AppData\Local\Qualcomm Atheros
2014-01-21 09:58 . 2014-01-21 09:58 -------- d-----w- c:\windows\LastGood.Tmp
2014-01-16 21:47 . 2014-01-23 13:35 -------- d-----w- c:\program files (x86)\Torntv V7.0
2014-01-16 13:19 . 2014-01-16 13:21 -------- d-----w- c:\program files\trend micro
2014-01-16 13:19 . 2014-01-16 13:19 -------- d-----w- C:\rsit
2014-01-15 19:50 . 2013-12-07 06:37 688640 ----a-w- c:\windows\system32\WSShared.dll
2014-01-15 19:50 . 2013-12-07 06:37 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 19:50 . 2013-12-07 05:15 562688 ----a-w- c:\windows\SysWow64\WSShared.dll
2014-01-15 19:50 . 2013-12-07 05:15 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 18:21 . 2013-10-31 05:56 915968 ----a-w- c:\windows\system32\MPSSVC.dll
2014-01-15 18:21 . 2013-10-31 05:56 758784 ----a-w- c:\windows\system32\FirewallAPI.dll
2014-01-15 18:21 . 2013-10-31 04:01 550400 ----a-w- c:\windows\SysWow64\FirewallAPI.dll
2014-01-15 18:21 . 2013-10-28 05:50 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-01-15 18:21 . 2013-10-28 04:05 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-01-15 18:21 . 2013-10-13 20:49 100696 ----a-w- c:\windows\system32\drivers\disk.sys
2014-01-15 18:21 . 2013-08-27 05:21 227840 ----a-w- c:\windows\system32\WebClnt.dll
2014-01-15 18:21 . 2013-08-27 05:19 104448 ----a-w- c:\windows\system32\davclnt.dll
2014-01-15 18:21 . 2013-08-26 22:29 199168 ----a-w- c:\windows\SysWow64\WebClnt.dll
2014-01-15 18:21 . 2013-08-26 22:28 86016 ----a-w- c:\windows\SysWow64\davclnt.dll
2014-01-15 18:21 . 2013-10-31 03:42 74752 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2014-01-11 00:04 . 2013-12-10 21:25 583 --s-a-w- c:\windows\SysWow64\mswrmcvi.vbe
2014-01-11 00:04 . 2013-12-10 21:25 5453 --s-a-w- c:\windows\SysWow64\msqmrljg.vbe
2014-01-11 00:04 . 2013-12-10 21:25 1645 --s-a-w- c:\windows\SysWow64\msiknm.vbe
2014-01-11 00:04 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\SysWow64\nircmdc.exe
2014-01-10 23:54 . 2014-01-10 23:54 -------- d-----w- c:\program files (x86)\Anvisoft
2014-01-10 23:45 . 2002-08-29 17:33 319488 ----a-r- c:\windows\SysWow64\MafiaSetup.exe
2014-01-10 23:45 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2014-01-10 23:42 . 2014-01-16 12:12 -------- d-----w- c:\program files\Mafia
2014-01-10 23:41 . 2002-08-29 17:33 319488 ----a-r- c:\users\Kuba\AppData\Roaming\MafiaSetup.exe
2014-01-10 18:13 . 2014-01-10 19:42 -------- d-----w- c:\users\Kuba\AppData\Roaming\BSplayer
2014-01-10 18:13 . 2014-01-10 18:13 -------- d-----w- c:\users\Kuba\AppData\Roaming\BSplayer Pro
2014-01-10 18:13 . 2014-01-10 18:13 -------- d-----w- c:\program files (x86)\Webteh
2014-01-10 18:12 . 2014-01-10 18:12 -------- d-----w- c:\users\Kuba\AppData\Roaming\AVG
2014-01-10 18:12 . 2014-01-10 18:13 -------- d-----w- c:\programdata\AVG
2014-01-10 18:12 . 2014-01-10 18:12 -------- d-sh--w- c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-01-10 18:11 . 2014-01-10 18:11 -------- d-----w- c:\users\Kuba\AppData\Roaming\OpenCandy
2014-01-10 02:13 . 2014-01-10 23:46 -------- d-----w- c:\program files (x86)\VideoPlayerV3
2014-01-09 20:31 . 2014-01-09 20:33 -------- d-----w- C:\BMW M3 Challenge
2014-01-09 13:32 . 2014-01-22 18:26 -------- d-----w- c:\users\Kuba\.xmoto
2014-01-09 13:32 . 2014-01-09 13:32 -------- d-----w- c:\program files (x86)\XMoto
2014-01-06 20:24 . 2014-01-09 08:51 -------- d-----w- c:\users\Kuba\AppData\Roaming\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----r- c:\program files (x86)\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----w- c:\programdata\Skype
2014-01-06 20:21 . 2014-01-06 20:23 -------- d-----w- c:\program files (x86)\Counter-Strike 1.6 Non-Steam
2014-01-04 22:51 . 2014-01-04 22:52 -------- d-----w- c:\users\Guest
2013-12-28 11:42 . 2013-12-29 20:02 -------- d-----w- c:\program files (x86)\MyPC Backup
2013-12-26 05:03 . 2013-11-01 01:45 23350272 ----a-w- c:\program files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-12-26 05:03 . 2013-11-01 01:16 22615040 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-12-25 21:09 . 2013-12-25 21:09 -------- d-----w- c:\program files (x86)\SecretSauce
2013-12-25 21:08 . 2014-01-17 05:28 -------- d-----w- c:\program files (x86)\TornTV.com
2013-12-25 21:03 . 2013-12-25 21:05 -------- d-----w- c:\users\Kuba\AppData\Roaming\deluge
2013-12-25 21:02 . 2013-08-23 07:22 2062848 ----a-w- c:\windows\system32\d3d11.dll
2013-12-25 21:02 . 2013-08-23 01:44 1711616 ----a-w- c:\windows\SysWow64\d3d11.dll
2013-12-25 21:02 . 2013-03-22 03:49 2382336 ----a-w- c:\windows\SysWow64\esent.dll
2013-12-25 21:02 . 2013-03-21 22:47 2851840 ----a-w- c:\windows\system32\esent.dll
2013-12-25 21:02 . 2013-11-23 06:43 420864 ----a-w- c:\windows\system32\WMPhoto.dll
2013-12-25 21:02 . 2013-11-23 05:05 368640 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-12-25 21:01 . 2013-08-02 06:28 10116608 ----a-w- c:\windows\system32\twinui.dll
2013-12-25 21:01 . 2013-08-02 05:08 8858112 ----a-w- c:\windows\SysWow64\twinui.dll
2013-12-25 21:01 . 2013-10-01 23:37 2035712 ----a-w- c:\windows\SysWow64\authui.dll
2013-12-25 21:01 . 2013-10-01 23:26 2304512 ----a-w- c:\windows\system32\authui.dll
2013-12-25 21:00 . 2014-01-10 23:47 -------- d-----w- c:\program files (x86)\Seznam.cz
2013-12-25 20:59 . 2013-12-25 20:59 -------- d-----w- c:\users\Kuba\.android
2013-12-25 20:59 . 2014-01-10 23:47 -------- d-----w- c:\users\Kuba\AppData\Roaming\Seznam.cz
2013-12-25 20:59 . 2014-01-23 13:15 -------- d-----w- c:\users\Kuba\AppData\Roaming\newnext.me
2013-12-25 20:59 . 2014-01-11 00:08 -------- d-----w- c:\users\Kuba\AppData\Local\Mobogenie
2013-12-25 20:59 . 2014-01-09 20:47 -------- d-----w- c:\users\Kuba\AppData\Local\cache
2013-12-25 20:59 . 2014-01-09 20:31 -------- d-----w- c:\users\Kuba\AppData\Local\genienext
2013-12-25 20:57 . 2013-11-01 05:38 312320 ----a-w- c:\windows\system32\msieftp.dll
2013-12-25 20:57 . 2013-11-01 03:49 273408 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-12-25 20:43 . 2013-10-27 22:41 965000 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C029EFEF-8663-4D31-A94C-068FCCAF47D4}\gapaengine.dll
2013-12-25 18:25 . 2014-01-11 00:09 -------- d-----w- c:\program files (x86)\SysPlayer
2013-12-25 18:24 . 2013-12-25 18:24 -------- d-----w- c:\users\Kuba\AppData\Local\Installer
2013-12-25 18:23 . 2013-12-25 18:23 -------- d-----w- c:\programdata\ShopperPro
2013-12-25 18:23 . 2014-01-20 16:36 -------- d-----w- c:\program files (x86)\ShopperPro
2013-12-25 18:22 . 2013-12-25 18:22 -------- d-----w- c:\program files\DCE
2013-12-25 18:22 . 2013-12-25 18:22 -------- d-----w- c:\users\Kuba\AppData\Local\CrashRpt
2013-12-25 18:21 . 2014-01-10 23:45 -------- d-----w- c:\users\Kuba\AppData\Roaming\uTorrent
2013-12-25 18:15 . 2013-12-25 18:17 -------- d-----w- c:\program files (x86)\Google
2013-12-25 18:15 . 2013-12-25 18:17 -------- d-----w- c:\users\Kuba\AppData\Local\Google
2013-12-25 18:03 . 2013-12-25 18:03 -------- d-----w- c:\users\Kuba\AppData\Roaming\TuneUp Software
2013-12-25 18:03 . 2013-12-25 18:08 -------- d-----w- C:\$AVG
2013-12-25 18:00 . 2013-12-25 18:09 -------- d-----w- c:\programdata\MFAData
2013-12-25 18:00 . 2013-12-25 18:00 -------- d--h--w- c:\programdata\Common Files
2013-12-25 18:00 . 2013-12-25 18:00 -------- d-----w- c:\users\Kuba\AppData\Local\MFAData
2013-12-25 10:25 . 2014-01-17 00:51 -------- d-----w- c:\windows\system32\MRT
2013-12-25 09:46 . 2014-01-10 22:51 78336 ----a-w- c:\windows\SysWow64\rp.dll
2013-12-25 09:17 . 2013-12-25 09:17 -------- d-----w- c:\users\Kuba\AppData\Roaming\GoobZo
2013-12-25 09:13 . 2013-12-25 09:13 -------- d-----w- c:\users\Kuba\AppData\Roaming\2K Sports
2013-12-25 08:38 . 2014-01-22 20:25 -------- d-----w- c:\users\Kuba\AppData\Local\CrashDumps
2013-12-25 08:31 . 2006-03-31 11:41 3927248 ----a-w- c:\windows\system32\d3dx9_30.dll
2013-12-24 21:38 . 2013-06-01 09:20 2219520 ----a-w- c:\windows\system32\dwmcore.dll
2013-12-24 21:34 . 2013-08-02 06:28 19758080 ----a-w- c:\windows\system32\shell32.dll
2013-12-24 21:33 . 2013-08-03 06:40 462336 ----a-w- c:\windows\system32\sysmon.ocx
2013-12-24 21:33 . 2013-08-03 06:40 566784 ----a-w- c:\windows\system32\wvc.dll
2013-12-24 21:33 . 2013-08-03 06:40 1374208 ----a-w- c:\windows\system32\wdc.dll
2013-12-24 21:33 . 2013-08-03 05:14 399360 ----a-w- c:\windows\SysWow64\sysmon.ocx
2013-12-24 21:33 . 2013-08-03 05:13 1245696 ----a-w- c:\windows\SysWow64\wdc.dll
2013-12-24 21:33 . 2013-08-03 05:13 437248 ----a-w- c:\windows\SysWow64\wvc.dll
2013-12-24 21:29 . 2013-12-24 21:29 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-12-24 21:29 . 2013-12-25 07:28 -------- d-----w- c:\users\Kuba\AppData\Roaming\DAEMON Tools Lite
2013-12-24 21:29 . 2013-12-24 21:29 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-12-24 21:28 . 2013-12-25 07:28 -------- d-----w- c:\programdata\DAEMON Tools Lite
2013-12-24 21:21 . 2013-12-24 21:27 -------- d-----w- c:\program files\Hry
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-19 07:33 . 2013-12-13 19:06 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-01-09 08:02 . 2012-07-26 08:14 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-09 08:02 . 2012-07-26 08:14 694240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-13 17:55 . 2013-12-13 17:55 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-12-12 08:31 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-11-06 23:18 . 2013-12-13 18:59 4036608 ----a-w- c:\windows\system32\win32k.sys
2013-10-28 00:12 . 2013-10-28 00:12 204568 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2013-10-28 00:12 . 2013-10-28 00:12 107288 ----a-w- c:\windows\system32\drivers\ssudbus.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]
2013-12-13 22:19 859720 ----a-w- c:\progra~2\VIDEOD~2\bar\1.bin\4zbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
2014-01-15 19:35 429416 ----a-w- c:\programdata\ShopperPro\ShopperPro.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]
2013-12-13 22:19 140360 ----a-w- c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{48586425-6bb7-4f51-8dc6-38c88e3ebb58}"= "c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll" [2013-12-13 859720]
.
[HKEY_CLASSES_ROOT\clsid\{48586425-6bb7-4f51-8dc6-38c88e3ebb58}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-10-20 16:47 627712 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="c:\users\Kuba\AppData\Roaming\newnext.me\nengine.dll" [2013-11-14 1283584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-25 642816]
"YouCam Tray"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2012-10-31 168464]
"UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2012-04-19 217088]
"RemoteControl10"="c:\program files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe" [2012-03-29 91432]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"VideoDownloadConverter EPM Support"="c:\progra~2\VIDEOD~2\bar\1.bin\4zmedint.exe" [2013-12-13 12872]
"VideoDownloadConverter Search Scope Monitor"="c:\progra~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" [2013-12-13 55368]
"VideoDownloadConverter_4z Browser Plugin Loader"="c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe" [2013-12-13 61512]
"VideoDownloadConverter_4z Browser Plugin Loader 64"="c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe" [2013-12-13 71752]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"mswrmcviSrv"="c:\windows\system32\mswrmcvi.vbe" [2013-12-10 583]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\System32\drivers\amdkmpfd.sys;c:\windows\SYSNATIVE\drivers\amdkmpfd.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
S2 DCE;Distributed Computing Experiment;c:\program files\DCE\dce.exe;c:\program files\DCE\dce.exe [x]
S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe;c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe [x]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe;c:\windows\SYSNATIVE\SAsrv.exe [x]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S2 Start8;Stardock Start8;c:\program files (x86)\Stardock\Start8\Start8Srv.exe;c:\program files (x86)\Stardock\Start8\Start8Srv.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VideoDownloadConverter_4zService;VideoDownloadConverterService;c:\progra~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe;c:\progra~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe [x]
S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-16 19:26 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 18:15]
.
2014-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 18:15]
.
2014-01-23 c:\windows\Tasks\Torntv V7.0-chromeinstaller-dev.job
- c:\program files (x86)\Torntv V7.0\Torntv V7.0-chromeinstaller.exe [2014-01-16 21:47]
.
2014-01-23 c:\windows\Tasks\Torntv V7.0-codedownloader.job
- c:\program files (x86)\Torntv V7.0\Torntv V7.0-codedownloader.exe [2014-01-16 21:47]
.
2014-01-23 c:\windows\Tasks\Torntv V7.0-enabler.job
- c:\program files (x86)\Torntv V7.0\Torntv V7.0-enabler.exe [2014-01-16 21:47]
.
2014-01-23 c:\windows\Tasks\Torntv V7.0-firefoxinstaller.job
- c:\program files (x86)\Torntv V7.0\Torntv V7.0-firefoxinstaller.exe [2014-01-16 21:47]
.
2014-01-23 c:\windows\Tasks\Torntv V7.0-updater.job
- c:\program files (x86)\Torntv V7.0\Torntv V7.0-updater.exe [2014-01-16 21:47]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-10-20 16:47 774144 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2013-01-31 36352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-04-24 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-04-24 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-04-24 442352]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2013-02-04 899680]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2013-03-05 1647616]
"RtsFT"="RTFTrack.exe" [2013-04-24 6339656]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-08-17 17097200]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-08-17 193008]
"VideoDownloadConverter Home Page Guard 64 bit"="c:\progra~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe" [2013-12-13 485448]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 62.129.50.20 85.135.32.100
FF - ProfilePath - c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\
FF - ExtSQL: 2013-12-12 21:11; gcffxtbr@WeatherBlink.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\gcffxtbr@WeatherBlink.com
FF - ExtSQL: 2013-12-13 21:41; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF - ExtSQL: 2013-12-13 23:19; 4zffxtbr@VideoDownloadConverter_4z.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
FF - ExtSQL: 2013-12-15 12:20; {746505DC-0E21-4667-97F8-72EA6BCF5EEF}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
FF - ExtSQL: 2014-01-06 21:24; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{11111111-1111-1111-1111-110411901140} - c:\program files (x86)\Torntv V7.0\Torntv V7.0-bho.dll
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-mcui_exe - c:\program files\McAfee.com\Agent\mcagent.exe
Wow6432Node-HKLM-Run-WeatherBlink EPM Support - c:\progra~2\WEATHE~2\bar\1.bin\gcmedint.exe
Wow6432Node-HKLM-Run-WeatherBlink Browser Plugin Loader 64 - c:\program files (x86)\WeatherBlink\bar\1.bin\gcbrmon64.exe
Wow6432Node-HKLM-Run-mobilegeni daemon - c:\program files (x86)\Mobogenie\DaemonProcess.exe
Toolbar-Locked - (no file)
WebBrowser-{48586425-6BB7-4F51-8DC6-38C88E3EBB58} - (no file)
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-Mafia Game - c:\windows\system32\MafiaSetup.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\windows\SysWOW64\SAsrv.exe
c:\program files (x86)\PANDORA.TV\PanService\KMPProcess.exe
c:\windows\SysWOW64\rundll32.exe
c:\windows\SysWOW64\WScript.exe
c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-01-23 14:41:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-23 13:41
.
Před spuštěním: 885 094 129 664 bytes free
Po spuštění: 886 178 934 784 bytes free
.
- - End Of File - - C9984C16A5F931BF30F21EF0F245D088
5FB38429D5D77768867C76DCBDB35194

Re: Fakepolice

Napsal: 23 led 2014 19:01
od karelfritz
Proces některého z programu mi pravděpodobně nějaké data mazal, a tak doufám, že by už můj pc mohl být v pořádku. Ale vy to pravděpodobně budete vědět lépe. Ješťě jednou vám mockrát děkuju za vaší ochotu a za vámi cennou radu. S pozdravem, Fritz.

Re: Fakepolice

Napsal: 24 led 2014 16:37
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    c:\windows\system32\mswrmcvi.vbe
    c:\users\Kuba\AppData\Roaming\newnext.me\nengine.dll
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}]
    
    Firefox::
    FF - ProfilePath - c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\
    FF - ExtSQL: 2013-12-12 21:11; gcffxtbr@WeatherBlink.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\gcffxtbr@WeatherBlink.com
    FF - ExtSQL: 2013-12-13 21:41; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
    FF - ExtSQL: 2013-12-13 23:19; 4zffxtbr@VideoDownloadConverter_4z.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
    FF - ExtSQL: 2013-12-15 12:20; {746505DC-0E21-4667-97F8-72EA6BCF5EEF}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
    FF - ExtSQL: 2014-01-06 21:24; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    
    Folder::
    c:\progra~2\VIDEOD~2
    c:\program files (x86)\MyPC Backup
    c:\program files (x86)\Torntv V7.0
    c:\program files (x86)\PANDORA.TV
    c:\users\Kuba\AppData\Roaming\newnext.me
    c:\program files (x86)\VideoDownloadConverter_4z
    c:\users\Kuba\AppData\Roaming\AVG
    c:\programdata\AVG
    c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
    c:\users\Kuba\AppData\Roaming\OpenCandy
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "VideoDownloadConverter Home Page Guard 64 bit"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NextLive"=-
    "DAEMON Tools Lite"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "UpdateP2GShortCut"=-
    "RemoteControl10"=-
    "GrooveMonitor"=-
    "VideoDownloadConverter EPM Support"=-
    "VideoDownloadConverter Search Scope Monitor"=-
    "VideoDownloadConverter_4z Browser Plugin Loader"=-
    "VideoDownloadConverter_4z Browser Plugin Loader 64"=-
    "Adobe ARM"=-
    "mswrmcviSrv"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{48586425-6bb7-4f51-8dc6-38c88e3ebb58}"=-
    [-HKEY_CLASSES_ROOT\clsid\{48586425-6bb7-4f51-8dc6-38c88e3ebb58}]
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    c:\windows\Tasks\Torntv V7.0-chromeinstaller-dev.job
    c:\windows\Tasks\Torntv V7.0-codedownloader.job
    c:\windows\Tasks\Torntv V7.0-enabler.job
    c:\windows\Tasks\Torntv V7.0-firefoxinstaller.job
    c:\windows\Tasks\Torntv V7.0-updater.job
    
    Driver::
    VideoDownloadConverter_4zService
    SkypeUpdate
    Skype C2C Service
    PanService
    
    AtJob::
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Fakepolice

Napsal: 26 led 2014 20:24
od karelfritz
ComboFix 14-01-22.01 - Kuba . 01. 2014 20:09:15.2.4 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.3962.2596 [GMT 1:00]
Spuštěný z: c:\users\Kuba\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Kuba\Desktop\CFScript.txt
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\Torntv V7.0-codedownloader.job"
"c:\windows\Tasks\Torntv V7.0-enabler.job"
"c:\windows\Tasks\Torntv V7.0-firefoxinstaller.job"
"c:\windows\Tasks\Torntv V7.0-chromeinstaller-dev.job"
"c:\windows\Tasks\Torntv V7.0-updater.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.i
c:\progra~2\VIDEOD~2
c:\progra~2\VIDEOD~2\bar\1.bin\4zauxstb.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zauxstb64.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zbar.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zbprtct.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zbrmon64.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zbrstub.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zbrstub64.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zdatact.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zdlghk.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zdlghk64.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zfeedmg.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zhighin.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zhkstub.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zhtmlmu.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zhttpct.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zidle.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zieovr.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zmedint.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zmlbtn.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zPlugin.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zradio.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zregfft.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zreghk.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zregiet.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zscript.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zskin.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zskplay.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zSrcAs.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4zSrchMn.exe
c:\progra~2\VIDEOD~2\bar\1.bin\4zsrchmr.dll
c:\progra~2\VIDEOD~2\bar\1.bin\4ztpinst.dll
c:\progra~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe
c:\progra~2\VIDEOD~2\bar\1.bin\AppIntegratorStub64.dll
c:\progra~2\VIDEOD~2\bar\1.bin\BOOTSTRAP.JS
c:\progra~2\VIDEOD~2\bar\1.bin\CREXT.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\CrExtP4z.exe
c:\progra~2\VIDEOD~2\bar\1.bin\DPNMNGR.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\EXEMANAGER.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\FF-NativeMessagingDispatcher.dll
c:\progra~2\VIDEOD~2\bar\1.bin\Hpg64.dll
c:\progra~2\VIDEOD~2\bar\1.bin\CHROME.MANIFEST
c:\progra~2\VIDEOD~2\bar\1.bin\chrome\4zffxtbr.jar
c:\progra~2\VIDEOD~2\bar\1.bin\INSTALL.RDF
c:\progra~2\VIDEOD~2\bar\1.bin\installKeys.js
c:\progra~2\VIDEOD~2\bar\1.bin\LOGO.BMP
c:\progra~2\VIDEOD~2\bar\1.bin\NP4zStub.dll
c:\progra~2\VIDEOD~2\bar\1.bin\T8EPMSUP.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\T8EXTEX.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\T8EXTPEX.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\T8HTML.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\T8RES.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\T8TICKER.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\ThirdPartyInstallers\VideoDownloadConverterSetup.exe
c:\progra~2\VIDEOD~2\bar\1.bin\UNIFIEDLOGGING.DLL
c:\progra~2\VIDEOD~2\bar\1.bin\VERIFY.DLL
c:\progra~2\VIDEOD~2\bar\gen1\COMMON.T8S
c:\progra~2\VIDEOD~2\bar\IE9Mesg\COMMON.T8S
c:\progra~2\VIDEOD~2\bar\Message\COMMON.T8S
c:\progra~2\VIDEOD~2\bar\Settings\s_pid.dat
c:\program files (x86)\MyPC Backup
c:\program files (x86)\MyPC Backup\DEL_UnRegisterExtensions.exe
c:\program files (x86)\PANDORA.TV
c:\program files (x86)\PANDORA.TV\PanService\avcodec-53.dll
c:\program files (x86)\PANDORA.TV\PanService\avformat-53.dll
c:\program files (x86)\PANDORA.TV\PanService\avutil-51.dll
c:\program files (x86)\PANDORA.TV\PanService\crossdomain.xml
c:\program files (x86)\PANDORA.TV\PanService\killp.exe
c:\program files (x86)\PANDORA.TV\PanService\KMPElevateExecutor.exe
c:\program files (x86)\PANDORA.TV\PanService\KMPProcess.exe
c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe
c:\program files (x86)\PANDORA.TV\PanService\KMPServiceStarter.exe
c:\program files (x86)\PANDORA.TV\PanService\libupnp.dll
c:\program files (x86)\PANDORA.TV\PanService\msvcp100.dll
c:\program files (x86)\PANDORA.TV\PanService\msvcr100.dll
c:\program files (x86)\PANDORA.TV\PanService\noname.gif
c:\program files (x86)\PANDORA.TV\PanService\PanConf.ini
c:\program files (x86)\PANDORA.TV\PanService\PanStreamer.dll
c:\program files (x86)\PANDORA.TV\PanService\Proxy.dll
c:\program files (x86)\PANDORA.TV\PanService\pthreadVC2.dll
c:\program files (x86)\PANDORA.TV\PanService\unins000.dat
c:\program files (x86)\PANDORA.TV\PanService\unins000.exe
c:\program files (x86)\PANDORA.TV\PanService\UnistAX.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zauxstb.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zauxstb64.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbprtct.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrstub.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrstub64.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zdatact.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zdlghk.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zdlghk64.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zfeedmg.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zhighin.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zhkstub.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zhtmlmu.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zhttpct.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zidle.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zieovr.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zmedint.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zmlbtn.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zPlugin.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zradio.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zregfft.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zreghk.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zregiet.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zscript.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zskin.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zskplay.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrchMn.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zsrchmr.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4ztpinst.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\AppIntegrator64.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\AppIntegratorStub64.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\BOOTSTRAP.JS
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\CREXT.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\CrExtP4z.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\DPNMNGR.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\EXEMANAGER.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\FF-NativeMessagingDispatcher.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\Hpg64.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\CHROME.MANIFEST
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\chrome\4zffxtbr.jar
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\INSTALL.RDF
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\installKeys.js
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\LOGO.BMP
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\T8EPMSUP.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\T8EXTEX.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\T8EXTPEX.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\T8HTML.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\T8RES.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\T8TICKER.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\ThirdPartyInstallers\VideoDownloadConverterSetup.exe
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\UNIFIEDLOGGING.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\VERIFY.DLL
c:\program files (x86)\VideoDownloadConverter_4z\bar\gen1\COMMON.T8S
c:\program files (x86)\VideoDownloadConverter_4z\bar\IE9Mesg\COMMON.T8S
c:\program files (x86)\VideoDownloadConverter_4z\bar\Message\COMMON.T8S
c:\program files (x86)\VideoDownloadConverter_4z\bar\Settings\s_pid.dat
c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}\{D3742F82-1C1A-4DCC-ABBD-0E831C0185CC}.msi
c:\programdata\AVG
c:\programdata\AVG\AWL\AvgRep.xml
c:\programdata\AVG\AWL\Program Statistics\ProgramStatistics.2013.tudb
c:\programdata\AVG\AWL\TUProgMan.10.tudb
c:\programdata\AVG\AWL\TUProgManagerCache.10.tudb
c:\programdata\AVG\AWL\TUTuningIndex.10.2.tudb
c:\programdata\AVG\AWL\TUUtilitiesSvc.13.tudb
c:\programdata\AVG\AWL2014\TUReportData.10.tudb
c:\users\Kuba\AppData\Roaming\AVG
c:\users\Kuba\AppData\Roaming\newnext.me
c:\users\Kuba\AppData\Roaming\newnext.me\cache\spark.bin
c:\users\Kuba\AppData\Roaming\newnext.me\nengine.cookie
c:\users\Kuba\AppData\Roaming\newnext.me\nengine.dll
c:\users\Kuba\AppData\Roaming\OpenCandy
c:\users\Kuba\AppData\Roaming\OpenCandy\100370EB1EEC4EFCAC91DA3E21F6C441\avg_tuht_stf_cs_2014_206_CZ.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_PanService
-------\Service_Skype C2C Service
-------\Service_SkypeUpdate
-------\Service_VideoDownloadConverter_4zService
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-26 do 2014-01-26 )))))))))))))))))))))))))))))))
.
.
2014-01-26 19:16 . 2014-01-26 19:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-26 17:18 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6B34B500-D98A-49EC-B1DE-258D49CD0253}\mpengine.dll
2014-01-21 09:59 . 2014-01-21 09:59 -------- d-----w- c:\users\Kuba\AppData\Local\Qualcomm Atheros
2014-01-21 09:58 . 2014-01-21 09:58 -------- d-----w- c:\windows\LastGood.Tmp
2014-01-16 13:19 . 2014-01-16 13:21 -------- d-----w- c:\program files\trend micro
2014-01-16 13:19 . 2014-01-16 13:19 -------- d-----w- C:\rsit
2014-01-15 19:50 . 2013-12-07 06:37 688640 ----a-w- c:\windows\system32\WSShared.dll
2014-01-15 19:50 . 2013-12-07 06:37 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 19:50 . 2013-12-07 05:15 562688 ----a-w- c:\windows\SysWow64\WSShared.dll
2014-01-15 19:50 . 2013-12-07 05:15 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 18:21 . 2013-10-31 05:56 915968 ----a-w- c:\windows\system32\MPSSVC.dll
2014-01-15 18:21 . 2013-10-31 05:56 758784 ----a-w- c:\windows\system32\FirewallAPI.dll
2014-01-15 18:21 . 2013-10-31 04:01 550400 ----a-w- c:\windows\SysWow64\FirewallAPI.dll
2014-01-15 18:21 . 2013-10-28 05:50 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-01-15 18:21 . 2013-10-28 04:05 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-01-15 18:21 . 2013-10-13 20:49 100696 ----a-w- c:\windows\system32\drivers\disk.sys
2014-01-15 18:21 . 2013-08-27 05:21 227840 ----a-w- c:\windows\system32\WebClnt.dll
2014-01-15 18:21 . 2013-08-27 05:19 104448 ----a-w- c:\windows\system32\davclnt.dll
2014-01-15 18:21 . 2013-08-26 22:29 199168 ----a-w- c:\windows\SysWow64\WebClnt.dll
2014-01-15 18:21 . 2013-08-26 22:28 86016 ----a-w- c:\windows\SysWow64\davclnt.dll
2014-01-15 18:21 . 2013-10-31 03:42 74752 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2014-01-11 00:04 . 2013-12-10 21:25 583 --s-a-w- c:\windows\SysWow64\mswrmcvi.vbe
2014-01-11 00:04 . 2013-12-10 21:25 5453 --s-a-w- c:\windows\SysWow64\msqmrljg.vbe
2014-01-11 00:04 . 2013-12-10 21:25 1645 --s-a-w- c:\windows\SysWow64\msiknm.vbe
2014-01-11 00:04 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\SysWow64\nircmdc.exe
2014-01-10 23:54 . 2014-01-10 23:54 -------- d-----w- c:\program files (x86)\Anvisoft
2014-01-10 23:45 . 2002-08-29 17:33 319488 ----a-r- c:\windows\SysWow64\MafiaSetup.exe
2014-01-10 23:45 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2014-01-10 23:42 . 2014-01-16 12:12 -------- d-----w- c:\program files\Mafia
2014-01-10 23:41 . 2002-08-29 17:33 319488 ----a-r- c:\users\Kuba\AppData\Roaming\MafiaSetup.exe
2014-01-10 18:13 . 2014-01-10 19:42 -------- d-----w- c:\users\Kuba\AppData\Roaming\BSplayer
2014-01-10 18:13 . 2014-01-10 18:13 -------- d-----w- c:\users\Kuba\AppData\Roaming\BSplayer Pro
2014-01-10 18:13 . 2014-01-10 18:13 -------- d-----w- c:\program files (x86)\Webteh
2014-01-10 02:13 . 2014-01-10 23:46 -------- d-----w- c:\program files (x86)\VideoPlayerV3
2014-01-09 20:31 . 2014-01-09 20:33 -------- d-----w- C:\BMW M3 Challenge
2014-01-09 13:32 . 2014-01-24 10:21 -------- d-----w- c:\users\Kuba\.xmoto
2014-01-09 13:32 . 2014-01-23 21:01 -------- d-----w- c:\program files (x86)\XMoto
2014-01-06 20:24 . 2014-01-09 08:51 -------- d-----w- c:\users\Kuba\AppData\Roaming\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----r- c:\program files (x86)\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----w- c:\programdata\Skype
2014-01-06 20:21 . 2014-01-23 20:37 -------- d-----w- c:\program files (x86)\Counter-Strike 1.6 Non-Steam
2014-01-04 22:51 . 2014-01-04 22:52 -------- d-----w- c:\users\Guest
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-19 07:33 . 2013-12-13 19:06 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-01-17 00:48 . 2013-12-25 10:25 86054176 ----a-w- c:\windows\system32\MRT.exe
2014-01-10 22:51 . 2013-12-25 09:46 78336 ----a-w- c:\windows\SysWow64\rp.dll
2014-01-09 08:02 . 2012-07-26 08:14 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-09 08:02 . 2012-07-26 08:14 694240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-24 21:29 . 2013-12-24 21:29 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-12-13 17:55 . 2013-12-13 17:55 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-12-12 08:31 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-11-23 06:43 . 2013-12-25 21:02 420864 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-23 05:05 . 2013-12-25 21:02 368640 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-06 23:18 . 2013-12-13 18:59 4036608 ----a-w- c:\windows\system32\win32k.sys
2013-11-01 05:38 . 2013-12-25 20:57 312320 ----a-w- c:\windows\system32\msieftp.dll
2013-11-01 03:49 . 2013-12-25 20:57 273408 ----a-w- c:\windows\SysWow64\msieftp.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110411901140}]
c:\program files (x86)\Torntv V7.0\Torntv V7.0-bho.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
2014-01-22 14:28 429416 ----a-w- c:\programdata\ShopperPro\ShopperPro.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-10-20 16:47 627712 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-25 642816]
"YouCam Tray"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2012-10-31 168464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\System32\drivers\amdkmpfd.sys;c:\windows\SYSNATIVE\drivers\amdkmpfd.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
S2 DCE;Distributed Computing Experiment;c:\program files\DCE\dce.exe;c:\program files\DCE\dce.exe [x]
S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe;c:\windows\SYSNATIVE\SAsrv.exe [x]
S2 Start8;Stardock Start8;c:\program files (x86)\Stardock\Start8\Start8Srv.exe;c:\program files (x86)\Stardock\Start8\Start8Srv.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-16 19:26 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 18:15]
.
2014-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 18:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-10-20 16:47 774144 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2013-01-31 36352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-04-24 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-04-24 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-04-24 442352]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2013-02-04 899680]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2013-03-05 1647616]
"RtsFT"="RTFTrack.exe" [2013-04-24 6339656]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-08-17 17097200]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-08-17 193008]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\
FF - ExtSQL: 2013-12-12 21:11; gcffxtbr@WeatherBlink.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\gcffxtbr@WeatherBlink.com
FF - ExtSQL: 2013-12-13 21:41; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF - ExtSQL: 2013-12-13 23:19; 4zffxtbr@VideoDownloadConverter_4z.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
FF - ExtSQL: 2013-12-15 12:20; {746505DC-0E21-4667-97F8-72EA6BCF5EEF}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
FF - ExtSQL: 2014-01-06 21:24; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{312f84fb-8970-4fd3-bddb-7012eac4afc9} - c:\progra~2\VIDEOD~2\bar\1.bin\4zbar.dll
BHO-{c547c6c2-561b-4169-a2a5-20ba771ca93b} - c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
Toolbar-Locked - (no file)
AddRemove-4F6D5E84-5826-4394-9F40-3A9A19165651_is1 - c:\program files (x86)\PANDORA.TV\PanService\unins000.exe
AddRemove-Mafia Game - c:\windows\system32\MafiaSetup.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\windows\SysWOW64\SAsrv.exe
c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-01-26 20:22:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-26 19:22
.
Před spuštěním: 871 633 989 632 bytes free
Po spuštění: 871 633 620 992 bytes free
.
- - End Of File - - FC77B263D6C3DE5BAED1D12A8BC67F25
5FB38429D5D77768867C76DCBDB35194

Re: Fakepolice

Napsal: 27 led 2014 06:42
od vyosek
Jeste jeden CFScript.txt, postup stejny

Kód: Vybrat vše

KillAll::

Firefox::
FF - ProfilePath - c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\
FF - ExtSQL: 2013-12-12 21:11; gcffxtbr@WeatherBlink.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\gcffxtbr@WeatherBlink.com
FF - ExtSQL: 2013-12-13 21:41; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF - ExtSQL: 2013-12-13 23:19; 4zffxtbr@VideoDownloadConverter_4z.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
FF - ExtSQL: 2013-12-15 12:20; {746505DC-0E21-4667-97F8-72EA6BCF5EEF}; 

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Collect::
c:\windows\SysWow64\mswrmcvi.vbe
c:\windows\SysWow64\msqmrljg.vbe
c:\windows\SysWow64\msiknm.vbe

Reboot::

Re: Fakepolice

Napsal: 27 led 2014 19:40
od karelfritz
ComboFix 14-01-22.01 - Kuba . 01. 2014 18:50:38.3.4 - x64
Microsoft Windows 8 6.2.9200.0.1250.420.1029.18.3962.2379 [GMT 1:00]
Spuštěný z: c:\users\Kuba\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Kuba\Desktop\CFScript.txt
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-27 do 2014-01-27 )))))))))))))))))))))))))))))))
.
.
2014-01-27 17:56 . 2014-01-27 17:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-27 17:24 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DE8F60F4-6034-4CEF-B13C-12F5CCE94D55}\mpengine.dll
2014-01-26 19:23 . 2014-01-27 17:57 -------- d-----w- c:\users\Kuba\AppData\Local\temp
2014-01-21 09:59 . 2014-01-21 09:59 -------- d-----w- c:\users\Kuba\AppData\Local\Qualcomm Atheros
2014-01-21 09:58 . 2014-01-21 09:58 -------- d-----w- c:\windows\LastGood.Tmp
2014-01-16 13:19 . 2014-01-16 13:21 -------- d-----w- c:\program files\trend micro
2014-01-16 13:19 . 2014-01-16 13:19 -------- d-----w- C:\rsit
2014-01-15 19:50 . 2013-12-07 06:37 688640 ----a-w- c:\windows\system32\WSShared.dll
2014-01-15 19:50 . 2013-12-07 06:37 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 19:50 . 2013-12-07 05:15 562688 ----a-w- c:\windows\SysWow64\WSShared.dll
2014-01-15 19:50 . 2013-12-07 05:15 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 18:21 . 2013-10-31 05:56 915968 ----a-w- c:\windows\system32\MPSSVC.dll
2014-01-15 18:21 . 2013-10-31 05:56 758784 ----a-w- c:\windows\system32\FirewallAPI.dll
2014-01-15 18:21 . 2013-10-31 04:01 550400 ----a-w- c:\windows\SysWow64\FirewallAPI.dll
2014-01-15 18:21 . 2013-10-28 05:50 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-01-15 18:21 . 2013-10-28 04:05 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-01-15 18:21 . 2013-10-13 20:49 100696 ----a-w- c:\windows\system32\drivers\disk.sys
2014-01-15 18:21 . 2013-08-27 05:21 227840 ----a-w- c:\windows\system32\WebClnt.dll
2014-01-15 18:21 . 2013-08-27 05:19 104448 ----a-w- c:\windows\system32\davclnt.dll
2014-01-15 18:21 . 2013-08-26 22:29 199168 ----a-w- c:\windows\SysWow64\WebClnt.dll
2014-01-15 18:21 . 2013-08-26 22:28 86016 ----a-w- c:\windows\SysWow64\davclnt.dll
2014-01-15 18:21 . 2013-10-31 03:42 74752 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2014-01-11 00:04 . 2013-12-10 21:25 583 ------w- c:\windows\SysWow64\mswrmcvi.vbe
2014-01-11 00:04 . 2013-12-10 21:25 5453 ------w- c:\windows\SysWow64\msqmrljg.vbe
2014-01-11 00:04 . 2013-12-10 21:25 1645 ------w- c:\windows\SysWow64\msiknm.vbe
2014-01-11 00:04 . 2013-08-11 14:40 43520 --s-a-w- c:\windows\SysWow64\nircmdc.exe
2014-01-10 23:54 . 2014-01-10 23:54 -------- d-----w- c:\program files (x86)\Anvisoft
2014-01-10 23:45 . 2002-08-29 17:33 319488 ----a-r- c:\windows\SysWow64\MafiaSetup.exe
2014-01-10 23:45 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2014-01-10 23:42 . 2014-01-16 12:12 -------- d-----w- c:\program files\Mafia
2014-01-10 23:41 . 2002-08-29 17:33 319488 ----a-r- c:\users\Kuba\AppData\Roaming\MafiaSetup.exe
2014-01-10 18:13 . 2014-01-10 19:42 -------- d-----w- c:\users\Kuba\AppData\Roaming\BSplayer
2014-01-10 18:13 . 2014-01-10 18:13 -------- d-----w- c:\users\Kuba\AppData\Roaming\BSplayer Pro
2014-01-10 18:13 . 2014-01-10 18:13 -------- d-----w- c:\program files (x86)\Webteh
2014-01-10 02:13 . 2014-01-10 23:46 -------- d-----w- c:\program files (x86)\VideoPlayerV3
2014-01-09 20:31 . 2014-01-09 20:33 -------- d-----w- C:\BMW M3 Challenge
2014-01-09 13:32 . 2014-01-24 10:21 -------- d-----w- c:\users\Kuba\.xmoto
2014-01-09 13:32 . 2014-01-23 21:01 -------- d-----w- c:\program files (x86)\XMoto
2014-01-06 20:24 . 2014-01-09 08:51 -------- d-----w- c:\users\Kuba\AppData\Roaming\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----r- c:\program files (x86)\Skype
2014-01-06 20:24 . 2014-01-06 20:24 -------- d-----w- c:\programdata\Skype
2014-01-06 20:21 . 2014-01-26 19:28 -------- d-----w- c:\program files (x86)\Counter-Strike 1.6 Non-Steam
2014-01-04 22:51 . 2014-01-04 22:52 -------- d-----w- c:\users\Guest
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-19 07:33 . 2013-12-13 19:06 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-01-17 00:48 . 2013-12-25 10:25 86054176 ----a-w- c:\windows\system32\MRT.exe
2014-01-10 22:51 . 2013-12-25 09:46 78336 ----a-w- c:\windows\SysWow64\rp.dll
2014-01-09 08:02 . 2012-07-26 08:14 78296 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-09 08:02 . 2012-07-26 08:14 694240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-24 21:29 . 2013-12-24 21:29 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-12-13 17:55 . 2013-12-13 17:55 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2013-12-12 08:31 . 2012-07-26 08:13 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-11-23 06:43 . 2013-12-25 21:02 420864 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-23 05:05 . 2013-12-25 21:02 368640 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-06 23:18 . 2013-12-13 18:59 4036608 ----a-w- c:\windows\system32\win32k.sys
2013-11-01 05:38 . 2013-12-25 20:57 312320 ----a-w- c:\windows\system32\msieftp.dll
2013-11-01 03:49 . 2013-12-25 20:57 273408 ----a-w- c:\windows\SysWow64\msieftp.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110411901140}]
c:\program files (x86)\Torntv V7.0\Torntv V7.0-bho.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]
c:\progra~2\VIDEOD~2\bar\1.bin\4zbar.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
2014-01-22 14:28 429416 ----a-w- c:\programdata\ShopperPro\ShopperPro.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]
c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll [BU]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-10-20 16:47 627712 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-25 642816]
"YouCam Tray"="c:\program files (x86)\Lenovo\YouCam\YouCamTray.exe" [2012-10-31 168464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"midi2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\System32\drivers\amdkmpfd.sys;c:\windows\SYSNATIVE\drivers\amdkmpfd.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
S2 DCE;Distributed Computing Experiment;c:\program files\DCE\dce.exe;c:\program files\DCE\dce.exe [x]
S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe;c:\windows\SYSNATIVE\SAsrv.exe [x]
S2 Start8;Stardock Start8;c:\program files (x86)\Stardock\Start8\Start8Srv.exe;c:\program files (x86)\Stardock\Start8\Start8Srv.exe [x]
S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-16 19:26 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 18:15]
.
2014-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-25 18:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2013-10-20 16:47 774144 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2013-01-31 36352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-04-24 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-04-24 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-04-24 442352]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2013-02-04 899680]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2013-03-05 1647616]
"RtsFT"="RTFTrack.exe" [2013-04-24 6339656]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-08-17 17097200]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-08-17 193008]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\
FF - ExtSQL: 2013-12-12 21:11; gcffxtbr@WeatherBlink.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\gcffxtbr@WeatherBlink.com
FF - ExtSQL: 2013-12-13 21:41; {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF - ExtSQL: 2013-12-13 23:19; 4zffxtbr@VideoDownloadConverter_4z.com; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
FF - ExtSQL: 2013-12-15 12:20; {746505DC-0E21-4667-97F8-72EA6BCF5EEF}; c:\users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
FF - ExtSQL: 2014-01-06 21:24; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
AddRemove-4F6D5E84-5826-4394-9F40-3A9A19165651_is1 - c:\program files (x86)\PANDORA.TV\PanService\unins000.exe
AddRemove-Mafia Game - c:\windows\system32\MafiaSetup.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\windows\SysWOW64\SAsrv.exe
c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-01-27 19:00:43 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-01-27 18:00
ComboFix2.txt 2014-01-26 19:22
.
Před spuštěním: 871 612 403 712 bytes free
Po spuštění: 871 495 602 176 bytes free
.
- - End Of File - - FF39360FE94813FABFD5A133C87DF6DA
5FB38429D5D77768867C76DCBDB35194

Re: Fakepolice

Napsal: 27 led 2014 20:01
od vyosek
:arrow: Nejak se mu nechce, zkusime jiny zpusob

:arrow: Poprosim o log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100

Re: Fakepolice

Napsal: 28 led 2014 22:36
od karelfritz
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-01-2014 02
Ran by Kuba (administrator) on JAKOB on 28-01-2014 22:31:34
Running from C:\Users\Kuba\Desktop
Windows 8 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
() C:\Program Files\DCE\dce.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Kuba\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [899680 2013-02-04] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2013-03-05] (Conexant Systems, Inc.)
HKLM\...\Run: [RtsFT] - C:\windows\RTFTrack.exe [6339656 2013-04-24] (Realtek semiconductor)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2876816 2013-03-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17097200 2013-08-17] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-08-17] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-04-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-10-31] (CyberLink Corp.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe -update plugin [839560 2013-12-13] (Adobe Systems Incorporated)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM - {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - DefaultScope {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain. ... earchTerms}
SearchScopes: HKCU - DefaultScope {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL =
SearchScopes: HKCU - {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL =
SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain. ... earchTerms}
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Shopper Pro - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro64.dll (Goobzo Ltd.)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: Torntv V7.0 - {11111111-1111-1111-1111-110411901140} - C:\Program Files (x86)\Torntv V7.0\Torntv V7.0-bho.dll No File
BHO-x32: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbar.dll No File
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Shopper Pro - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll No File
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default
FF user.js: detected! => C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @VideoDownloadConverter_4z.com/Plugin - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll No File
FF Plugin-x32: @VideoDownloadConverter_ScriptHelper.com/Plugin - C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll (Mindspark)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WeatherBlink.com/Plugin - C:\Program Files (x86)\WeatherBlink\bar\1.bin\NPgcStub.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: intel.com/AppUp - C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: VideoDownloadConverter - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com [2013-12-15]
FF Extension: WeatherBlink - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\Extensions\gcffxtbr@WeatherBlink.com [2014-01-22]
FF Extension: Shopper-Pro - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [2013-12-25]
FF Extension: Download Statusbar - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013-12-13]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-01-06]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-01-06]

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/?clid=16194
CHR Extension: (Dokumenty Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-25]
CHR Extension: (Disk Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-25]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-01-11]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-01-11]
CHR Extension: (YouTube) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-25]
CHR Extension: (Spry this!) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cigiagpbkapepgklncnajbakkpkopmam [2014-01-11]
CHR Extension: (Vyhledávání Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-25]
CHR Extension: (CSS reload!) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfohdbmjdkfijghgklbickfnaepghgba [2014-01-11]
CHR Extension: (Skype Click to Call) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-01-06]
CHR Extension: (Peněženka Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-25]
CHR Extension: (ShopperPro) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhagnahfpegocdhlopgljpaafeogmcc [2013-12-25]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-01-11]
CHR Extension: (Gmail) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-25]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]

==================== Services (Whitelisted) =================

U2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-25] (Qualcomm Atheros Commnucations)
U2 DCE; C:\Program Files\DCE\dce.exe [59392 2013-12-18] ()
U2 ETDService; C:\Program Files\Elantech\ETDService.exe [92160 2013-02-25] (ELAN Microelectronics Corp.)
U2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
U2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
U2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [142960 2013-03-19] (Stardock Software, Inc)
U2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
U2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-01-25] (Atheros)

==================== Drivers (Whitelisted) ====================

U0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36520 2012-09-13] (Advanced Micro Devices, Inc.)
U3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-25] (Qualcomm Atheros)
U3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
U1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-12-24] (Disc Soft Ltd)
U3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243144 2013-04-24] (Realtek Semiconductor Corp.)
U3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
U3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-28 22:30 - 2014-01-28 22:31 - 00016389 _____ C:\Users\Kuba\Desktop\Addition.txt
2014-01-28 22:29 - 2014-01-28 22:31 - 00016786 _____ C:\Users\Kuba\Desktop\FRST.txt
2014-01-28 22:29 - 2014-01-28 22:29 - 00000000 ____D C:\FRST
2014-01-28 22:25 - 2014-01-28 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Desktop\FRSTLauncher.exe
2014-01-28 22:24 - 2014-01-28 22:24 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Downloads\Nepotvrzeno 239438.crdownload
2014-01-28 22:23 - 2014-01-28 22:23 - 02079232 _____ (Farbar) C:\Users\Kuba\Desktop\FRST64.exe
2014-01-28 22:23 - 2014-01-28 22:23 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Downloads\Nepotvrzeno 558986.crdownload
2014-01-27 20:27 - 2014-01-27 20:44 - 156677518 _____ C:\Users\Kuba\Downloads\Nessa-Nikola-Jiraskova,-super-scena-a-hlavne-konec,-Porno.mp4
2014-01-27 19:00 - 2014-01-27 19:00 - 00018756 _____ C:\ComboFix.txt
2014-01-27 18:50 - 2014-01-27 18:50 - 00001204 _____ C:\CF-Submit.htm
2014-01-23 22:48 - 2014-01-23 23:18 - 532790941 _____ C:\Users\Kuba\Downloads\školní-atlas-dnešního-světa.zip
2014-01-23 15:04 - 2014-01-23 15:04 - 00003082 _____ C:\windows\System32\Tasks\{72579874-B093-4CBC-829F-8944C9FBA38E}
2014-01-23 14:41 - 2014-01-23 14:41 - 00050450 _____ C:\Users\Kuba\Desktop\ComboFix.txt
2014-01-23 14:26 - 2014-01-27 19:39 - 00000000 ____D C:\Qoobox
2014-01-23 14:26 - 2014-01-26 20:16 - 00000000 ____D C:\windows\erdnt
2014-01-23 14:26 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
2014-01-23 14:26 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
2014-01-23 14:26 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-01-23 14:26 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-01-23 14:26 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-01-23 14:26 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\windows\SWXCACLS.exe
2014-01-23 14:26 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
2014-01-23 14:26 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
2014-01-23 14:26 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
2014-01-23 14:24 - 2014-01-23 14:24 - 05173757 ____R (Swearware) C:\Users\Kuba\Desktop\ComboFix.exe
2014-01-23 14:22 - 2014-01-23 14:22 - 00001986 _____ C:\Users\Kuba\Desktop\Rkill.txt
2014-01-23 14:18 - 2014-01-23 14:19 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Kuba\Desktop\rkill.com
2014-01-21 10:59 - 2014-01-21 10:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\Qualcomm Atheros
2014-01-21 10:58 - 2014-01-21 10:58 - 00000000 ____D C:\windows\LastGood.Tmp
2014-01-16 22:46 - 2014-01-16 22:46 - 00000848 _____ C:\Users\Kuba\Desktop\TornTV.lnk
2014-01-16 22:45 - 2014-01-16 22:46 - 00446816 _____ C:\Users\Kuba\Downloads\This_is_England[2006]DvDrip[Eng]_FXG.exe
2014-01-16 17:15 - 2014-01-16 17:15 - 01665329 _____ C:\Users\Kuba\Downloads\Mafia-Crack---No-CD.rar
2014-01-16 17:13 - 2014-01-16 17:15 - 08891697 _____ (Lingtion earning Studio ) C:\Users\Kuba\Downloads\Mafia-crack.exe
2014-01-16 14:19 - 2014-01-16 14:21 - 00000000 ____D C:\Program Files\trend micro
2014-01-16 14:19 - 2014-01-16 14:19 - 00935175 _____ C:\Users\Kuba\Downloads\RSITx64.exe
2014-01-16 14:19 - 2014-01-16 14:19 - 00000000 ____D C:\rsit
2014-01-16 13:13 - 2014-01-16 13:13 - 00000788 _____ C:\Users\Kuba\Desktop\Mafia.lnk
2014-01-16 13:13 - 2014-01-16 13:13 - 00000788 _____ C:\Users\Guest\Desktop\Mafia.lnk
2014-01-16 13:13 - 2014-01-16 13:13 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mafia
2014-01-16 10:03 - 2014-01-16 10:04 - 00000000 ____D C:\Users\Kuba\Desktop\Hudba
2014-01-15 23:17 - 2014-01-15 23:17 - 00000000 ____D C:\Users\Kuba\Downloads\Subs
2014-01-15 20:50 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2014-01-15 20:50 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 20:50 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2014-01-15 20:50 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 19:21 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
2014-01-15 19:21 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\windows\system32\FirewallAPI.dll
2014-01-15 19:21 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\windows\SysWOW64\FirewallAPI.dll
2014-01-15 19:21 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mpsdrv.sys
2014-01-15 19:21 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\windows\system32\SHCore.dll
2014-01-15 19:21 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\windows\SysWOW64\SHCore.dll
2014-01-15 19:21 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\disk.sys
2014-01-15 19:21 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2014-01-15 19:21 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2014-01-15 19:21 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2014-01-15 19:21 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2014-01-15 11:14 - 2014-01-24 15:06 - 00000000 ____D C:\Users\Kuba\Desktop\Filmy
2014-01-15 08:55 - 2014-01-15 08:55 - 00418107 _____ C:\Users\Kuba\Downloads\nj.jpeg
2014-01-15 02:19 - 2014-01-23 02:30 - 00000270 _____ C:\Users\Kuba\Desktop\VypinacPC.ini
2014-01-14 22:42 - 2014-01-14 22:42 - 00349766 _____ C:\Users\Kuba\Downloads\VypinacPC_v1.2.zip
2014-01-14 22:42 - 2012-04-19 11:06 - 00617984 _____ () C:\Users\Kuba\Desktop\VypinacPC.exe
2014-01-11 01:14 - 2014-01-11 01:15 - 00000000 ____D C:\Users\Kuba\Desktop\smg
2014-01-11 01:04 - 2013-12-10 22:25 - 00005453 ____N C:\windows\SysWOW64\msqmrljg.vbe
2014-01-11 01:04 - 2013-12-10 22:25 - 00001645 ____N C:\windows\SysWOW64\msiknm.vbe
2014-01-11 01:04 - 2013-12-10 22:25 - 00000583 ____N C:\windows\SysWOW64\mswrmcvi.vbe
2014-01-11 01:04 - 2013-08-11 15:40 - 00043520 ____S (NirSoft) C:\windows\SysWOW64\nircmdc.exe
2014-01-11 00:57 - 2014-01-11 00:57 - 00003108 _____ C:\windows\System32\Tasks\{6E99D240-AFF6-486C-86A5-4325AA5EA4BD}
2014-01-11 00:54 - 2014-01-11 00:54 - 01381864 _____ (Anvisoft Corporation) C:\Users\Kuba\Downloads\AnviUnIns.exe
2014-01-11 00:54 - 2014-01-11 00:54 - 00000000 ____D C:\Program Files (x86)\Anvisoft
2014-01-11 00:45 - 2002-08-29 18:33 - 00319488 ____R () C:\windows\SysWOW64\MafiaSetup.exe
2014-01-11 00:45 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\windows\IsUninst.exe
2014-01-11 00:42 - 2014-01-16 13:12 - 00000000 ____D C:\Program Files\Mafia
2014-01-11 00:41 - 2002-08-29 18:33 - 00319488 ____R () C:\Users\Kuba\AppData\Roaming\MafiaSetup.exe
2014-01-10 23:55 - 2014-01-10 23:55 - 00000000 ____D C:\Users\Kuba\Downloads\MAFIA
2014-01-10 19:15 - 2014-01-10 19:15 - 00001133 _____ C:\Users\Public\Desktop\BS.Player FREE.lnk
2014-01-10 19:13 - 2014-01-10 20:42 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\BSplayer
2014-01-10 19:13 - 2014-01-10 19:13 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\BSplayer Pro
2014-01-10 19:13 - 2014-01-10 19:13 - 00000000 ____D C:\Program Files (x86)\Webteh
2014-01-10 19:12 - 2014-01-10 19:12 - 10511384 _____ C:\Users\Kuba\Downloads\bsplayer_installer.exe
2014-01-10 03:13 - 2014-01-11 00:46 - 00000000 ____D C:\Program Files (x86)\VideoPlayerV3
2014-01-09 21:35 - 2014-01-09 21:35 - 00000000 ____D C:\Users\Kuba\Documents\BMW
2014-01-09 21:31 - 2014-01-09 21:33 - 00000000 ____D C:\BMW M3 Challenge
2014-01-09 14:32 - 2014-01-28 12:40 - 00000000 ____D C:\Users\Kuba\.xmoto
2014-01-09 14:32 - 2014-01-23 22:01 - 00000000 ____D C:\Program Files (x86)\XMoto
2014-01-09 14:32 - 2014-01-09 14:32 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\X-Moto
2014-01-08 22:13 - 2014-01-08 22:13 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2014-01-08 22:12 - 2014-01-08 22:12 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-01-08 20:20 - 2014-01-08 20:20 - 00003174 _____ C:\windows\System32\Tasks\{563777A6-1806-4CEE-8A1E-5D28EB35FF79}
2014-01-08 20:18 - 2014-01-08 20:18 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Kuba\Downloads\SkypeSetup.exe
2014-01-08 15:59 - 2014-01-08 15:59 - 00113016 _____ C:\Users\Kuba\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-08 08:50 - 2014-01-08 08:50 - 00000000 ____D C:\Users\Kuba\Downloads\documents-export-2014-01-07
2014-01-07 23:44 - 2014-01-07 23:44 - 00570856 _____ C:\Users\Kuba\Downloads\ZSV-Maturitni-otazky.rar
2014-01-07 23:44 - 2014-01-07 23:44 - 00443400 _____ C:\Users\Kuba\Downloads\ZSV---maturitní-otázky.rar
2014-01-07 23:43 - 2014-01-07 23:44 - 08429477 _____ C:\Users\Kuba\Downloads\zsv-maturitní-otázky.rar
2014-01-07 10:10 - 2014-01-28 14:39 - 00000000 ____D C:\Users\Kuba\Desktop\Škola
2014-01-06 21:24 - 2014-01-09 09:51 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Skype
2014-01-06 21:24 - 2014-01-06 21:24 - 00002731 _____ C:\Users\Public\Desktop\Skype.lnk
2014-01-06 21:24 - 2014-01-06 21:24 - 00000000 ___RD C:\Program Files (x86)\Skype
2014-01-06 21:24 - 2014-01-06 21:24 - 00000000 ____D C:\ProgramData\Skype
2014-01-06 21:23 - 2014-01-06 21:23 - 00002144 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Counter-Strike 1.6 Non-Steam.lnk
2014-01-06 21:23 - 2014-01-06 21:23 - 00002140 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\CS 1.6 Servery.lnk
2014-01-06 21:21 - 2014-01-27 19:57 - 00000000 ____D C:\Program Files (x86)\Counter-Strike 1.6 Non-Steam
2014-01-06 21:09 - 2014-01-06 21:10 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Kuba\Downloads\SkypeSetupFull.exe
2014-01-04 23:52 - 2014-01-04 23:52 - 00001421 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Adobe
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest\AppData\Local\VirtualStore
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest\AppData\Local\Packages
2014-01-04 23:51 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest
2014-01-04 23:51 - 2014-01-04 23:51 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Šablony
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Soubory cookie
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Poslední
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Okolní tiskárny
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Okolní síť
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Nabídka Start
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Dokumenty
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Documents\Obrázky
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Documents\Hudba
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Documents\Filmy
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Data aplikací
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\AppData\Local\Data aplikací
2014-01-04 23:51 - 2013-12-13 22:30 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-01-04 23:51 - 2013-08-17 16:25 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-01-04 23:51 - 2013-08-17 16:13 - 00001151 _____ C:\Users\Guest\Desktop\Cyberlink Power2Go.lnk
2014-01-04 23:51 - 2013-08-17 16:13 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-01-04 23:51 - 2013-02-04 07:18 - 00000189 _____ C:\Users\Guest\Desktop\Lenovo Telephony Start Now.url
2014-01-04 23:51 - 2012-07-26 09:13 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-04 23:51 - 2012-07-26 09:13 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-01-02 11:25 - 2014-01-02 11:25 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1 (3).exe
2014-01-02 11:21 - 2014-01-02 11:22 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1.exe
2014-01-02 11:21 - 2014-01-02 11:22 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1 (2).exe
2014-01-02 11:21 - 2014-01-02 11:22 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1 (1).exe

==================== One Month Modified Files and Folders =======

2014-01-28 22:31 - 2014-01-28 22:30 - 00016389 _____ C:\Users\Kuba\Desktop\Addition.txt
2014-01-28 22:31 - 2014-01-28 22:29 - 00016786 _____ C:\Users\Kuba\Desktop\FRST.txt
2014-01-28 22:29 - 2014-01-28 22:29 - 00000000 ____D C:\FRST
2014-01-28 22:25 - 2014-01-28 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Desktop\FRSTLauncher.exe
2014-01-28 22:25 - 2013-12-25 19:15 - 00000960 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-28 22:24 - 2014-01-28 22:24 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Downloads\Nepotvrzeno 239438.crdownload
2014-01-28 22:23 - 2014-01-28 22:23 - 02079232 _____ (Farbar) C:\Users\Kuba\Desktop\FRST64.exe
2014-01-28 22:23 - 2014-01-28 22:23 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Downloads\Nepotvrzeno 558986.crdownload
2014-01-28 22:23 - 2013-12-13 20:01 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\ClassicShell
2014-01-28 22:00 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\sru
2014-01-28 20:46 - 2012-07-26 09:12 - 00000000 ____D C:\windows\system32\NDF
2014-01-28 20:15 - 2013-08-17 15:33 - 01290667 _____ C:\windows\WindowsUpdate.log
2014-01-28 19:55 - 2013-12-25 09:38 - 00000000 ____D C:\Users\Kuba\AppData\Local\CrashDumps
2014-01-28 19:25 - 2013-12-25 19:15 - 00000956 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-28 14:39 - 2014-01-07 10:10 - 00000000 ____D C:\Users\Kuba\Desktop\Škola
2014-01-28 12:40 - 2014-01-09 14:32 - 00000000 ____D C:\Users\Kuba\.xmoto
2014-01-28 12:00 - 2013-08-17 16:16 - 00728526 _____ C:\windows\system32\perfh005.dat
2014-01-28 12:00 - 2013-08-17 16:16 - 00148542 _____ C:\windows\system32\perfc005.dat
2014-01-28 12:00 - 2012-07-26 08:28 - 01717852 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-28 11:21 - 2013-12-12 10:22 - 03489280 _____ C:\Users\Public\CAFADEBUG.log
2014-01-28 11:21 - 2012-07-26 08:22 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-28 11:03 - 2013-12-13 21:49 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\vlc
2014-01-27 20:44 - 2014-01-27 20:27 - 156677518 _____ C:\Users\Kuba\Downloads\Nessa-Nikola-Jiraskova,-super-scena-a-hlavne-konec,-Porno.mp4
2014-01-27 19:57 - 2014-01-06 21:21 - 00000000 ____D C:\Program Files (x86)\Counter-Strike 1.6 Non-Steam
2014-01-27 19:39 - 2014-01-23 14:26 - 00000000 ____D C:\Qoobox
2014-01-27 19:00 - 2014-01-27 19:00 - 00018756 _____ C:\ComboFix.txt
2014-01-27 18:57 - 2013-03-25 22:02 - 00030994 _____ C:\windows\PFRO.log
2014-01-27 18:57 - 2012-07-26 06:26 - 00000215 _____ C:\windows\system.ini
2014-01-27 18:50 - 2014-01-27 18:50 - 00001204 _____ C:\CF-Submit.htm
2014-01-26 20:17 - 2012-07-26 06:26 - 75087872 _____ C:\windows\system32\config\SOFTWARE.bak
2014-01-26 20:17 - 2012-07-26 06:26 - 12582912 _____ C:\windows\system32\config\SYSTEM.bak
2014-01-26 20:17 - 2012-07-26 06:26 - 00737280 _____ C:\windows\system32\config\DEFAULT.bak
2014-01-26 20:17 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\BBI
2014-01-26 20:17 - 2012-07-26 06:26 - 00028672 _____ C:\windows\system32\config\SAM.bak
2014-01-26 20:17 - 2012-07-26 06:26 - 00024576 _____ C:\windows\system32\config\SECURITY.bak
2014-01-26 20:16 - 2014-01-23 14:26 - 00000000 ____D C:\windows\erdnt
2014-01-24 15:06 - 2014-01-15 11:14 - 00000000 ____D C:\Users\Kuba\Desktop\Filmy
2014-01-24 10:09 - 2013-12-25 19:23 - 00000000 ____D C:\Program Files (x86)\ShopperPro
2014-01-23 23:18 - 2014-01-23 22:48 - 532790941 _____ C:\Users\Kuba\Downloads\školní-atlas-dnešního-světa.zip
2014-01-23 22:30 - 2013-12-25 19:23 - 00004152 _____ C:\windows\System32\Tasks\ShopperPro
2014-01-23 22:30 - 2013-12-25 19:23 - 00003560 _____ C:\windows\System32\Tasks\ShopperProUpd
2014-01-23 22:01 - 2014-01-09 14:32 - 00000000 ____D C:\Program Files (x86)\XMoto
2014-01-23 18:55 - 2013-12-12 09:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2014-01-23 15:04 - 2014-01-23 15:04 - 00003082 _____ C:\windows\System32\Tasks\{72579874-B093-4CBC-829F-8944C9FBA38E}
2014-01-23 14:41 - 2014-01-23 14:41 - 00050450 _____ C:\Users\Kuba\Desktop\ComboFix.txt
2014-01-23 14:41 - 2012-07-26 06:37 - 00000000 ___HD C:\Users\Default
2014-01-23 14:24 - 2014-01-23 14:24 - 05173757 ____R (Swearware) C:\Users\Kuba\Desktop\ComboFix.exe
2014-01-23 14:22 - 2014-01-23 14:22 - 00001986 _____ C:\Users\Kuba\Desktop\Rkill.txt
2014-01-23 14:19 - 2014-01-23 14:18 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Kuba\Desktop\rkill.com
2014-01-23 02:30 - 2014-01-15 02:19 - 00000270 _____ C:\Users\Kuba\Desktop\VypinacPC.ini
2014-01-22 13:40 - 2012-07-26 08:21 - 00045098 _____ C:\windows\setupact.log
2014-01-22 06:46 - 2013-12-12 09:35 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Atheros
2014-01-21 11:04 - 2013-12-13 21:06 - 00000000 ____D C:\Users\Kuba\Documents\Youcam
2014-01-21 10:59 - 2014-01-21 10:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\Qualcomm Atheros
2014-01-21 10:58 - 2014-01-21 10:58 - 00000000 ____D C:\windows\LastGood.Tmp
2014-01-20 08:45 - 2013-12-12 09:36 - 00000000 ____D C:\Users\Kuba\Documents\Bluetooth Folder
2014-01-19 08:33 - 2013-12-13 20:06 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-01-18 11:28 - 2012-07-26 09:12 - 00000000 ____D C:\windows\rescache
2014-01-17 06:28 - 2013-12-25 22:08 - 00000000 ____D C:\Program Files (x86)\TornTV.com
2014-01-17 02:00 - 2012-07-26 09:12 - 00000000 ____D C:\windows\WinStore
2014-01-17 01:51 - 2013-12-25 11:25 - 00000000 ____D C:\windows\system32\MRT
2014-01-17 01:48 - 2013-12-25 11:25 - 86054176 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-01-16 22:46 - 2014-01-16 22:46 - 00000848 _____ C:\Users\Kuba\Desktop\TornTV.lnk
2014-01-16 22:46 - 2014-01-16 22:45 - 00446816 _____ C:\Users\Kuba\Downloads\This_is_England[2006]DvDrip[Eng]_FXG.exe
2014-01-16 22:46 - 2013-12-25 22:08 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
2014-01-16 20:28 - 2013-12-25 19:17 - 00002194 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-16 17:15 - 2014-01-16 17:15 - 01665329 _____ C:\Users\Kuba\Downloads\Mafia-Crack---No-CD.rar
2014-01-16 17:15 - 2014-01-16 17:13 - 08891697 _____ (Lingtion earning Studio ) C:\Users\Kuba\Downloads\Mafia-crack.exe
2014-01-16 14:21 - 2014-01-16 14:19 - 00000000 ____D C:\Program Files\trend micro
2014-01-16 14:19 - 2014-01-16 14:19 - 00935175 _____ C:\Users\Kuba\Downloads\RSITx64.exe
2014-01-16 14:19 - 2014-01-16 14:19 - 00000000 ____D C:\rsit
2014-01-16 13:13 - 2014-01-16 13:13 - 00000788 _____ C:\Users\Kuba\Desktop\Mafia.lnk
2014-01-16 13:13 - 2014-01-16 13:13 - 00000788 _____ C:\Users\Guest\Desktop\Mafia.lnk
2014-01-16 13:13 - 2014-01-16 13:13 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mafia
2014-01-16 13:12 - 2014-01-11 00:42 - 00000000 ____D C:\Program Files\Mafia
2014-01-16 10:04 - 2014-01-16 10:03 - 00000000 ____D C:\Users\Kuba\Desktop\Hudba
2014-01-15 23:17 - 2014-01-15 23:17 - 00000000 ____D C:\Users\Kuba\Downloads\Subs
2014-01-15 08:55 - 2014-01-15 08:55 - 00418107 _____ C:\Users\Kuba\Downloads\nj.jpeg
2014-01-15 07:41 - 2013-12-13 23:19 - 00000000 ____D C:\Users\Kuba\AppData\Local\VideoDownloadConverter_4z
2014-01-14 22:42 - 2014-01-14 22:42 - 00349766 _____ C:\Users\Kuba\Downloads\VypinacPC_v1.2.zip
2014-01-11 01:22 - 2013-12-12 10:27 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-351616307-1888091640-2631766136-1001
2014-01-11 01:15 - 2014-01-11 01:14 - 00000000 ____D C:\Users\Kuba\Desktop\smg
2014-01-11 01:09 - 2013-12-25 19:25 - 00000000 ____D C:\Program Files (x86)\SysPlayer
2014-01-11 01:08 - 2013-12-25 21:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\Mobogenie
2014-01-11 00:57 - 2014-01-11 00:57 - 00003108 _____ C:\windows\System32\Tasks\{6E99D240-AFF6-486C-86A5-4325AA5EA4BD}
2014-01-11 00:54 - 2014-01-11 00:54 - 01381864 _____ (Anvisoft Corporation) C:\Users\Kuba\Downloads\AnviUnIns.exe
2014-01-11 00:54 - 2014-01-11 00:54 - 00000000 ____D C:\Program Files (x86)\Anvisoft
2014-01-11 00:49 - 2013-12-12 09:33 - 00000000 ____D C:\Users\Kuba\AppData\Local\VirtualStore
2014-01-11 00:47 - 2013-12-25 22:00 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2014-01-11 00:47 - 2013-12-25 21:59 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Seznam.cz
2014-01-11 00:46 - 2014-01-10 03:13 - 00000000 ____D C:\Program Files (x86)\VideoPlayerV3
2014-01-11 00:45 - 2013-12-25 19:21 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\uTorrent
2014-01-10 23:55 - 2014-01-10 23:55 - 00000000 ____D C:\Users\Kuba\Downloads\MAFIA
2014-01-10 23:51 - 2013-12-25 10:46 - 00078336 _____ C:\windows\SysWOW64\rp.dll
2014-01-10 20:42 - 2014-01-10 19:13 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\BSplayer
2014-01-10 19:15 - 2014-01-10 19:15 - 00001133 _____ C:\Users\Public\Desktop\BS.Player FREE.lnk
2014-01-10 19:13 - 2014-01-10 19:13 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\BSplayer Pro
2014-01-10 19:13 - 2014-01-10 19:13 - 00000000 ____D C:\Program Files (x86)\Webteh
2014-01-10 19:12 - 2014-01-10 19:12 - 10511384 _____ C:\Users\Kuba\Downloads\bsplayer_installer.exe
2014-01-10 19:07 - 2013-12-25 21:59 - 00000557 _____ C:\Users\Kuba\daemonprocess.txt
2014-01-09 21:47 - 2013-12-25 21:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\cache
2014-01-09 21:35 - 2014-01-09 21:35 - 00000000 ____D C:\Users\Kuba\Documents\BMW
2014-01-09 21:33 - 2014-01-09 21:31 - 00000000 ____D C:\BMW M3 Challenge
2014-01-09 21:31 - 2013-12-25 21:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\genienext
2014-01-09 14:32 - 2014-01-09 14:32 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\X-Moto
2014-01-09 14:32 - 2013-12-12 09:32 - 00000000 ____D C:\Users\Kuba
2014-01-09 09:51 - 2014-01-06 21:24 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Skype
2014-01-09 09:02 - 2012-07-26 09:14 - 00694240 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-01-09 09:02 - 2012-07-26 09:14 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-08 22:13 - 2014-01-08 22:13 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ccdcmbx64_01009.Wdf
2014-01-08 22:12 - 2014-01-08 22:12 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-01-08 20:20 - 2014-01-08 20:20 - 00003174 _____ C:\windows\System32\Tasks\{563777A6-1806-4CEE-8A1E-5D28EB35FF79}
2014-01-08 20:18 - 2014-01-08 20:18 - 01551008 _____ (Skype Technologies S.A.) C:\Users\Kuba\Downloads\SkypeSetup.exe
2014-01-08 15:59 - 2014-01-08 15:59 - 00113016 _____ C:\Users\Kuba\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-08 08:50 - 2014-01-08 08:50 - 00000000 ____D C:\Users\Kuba\Downloads\documents-export-2014-01-07
2014-01-07 23:44 - 2014-01-07 23:44 - 00570856 _____ C:\Users\Kuba\Downloads\ZSV-Maturitni-otazky.rar
2014-01-07 23:44 - 2014-01-07 23:44 - 00443400 _____ C:\Users\Kuba\Downloads\ZSV---maturitní-otázky.rar
2014-01-07 23:44 - 2014-01-07 23:43 - 08429477 _____ C:\Users\Kuba\Downloads\zsv-maturitní-otázky.rar
2014-01-06 21:24 - 2014-01-06 21:24 - 00002731 _____ C:\Users\Public\Desktop\Skype.lnk
2014-01-06 21:24 - 2014-01-06 21:24 - 00000000 ___RD C:\Program Files (x86)\Skype
2014-01-06 21:24 - 2014-01-06 21:24 - 00000000 ____D C:\ProgramData\Skype
2014-01-06 21:23 - 2014-01-06 21:23 - 00002144 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Counter-Strike 1.6 Non-Steam.lnk
2014-01-06 21:23 - 2014-01-06 21:23 - 00002140 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\CS 1.6 Servery.lnk
2014-01-06 21:10 - 2014-01-06 21:09 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Kuba\Downloads\SkypeSetupFull.exe
2014-01-04 23:52 - 2014-01-04 23:52 - 00001421 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Adobe
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest\AppData\Local\VirtualStore
2014-01-04 23:52 - 2014-01-04 23:52 - 00000000 ____D C:\Users\Guest\AppData\Local\Packages
2014-01-04 23:52 - 2014-01-04 23:51 - 00000000 ____D C:\Users\Guest
2014-01-04 23:51 - 2014-01-04 23:51 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Šablony
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Soubory cookie
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Poslední
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Okolní tiskárny
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Okolní síť
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Nabídka Start
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Dokumenty
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Documents\Obrázky
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Documents\Hudba
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Documents\Filmy
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\Data aplikací
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-01-04 23:51 - 2014-01-04 23:51 - 00000000 _SHDL C:\Users\Guest\AppData\Local\Data aplikací
2014-01-02 11:25 - 2014-01-02 11:25 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1 (3).exe
2014-01-02 11:22 - 2014-01-02 11:21 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1.exe
2014-01-02 11:22 - 2014-01-02 11:21 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1 (2).exe
2014-01-02 11:22 - 2014-01-02 11:21 - 00446600 _____ C:\Users\Kuba\Downloads\Bluetooth_WIDCOMM_Driver_4.0.1 (1).exe
2013-12-29 21:02 - 2013-12-12 10:47 - 00000000 ____D C:\ProgramData\Stardock
2013-12-29 21:02 - 2013-12-12 09:35 - 00000000 ___RD C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-27 08:49

==================== End Of Log ============================

Re: Fakepolice

Napsal: 28 led 2014 22:37
od karelfritz
A tady ten addition

Re: Fakepolice

Napsal: 29 led 2014 11:11
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_170_Plugin.exe -update plugin [839560 2013-12-13] (Adobe Systems Incorporated)
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    SearchScopes: HKLM - DefaultScope {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
    SearchScopes: HKLM - {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
    SearchScopes: HKLM-x32 - DefaultScope {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
    SearchScopes: HKLM-x32 - {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
    SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^cz&si=pconvFF&ptb=10503D10-35B8-4DCA-A081-AEB292164B17&ind=2014011206&n=780b5f46&psa=&st=sb&searchfor={searchTerms}
    SearchScopes: HKCU - DefaultScope {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL =
    SearchScopes: HKCU - {6BB1FB1E-3AA3-42BB-8AA8-AB55F0610203} URL =
    SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^cz&si=pconvFF&ptb=10503D10-35B8-4DCA-A081-AEB292164B17&ind=2014011206&n=780b5f46&psa=&st=sb&searchfor={searchTerms}
    BHO-x32: Torntv V7.0 - {11111111-1111-1111-1111-110411901140} - C:\Program Files (x86)\Torntv V7.0\Torntv V7.0-bho.dll No File
    BHO-x32: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbar.dll No File
    BHO-x32: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll No File
    
    FF Plugin-x32: @VideoDownloadConverter_4z.com/Plugin - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll No File
    FF Plugin-x32: @VideoDownloadConverter_ScriptHelper.com/Plugin - C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll (Mindspark)
    FF Plugin-x32: @WeatherBlink.com/Plugin - C:\Program Files (x86)\WeatherBlink\bar\1.bin\NPgcStub.dll No File
    FF Plugin HKCU: intel.com/AppUp - C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll No File
    FF Extension: VideoDownloadConverter - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com [2013-12-15]
    FF Extension: WeatherBlink - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\84fmc42q.default\Extensions\gcffxtbr@WeatherBlink.com [2014-01-22]
    
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
    
    2014-01-28 22:25 - 2014-01-28 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Desktop\FRSTLauncher.exe
    2014-01-28 22:24 - 2014-01-28 22:24 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Downloads\Nepotvrzeno 239438.crdownload
    2014-01-28 22:23 - 2014-01-28 22:23 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Downloads\Nepotvrzeno 558986.crdownload
    2014-01-27 19:00 - 2014-01-27 19:00 - 00018756 _____ C:\ComboFix.txt
    2014-01-27 18:50 - 2014-01-27 18:50 - 00001204 _____ C:\CF-Submit.htm
    2014-01-23 14:22 - 2014-01-23 14:22 - 00001986 _____ C:\Users\Kuba\Desktop\Rkill.txt
    2014-01-23 14:18 - 2014-01-23 14:19 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Kuba\Desktop\rkill.com
    2014-01-16 22:46 - 2014-01-16 22:46 - 00000848 _____ C:\Users\Kuba\Desktop\TornTV.lnk
    2014-01-16 14:19 - 2014-01-16 14:19 - 00935175 _____ C:\Users\Kuba\Downloads\RSITx64.exe
    2014-01-11 01:04 - 2013-12-10 22:25 - 00005453 ____N C:\windows\SysWOW64\msqmrljg.vbe
    2014-01-11 01:04 - 2013-12-10 22:25 - 00001645 ____N C:\windows\SysWOW64\msiknm.vbe
    2014-01-11 01:04 - 2013-12-10 22:25 - 00000583 ____N C:\windows\SysWOW64\mswrmcvi.vbe
    2014-01-28 22:25 - 2014-01-28 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Kuba\Desktop\FRSTLauncher.exe
    2014-01-27 18:50 - 2014-01-27 18:50 - 00001204 _____ C:\CF-Submit.htm
    2014-01-26 20:17 - 2012-07-26 06:26 - 75087872 _____ C:\windows\system32\config\SOFTWARE.bak
    2014-01-26 20:17 - 2012-07-26 06:26 - 12582912 _____ C:\windows\system32\config\SYSTEM.bak
    2014-01-26 20:17 - 2012-07-26 06:26 - 00737280 _____ C:\windows\system32\config\DEFAULT.bak
    2014-01-26 20:17 - 2012-07-26 06:26 - 00262144 ___SH C:\windows\system32\config\BBI
    2014-01-26 20:17 - 2012-07-26 06:26 - 00028672 _____ C:\windows\system32\config\SAM.bak
    2014-01-26 20:17 - 2012-07-26 06:26 - 00024576 _____ C:\windows\system32\config\SECURITY.bak
    
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    
    U3 catchme; \??\C:\ComboFix\catchme.sys [x]
    
    C:\windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\windows\tasks\GoogleUpdateTaskMachineUA.job
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt