Prosím o kontrolu logu - reklamy a vyskakovací okna
Napsal: 03 bře 2014 13:48
Pěkný den,
prosím o kontrolu logu. Zobrazují se mi v prohlížečích reklamy a vyskakují okna s reklamou... Jako antivir běžně používám Aviru, projel jsem Online Scannerm Esetu, spustil jsem ADWCleaner, vše něco odstranilo, ale nic neřeší výše popsaný problém...
Děkuji za pomoc!
Logfile of random's system information tool 1.08 (written by random/random)
Run by Mattel at 2014-03-03 13:49:17
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 33 GB (33%) free of 100 GB
Total RAM: 4063 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:49:23, on 3.3.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Users\Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera_crashreporter.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Program Files\trend micro\Mattel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://expresradio.idnes.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:9880
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 127.94.0.1 client.openvpn.net
O1 - Hosts: 127.94.0.2 openvpn-client.otik.fnplzen.cz
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKCU\..\Run: [Copy] "C:\Users\Mattel\AppData\Roaming\Copy\CopyAgent.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Dropbox.lnk = Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{487A3504-D17D-4056-AA7D-551A77A821D3}: NameServer = 91.221.2.254,91.221.2.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{487A3504-D17D-4056-AA7D-551A77A821D3}: NameServer = 91.221.2.254,91.221.2.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{487A3504-D17D-4056-AA7D-551A77A821D3}: NameServer = 91.221.2.254,91.221.2.253
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinRST - Unknown owner - C:\Program Files (x86)\WinRST\WinRST.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 11936 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
atieclxx
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 4082016
\??\C:\Windows\system32\conhost.exe "595445974-73286611-1095538636-173113832364450283415988083721418259271755444189
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe"
"C:\Program Files\Sony\VAIO Power Management\SPMService.exe"
"C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe"
"C:\Program Files (x86)\WinRST\WinRST.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe"
WLIDSvcM.exe 2684
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000778
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" /Start
"C:\Program Files\Apoint\Apoint.exe"
"C:\Users\Mattel\AppData\Roaming\Copy\CopyAgent.exe"
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Users\Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files\Apoint\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files\Apoint\Apvfb.exe"
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "-1333545346-1186133116-1449601647463780493657223171056617415-969273212137581354
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c322c633-5c7f-4b76-9d29-b96cf90a2b2d -SystemEventPortName:HostProcess-46bdf082-2755-4b72-80c0-1d68b4e53db4 -IoCancelEventPortName:HostProcess-d3173541-18fa-4853-b98c-152c31398f22 -NonStateChangingEventPortName:HostProcess-756892ef-e931-4d59-832d-751d54f68f37 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a16a7c5c-7515-4be2-b2eb-b21108f13593 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --ran-launcher /crash-reporter-parent-id=5092
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=gpu-process --channel="5092.0.386742222\906254902" --crash-reporter-pid=5100 --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,27 --gpu-vendor-id=0x1002 --gpu-device-id=0x9553 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.7000 --crash-reporter-pid=5100 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.3.1876620626\505254418" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.4.1115644726\2002634471" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.5.568698871\116596360" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.6.1500568894\1802321678" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.7.130932514\1684567230" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.8.1528824711\146998087" /prefetch:673131151
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe"
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --lang=cs --channel="5092.16.641582657\1846947418" --crash-reporter-pid=5100 /prefetch:-390060480
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe" lng=1029
"C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe" "/base-dir=C:\Program Files (x86)\ESET\ESET Online Scanner" /lang=1029 /as
\??\C:\Windows\system32\conhost.exe "477430262-805421-1813988790-7842829261192832108243683251-1615662370842009349
"C:\Users\Mattel\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2013-09-13 878296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-09-10 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-01-28 583520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office15\URLREDIR.DLL [2013-09-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL [2013-11-02 1727176]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-09-10 170912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2009-09-25 208384]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-09-24 7938080]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-09-24 1833504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Copy"=C:\Users\Mattel\AppData\Roaming\Copy\CopyAgent.exe [2014-02-08 15501968]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2013-12-13 831488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTibMounterMonitor]
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [2013-01-10 1105328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CNAP2 Launcher]
C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [2010-10-15 226784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CorelDRAW Graphics Suite 11b]
C:\Program Files (x86)\Corel\Corel Graphics 12\Languages\CZ\Programs\Registration.exe [2004-06-23 729088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-07-03 3673184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIMProbíhá stahování aktualizace...1338924290338]
C:\Program Files\Corel\CorelDRAW Graphics Suite X6\Draw\DIM.EXE [2012-02-23 237944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Služba Acronis Scheduler2]
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2013-02-15 516928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\Mattel\AppData\Roaming\Spotify\Spotify.exe [2014-02-02 6118400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Mattel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-02-02 1171968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2013-04-18 6391960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Users\Mattel\AppData\Roaming\uTorrent\uTorrent.exe [2014-02-06 905296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2013-12-13 831488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Service 16]
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2013-12-13 831488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Mersite Presence 3 Virtuální terminál.lnk]
C:\PROGRA~2\MERSIT~1\VIRTUA~1\PRESEN~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mattel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EvernoteClipper.lnk]
C:\PROGRA~2\Evernote\Evernote\EVERNO~2.EXE [2014-01-28 1104736]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-09 684600]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2014-01-29 172600]
C:\Users\Mattel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-03-03 13:49:17 ----D---- C:\rsit
2014-03-03 13:49:17 ----D---- C:\Program Files\trend micro
2014-03-03 13:40:09 ----D---- C:\AdwCleaner
2014-03-03 13:15:04 ----A---- C:\Windows\ntbtlog.txt
2014-03-03 09:10:14 ----D---- C:\Program Files (x86)\ESET
2014-03-02 20:14:43 ----D---- C:\Program Files (x86)\EASEUS
2014-03-02 20:11:12 ----D---- C:\ProgramData\TEMP
2014-03-02 20:10:24 ----D---- C:\Program Files (x86)\WinRST
2014-02-26 14:57:30 ----D---- C:\Program Files (x86)\Activision
2014-02-26 14:54:30 ----SHD---- C:\Windows\ftpcache
2014-02-26 14:15:58 ----D---- C:\Users\Mattel\AppData\Roaming\Poedit
2014-02-26 10:46:20 ----D---- C:\Program Files (x86)\OpenVPN Technologies
2014-02-26 08:34:37 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-02-26 08:34:37 ----A---- C:\Windows\system32\mstscax.dll
2014-02-25 09:48:00 ----D---- C:\Users\Mattel\AppData\Roaming\Syncfusion
2014-02-25 09:47:00 ----D---- C:\Program Files (x86)\Syncfusion
2014-02-17 09:14:20 ----D---- C:\Program Files\Microsoft.NET
2014-02-17 09:11:14 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-17 09:11:12 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-17 09:11:12 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-17 09:11:12 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2014-02-17 09:11:11 ----A---- C:\Windows\system32\wksprtPS.dll
2014-02-17 09:11:11 ----A---- C:\Windows\system32\wksprt.exe
2014-02-17 09:11:11 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-02-17 09:11:11 ----A---- C:\Windows\system32\tsgqec.dll
2014-02-17 09:11:11 ----A---- C:\Windows\system32\mstsc.exe
2014-02-17 09:11:11 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-02-17 09:11:10 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-02-17 09:11:10 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-02-17 09:09:01 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-02-17 09:09:00 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-02-13 19:13:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-02-13 19:13:06 ----A---- C:\Windows\system32\vbscript.dll
2014-02-13 18:32:22 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-02-13 18:32:22 ----A---- C:\Windows\system32\msrating.dll
2014-02-13 18:32:21 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-02-13 18:32:21 ----A---- C:\Windows\system32\ieui.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\jsproxy.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\iernonce.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\ie4uinit.exe
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-02-13 18:32:19 ----A---- C:\Windows\system32\msfeeds.dll
2014-02-13 18:32:19 ----A---- C:\Windows\system32\ieUnatt.exe
2014-02-13 18:32:19 ----A---- C:\Windows\system32\iesetup.dll
2014-02-13 18:32:17 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-02-13 18:32:17 ----A---- C:\Windows\system32\mshtml.dll
2014-02-13 18:32:17 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-02-13 18:32:17 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-02-13 18:32:16 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-02-13 18:32:16 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-02-13 18:32:16 ----A---- C:\Windows\system32\jscript9diag.dll
2014-02-13 18:32:16 ----A---- C:\Windows\system32\ieapfltr.dll
2014-02-13 18:32:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-02-13 18:32:15 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-02-13 18:32:15 ----A---- C:\Windows\system32\wininet.dll
2014-02-13 18:32:15 ----A---- C:\Windows\system32\urlmon.dll
2014-02-13 18:32:15 ----A---- C:\Windows\system32\iertutil.dll
2014-02-13 18:32:14 ----A---- C:\Windows\system32\ieframe.dll
2014-02-13 18:32:13 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-02-13 18:32:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-02-13 18:32:11 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-02-13 18:32:11 ----A---- C:\Windows\system32\jscript9.dll
2014-02-13 08:14:41 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-02-13 08:14:41 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-02-13 08:14:41 ----A---- C:\Windows\system32\msxml3r.dll
2014-02-13 08:14:41 ----A---- C:\Windows\system32\msxml3.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\msdrm.dll
2014-02-13 08:14:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-02-13 08:14:08 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-02-13 08:14:08 ----A---- C:\Windows\system32\d3d10warp.dll
2014-02-13 08:14:08 ----A---- C:\Windows\system32\d2d1.dll
2014-02-11 16:47:42 ----D---- C:\Windows\en
2014-02-11 16:47:30 ----D---- C:\Windows\cs
2014-02-11 16:46:54 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-02-11 16:45:54 ----D---- C:\Program Files (x86)\Windows Live
2014-02-11 16:44:59 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-02-11 16:44:59 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-02-11 16:44:59 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-02-11 16:44:59 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-02-11 16:44:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-02-11 16:44:58 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-02-11 16:44:57 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-02-11 16:44:57 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-02-11 16:43:47 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-02-11 16:43:47 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-02-11 16:43:08 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-02-11 16:43:08 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-02-11 16:24:48 ----D---- C:\Users\Mattel\AppData\Roaming\FastStone
2014-02-11 16:23:21 ----D---- C:\Program Files (x86)\FastStone Capture
2014-02-11 13:54:12 ----D---- C:\Users\Mattel\AppData\Roaming\Mozilla
2014-02-10 14:55:44 ----D---- C:\ProgramData\regid.1986-12.com.adobe
======List of files/folders modified in the last 1 months======
2014-03-03 13:49:23 ----D---- C:\Windows\Temp
2014-03-03 13:49:17 ----RD---- C:\Program Files
2014-03-03 13:47:34 ----D---- C:\Users\Mattel\AppData\Roaming\Dropbox
2014-03-03 13:45:57 ----D---- C:\Users\Mattel\AppData\Roaming\Copy
2014-03-03 13:41:42 ----D---- C:\Windows\system32\config
2014-03-03 13:41:19 ----D---- C:\Windows\System32
2014-03-03 13:41:18 ----D---- C:\Windows\SysWOW64
2014-03-03 13:39:57 ----D---- C:\Users\Mattel\AppData\Roaming\Skype
2014-03-03 13:21:38 ----RD---- C:\Program Files (x86)
2014-03-03 13:15:04 ----D---- C:\Windows
2014-03-03 09:04:41 ----D---- C:\Windows\system32\Tasks
2014-03-03 09:04:37 ----D---- C:\Windows\Tasks
2014-03-03 09:03:46 ----SHD---- C:\System Volume Information
2014-03-02 20:14:43 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-03-02 20:11:12 ----HD---- C:\ProgramData
2014-03-02 20:09:31 ----D---- C:\Windows\inf
2014-03-02 20:09:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-03-02 20:03:08 ----D---- C:\Windows\system32\drivers
2014-03-02 15:57:14 ----D---- C:\Windows\rescache
2014-03-02 15:56:19 ----D---- C:\Windows\system32\catroot2
2014-02-28 14:35:38 ----D---- C:\Users\Mattel\AppData\Roaming\TeamViewer
2014-02-28 10:44:43 ----RSD---- C:\Windows\Fonts
2014-02-28 10:44:31 ----D---- C:\Program Files (x86)\TeamViewer
2014-02-28 09:31:47 ----D---- C:\Program Files (x86)\Opera Next
2014-02-27 19:05:29 ----D---- C:\Users\Mattel\AppData\Roaming\uTorrent
2014-02-26 14:31:14 ----SHD---- C:\Windows\Installer
2014-02-26 11:44:15 ----D---- C:\Windows\winsxs
2014-02-26 11:44:10 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-02-26 11:44:10 ----D---- C:\Windows\system32\cs-CZ
2014-02-26 10:46:30 ----D---- C:\Windows\system32\catroot
2014-02-26 10:46:29 ----D---- C:\Windows\system32\DriverStore
2014-02-26 08:39:51 ----D---- C:\Windows\Prefetch
2014-02-25 21:52:57 ----D---- C:\Program Files (x86)\Common Files
2014-02-23 17:18:34 ----D---- C:\Program Files (x86)\Opera Developer
2014-02-21 18:15:23 ----D---- C:\Program Files (x86)\SharePod
2014-02-20 14:50:00 ----SD---- C:\Users\Mattel\AppData\Roaming\Microsoft
2014-02-17 11:35:21 ----D---- C:\Windows\SYSWOW64\wbem
2014-02-17 11:35:21 ----D---- C:\Windows\system32\wbem
2014-02-17 11:35:21 ----D---- C:\Windows\system32\drivers\en-US
2014-02-17 09:14:54 ----RSD---- C:\Windows\assembly
2014-02-17 09:14:20 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-02-17 09:11:02 ----D---- C:\ProgramData\Microsoft Help
2014-02-15 10:28:16 ----D---- C:\Users\Mattel\AppData\Roaming\Spotify
2014-02-15 03:05:57 ----D---- C:\Windows\Microsoft.NET
2014-02-15 03:03:22 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-02-13 19:30:04 ----D---- C:\Program Files\Internet Explorer
2014-02-13 19:30:04 ----D---- C:\Program Files (x86)\Internet Explorer
2014-02-13 19:22:51 ----A---- C:\Windows\win.ini
2014-02-11 16:46:18 ----SD---- C:\ProgramData\Microsoft
2014-02-11 16:45:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-02-11 16:44:14 ----D---- C:\ProgramData\Corel
2014-02-10 14:06:20 ----D---- C:\Windows\system32\drivers\UMDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2013-09-10 108832]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2013-09-10 233760]
R0 tib;Acronis TIB Manager; C:\Windows\system32\DRIVERS\tib.sys [2013-09-10 1120032]
R0 tib_mounter;Acronis TIB Mounter; C:\Windows\system32\DRIVERS\tib_mounter.sys [2013-09-10 183224]
R0 vididr;Acronis Virtual Disk; C:\Windows\system32\DRIVERS\vididr.sys [2013-09-10 161568]
R0 vidsflt;Acronis Disk Storage Filter; C:\Windows\system32\DRIVERS\vidsflt.sys [2013-09-10 117024]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2013-12-09 131576]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2013-12-09 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-09-10 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-09-10 231376]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2013-12-18 252688]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2013-12-18 126736]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2013-12-09 108440]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimssn64.sys [2009-09-24 86528]
R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2013-09-10 367200]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 359936]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-09-25 250928]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-09-24 1822112]
R3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-09-25 201472]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-03 11392]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2013-12-18 140560]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2013-12-18 154896]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 11922944]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 tapoas;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2011-08-19 30720]
S3 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys [2013-09-10 1462560]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VBoxUSB;VirtualBox USB; C:\Windows\System32\Drivers\VBoxUSB.sys [2013-12-18 113936]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2013-02-15 1143720]
R2 afcdpsrv;Acronis Nonstop Backup Service; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2013-09-10 3779576]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 238080]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-12-09 440376]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-12-09 440376]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-01-29 109112]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-09-21 1420560]
R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2009-09-21 831760]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2009-09-24 189984]
R2 syncagentsrv;Acronis Sync Agent Service; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2013-03-26 7091584]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-02-17 4915040]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe [2009-07-01 204648]
R2 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2009-08-22 411496]
R2 WinRST;WinRST; C:\Program Files (x86)\WinRST\WinRST.exe [2014-02-21 59904]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-10 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-10 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 VsEtwService120;Visual Studio ETW Event Collection Service; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [2013-10-04 87728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-09-10 1255736]
S4 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-12-09 1011768]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
prosím o kontrolu logu. Zobrazují se mi v prohlížečích reklamy a vyskakují okna s reklamou... Jako antivir běžně používám Aviru, projel jsem Online Scannerm Esetu, spustil jsem ADWCleaner, vše něco odstranilo, ale nic neřeší výše popsaný problém...
Děkuji za pomoc!
Logfile of random's system information tool 1.08 (written by random/random)
Run by Mattel at 2014-03-03 13:49:17
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 33 GB (33%) free of 100 GB
Total RAM: 4063 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:49:23, on 3.3.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Users\Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera_crashreporter.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Program Files\trend micro\Mattel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://expresradio.idnes.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:9880
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 127.94.0.1 client.openvpn.net
O1 - Hosts: 127.94.0.2 openvpn-client.otik.fnplzen.cz
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKCU\..\Run: [Copy] "C:\Users\Mattel\AppData\Roaming\Copy\CopyAgent.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Dropbox.lnk = Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{487A3504-D17D-4056-AA7D-551A77A821D3}: NameServer = 91.221.2.254,91.221.2.253
O17 - HKLM\System\CS1\Services\Tcpip\..\{487A3504-D17D-4056-AA7D-551A77A821D3}: NameServer = 91.221.2.254,91.221.2.253
O17 - HKLM\System\CS2\Services\Tcpip\..\{487A3504-D17D-4056-AA7D-551A77A821D3}: NameServer = 91.221.2.254,91.221.2.253
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinRST - Unknown owner - C:\Program Files (x86)\WinRST\WinRST.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 11936 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
atieclxx
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 4082016
\??\C:\Windows\system32\conhost.exe "595445974-73286611-1095538636-173113832364450283415988083721418259271755444189
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe"
"C:\Program Files\Sony\VAIO Power Management\SPMService.exe"
"C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe"
"C:\Program Files (x86)\WinRST\WinRST.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe"
WLIDSvcM.exe 2684
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000778
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" /Start
"C:\Program Files\Apoint\Apoint.exe"
"C:\Users\Mattel\AppData\Roaming\Copy\CopyAgent.exe"
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Users\Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files\Apoint\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files\Apoint\Apvfb.exe"
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "-1333545346-1186133116-1449601647463780493657223171056617415-969273212137581354
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c322c633-5c7f-4b76-9d29-b96cf90a2b2d -SystemEventPortName:HostProcess-46bdf082-2755-4b72-80c0-1d68b4e53db4 -IoCancelEventPortName:HostProcess-d3173541-18fa-4853-b98c-152c31398f22 -NonStateChangingEventPortName:HostProcess-756892ef-e931-4d59-832d-751d54f68f37 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a16a7c5c-7515-4be2-b2eb-b21108f13593 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --ran-launcher /crash-reporter-parent-id=5092
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=gpu-process --channel="5092.0.386742222\906254902" --crash-reporter-pid=5100 --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,27 --gpu-vendor-id=0x1002 --gpu-device-id=0x9553 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.7000 --crash-reporter-pid=5100 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.3.1876620626\505254418" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.4.1115644726\2002634471" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.5.568698871\116596360" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.6.1500568894\1802321678" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.7.130932514\1684567230" /prefetch:673131151
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --disable-delegated-renderer --crash-reporter-pid=5100 --channel="5092.8.1528824711\146998087" /prefetch:673131151
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe"
"C:\Program Files (x86)\Opera Next\20.0.1387.59\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --lang=cs --channel="5092.16.641582657\1846947418" --crash-reporter-pid=5100 /prefetch:-390060480
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe" lng=1029
"C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe" "/base-dir=C:\Program Files (x86)\ESET\ESET Online Scanner" /lang=1029 /as
\??\C:\Windows\system32\conhost.exe "477430262-805421-1813988790-7842829261192832108243683251-1615662370842009349
"C:\Users\Mattel\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2013-09-13 878296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-09-10 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-01-28 583520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office15\URLREDIR.DLL [2013-09-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL [2013-11-02 1727176]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-09-10 170912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2009-09-25 208384]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-09-24 7938080]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-09-24 1833504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Copy"=C:\Users\Mattel\AppData\Roaming\Copy\CopyAgent.exe [2014-02-08 15501968]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2013-12-13 831488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTibMounterMonitor]
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [2013-01-10 1105328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CNAP2 Launcher]
C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [2010-10-15 226784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CorelDRAW Graphics Suite 11b]
C:\Program Files (x86)\Corel\Corel Graphics 12\Languages\CZ\Programs\Registration.exe [2004-06-23 729088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-07-03 3673184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIMProbíhá stahování aktualizace...1338924290338]
C:\Program Files\Corel\CorelDRAW Graphics Suite X6\Draw\DIM.EXE [2012-02-23 237944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Služba Acronis Scheduler2]
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2013-02-15 516928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\Mattel\AppData\Roaming\Spotify\Spotify.exe [2014-02-02 6118400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Mattel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-02-02 1171968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2013-04-18 6391960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Users\Mattel\AppData\Roaming\uTorrent\uTorrent.exe [2014-02-06 905296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2013-12-13 831488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Service 16]
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2013-12-13 831488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Mersite Presence 3 Virtuální terminál.lnk]
C:\PROGRA~2\MERSIT~1\VIRTUA~1\PRESEN~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mattel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EvernoteClipper.lnk]
C:\PROGRA~2\Evernote\Evernote\EVERNO~2.EXE [2014-01-28 1104736]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-09 684600]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2014-01-29 172600]
C:\Users\Mattel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Mattel\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-03-03 13:49:17 ----D---- C:\rsit
2014-03-03 13:49:17 ----D---- C:\Program Files\trend micro
2014-03-03 13:40:09 ----D---- C:\AdwCleaner
2014-03-03 13:15:04 ----A---- C:\Windows\ntbtlog.txt
2014-03-03 09:10:14 ----D---- C:\Program Files (x86)\ESET
2014-03-02 20:14:43 ----D---- C:\Program Files (x86)\EASEUS
2014-03-02 20:11:12 ----D---- C:\ProgramData\TEMP
2014-03-02 20:10:24 ----D---- C:\Program Files (x86)\WinRST
2014-02-26 14:57:30 ----D---- C:\Program Files (x86)\Activision
2014-02-26 14:54:30 ----SHD---- C:\Windows\ftpcache
2014-02-26 14:15:58 ----D---- C:\Users\Mattel\AppData\Roaming\Poedit
2014-02-26 10:46:20 ----D---- C:\Program Files (x86)\OpenVPN Technologies
2014-02-26 08:34:37 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-02-26 08:34:37 ----A---- C:\Windows\system32\mstscax.dll
2014-02-25 09:48:00 ----D---- C:\Users\Mattel\AppData\Roaming\Syncfusion
2014-02-25 09:47:00 ----D---- C:\Program Files (x86)\Syncfusion
2014-02-17 09:14:20 ----D---- C:\Program Files\Microsoft.NET
2014-02-17 09:11:14 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-17 09:11:12 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-17 09:11:12 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-17 09:11:12 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-02-17 09:11:11 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2014-02-17 09:11:11 ----A---- C:\Windows\system32\wksprtPS.dll
2014-02-17 09:11:11 ----A---- C:\Windows\system32\wksprt.exe
2014-02-17 09:11:11 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-02-17 09:11:11 ----A---- C:\Windows\system32\tsgqec.dll
2014-02-17 09:11:11 ----A---- C:\Windows\system32\mstsc.exe
2014-02-17 09:11:11 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-02-17 09:11:10 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-02-17 09:11:10 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-02-17 09:09:01 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-02-17 09:09:00 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-02-13 19:13:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-02-13 19:13:06 ----A---- C:\Windows\system32\vbscript.dll
2014-02-13 18:32:22 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-02-13 18:32:22 ----A---- C:\Windows\system32\msrating.dll
2014-02-13 18:32:21 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-02-13 18:32:21 ----A---- C:\Windows\system32\ieui.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\jsproxy.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\iernonce.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 18:32:20 ----A---- C:\Windows\system32\ie4uinit.exe
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-02-13 18:32:19 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-02-13 18:32:19 ----A---- C:\Windows\system32\msfeeds.dll
2014-02-13 18:32:19 ----A---- C:\Windows\system32\ieUnatt.exe
2014-02-13 18:32:19 ----A---- C:\Windows\system32\iesetup.dll
2014-02-13 18:32:17 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-02-13 18:32:17 ----A---- C:\Windows\system32\mshtml.dll
2014-02-13 18:32:17 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-02-13 18:32:17 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-02-13 18:32:16 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-02-13 18:32:16 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-02-13 18:32:16 ----A---- C:\Windows\system32\jscript9diag.dll
2014-02-13 18:32:16 ----A---- C:\Windows\system32\ieapfltr.dll
2014-02-13 18:32:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-02-13 18:32:15 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-02-13 18:32:15 ----A---- C:\Windows\system32\wininet.dll
2014-02-13 18:32:15 ----A---- C:\Windows\system32\urlmon.dll
2014-02-13 18:32:15 ----A---- C:\Windows\system32\iertutil.dll
2014-02-13 18:32:14 ----A---- C:\Windows\system32\ieframe.dll
2014-02-13 18:32:13 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-02-13 18:32:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-02-13 18:32:11 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-02-13 18:32:11 ----A---- C:\Windows\system32\jscript9.dll
2014-02-13 08:14:41 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-02-13 08:14:41 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-02-13 08:14:41 ----A---- C:\Windows\system32\msxml3r.dll
2014-02-13 08:14:41 ----A---- C:\Windows\system32\msxml3.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-02-13 08:14:12 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc_isv.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\secproc.dll
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\RMActivate.exe
2014-02-13 08:14:12 ----A---- C:\Windows\system32\msdrm.dll
2014-02-13 08:14:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-02-13 08:14:08 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-02-13 08:14:08 ----A---- C:\Windows\system32\d3d10warp.dll
2014-02-13 08:14:08 ----A---- C:\Windows\system32\d2d1.dll
2014-02-11 16:47:42 ----D---- C:\Windows\en
2014-02-11 16:47:30 ----D---- C:\Windows\cs
2014-02-11 16:46:54 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-02-11 16:45:54 ----D---- C:\Program Files (x86)\Windows Live
2014-02-11 16:44:59 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-02-11 16:44:59 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-02-11 16:44:59 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-02-11 16:44:59 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-02-11 16:44:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-02-11 16:44:58 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-02-11 16:44:57 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-02-11 16:44:57 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-02-11 16:43:47 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-02-11 16:43:47 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-02-11 16:43:08 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-02-11 16:43:08 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-02-11 16:24:48 ----D---- C:\Users\Mattel\AppData\Roaming\FastStone
2014-02-11 16:23:21 ----D---- C:\Program Files (x86)\FastStone Capture
2014-02-11 13:54:12 ----D---- C:\Users\Mattel\AppData\Roaming\Mozilla
2014-02-10 14:55:44 ----D---- C:\ProgramData\regid.1986-12.com.adobe
======List of files/folders modified in the last 1 months======
2014-03-03 13:49:23 ----D---- C:\Windows\Temp
2014-03-03 13:49:17 ----RD---- C:\Program Files
2014-03-03 13:47:34 ----D---- C:\Users\Mattel\AppData\Roaming\Dropbox
2014-03-03 13:45:57 ----D---- C:\Users\Mattel\AppData\Roaming\Copy
2014-03-03 13:41:42 ----D---- C:\Windows\system32\config
2014-03-03 13:41:19 ----D---- C:\Windows\System32
2014-03-03 13:41:18 ----D---- C:\Windows\SysWOW64
2014-03-03 13:39:57 ----D---- C:\Users\Mattel\AppData\Roaming\Skype
2014-03-03 13:21:38 ----RD---- C:\Program Files (x86)
2014-03-03 13:15:04 ----D---- C:\Windows
2014-03-03 09:04:41 ----D---- C:\Windows\system32\Tasks
2014-03-03 09:04:37 ----D---- C:\Windows\Tasks
2014-03-03 09:03:46 ----SHD---- C:\System Volume Information
2014-03-02 20:14:43 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-03-02 20:11:12 ----HD---- C:\ProgramData
2014-03-02 20:09:31 ----D---- C:\Windows\inf
2014-03-02 20:09:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-03-02 20:03:08 ----D---- C:\Windows\system32\drivers
2014-03-02 15:57:14 ----D---- C:\Windows\rescache
2014-03-02 15:56:19 ----D---- C:\Windows\system32\catroot2
2014-02-28 14:35:38 ----D---- C:\Users\Mattel\AppData\Roaming\TeamViewer
2014-02-28 10:44:43 ----RSD---- C:\Windows\Fonts
2014-02-28 10:44:31 ----D---- C:\Program Files (x86)\TeamViewer
2014-02-28 09:31:47 ----D---- C:\Program Files (x86)\Opera Next
2014-02-27 19:05:29 ----D---- C:\Users\Mattel\AppData\Roaming\uTorrent
2014-02-26 14:31:14 ----SHD---- C:\Windows\Installer
2014-02-26 11:44:15 ----D---- C:\Windows\winsxs
2014-02-26 11:44:10 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-02-26 11:44:10 ----D---- C:\Windows\system32\cs-CZ
2014-02-26 10:46:30 ----D---- C:\Windows\system32\catroot
2014-02-26 10:46:29 ----D---- C:\Windows\system32\DriverStore
2014-02-26 08:39:51 ----D---- C:\Windows\Prefetch
2014-02-25 21:52:57 ----D---- C:\Program Files (x86)\Common Files
2014-02-23 17:18:34 ----D---- C:\Program Files (x86)\Opera Developer
2014-02-21 18:15:23 ----D---- C:\Program Files (x86)\SharePod
2014-02-20 14:50:00 ----SD---- C:\Users\Mattel\AppData\Roaming\Microsoft
2014-02-17 11:35:21 ----D---- C:\Windows\SYSWOW64\wbem
2014-02-17 11:35:21 ----D---- C:\Windows\system32\wbem
2014-02-17 11:35:21 ----D---- C:\Windows\system32\drivers\en-US
2014-02-17 09:14:54 ----RSD---- C:\Windows\assembly
2014-02-17 09:14:20 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-02-17 09:11:02 ----D---- C:\ProgramData\Microsoft Help
2014-02-15 10:28:16 ----D---- C:\Users\Mattel\AppData\Roaming\Spotify
2014-02-15 03:05:57 ----D---- C:\Windows\Microsoft.NET
2014-02-15 03:03:22 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-02-13 19:30:04 ----D---- C:\Program Files\Internet Explorer
2014-02-13 19:30:04 ----D---- C:\Program Files (x86)\Internet Explorer
2014-02-13 19:22:51 ----A---- C:\Windows\win.ini
2014-02-11 16:46:18 ----SD---- C:\ProgramData\Microsoft
2014-02-11 16:45:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-02-11 16:44:14 ----D---- C:\ProgramData\Corel
2014-02-10 14:06:20 ----D---- C:\Windows\system32\drivers\UMDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2013-09-10 108832]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2013-09-10 233760]
R0 tib;Acronis TIB Manager; C:\Windows\system32\DRIVERS\tib.sys [2013-09-10 1120032]
R0 tib_mounter;Acronis TIB Mounter; C:\Windows\system32\DRIVERS\tib_mounter.sys [2013-09-10 183224]
R0 vididr;Acronis Virtual Disk; C:\Windows\system32\DRIVERS\vididr.sys [2013-09-10 161568]
R0 vidsflt;Acronis Disk Storage Filter; C:\Windows\system32\DRIVERS\vidsflt.sys [2013-09-10 117024]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2013-12-09 131576]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2013-12-09 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-09-10 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-09-10 231376]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2013-12-18 252688]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2013-12-18 126736]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2013-12-09 108440]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimssn64.sys [2009-09-24 86528]
R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2013-09-10 367200]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 359936]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-09-25 250928]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-09-24 1822112]
R3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-09-25 201472]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-03 11392]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2013-12-18 140560]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2013-12-18 154896]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 11922944]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 tapoas;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2011-08-19 30720]
S3 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys [2013-09-10 1462560]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VBoxUSB;VirtualBox USB; C:\Windows\System32\Drivers\VBoxUSB.sys [2013-12-18 113936]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2013-02-15 1143720]
R2 afcdpsrv;Acronis Nonstop Backup Service; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2013-09-10 3779576]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 238080]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-12-09 440376]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-12-09 440376]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-01-29 109112]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-09-21 1420560]
R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2009-09-21 831760]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2009-09-24 189984]
R2 syncagentsrv;Acronis Sync Agent Service; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2013-03-26 7091584]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-02-17 4915040]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe [2009-07-01 204648]
R2 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2009-08-22 411496]
R2 WinRST;WinRST; C:\Program Files (x86)\WinRST\WinRST.exe [2014-02-21 59904]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-10 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-10 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 VsEtwService120;Visual Studio ETW Event Collection Service; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [2013-10-04 87728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-09-10 1255736]
S4 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2013-12-09 1011768]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------