Stránka 1 z 1

BSOD, explorer.exe po loginu dlouho nacita

Napsal: 18 čer 2014 17:48
od mnevidal
BSOD asi byla způsobena vadným exter. HDD, ale pro jistotu to nezatajím. Podarilo se mi dokonce odstranit černou obrazovku po loginu do windows a teď po loginu se normálně načte interface ale trvá (cca 3-5 min) nez zacne byt PC pouzivatelne. (poznam to podle opoždeného zvuku přihlašení).

Předem děkuji za odpověd ;)

Prediktivně vkládám log z RSIT

Logfile of random's system information tool 1.10 (written by random/random)
Run by Petra at 2014-06-18 18:46:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 515 GB (88%) free of 588 GB
Total RAM: 4030 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:46:30, on 18.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Petra.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.co ... 5.24.0.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO System - Cleaner Service (Cleaner_Validator) - Unknown owner - C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: McNeel Update Service 5.0 (McNeelUpdate) - Robert McNeel & Associates - C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VRLService - Unknown owner - C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe

--
End of file - 15617 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\system32\WLANExt.exe 31246976
\??\C:\windows\system32\conhost.exe "-157473640036904568920936385271041321141-6968205491503703068866703440-214387123
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\windows\system32\Dwm.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
"taskhost.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe"
"c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"
"C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 4868
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"

"C:\Users\Petra\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\AutoKMS.job - C:\windows\AutoKMS.exe
C:\windows\tasks\COMODO Updater.job - C:\Program Files\COMODO\COMODO System-Cleaner\Updater.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\HPCeeScheduleForPETRA-HP$.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPETRA-HP$ (null)
C:\windows\tasks\HPCeeScheduleForPetra.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPetra (null)

=========Mozilla firefox=========

ProfilePath - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\yglywmtp.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-06-16 581824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-02-07 117248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-06 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-06-16 436600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-01-27 167960]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-01-27 391704]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-01-27 418328]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-06 615584]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-06 379040]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2014-05-19 1664000]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSK DLMSession]
C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [2014-02-05 1627032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
C:\Users\Petra\AppData\Local\Akamai\netsession_win.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comodo_TE_{B9B19C9E-4F55-443C-B1C6-ED38C7F8E3CD}]
C:\Users\Petra\AppData\Local\Temp\cisfe4751\cmdinstall.exe -cmdfile C:\Users\Petra\AppData\Local\Temp\cisfe4751 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun]
c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2010-11-24 517456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\File Sanitizer]
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2011-02-07 12274688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager]
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy]
c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-02-11 76344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MfeEpePcMonitor]
C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [2011-02-09 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-03 15028104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodecPackUpdateChecker.lnk]
C:\Windows\SysWOW64\C2MP\UPDATE~1.EXE [2014-05-20 48688]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-28 336384]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
""= []
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-06-16 3890208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-01-27 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
EpePcNp64
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.ac3filter"=ac3filter64.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-06-18 18:46:04 ----D---- C:\rsit
2014-06-18 18:46:04 ----D---- C:\Program Files\trend micro
2014-06-18 17:45:50 ----D---- C:\Program Files (x86)\MRU-Blaster
2014-06-18 17:45:50 ----A---- C:\windows\SYSWOW64\MSSTDFMT.DLL
2014-06-18 17:26:43 ----D---- C:\Program Files\CCleaner
2014-06-18 14:24:20 ----D---- C:\cmospwd-5.0
2014-06-18 14:08:24 ----N---- C:\windows\KMSEmulator.exe
2014-06-18 12:00:31 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2014-06-18 03:01:01 ----A---- C:\windows\system32\MRT.exe
2014-06-18 02:03:42 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-17 20:38:46 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-17 20:38:46 ----A---- C:\windows\system32\rdpcorets.dll
2014-06-17 20:38:40 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-06-17 20:38:40 ----A---- C:\windows\system32\mstscax.dll
2014-06-17 18:39:33 ----D---- C:\ProgramData\Oracle
2014-06-17 18:34:58 ----D---- C:\ProgramData\Sun
2014-06-17 18:34:28 ----D---- C:\Program Files (x86)\Java
2014-06-17 17:53:46 ----D---- C:\ProgramData\McAfee
2014-06-17 16:38:53 ----D---- C:\windows\system32\MRT
2014-06-17 13:31:22 ----A---- C:\windows\system32\TsUsbGDCoInstaller.dll
2014-06-17 13:31:16 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-06-17 13:31:16 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-06-17 13:31:16 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\wksprtPS.dll
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\MsRdpWebAccess.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\wksprtPS.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\tsgqec.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\MsRdpWebAccess.dll
2014-06-17 13:31:14 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-06-17 13:31:14 ----A---- C:\windows\system32\wksprt.exe
2014-06-17 13:31:14 ----A---- C:\windows\system32\TSWbPrxy.exe
2014-06-17 13:31:13 ----A---- C:\windows\system32\mstsc.exe
2014-06-17 13:31:12 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2014-06-17 13:31:12 ----A---- C:\windows\system32\rdvidcrl.dll
2014-06-17 13:30:07 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys
2014-06-17 13:30:02 ----A---- C:\windows\SYSWOW64\rdpendp_winip.dll
2014-06-17 13:30:02 ----A---- C:\windows\system32\rdpudd.dll
2014-06-17 13:30:02 ----A---- C:\windows\system32\rdpendp_winip.dll
2014-06-17 13:23:14 ----A---- C:\windows\SYSWOW64\TSWorkspace.dll
2014-06-17 13:23:14 ----A---- C:\windows\system32\TSWorkspace.dll
2014-06-17 13:23:09 ----A---- C:\windows\SYSWOW64\qdvd.dll
2014-06-17 13:23:09 ----A---- C:\windows\system32\qdvd.dll
2014-06-17 12:17:58 ----D---- C:\ProgramData\Comodo
2014-06-16 23:24:45 ----D---- C:\Users\Petra\AppData\Roaming\IDT
2014-06-16 22:51:43 ----D---- C:\Users\Petra\AppData\Roaming\AVAST Software
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswVmm.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswstm.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswsp.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswsnx.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswHwid.sys
2014-06-16 22:45:08 ----A---- C:\windows\system32\aswBoot.exe
2014-06-16 22:45:04 ----A---- C:\windows\avastSS.scr
2014-06-16 22:39:30 ----D---- C:\Program Files\AVAST Software
2014-06-16 22:36:14 ----D---- C:\ProgramData\AVAST Software
2014-06-16 22:24:47 ----D---- C:\windows\pss
2014-06-16 22:02:03 ----A---- C:\windows\CSC_ServiceDump.dat
2014-06-16 22:02:03 ----A---- C:\windows\CSC_ActiveCleanLog.dat
2014-06-16 21:14:27 ----D---- C:\Program Files\COMODO
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\mfc71.dll
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\gdiplus.dll
2014-06-16 21:12:58 ----D---- C:\Program Files (x86)\USBTest
2014-06-16 21:08:55 ----D---- C:\Users\Petra\AppData\Roaming\ArcSoft
2014-06-12 11:04:26 ----A---- C:\windows\SYSWOW64\usp10.dll
2014-06-12 11:04:26 ----A---- C:\windows\system32\usp10.dll
2014-06-12 11:04:26 ----A---- C:\windows\system32\drivers\tcpip.sys
2014-06-12 11:04:26 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 11:04:25 ----A---- C:\windows\SYSWOW64\msxml6.dll
2014-06-12 11:04:25 ----A---- C:\windows\system32\msxml6.dll
2014-06-12 11:04:25 ----A---- C:\windows\system32\msxml3.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml6r.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml3.dll
2014-06-12 11:04:24 ----A---- C:\windows\system32\msxml6r.dll
2014-06-12 11:04:24 ----A---- C:\windows\system32\msxml3r.dll
2014-06-12 11:04:23 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-06-12 11:04:22 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 11:04:22 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-06-12 11:04:21 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\urlmon.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\ieetwcollector.exe
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-06-12 11:04:19 ----A---- C:\windows\system32\msfeeds.dll
2014-06-12 11:04:19 ----A---- C:\windows\system32\dxtmsft.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\iesetup.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\iertutil.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\ie4uinit.exe
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-06-12 11:04:17 ----A---- C:\windows\system32\jsproxy.dll
2014-06-12 11:04:17 ----A---- C:\windows\system32\iernonce.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\ieui.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\ieframe.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\dxtrans.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\mshtmled.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\jscript9diag.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\jscript9.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\ieUnatt.exe
2014-06-12 11:04:14 ----A---- C:\windows\system32\wininet.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\vbscript.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\msrating.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\ieapfltr.dll
2014-06-12 11:04:13 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 11:04:13 ----A---- C:\windows\system32\mshtml.dll
2014-06-12 11:02:12 ----A---- C:\windows\system32\aepdu.dll
2014-06-12 11:02:12 ----A---- C:\windows\system32\aeinv.dll
2014-05-28 14:56:28 ----D---- C:\Users\Petra\AppData\Roaming\AVG
2014-05-28 14:56:22 ----D---- C:\Program Files (x86)\AVG
2014-05-28 14:53:04 ----D---- C:\ProgramData\AVG
2014-05-28 14:49:18 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-05-28 14:49:18 ----HD---- C:\ProgramData\Common Files
2014-05-28 14:48:34 ----D---- C:\Users\Petra\AppData\Roaming\OpenCandy
2014-05-28 14:48:04 ----D---- C:\windows\SYSWOW64\C2MP
2014-05-28 14:45:51 ----D---- C:\ProgramData\VistaCodecs
2014-05-26 22:05:37 ----D---- C:\Program Files\Kolor
2014-05-26 14:12:06 ----D---- C:\windows\Minidump
2014-05-21 15:34:40 ----D---- C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-05-20 15:03:52 ----A---- C:\windows\SYSWOW64\DiscHandler.exe
2014-05-19 13:10:53 ----A---- C:\windows\system32\athihvs.dll
2014-05-19 13:10:33 ----D---- C:\ProgramData\Qualcomm Atheros
2014-05-19 13:01:06 ----D---- C:\Users\Petra\AppData\Roaming\Macrovision
2014-05-19 13:01:05 ----D---- C:\Users\Petra\AppData\Roaming\FLEXnet
2014-05-19 13:00:54 ----D---- C:\windows\DPDrv
2014-05-19 12:47:21 ----A---- C:\windows\system32\drivers\volsnap.sys
2014-05-19 12:45:20 ----A---- C:\windows\system32\umpo.dll
2014-05-19 12:40:56 ----A---- C:\windows\system32\RtNicProp64.dll
2014-05-19 12:40:56 ----A---- C:\windows\system32\drivers\Rt64win7.sys
2014-05-19 12:28:27 ----A---- C:\windows\system32\drivers\jmcr.sys
2014-05-19 12:26:20 ----N---- C:\windows\system32\stapi64.dll
2014-05-19 12:26:20 ----A---- C:\windows\system32\stcplx64.dll
2014-05-19 12:26:20 ----A---- C:\windows\system32\stapo64.dll
2014-05-19 12:26:20 ----A---- C:\windows\system32\st646428.dll
2014-05-19 12:26:20 ----A---- C:\windows\system32\drivers\stwrt64.sys
2014-05-19 12:26:15 ----D---- C:\Program Files\IDT
2014-05-19 12:21:39 ----A---- C:\windows\SYSWOW64\SETE4B9.TMP
2014-05-19 12:21:39 ----A---- C:\windows\SYSWOW64\SETE499.TMP
2014-05-19 12:21:39 ----A---- C:\windows\system32\WdfCoInstaller01011.dll
2014-05-19 12:21:39 ----A---- C:\windows\system32\SynCOM.dll

======List of files/folders modified in the last 1 month======

2014-06-18 18:46:17 ----D---- C:\windows\Prefetch
2014-06-18 18:46:04 ----RD---- C:\Program Files
2014-06-18 18:09:39 ----D---- C:\windows\system32\config
2014-06-18 18:01:27 ----D---- C:\windows\Temp
2014-06-18 18:01:26 ----A---- C:\windows\SYSWOW64\log.txt
2014-06-18 17:59:33 ----D---- C:\ProgramData\PDFC
2014-06-18 17:45:50 ----RD---- C:\Program Files (x86)
2014-06-18 17:45:50 ----D---- C:\windows\SysWOW64
2014-06-18 17:36:35 ----D---- C:\windows\inf
2014-06-18 17:33:50 ----D---- C:\Windows
2014-06-18 17:30:07 ----D---- C:\Users\Petra\AppData\Roaming\Skype
2014-06-18 17:30:04 ----D---- C:\windows\Panther
2014-06-18 17:30:00 ----D---- C:\windows\Logs
2014-06-18 17:30:00 ----D---- C:\windows\debug
2014-06-18 17:26:47 ----D---- C:\windows\system32\Tasks
2014-06-18 17:12:16 ----D---- C:\Program Files (x86)\Adobe
2014-06-18 16:01:38 ----D---- C:\windows\System32
2014-06-18 16:01:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-06-18 15:30:49 ----D---- C:\windows\system32\catroot2
2014-06-18 14:06:30 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-18 12:00:32 ----SHD---- C:\windows\Installer
2014-06-18 12:00:32 ----SHD---- C:\Config.Msi
2014-06-18 12:00:32 ----D---- C:\windows\Downloaded Program Files
2014-06-18 11:56:23 ----SHD---- C:\System Volume Information
2014-06-18 11:38:32 ----D---- C:\Program Files (x86)\Hewlett-Packard
2014-06-18 11:38:30 ----RSD---- C:\windows\assembly
2014-06-18 11:38:20 ----D---- C:\swsetup
2014-06-18 11:32:04 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-06-18 06:22:56 ----D---- C:\windows\Tasks
2014-06-18 06:22:56 ----D---- C:\windows\system32\wfp
2014-06-18 06:22:56 ----D---- C:\windows\system32\DriverStore
2014-06-18 06:22:56 ----D---- C:\windows\system32\drivers
2014-06-18 06:22:55 ----D---- C:\windows\system32\wbem
2014-06-18 06:22:54 ----D---- C:\windows\system32\CodeIntegrity
2014-06-18 06:22:49 ----D---- C:\ProgramData\WildTangent
2014-06-18 06:22:47 ----D---- C:\Program Files\Validity Sensors
2014-06-18 06:22:46 ----D---- C:\Program Files\Hewlett-Packard
2014-06-18 06:22:45 ----D---- C:\Program Files (x86)\HP Games
2014-06-18 06:22:41 ----D---- C:\Program Files (x86)\Google
2014-06-18 06:22:41 ----D---- C:\Program Files (x86)\Common Files
2014-06-18 06:21:47 ----D---- C:\windows\registration
2014-06-18 06:18:55 ----HD---- C:\ProgramData
2014-06-18 04:51:50 ----D---- C:\windows\system32\LogFiles
2014-06-18 03:57:30 ----D---- C:\windows\rescache
2014-06-18 03:00:54 ----D---- C:\windows\winsxs
2014-06-18 03:00:49 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-06-18 03:00:49 ----D---- C:\windows\system32\cs-CZ
2014-06-17 20:38:18 ----D---- C:\windows\system32\catroot
2014-06-17 20:33:25 ----D---- C:\ProgramData\Hewlett-Packard
2014-06-17 17:24:41 ----D---- C:\Users\Petra\AppData\Roaming\hpqLog
2014-06-17 17:18:54 ----D---- C:\windows\system32\appmgmt
2014-06-17 13:32:30 ----D---- C:\windows\SYSWOW64\wbem
2014-06-17 13:32:30 ----D---- C:\windows\system32\drivers\en-US
2014-06-17 13:32:29 ----D---- C:\windows\SYSWOW64\en-US
2014-06-17 13:32:29 ----D---- C:\windows\system32\en-US
2014-06-17 13:32:29 ----D---- C:\windows\PolicyDefinitions
2014-06-16 22:55:46 ----D---- C:\windows\SYSWOW64\config
2014-06-16 21:08:57 ----HD---- C:\ProgramData\ArcSoft
2014-06-13 20:19:09 ----D---- C:\Program Files\Internet Explorer
2014-06-13 20:18:38 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-13 20:02:33 ----SD---- C:\windows\system32\CompatTel
2014-06-04 00:26:01 ----SD---- C:\Users\Petra\AppData\Roaming\Microsoft
2014-06-01 01:54:55 ----D---- C:\windows\system32\NDF
2014-05-28 15:23:51 ----D---- C:\ProgramData\ASGVIS
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_UNRAR.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_SAMPLERATE.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBMAD.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBDTS.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBA52.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\XVIDVFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\XVIDCORE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\X264VFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\VSFILTER.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TOMSMOCOMP_FF.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TAK_DECO_LIB.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\SWSCALE-LAV-2.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\OPTIMFROG.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\OGM.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MP4.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKZLIB.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKX.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKV2VFR.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKUNICODE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LIBMPEG2_FF.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LIBBLURAY.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LAGARITH.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\GDSMUX.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FFMPEG.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FF_WMV9.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FF_VFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\DXR.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\DSMUX.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSWV.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSOPUS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSFLAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSCD.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_TTA.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_TAK.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_OFR.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_MPC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_APE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_ALAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_AAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVUTIL-LAV-52.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVSS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVRESAMPLE-LAV-1.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVI.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVFORMAT-LAV-55.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVFILTER-LAV-4.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVCODEC-LAV-55.DLL.NEW
2014-05-26 09:58:15 ----D---- C:\Users\Petra\AppData\Roaming\skypePM
2014-05-21 15:39:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-05-21 15:38:58 ----D---- C:\windows\Help
2014-05-19 14:46:29 ----D---- C:\windows\system32\wdi
2014-05-19 13:11:30 ----D---- C:\Program Files (x86)\Atheros
2014-05-19 13:10:54 ----D---- C:\windows\system32\zh-TW
2014-05-19 13:10:54 ----D---- C:\windows\system32\zh-CN
2014-05-19 13:10:54 ----D---- C:\windows\system32\tr-TR
2014-05-19 13:10:54 ----D---- C:\windows\system32\sv-SE
2014-05-19 13:10:54 ----D---- C:\windows\system32\ru-RU
2014-05-19 13:10:54 ----D---- C:\windows\system32\pt-PT
2014-05-19 13:10:54 ----D---- C:\windows\system32\pl-PL
2014-05-19 13:10:54 ----D---- C:\windows\system32\nn-NO
2014-05-19 13:10:54 ----D---- C:\windows\system32\nl-NL
2014-05-19 13:10:54 ----D---- C:\windows\system32\ko-KR
2014-05-19 13:10:54 ----D---- C:\windows\system32\ja-JP
2014-05-19 13:10:54 ----D---- C:\windows\system32\it-IT
2014-05-19 13:10:54 ----D---- C:\windows\system32\hu-HU
2014-05-19 13:10:54 ----D---- C:\windows\system32\fr-FR
2014-05-19 13:10:54 ----D---- C:\windows\system32\fi-FI
2014-05-19 13:10:54 ----D---- C:\windows\system32\es-ES
2014-05-19 13:10:53 ----D---- C:\windows\system32\el-GR
2014-05-19 13:10:53 ----D---- C:\windows\system32\de-DE
2014-05-19 13:10:53 ----D---- C:\windows\system32\da-DK
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\zh-Hant
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\zh-Hans
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\ru
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\pt-BR
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\ko
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\ja
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\it
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\fr
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\es
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\de
2014-05-19 13:01:00 ----D---- C:\windows\SYSWOW64\cs
2014-05-19 13:01:00 ----D---- C:\windows\system32\zh-Hant
2014-05-19 13:01:00 ----D---- C:\windows\system32\zh-Hans
2014-05-19 13:01:00 ----D---- C:\windows\system32\ru
2014-05-19 13:01:00 ----D---- C:\windows\system32\pt-BR
2014-05-19 13:01:00 ----D---- C:\windows\system32\ko
2014-05-19 13:01:00 ----D---- C:\windows\system32\ja
2014-05-19 13:01:00 ----D---- C:\windows\system32\it
2014-05-19 13:01:00 ----D---- C:\windows\system32\fr
2014-05-19 13:01:00 ----D---- C:\windows\system32\es
2014-05-19 13:01:00 ----D---- C:\windows\system32\de
2014-05-19 13:01:00 ----D---- C:\windows\system32\cs
2014-05-19 12:59:38 ----D---- C:\ProgramData\HPQLOG
2014-05-19 12:45:00 ----D---- C:\windows\SYSWOW64\drivers
2014-05-19 12:45:00 ----D---- C:\windows\SoftwareDistribution
2014-05-19 12:40:56 ----D---- C:\Program Files (x86)\Realtek
2014-05-19 12:40:26 ----A---- C:\windows\system32\RTNUninst64.dll
2014-05-19 12:26:02 ----A---- C:\windows\system32\stlang64.dll
2014-05-19 12:26:02 ----A---- C:\windows\system32\IDTNX.dll
2014-05-19 12:26:02 ----A---- C:\windows\system32\IDTNJ.exe
2014-05-19 12:26:02 ----A---- C:\windows\system32\IDTNHP.dll
2014-05-19 12:26:02 ----A---- C:\windows\system32\IDTNGUI.exe
2014-05-19 12:26:02 ----A---- C:\windows\sttray64.exe
2014-05-19 12:26:01 ----A---- C:\windows\system32\HPToneCtrls64.dll
2014-05-19 12:26:01 ----A---- C:\windows\system32\AESTEC64.dll
2014-05-19 12:26:01 ----A---- C:\windows\system32\AESTCo64.dll
2014-05-19 12:26:01 ----A---- C:\windows\system32\AESTAR64.dll
2014-05-19 12:26:01 ----A---- C:\windows\system32\AESTAC64.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-06-16 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-06-16 208416]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-01-26 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2011-02-09 168008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-06-16 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-06-16 1039096]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-06-16 423240]
R1 CFRMD;CFRMD; C:\windows\system32\DRIVERS\CFRMD.sys [2010-12-09 79552]
R1 CFRPD;CFRPD; C:\windows\system32\DRIVERS\CFRPD.sys [2010-12-09 41472]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-06-16 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-06-16 79184]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-06-16 85328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-01-26 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-28 9319424]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-28 303616]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2011-01-06 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-12-20 3837440]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2011-01-06 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2011-01-06 28832]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-06 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-06 154272]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2011-01-06 279200]
R3 BthEnum;Služba Bluetooth Enumerator; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-12-03 25912]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2014-05-19 175928]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2014-05-19 708200]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2014-05-19 543744]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-10-30 549104]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
S2 ioperm;ioperm support for Cygwin driver; \??\c:\cmospwd-5.0\windows\ioperm.sys [2004-11-26 12800]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-06 201376]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2011-02-07 63336]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2014-05-19 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-28 203264]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-06 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-06 53920]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-06-16 50344]
R2 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 371648]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-11-10 486224]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-01-26 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 210896]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
R2 McNeelUpdate;McNeel Update Service 5.0; C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [2012-10-25 67752]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2014-05-19 323072]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R2 VRLService;VRLService; C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE [2012-12-06 212992]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 116648]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16 257712]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-02-04 464480]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-04-14 1432400]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-09-30 246520]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 116648]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-05-30 111616]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-18 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-04-16 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 18 čer 2014 18:54
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 13:58
od mnevidal
Omlouvám se za delší odmlku a posílám log :)

# AdwCleaner v3.212 - Report created 19/06/2014 at 14:53:12
# Updated 05/06/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Petra - PETRA-HP
# Running from : C:\Users\Petra\Desktop\adwcleaner_3.212.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Petra\AppData\Roaming\OpenCandy

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKCU\Software\InstallCore

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Mozilla Firefox v30.0 (cs)

[ File : C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\yglywmtp.default\prefs.js ]


-\\ Google Chrome v35.0.1916.153

*************************

AdwCleaner[R0].txt - [1479 octets] - [19/06/2014 14:51:20]
AdwCleaner[R1].txt - [1537 octets] - [19/06/2014 14:52:43]
AdwCleaner[S0].txt - [1308 octets] - [19/06/2014 14:53:12]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1368 octets] ##########

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 16:58
od Rudy
Dejte nový log RSIT.

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 18:53
od mnevidal
Logfile of random's system information tool 1.10 (written by random/random)
Run by Petra at 2014-06-19 19:52:48
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 511 GB (87%) free of 588 GB
Total RAM: 4030 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:52:52, on 19.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Petra.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.co ... 5.24.0.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO System - Cleaner Service (Cleaner_Validator) - Unknown owner - C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: McNeel Update Service 5.0 (McNeelUpdate) - Robert McNeel & Associates - C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VRLService - Unknown owner - C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe

--
End of file - 15617 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\windows\system32\WLANExt.exe 30094496
\??\C:\windows\system32\conhost.exe "-113807508899996685-244520694197791287-203722813615267646711223721054259857711
"C:\windows\system32\Dwm.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
"taskhost.exe"
"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\windows\system32\NOTEPAD.EXE" C:\AdwCleaner\AdwCleaner[S0].txt
"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe"
"c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"
"C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1136
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"

"C:\Users\Petra\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\AutoKMS.job - C:\windows\AutoKMS.exe
C:\windows\tasks\COMODO Updater.job - C:\Program Files\COMODO\COMODO System-Cleaner\Updater.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\HPCeeScheduleForPETRA-HP$.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPETRA-HP$ (null)
C:\windows\tasks\HPCeeScheduleForPetra.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPetra (null)

=========Mozilla firefox=========

ProfilePath - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\yglywmtp.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-06-16 581824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-02-07 117248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-06 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-06-16 436600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-01-27 167960]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-01-27 391704]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-01-27 418328]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-06 615584]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-06 379040]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2014-05-19 1664000]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSK DLMSession]
C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [2014-02-05 1627032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
C:\Users\Petra\AppData\Local\Akamai\netsession_win.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comodo_TE_{B9B19C9E-4F55-443C-B1C6-ED38C7F8E3CD}]
C:\Users\Petra\AppData\Local\Temp\cisfe4751\cmdinstall.exe -cmdfile C:\Users\Petra\AppData\Local\Temp\cisfe4751 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun]
c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2010-11-24 517456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\File Sanitizer]
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2011-02-07 12274688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager]
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy]
c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-02-11 76344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MfeEpePcMonitor]
C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [2011-02-09 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-03 15028104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodecPackUpdateChecker.lnk]
C:\Windows\SysWOW64\C2MP\UPDATE~1.EXE [2014-05-20 48688]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-28 336384]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
""= []
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-06-16 3890208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-01-27 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
EpePcNp64
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.ac3filter"=ac3filter64.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-06-19 14:51:49 ----A---- C:\windows\SYSWOW64\sqlite3.dll
2014-06-19 02:37:44 ----D---- C:\AdwCleaner
2014-06-18 18:46:04 ----D---- C:\rsit
2014-06-18 18:46:04 ----D---- C:\Program Files\trend micro
2014-06-18 17:45:50 ----D---- C:\Program Files (x86)\MRU-Blaster
2014-06-18 17:45:50 ----A---- C:\windows\SYSWOW64\MSSTDFMT.DLL
2014-06-18 17:26:43 ----D---- C:\Program Files\CCleaner
2014-06-18 14:24:20 ----D---- C:\cmospwd-5.0
2014-06-18 14:08:24 ----N---- C:\windows\KMSEmulator.exe
2014-06-18 12:00:31 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2014-06-18 03:01:01 ----A---- C:\windows\system32\MRT.exe
2014-06-18 02:03:42 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-17 20:38:46 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-17 20:38:46 ----A---- C:\windows\system32\rdpcorets.dll
2014-06-17 20:38:40 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-06-17 20:38:40 ----A---- C:\windows\system32\mstscax.dll
2014-06-17 18:39:33 ----D---- C:\ProgramData\Oracle
2014-06-17 18:34:58 ----D---- C:\ProgramData\Sun
2014-06-17 18:34:28 ----D---- C:\Program Files (x86)\Java
2014-06-17 17:53:46 ----D---- C:\ProgramData\McAfee
2014-06-17 16:38:53 ----D---- C:\windows\system32\MRT
2014-06-17 13:31:22 ----A---- C:\windows\system32\TsUsbGDCoInstaller.dll
2014-06-17 13:31:16 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-06-17 13:31:16 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-06-17 13:31:16 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\wksprtPS.dll
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\MsRdpWebAccess.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\wksprtPS.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\tsgqec.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\MsRdpWebAccess.dll
2014-06-17 13:31:14 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-06-17 13:31:14 ----A---- C:\windows\system32\wksprt.exe
2014-06-17 13:31:14 ----A---- C:\windows\system32\TSWbPrxy.exe
2014-06-17 13:31:13 ----A---- C:\windows\system32\mstsc.exe
2014-06-17 13:31:12 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2014-06-17 13:31:12 ----A---- C:\windows\system32\rdvidcrl.dll
2014-06-17 13:30:07 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys
2014-06-17 13:30:02 ----A---- C:\windows\SYSWOW64\rdpendp_winip.dll
2014-06-17 13:30:02 ----A---- C:\windows\system32\rdpudd.dll
2014-06-17 13:30:02 ----A---- C:\windows\system32\rdpendp_winip.dll
2014-06-17 13:23:14 ----A---- C:\windows\SYSWOW64\TSWorkspace.dll
2014-06-17 13:23:14 ----A---- C:\windows\system32\TSWorkspace.dll
2014-06-17 13:23:09 ----A---- C:\windows\SYSWOW64\qdvd.dll
2014-06-17 13:23:09 ----A---- C:\windows\system32\qdvd.dll
2014-06-17 12:17:58 ----D---- C:\ProgramData\Comodo
2014-06-16 23:24:45 ----D---- C:\Users\Petra\AppData\Roaming\IDT
2014-06-16 22:51:43 ----D---- C:\Users\Petra\AppData\Roaming\AVAST Software
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswVmm.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswstm.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswsp.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswsnx.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswHwid.sys
2014-06-16 22:45:08 ----A---- C:\windows\system32\aswBoot.exe
2014-06-16 22:45:04 ----A---- C:\windows\avastSS.scr
2014-06-16 22:39:30 ----D---- C:\Program Files\AVAST Software
2014-06-16 22:36:14 ----D---- C:\ProgramData\AVAST Software
2014-06-16 22:24:47 ----D---- C:\windows\pss
2014-06-16 22:02:03 ----A---- C:\windows\CSC_ServiceDump.dat
2014-06-16 22:02:03 ----A---- C:\windows\CSC_ActiveCleanLog.dat
2014-06-16 21:14:27 ----D---- C:\Program Files\COMODO
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\mfc71.dll
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\gdiplus.dll
2014-06-16 21:12:58 ----D---- C:\Program Files (x86)\USBTest
2014-06-16 21:08:55 ----D---- C:\Users\Petra\AppData\Roaming\ArcSoft
2014-06-12 11:04:26 ----A---- C:\windows\SYSWOW64\usp10.dll
2014-06-12 11:04:26 ----A---- C:\windows\system32\usp10.dll
2014-06-12 11:04:26 ----A---- C:\windows\system32\drivers\tcpip.sys
2014-06-12 11:04:26 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 11:04:25 ----A---- C:\windows\SYSWOW64\msxml6.dll
2014-06-12 11:04:25 ----A---- C:\windows\system32\msxml6.dll
2014-06-12 11:04:25 ----A---- C:\windows\system32\msxml3.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml6r.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml3.dll
2014-06-12 11:04:24 ----A---- C:\windows\system32\msxml6r.dll
2014-06-12 11:04:24 ----A---- C:\windows\system32\msxml3r.dll
2014-06-12 11:04:23 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-06-12 11:04:22 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 11:04:22 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-06-12 11:04:21 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\urlmon.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\ieetwcollector.exe
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-06-12 11:04:19 ----A---- C:\windows\system32\msfeeds.dll
2014-06-12 11:04:19 ----A---- C:\windows\system32\dxtmsft.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\iesetup.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\iertutil.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\ie4uinit.exe
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-06-12 11:04:17 ----A---- C:\windows\system32\jsproxy.dll
2014-06-12 11:04:17 ----A---- C:\windows\system32\iernonce.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\ieui.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\ieframe.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\dxtrans.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\mshtmled.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\jscript9diag.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\jscript9.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\ieUnatt.exe
2014-06-12 11:04:14 ----A---- C:\windows\system32\wininet.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\vbscript.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\msrating.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\ieapfltr.dll
2014-06-12 11:04:13 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 11:04:13 ----A---- C:\windows\system32\mshtml.dll
2014-06-12 11:02:12 ----A---- C:\windows\system32\aepdu.dll
2014-06-12 11:02:12 ----A---- C:\windows\system32\aeinv.dll
2014-05-28 14:56:28 ----D---- C:\Users\Petra\AppData\Roaming\AVG
2014-05-28 14:56:22 ----D---- C:\Program Files (x86)\AVG
2014-05-28 14:53:04 ----D---- C:\ProgramData\AVG
2014-05-28 14:49:18 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-05-28 14:49:18 ----HD---- C:\ProgramData\Common Files
2014-05-28 14:48:04 ----D---- C:\windows\SYSWOW64\C2MP
2014-05-28 14:45:51 ----D---- C:\ProgramData\VistaCodecs
2014-05-26 22:05:37 ----D---- C:\Program Files\Kolor
2014-05-26 14:12:06 ----D---- C:\windows\Minidump
2014-05-21 15:34:40 ----D---- C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-05-20 15:03:52 ----A---- C:\windows\SYSWOW64\DiscHandler.exe

======List of files/folders modified in the last 1 month======

2014-06-19 15:31:43 ----D---- C:\windows\Temp
2014-06-19 15:28:25 ----D---- C:\windows\Prefetch
2014-06-19 15:11:41 ----D---- C:\windows\system32\config
2014-06-19 15:00:03 ----A---- C:\windows\SYSWOW64\log.txt
2014-06-19 14:58:08 ----D---- C:\ProgramData\PDFC
2014-06-19 14:51:49 ----D---- C:\windows\SysWOW64
2014-06-18 18:46:04 ----RD---- C:\Program Files
2014-06-18 17:45:50 ----RD---- C:\Program Files (x86)
2014-06-18 17:36:35 ----D---- C:\windows\inf
2014-06-18 17:33:50 ----D---- C:\Windows
2014-06-18 17:30:07 ----D---- C:\Users\Petra\AppData\Roaming\Skype
2014-06-18 17:30:04 ----D---- C:\windows\Panther
2014-06-18 17:30:00 ----D---- C:\windows\Logs
2014-06-18 17:30:00 ----D---- C:\windows\debug
2014-06-18 17:26:47 ----D---- C:\windows\system32\Tasks
2014-06-18 17:12:16 ----D---- C:\Program Files (x86)\Adobe
2014-06-18 16:01:38 ----D---- C:\windows\System32
2014-06-18 16:01:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-06-18 15:30:49 ----D---- C:\windows\system32\catroot2
2014-06-18 14:06:30 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-18 12:00:32 ----SHD---- C:\windows\Installer
2014-06-18 12:00:32 ----SHD---- C:\Config.Msi
2014-06-18 12:00:32 ----D---- C:\windows\Downloaded Program Files
2014-06-18 11:56:23 ----SHD---- C:\System Volume Information
2014-06-18 11:38:32 ----D---- C:\Program Files (x86)\Hewlett-Packard
2014-06-18 11:38:30 ----RSD---- C:\windows\assembly
2014-06-18 11:38:20 ----D---- C:\swsetup
2014-06-18 11:32:04 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-06-18 06:22:56 ----D---- C:\windows\Tasks
2014-06-18 06:22:56 ----D---- C:\windows\system32\wfp
2014-06-18 06:22:56 ----D---- C:\windows\system32\DriverStore
2014-06-18 06:22:56 ----D---- C:\windows\system32\drivers
2014-06-18 06:22:55 ----D---- C:\windows\system32\wbem
2014-06-18 06:22:54 ----D---- C:\windows\system32\CodeIntegrity
2014-06-18 06:22:49 ----D---- C:\ProgramData\WildTangent
2014-06-18 06:22:47 ----D---- C:\Program Files\Validity Sensors
2014-06-18 06:22:46 ----D---- C:\Program Files\Hewlett-Packard
2014-06-18 06:22:45 ----D---- C:\Program Files (x86)\HP Games
2014-06-18 06:22:41 ----D---- C:\Program Files (x86)\Google
2014-06-18 06:22:41 ----D---- C:\Program Files (x86)\Common Files
2014-06-18 06:21:47 ----D---- C:\windows\registration
2014-06-18 06:18:55 ----HD---- C:\ProgramData
2014-06-18 04:51:50 ----D---- C:\windows\system32\LogFiles
2014-06-18 03:57:30 ----D---- C:\windows\rescache
2014-06-18 03:00:54 ----D---- C:\windows\winsxs
2014-06-18 03:00:49 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-06-18 03:00:49 ----D---- C:\windows\system32\cs-CZ
2014-06-17 20:38:18 ----D---- C:\windows\system32\catroot
2014-06-17 20:33:25 ----D---- C:\ProgramData\Hewlett-Packard
2014-06-17 17:24:41 ----D---- C:\Users\Petra\AppData\Roaming\hpqLog
2014-06-17 17:18:54 ----D---- C:\windows\system32\appmgmt
2014-06-17 13:32:30 ----D---- C:\windows\SYSWOW64\wbem
2014-06-17 13:32:30 ----D---- C:\windows\system32\drivers\en-US
2014-06-17 13:32:29 ----D---- C:\windows\SYSWOW64\en-US
2014-06-17 13:32:29 ----D---- C:\windows\system32\en-US
2014-06-17 13:32:29 ----D---- C:\windows\PolicyDefinitions
2014-06-16 22:55:46 ----D---- C:\windows\SYSWOW64\config
2014-06-16 21:08:57 ----HD---- C:\ProgramData\ArcSoft
2014-06-13 20:19:09 ----D---- C:\Program Files\Internet Explorer
2014-06-13 20:18:38 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-13 20:02:33 ----SD---- C:\windows\system32\CompatTel
2014-06-04 00:26:01 ----SD---- C:\Users\Petra\AppData\Roaming\Microsoft
2014-06-01 01:54:55 ----D---- C:\windows\system32\NDF
2014-05-28 15:23:51 ----D---- C:\ProgramData\ASGVIS
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_UNRAR.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_SAMPLERATE.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBMAD.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBDTS.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBA52.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\XVIDVFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\XVIDCORE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\X264VFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\VSFILTER.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TOMSMOCOMP_FF.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TAK_DECO_LIB.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\SWSCALE-LAV-2.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\OPTIMFROG.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\OGM.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MP4.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKZLIB.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKX.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKV2VFR.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKUNICODE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LIBMPEG2_FF.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LIBBLURAY.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LAGARITH.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\GDSMUX.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FFMPEG.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FF_WMV9.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FF_VFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\DXR.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\DSMUX.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSWV.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSOPUS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSFLAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSCD.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_TTA.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_TAK.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_OFR.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_MPC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_APE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_ALAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_AAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVUTIL-LAV-52.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVSS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVRESAMPLE-LAV-1.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVI.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVFORMAT-LAV-55.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVFILTER-LAV-4.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVCODEC-LAV-55.DLL.NEW
2014-05-26 09:58:15 ----D---- C:\Users\Petra\AppData\Roaming\skypePM
2014-05-21 15:39:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-05-21 15:38:58 ----D---- C:\windows\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-06-16 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-06-16 208416]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-01-26 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2011-02-09 168008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-06-16 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-06-16 1039096]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-06-16 423240]
R1 CFRMD;CFRMD; C:\windows\system32\DRIVERS\CFRMD.sys [2010-12-09 79552]
R1 CFRPD;CFRPD; C:\windows\system32\DRIVERS\CFRPD.sys [2010-12-09 41472]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-06-16 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-06-16 79184]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-06-16 85328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-01-26 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-28 9319424]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-28 303616]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2011-01-06 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-12-20 3837440]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2011-01-06 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2011-01-06 28832]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-06 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-06 154272]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2011-01-06 279200]
R3 BthEnum;Služba Bluetooth Enumerator; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-12-03 25912]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2014-05-19 175928]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2014-05-19 708200]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2014-05-19 543744]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-10-30 549104]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
S2 ioperm;ioperm support for Cygwin driver; \??\c:\cmospwd-5.0\windows\ioperm.sys [2004-11-26 12800]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-06 201376]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2011-02-07 63336]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2014-05-19 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-28 203264]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-06 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-06 53920]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-06-16 50344]
R2 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 371648]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-11-10 486224]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-01-26 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 210896]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
R2 McNeelUpdate;McNeel Update Service 5.0; C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [2012-10-25 67752]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2014-05-19 323072]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R2 VRLService;VRLService; C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE [2012-12-06 212992]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 116648]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16 257712]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-02-04 464480]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-04-14 1432400]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-09-30 246520]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 116648]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-05-30 111616]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-18 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-04-16 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 19:35
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\windows\tasks\AutoKMS.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Users\Petra\AppData\Local\Akamai
C:\windows\KMSEmulator.exe
C:\ProgramData\McAfee
C:\Program Files (x86)\AVG
C:\ProgramData\AVG

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 20:38
od mnevidal
Log z RSIT po skenu:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Petra at 2014-06-19 21:37:49
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 511 GB (87%) free of 588 GB
Total RAM: 4030 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:37:55, on 19.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Petra.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.co ... 5.24.0.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO System - Cleaner Service (Cleaner_Validator) - Unknown owner - C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: McNeel Update Service 5.0 (McNeelUpdate) - Robert McNeel & Associates - C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VRLService - Unknown owner - C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe

--
End of file - 15617 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"

C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\system32\WLANExt.exe 29366608
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
\??\C:\windows\system32\conhost.exe "-1401389372798537589-493042319-2109665244112372463-1538363931351156932-900202484
taskeng.exe {B329D54B-BCBE-470F-A5DF-CC5ED9400DEA}
C:\windows\System32\spoolsv.exe
"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe"
"c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"
"C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3516
C:\windows\system32\wbem\unsecapp.exe -Embedding
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2457981983-2278425531-3074817488-10012_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2457981983-2278425531-3074817488-10012 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Users\Petra\Downloads\RSITx64.exe"
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\COMODO Updater.job - C:\Program Files\COMODO\COMODO System-Cleaner\Updater.exe
C:\windows\tasks\HPCeeScheduleForPETRA-HP$.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPETRA-HP$ (null)
C:\windows\tasks\HPCeeScheduleForPetra.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPetra (null)

=========Mozilla firefox=========

ProfilePath - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\yglywmtp.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-06-16 581824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-02-07 117248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-06 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-06-16 436600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-01-27 167960]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-01-27 391704]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-01-27 418328]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-06 615584]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-06 379040]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2014-05-19 1664000]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSK DLMSession]
C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [2014-02-05 1627032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
C:\Users\Petra\AppData\Local\Akamai\netsession_win.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comodo_TE_{B9B19C9E-4F55-443C-B1C6-ED38C7F8E3CD}]
C:\Users\Petra\AppData\Local\Temp\cisfe4751\cmdinstall.exe -cmdfile C:\Users\Petra\AppData\Local\Temp\cisfe4751 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun]
c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2010-11-24 517456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\File Sanitizer]
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2011-02-07 12274688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager]
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy]
c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-02-11 76344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MfeEpePcMonitor]
C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [2011-02-09 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-03 15028104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodecPackUpdateChecker.lnk]
C:\Windows\SysWOW64\C2MP\UPDATE~1.EXE [2014-05-20 48688]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-28 336384]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
""= []
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-06-16 3890208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-01-27 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
EpePcNp64
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.ac3filter"=ac3filter64.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-06-19 21:30:33 ----D---- C:\_OTM
2014-06-19 14:51:49 ----A---- C:\windows\SYSWOW64\sqlite3.dll
2014-06-19 02:37:44 ----D---- C:\AdwCleaner
2014-06-18 18:46:04 ----D---- C:\rsit
2014-06-18 18:46:04 ----D---- C:\Program Files\trend micro
2014-06-18 17:45:50 ----D---- C:\Program Files (x86)\MRU-Blaster
2014-06-18 17:45:50 ----A---- C:\windows\SYSWOW64\MSSTDFMT.DLL
2014-06-18 17:26:43 ----D---- C:\Program Files\CCleaner
2014-06-18 14:24:20 ----D---- C:\cmospwd-5.0
2014-06-18 12:00:31 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2014-06-18 03:01:01 ----A---- C:\windows\system32\MRT.exe
2014-06-18 02:03:42 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-17 20:38:46 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-17 20:38:46 ----A---- C:\windows\system32\rdpcorets.dll
2014-06-17 20:38:40 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-06-17 20:38:40 ----A---- C:\windows\system32\mstscax.dll
2014-06-17 18:39:33 ----D---- C:\ProgramData\Oracle
2014-06-17 18:34:58 ----D---- C:\ProgramData\Sun
2014-06-17 18:34:28 ----D---- C:\Program Files (x86)\Java
2014-06-17 16:38:53 ----D---- C:\windows\system32\MRT
2014-06-17 13:31:22 ----A---- C:\windows\system32\TsUsbGDCoInstaller.dll
2014-06-17 13:31:16 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-06-17 13:31:16 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-06-17 13:31:16 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\wksprtPS.dll
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2014-06-17 13:31:15 ----A---- C:\windows\SYSWOW64\MsRdpWebAccess.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\wksprtPS.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\tsgqec.dll
2014-06-17 13:31:15 ----A---- C:\windows\system32\MsRdpWebAccess.dll
2014-06-17 13:31:14 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-06-17 13:31:14 ----A---- C:\windows\system32\wksprt.exe
2014-06-17 13:31:14 ----A---- C:\windows\system32\TSWbPrxy.exe
2014-06-17 13:31:13 ----A---- C:\windows\system32\mstsc.exe
2014-06-17 13:31:12 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2014-06-17 13:31:12 ----A---- C:\windows\system32\rdvidcrl.dll
2014-06-17 13:30:07 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys
2014-06-17 13:30:02 ----A---- C:\windows\SYSWOW64\rdpendp_winip.dll
2014-06-17 13:30:02 ----A---- C:\windows\system32\rdpudd.dll
2014-06-17 13:30:02 ----A---- C:\windows\system32\rdpendp_winip.dll
2014-06-17 13:23:14 ----A---- C:\windows\SYSWOW64\TSWorkspace.dll
2014-06-17 13:23:14 ----A---- C:\windows\system32\TSWorkspace.dll
2014-06-17 13:23:09 ----A---- C:\windows\SYSWOW64\qdvd.dll
2014-06-17 13:23:09 ----A---- C:\windows\system32\qdvd.dll
2014-06-17 12:17:58 ----D---- C:\ProgramData\Comodo
2014-06-16 23:24:45 ----D---- C:\Users\Petra\AppData\Roaming\IDT
2014-06-16 22:51:43 ----D---- C:\Users\Petra\AppData\Roaming\AVAST Software
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswVmm.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswstm.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswsp.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswsnx.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2014-06-16 22:45:15 ----A---- C:\windows\system32\drivers\aswHwid.sys
2014-06-16 22:45:08 ----A---- C:\windows\system32\aswBoot.exe
2014-06-16 22:45:04 ----A---- C:\windows\avastSS.scr
2014-06-16 22:39:30 ----D---- C:\Program Files\AVAST Software
2014-06-16 22:36:14 ----D---- C:\ProgramData\AVAST Software
2014-06-16 22:24:47 ----D---- C:\windows\pss
2014-06-16 22:02:03 ----A---- C:\windows\CSC_ServiceDump.dat
2014-06-16 22:02:03 ----A---- C:\windows\CSC_ActiveCleanLog.dat
2014-06-16 21:14:27 ----D---- C:\Program Files\COMODO
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\mfc71.dll
2014-06-16 21:14:07 ----A---- C:\windows\SYSWOW64\gdiplus.dll
2014-06-16 21:12:58 ----D---- C:\Program Files (x86)\USBTest
2014-06-16 21:08:55 ----D---- C:\Users\Petra\AppData\Roaming\ArcSoft
2014-06-12 11:04:26 ----A---- C:\windows\SYSWOW64\usp10.dll
2014-06-12 11:04:26 ----A---- C:\windows\system32\usp10.dll
2014-06-12 11:04:26 ----A---- C:\windows\system32\drivers\tcpip.sys
2014-06-12 11:04:26 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 11:04:25 ----A---- C:\windows\SYSWOW64\msxml6.dll
2014-06-12 11:04:25 ----A---- C:\windows\system32\msxml6.dll
2014-06-12 11:04:25 ----A---- C:\windows\system32\msxml3.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml6r.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2014-06-12 11:04:24 ----A---- C:\windows\SYSWOW64\msxml3.dll
2014-06-12 11:04:24 ----A---- C:\windows\system32\msxml6r.dll
2014-06-12 11:04:24 ----A---- C:\windows\system32\msxml3r.dll
2014-06-12 11:04:23 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-06-12 11:04:22 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-06-12 11:04:22 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 11:04:22 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-06-12 11:04:21 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-06-12 11:04:20 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\urlmon.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-06-12 11:04:20 ----A---- C:\windows\system32\ieetwcollector.exe
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-06-12 11:04:19 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-06-12 11:04:19 ----A---- C:\windows\system32\msfeeds.dll
2014-06-12 11:04:19 ----A---- C:\windows\system32\dxtmsft.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\iesetup.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\iertutil.dll
2014-06-12 11:04:18 ----A---- C:\windows\system32\ie4uinit.exe
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-06-12 11:04:17 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-06-12 11:04:17 ----A---- C:\windows\system32\jsproxy.dll
2014-06-12 11:04:17 ----A---- C:\windows\system32\iernonce.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\ieui.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\ieframe.dll
2014-06-12 11:04:16 ----A---- C:\windows\system32\dxtrans.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\mshtmled.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\jscript9diag.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\jscript9.dll
2014-06-12 11:04:15 ----A---- C:\windows\system32\ieUnatt.exe
2014-06-12 11:04:14 ----A---- C:\windows\system32\wininet.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\vbscript.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\msrating.dll
2014-06-12 11:04:14 ----A---- C:\windows\system32\ieapfltr.dll
2014-06-12 11:04:13 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 11:04:13 ----A---- C:\windows\system32\mshtml.dll
2014-06-12 11:02:12 ----A---- C:\windows\system32\aepdu.dll
2014-06-12 11:02:12 ----A---- C:\windows\system32\aeinv.dll
2014-05-28 14:56:28 ----D---- C:\Users\Petra\AppData\Roaming\AVG
2014-05-28 14:49:18 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-05-28 14:49:18 ----HD---- C:\ProgramData\Common Files
2014-05-28 14:48:04 ----D---- C:\windows\SYSWOW64\C2MP
2014-05-28 14:45:51 ----D---- C:\ProgramData\VistaCodecs
2014-05-26 22:05:37 ----D---- C:\Program Files\Kolor
2014-05-26 14:12:06 ----D---- C:\windows\Minidump
2014-05-21 15:34:40 ----D---- C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-05-20 15:03:52 ----A---- C:\windows\SYSWOW64\DiscHandler.exe

======List of files/folders modified in the last 1 month======

2014-06-19 21:36:55 ----D---- C:\windows\Temp
2014-06-19 21:36:55 ----A---- C:\windows\SYSWOW64\log.txt
2014-06-19 21:36:32 ----D---- C:\windows\Prefetch
2014-06-19 21:34:54 ----D---- C:\windows\system32\config
2014-06-19 21:34:53 ----D---- C:\ProgramData\PDFC
2014-06-19 21:30:44 ----D---- C:\windows\SysWOW64
2014-06-19 21:30:34 ----RD---- C:\Program Files (x86)
2014-06-19 21:30:34 ----HD---- C:\ProgramData
2014-06-19 21:30:34 ----D---- C:\windows\Tasks
2014-06-19 21:30:34 ----D---- C:\Windows
2014-06-18 18:46:04 ----RD---- C:\Program Files
2014-06-18 17:36:35 ----D---- C:\windows\inf
2014-06-18 17:30:07 ----D---- C:\Users\Petra\AppData\Roaming\Skype
2014-06-18 17:30:04 ----D---- C:\windows\Panther
2014-06-18 17:30:00 ----D---- C:\windows\Logs
2014-06-18 17:30:00 ----D---- C:\windows\debug
2014-06-18 17:26:47 ----D---- C:\windows\system32\Tasks
2014-06-18 17:12:16 ----D---- C:\Program Files (x86)\Adobe
2014-06-18 16:01:38 ----D---- C:\windows\System32
2014-06-18 16:01:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-06-18 15:30:49 ----D---- C:\windows\system32\catroot2
2014-06-18 14:06:30 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-18 12:00:32 ----SHD---- C:\windows\Installer
2014-06-18 12:00:32 ----SHD---- C:\Config.Msi
2014-06-18 12:00:32 ----D---- C:\windows\Downloaded Program Files
2014-06-18 11:56:23 ----SHD---- C:\System Volume Information
2014-06-18 11:38:32 ----D---- C:\Program Files (x86)\Hewlett-Packard
2014-06-18 11:38:30 ----RSD---- C:\windows\assembly
2014-06-18 11:38:20 ----D---- C:\swsetup
2014-06-18 11:32:04 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-06-18 06:22:56 ----D---- C:\windows\system32\wfp
2014-06-18 06:22:56 ----D---- C:\windows\system32\DriverStore
2014-06-18 06:22:56 ----D---- C:\windows\system32\drivers
2014-06-18 06:22:55 ----D---- C:\windows\system32\wbem
2014-06-18 06:22:54 ----D---- C:\windows\system32\CodeIntegrity
2014-06-18 06:22:49 ----D---- C:\ProgramData\WildTangent
2014-06-18 06:22:47 ----D---- C:\Program Files\Validity Sensors
2014-06-18 06:22:46 ----D---- C:\Program Files\Hewlett-Packard
2014-06-18 06:22:45 ----D---- C:\Program Files (x86)\HP Games
2014-06-18 06:22:41 ----D---- C:\Program Files (x86)\Google
2014-06-18 06:22:41 ----D---- C:\Program Files (x86)\Common Files
2014-06-18 06:21:47 ----D---- C:\windows\registration
2014-06-18 04:51:50 ----D---- C:\windows\system32\LogFiles
2014-06-18 03:57:30 ----D---- C:\windows\rescache
2014-06-18 03:00:54 ----D---- C:\windows\winsxs
2014-06-18 03:00:49 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-06-18 03:00:49 ----D---- C:\windows\system32\cs-CZ
2014-06-17 20:38:18 ----D---- C:\windows\system32\catroot
2014-06-17 20:33:25 ----D---- C:\ProgramData\Hewlett-Packard
2014-06-17 17:24:41 ----D---- C:\Users\Petra\AppData\Roaming\hpqLog
2014-06-17 17:18:54 ----D---- C:\windows\system32\appmgmt
2014-06-17 13:32:30 ----D---- C:\windows\SYSWOW64\wbem
2014-06-17 13:32:30 ----D---- C:\windows\system32\drivers\en-US
2014-06-17 13:32:29 ----D---- C:\windows\SYSWOW64\en-US
2014-06-17 13:32:29 ----D---- C:\windows\system32\en-US
2014-06-17 13:32:29 ----D---- C:\windows\PolicyDefinitions
2014-06-16 22:55:46 ----D---- C:\windows\SYSWOW64\config
2014-06-16 21:08:57 ----HD---- C:\ProgramData\ArcSoft
2014-06-13 20:19:09 ----D---- C:\Program Files\Internet Explorer
2014-06-13 20:18:38 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-13 20:02:33 ----SD---- C:\windows\system32\CompatTel
2014-06-04 00:26:01 ----SD---- C:\Users\Petra\AppData\Roaming\Microsoft
2014-06-01 01:54:55 ----D---- C:\windows\system32\NDF
2014-05-28 15:23:51 ----D---- C:\ProgramData\ASGVIS
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_UNRAR.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_SAMPLERATE.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBMAD.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBDTS.DLL.NEW
2014-05-28 14:48:27 ----A---- C:\windows\SYSWOW64\FF_LIBA52.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\XVIDVFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\XVIDCORE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\X264VFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\VSFILTER.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TOMSMOCOMP_FF.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\TAK_DECO_LIB.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\SWSCALE-LAV-2.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\OPTIMFROG.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\OGM.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MP4.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKZLIB.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKX.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKV2VFR.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\MKUNICODE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LIBMPEG2_FF.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LIBBLURAY.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\LAGARITH.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\GDSMUX.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FFMPEG.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FF_WMV9.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\FF_VFW.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\DXR.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\DSMUX.EXE.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSWV.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSOPUS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSFLAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASSCD.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_TTA.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_TAK.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_OFR.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_MPC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_APE.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_ALAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS_AAC.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\BASS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVUTIL-LAV-52.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVSS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVS.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVRESAMPLE-LAV-1.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVI.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVFORMAT-LAV-55.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVFILTER-LAV-4.DLL.NEW
2014-05-28 14:48:26 ----A---- C:\windows\SYSWOW64\AVCODEC-LAV-55.DLL.NEW
2014-05-26 09:58:15 ----D---- C:\Users\Petra\AppData\Roaming\skypePM
2014-05-21 15:39:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-05-21 15:38:58 ----D---- C:\windows\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-06-16 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-06-16 208416]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-01-26 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2011-02-09 168008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-06-16 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-06-16 1039096]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-06-16 423240]
R1 CFRMD;CFRMD; C:\windows\system32\DRIVERS\CFRMD.sys [2010-12-09 79552]
R1 CFRPD;CFRPD; C:\windows\system32\DRIVERS\CFRPD.sys [2010-12-09 41472]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-06-16 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-06-16 79184]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-06-16 85328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-01-26 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-28 9319424]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-28 303616]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2011-01-06 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-12-20 3837440]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2011-01-06 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2011-01-06 28832]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-06 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-06 154272]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2011-01-06 279200]
R3 BthEnum;Služba Bluetooth Enumerator; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-12-03 25912]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2014-05-19 175928]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2014-05-19 708200]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2014-05-19 543744]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-10-30 549104]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
S2 ioperm;ioperm support for Cygwin driver; \??\c:\cmospwd-5.0\windows\ioperm.sys [2004-11-26 12800]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-06 201376]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2011-02-07 63336]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2014-05-19 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-28 203264]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-06 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-06 53920]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-06-16 50344]
R2 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 371648]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-11-10 486224]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-01-26 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 210896]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
R2 McNeelUpdate;McNeel Update Service 5.0; C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [2012-10-25 67752]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2014-05-19 323072]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R2 VRLService;VRLService; C:\PROGRA~3\ASGVIS\DONGLE~1\STARTV~1.EXE [2012-12-06 212992]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 116648]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-16 257712]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-02-04 464480]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-04-14 1432400]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-09-30 246520]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 116648]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-05-30 111616]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-18 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-04-16 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 20:47
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Petra.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 19 čer 2014 22:22
od mnevidal
Po rebootu mě šokoval po welcome obrazovce následující zvuk "přihlášení" vypadá že všechno šlape jako dřív! Jestli je to vše tak vám velice děkuji za pomoc!

**po dalším rebootu to bohužel tak slavné není :(

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 20 čer 2014 15:52
od Rudy
Pokud ještě máte nějaký problém, dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 22 čer 2014 20:50
od mnevidal
Pořád po loginu strašně dlouho trvá než se jakoby probere, tak pro jistotu...

ComboFix 14-06-21.02 - Petra 22.06.2014 20:38:55.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4030.2056 [GMT 2:00]
Spuštěný z: c:\users\Petra\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-05-22 do 2014-06-22 )))))))))))))))))))))))))))))))
.
.
2014-06-22 18:45 . 2014-06-22 18:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-19 12:51 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-19 00:37 . 2014-06-19 12:53 -------- d-----w- C:\AdwCleaner
2014-06-18 16:46 . 2014-06-19 21:11 -------- d-----w- c:\program files\trend micro
2014-06-18 15:45 . 2014-06-18 15:45 -------- d-----w- c:\program files (x86)\MRU-Blaster
2014-06-18 15:45 . 2012-05-25 11:03 118784 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2014-06-18 15:26 . 2014-06-18 15:26 -------- d-----w- c:\program files\CCleaner
2014-06-18 12:24 . 2014-06-18 12:24 -------- d-----w- C:\cmospwd-5.0
2014-06-18 10:00 . 2014-06-18 10:00 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2014-06-17 18:38 . 2014-05-08 09:32 3178496 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-17 18:38 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-17 18:38 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-06-17 18:38 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-06-17 16:39 . 2014-06-17 16:39 -------- d-----w- c:\programdata\Oracle
2014-06-17 16:34 . 2014-06-17 16:34 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-06-17 16:34 . 2014-06-17 16:34 -------- d-----w- c:\program files (x86)\Java
2014-06-17 14:38 . 2014-06-18 01:03 -------- d-----w- c:\windows\system32\MRT
2014-06-17 11:30 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2014-06-17 11:30 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2014-06-17 11:30 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2014-06-17 11:30 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2014-06-17 11:23 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-06-17 11:23 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-06-17 11:23 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-06-17 11:23 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-06-17 10:17 . 2014-06-17 10:17 -------- d-----w- c:\programdata\Comodo
2014-06-16 21:24 . 2014-06-16 21:24 -------- d-----w- c:\users\Petra\AppData\Roaming\IDT
2014-06-16 20:51 . 2014-06-16 20:51 -------- d-----w- c:\users\Petra\AppData\Roaming\AVAST Software
2014-06-16 20:45 . 2014-06-16 20:48 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-06-16 20:45 . 2014-06-16 20:48 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-06-16 20:45 . 2014-06-16 20:48 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-06-16 20:45 . 2014-06-16 20:45 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-06-16 20:45 . 2014-06-16 20:45 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-06-16 20:45 . 2014-06-16 20:45 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-06-16 20:45 . 2014-06-16 20:45 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-06-16 20:45 . 2014-06-16 20:45 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-06-16 20:45 . 2014-06-16 20:45 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-06-16 20:45 . 2014-06-16 20:45 43152 ----a-w- c:\windows\avastSS.scr
2014-06-16 20:39 . 2014-06-16 20:39 -------- d-----w- c:\program files\AVAST Software
2014-06-16 20:36 . 2014-06-16 20:36 -------- d-----w- c:\programdata\AVAST Software
2014-06-16 20:02 . 2014-06-22 18:46 20435 ----a-w- c:\windows\cscmondump.bin
2014-06-16 19:14 . 2014-06-16 19:14 -------- d-----w- c:\program files\COMODO
2014-06-16 19:14 . 2014-06-16 19:14 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2014-06-16 19:14 . 2014-06-16 19:14 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2014-06-16 19:14 . 2014-06-16 19:14 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2014-06-16 19:12 . 2014-06-16 19:12 -------- d-----w- c:\program files (x86)\USBTest
2014-06-16 19:08 . 2014-06-16 19:08 -------- d-----w- c:\users\Petra\AppData\Roaming\ArcSoft
2014-06-16 18:54 . 2014-06-16 18:54 -------- d-----w- c:\users\Petra\AppData\Local\Hewlett-Packard_Developme
2014-06-12 09:02 . 2014-06-08 09:13 506368 ----a-w- c:\windows\system32\aepdu.dll
2014-06-12 09:02 . 2014-06-08 09:08 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-05-28 12:56 . 2014-05-28 12:56 -------- d-----w- c:\users\Petra\AppData\Roaming\AVG
2014-05-28 12:56 . 2014-05-28 12:56 -------- d-----w- c:\users\Petra\AppData\Local\AVG
2014-05-28 12:56 . 2014-05-31 22:35 -------- d-----w- c:\users\Petra\AppData\Local\Diagnostics
2014-05-28 12:49 . 2014-05-28 12:49 -------- d-sh--w- c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-05-28 12:49 . 2014-05-28 12:49 -------- d--h--w- c:\programdata\Common Files
2014-05-28 12:48 . 2014-05-28 12:48 -------- d-----w- c:\windows\SysWow64\C2MP
2014-05-28 12:45 . 2014-05-28 12:45 -------- d-----w- c:\programdata\VistaCodecs
2014-05-26 20:05 . 2014-05-26 20:05 -------- d-----w- c:\users\Petra\AppData\Local\Kolor
2014-05-26 20:05 . 2014-05-26 20:05 -------- d-----w- c:\program files\Kolor
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-22 12:34 . 2014-05-11 13:22 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-05-20 13:03 . 2014-05-20 13:03 45384 ----a-w- c:\windows\SysWow64\DiscHandler.exe
2014-05-19 10:40 . 2014-05-19 10:40 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-05-19 10:40 . 2014-05-19 10:40 708200 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2014-05-19 10:40 . 2011-05-12 00:30 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-05-19 10:28 . 2014-05-19 10:28 175928 ----a-w- c:\windows\system32\drivers\jmcr.sys
2014-05-19 10:26 . 2014-05-19 10:26 672256 ------w- c:\windows\system32\stapi64.dll
2014-05-19 10:26 . 2014-05-19 10:26 543744 ----a-w- c:\windows\system32\drivers\stwrt64.sys
2014-05-19 10:26 . 2014-05-19 10:26 499200 ----a-w- c:\windows\system32\stcplx64.dll
2014-05-19 10:26 . 2014-05-19 10:26 255488 ----a-w- c:\windows\system32\st646428.dll
2014-05-19 10:26 . 2014-05-19 10:26 2188800 ----a-w- c:\windows\system32\stapo64.dll
2014-05-19 10:26 . 2014-04-14 10:18 8013312 ----a-w- c:\windows\system32\IDTNHP.dll
2014-05-19 10:26 . 2014-04-14 10:18 8003072 ----a-w- c:\windows\system32\IDTNGUI.exe
2014-05-19 10:26 . 2014-04-14 10:18 253952 ----a-w- c:\windows\system32\IDTNJ.exe
2014-05-19 10:26 . 2014-04-14 10:18 2214912 ----a-w- c:\windows\system32\IDTNX.dll
2014-05-19 10:26 . 2014-04-14 10:18 1664000 ----a-w- c:\windows\sttray64.exe
2014-05-19 10:26 . 2014-04-14 10:18 6102016 ----a-w- c:\windows\system32\stlang64.dll
2014-05-19 10:26 . 2014-04-14 10:18 74336 ----a-w- c:\windows\system32\AESTAR64.dll
2014-05-19 10:26 . 2014-04-14 10:18 442368 ----a-w- c:\windows\system32\AESTEC64.dll
2014-05-19 10:26 . 2014-04-14 10:18 224256 ----a-w- c:\windows\system32\HPToneCtrls64.dll
2014-05-19 10:26 . 2014-04-14 10:18 200288 ----a-w- c:\windows\system32\AESTAC64.dll
2014-05-19 10:26 . 2014-04-14 10:18 90624 ----a-w- c:\windows\system32\AESTCo64.dll
2014-05-19 10:26 . 2014-04-14 10:18 1821184 ----a-w- c:\windows\system32\IDTNC64.cpl
2014-05-19 10:21 . 2014-05-19 10:21 1795952 ----a-w- c:\windows\system32\WdfCoInstaller01011.dll
2014-05-19 10:21 . 2014-05-19 10:21 92 ----a-w- c:\windows\system32\calibration.bin
2014-05-16 21:17 . 2014-04-15 21:29 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-16 21:17 . 2014-04-15 21:29 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-13 15:05 . 2014-05-13 15:05 4009984 ----a-w- c:\windows\system32\ffmpeg.dll
2014-05-13 15:05 . 2014-05-13 15:05 474624 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2014-05-13 15:05 . 2014-05-13 15:05 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2014-05-13 15:05 . 2014-05-13 15:05 4374528 ----a-w- c:\windows\system32\ffdshow.ax
2014-05-13 15:04 . 2014-05-13 15:04 631296 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2014-05-13 15:04 . 2014-05-13 15:04 222720 ----a-w- c:\windows\system32\ff_libdts.dll
2014-05-13 15:04 . 2014-05-13 15:04 156672 ----a-w- c:\windows\system32\ff_libmad.dll
2014-05-13 15:04 . 2014-05-13 15:04 116224 ----a-w- c:\windows\system32\ff_liba52.dll
2014-05-13 15:04 . 2014-05-13 15:04 114688 ----a-w- c:\windows\system32\ff_wmv9.dll
2014-05-13 15:04 . 2014-05-13 15:04 190464 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2014-05-13 15:04 . 2014-05-13 15:04 183296 ----a-w- c:\windows\system32\ff_unrar.dll
2014-05-13 15:04 . 2014-05-13 15:04 1532928 ----a-w- c:\windows\system32\ff_samplerate.dll
2014-05-13 15:02 . 2014-05-13 15:02 3916288 ----a-w- c:\windows\SysWow64\ffmpeg.dll
2014-05-13 15:01 . 2014-05-13 15:01 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2014-05-13 15:01 . 2014-05-13 15:01 3502592 ----a-w- c:\windows\SysWow64\ffdshow.ax
2014-05-13 15:01 . 2014-05-13 15:01 271360 ----a-w- c:\windows\SysWow64\TomsMoComp_ff.dll
2014-05-13 15:00 . 2014-05-13 15:00 99840 ----a-w- c:\windows\SysWow64\ff_wmv9.dll
2014-05-13 15:00 . 2014-05-13 15:00 157184 ----a-w- c:\windows\SysWow64\ff_unrar.dll
2014-05-13 15:00 . 2014-05-13 15:00 211968 ----a-w- c:\windows\SysWow64\ff_libdts.dll
2014-05-13 15:00 . 2014-05-13 15:00 1525760 ----a-w- c:\windows\SysWow64\ff_samplerate.dll
2014-05-13 15:00 . 2014-05-13 15:00 147456 ----a-w- c:\windows\SysWow64\ff_libmad.dll
2014-05-13 15:00 . 2014-05-13 15:00 114688 ----a-w- c:\windows\SysWow64\ff_liba52.dll
2014-05-13 15:00 . 2014-05-13 15:00 136704 ----a-w- c:\windows\SysWow64\libmpeg2_ff.dll
2014-04-30 23:20 . 2014-05-23 13:31 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2ECD638F-86FE-43DE-8982-0D93D5FB624A}\mpengine.dll
2014-04-20 12:42 . 2014-04-20 12:42 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-04-20 12:42 . 2014-04-20 12:42 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-04-20 12:42 . 2014-04-20 12:42 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-04-20 12:42 . 2014-04-20 12:42 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-04-20 12:42 . 2014-04-20 12:42 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-04-20 12:42 . 2014-04-20 12:42 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-04-20 12:42 . 2014-04-20 12:42 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-04-20 12:42 . 2014-04-20 12:42 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-04-20 12:42 . 2014-04-20 12:42 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-04-20 12:42 . 2014-04-20 12:42 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-04-20 12:42 . 2014-04-20 12:42 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-04-20 12:42 . 2014-04-20 12:42 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-04-20 12:42 . 2014-04-20 12:42 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-04-20 12:42 . 2014-04-20 12:42 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-20 12:42 . 2014-04-20 12:42 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-20 12:42 . 2014-04-20 12:42 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-04-20 12:42 . 2014-04-20 12:42 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-04-20 12:42 . 2014-04-20 12:42 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-20 12:42 . 2014-04-20 12:42 81408 ----a-w- c:\windows\system32\icardie.dll
2014-04-20 12:42 . 2014-04-20 12:42 774144 ----a-w- c:\windows\system32\jscript.dll
2014-04-20 12:42 . 2014-04-20 12:42 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-04-20 12:42 . 2014-04-20 12:42 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-04-20 12:42 . 2014-04-20 12:42 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-04-20 12:42 . 2014-04-20 12:42 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-04-20 12:42 . 2014-04-20 12:42 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-04-20 12:42 . 2014-04-20 12:42 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-04-20 12:42 . 2014-04-20 12:42 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-20 12:42 . 2014-04-20 12:42 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-04-20 12:42 . 2014-04-20 12:42 413696 ----a-w- c:\windows\system32\html.iec
2014-04-20 12:42 . 2014-04-20 12:42 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-20 12:42 . 2014-04-20 12:42 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-04-20 12:42 . 2014-04-20 12:42 247808 ----a-w- c:\windows\system32\msls31.dll
2014-04-20 12:42 . 2014-04-20 12:42 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-04-20 12:42 . 2014-04-20 12:42 235520 ----a-w- c:\windows\system32\url.dll
2014-04-20 12:42 . 2014-04-20 12:42 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-04-20 12:42 . 2014-04-20 12:42 147968 ----a-w- c:\windows\system32\occache.dll
2014-04-20 12:42 . 2014-04-20 12:42 143872 ----a-w- c:\windows\system32\wextract.exe
2014-04-20 12:42 . 2014-04-20 12:42 13824 ----a-w- c:\windows\system32\mshta.exe
2014-04-20 12:42 . 2014-04-20 12:42 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-04-20 12:42 . 2014-04-20 12:42 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-04-20 12:42 . 2014-04-20 12:42 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-20 12:42 . 2014-04-20 12:42 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-04-20 12:42 . 2014-04-20 12:42 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-20 12:42 . 2014-04-20 12:42 101376 ----a-w- c:\windows\system32\inseng.dll
2014-04-18 01:32 . 2014-04-18 01:32 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 299576]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-28 336384]
"HP HD Webcam [Fixed]_Monitor"="c:\program files (x86)\HP HD Webcam [Fixed]\monitor.exe" [2010-11-26 11:31 267128]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-06-16 3890208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 ioperm;ioperm support for Cygwin driver;c:\cmospwd-5.0\windows\ioperm.sys;c:\cmospwd-5.0\windows\ioperm.sys [x]
R2 XobniService;XobniService;c:\program files (x86)\Xobni\XobniService.exe;c:\program files (x86)\Xobni\XobniService.exe [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 MfeEpePc;MfeEpePc; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRMD.sys [x]
S1 CFRPD;CFRPD;c:\windows\system32\DRIVERS\CFRPD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRPD.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [x]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [x]
S2 McNeelUpdate;McNeel Update Service 5.0;c:\program files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe;c:\program files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe;c:\windows\SYSNATIVE\vcsFPService.exe [x]
S2 VRLService;VRLService;c:\progra~3\ASGVIS\DONGLE~1\STARTV~1.EXE;c:\progra~3\ASGVIS\DONGLE~1\STARTV~1.EXE [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftVCapture.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SPUVCbv;SPUVCb Driver Service;c:\windows\system32\Drivers\SPUVCbv_x64.sys;c:\windows\SYSNATIVE\Drivers\SPUVCbv_x64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-16 20:48 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-15 21:17]
.
2014-06-18 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2014-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 20:45]
.
2014-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 20:45]
.
2014-06-22 c:\windows\Tasks\HPCeeScheduleForPETRA-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 02:43]
.
2014-06-22 c:\windows\Tasks\HPCeeScheduleForPetra.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 02:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-06-16 20:45 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-27 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-27 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-27 418328]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-06 615584]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-06 379040]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2014-05-19 1664000]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.10.11.1 192.168.0.1
TCP: Interfaces\{2A0B24E1-768D-4D85-A52F-B1A8AF054611}\6596275737: NameServer = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\yglywmtp.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-06-22 20:54:45 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-06-22 18:54
.
Před spuštěním: Volných bajtů: 538 199 470 080
Po spuštění: Volných bajtů: 537 475 100 672
.
- - End Of File - - 3986D9FB7892D88A329D1F396CF46CBB

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 22 čer 2014 21:33
od Rudy
Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 23 čer 2014 09:31
od mnevidal
log z combofix(u)

ComboFix 14-06-23.01 - Petra 23.06.2014 9:56.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4030.2158 [GMT 2:00]
Spuštěný z: c:\users\Petra\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Petra\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-05-23 do 2014-06-23 )))))))))))))))))))))))))))))))
.
.
2014-06-23 08:03 . 2014-06-23 08:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-19 12:51 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-19 00:37 . 2014-06-19 12:53 -------- d-----w- C:\AdwCleaner
2014-06-18 16:46 . 2014-06-19 21:11 -------- d-----w- c:\program files\trend micro
2014-06-18 15:45 . 2014-06-18 15:45 -------- d-----w- c:\program files (x86)\MRU-Blaster
2014-06-18 15:45 . 2012-05-25 11:03 118784 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2014-06-18 15:26 . 2014-06-18 15:26 -------- d-----w- c:\program files\CCleaner
2014-06-18 12:24 . 2014-06-18 12:24 -------- d-----w- C:\cmospwd-5.0
2014-06-18 10:00 . 2014-06-18 10:00 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2014-06-17 18:38 . 2014-05-08 09:32 3178496 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-17 18:38 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-17 18:38 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-06-17 18:38 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll
2014-06-17 16:39 . 2014-06-17 16:39 -------- d-----w- c:\programdata\Oracle
2014-06-17 16:34 . 2014-06-17 16:34 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-06-17 16:34 . 2014-06-17 16:34 -------- d-----w- c:\program files (x86)\Java
2014-06-17 14:38 . 2014-06-18 01:03 -------- d-----w- c:\windows\system32\MRT
2014-06-17 11:30 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
2014-06-17 11:30 . 2012-08-23 14:13 243200 ----a-w- c:\windows\system32\rdpudd.dll
2014-06-17 11:30 . 2012-08-23 11:12 192000 ----a-w- c:\windows\SysWow64\rdpendp_winip.dll
2014-06-17 11:30 . 2012-08-23 10:51 228864 ----a-w- c:\windows\system32\rdpendp_winip.dll
2014-06-17 11:23 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-06-17 11:23 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-06-17 11:23 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2014-06-17 11:23 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-06-17 10:17 . 2014-06-17 10:17 -------- d-----w- c:\programdata\Comodo
2014-06-16 21:24 . 2014-06-16 21:24 -------- d-----w- c:\users\Petra\AppData\Roaming\IDT
2014-06-16 20:51 . 2014-06-16 20:51 -------- d-----w- c:\users\Petra\AppData\Roaming\AVAST Software
2014-06-16 20:45 . 2014-06-16 20:48 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-06-16 20:45 . 2014-06-16 20:48 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-06-16 20:45 . 2014-06-16 20:48 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-06-16 20:45 . 2014-06-16 20:45 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-06-16 20:45 . 2014-06-16 20:45 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-06-16 20:45 . 2014-06-16 20:45 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-06-16 20:45 . 2014-06-16 20:45 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-06-16 20:45 . 2014-06-16 20:45 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-06-16 20:45 . 2014-06-16 20:45 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-06-16 20:45 . 2014-06-16 20:45 43152 ----a-w- c:\windows\avastSS.scr
2014-06-16 20:39 . 2014-06-16 20:39 -------- d-----w- c:\program files\AVAST Software
2014-06-16 20:36 . 2014-06-16 20:36 -------- d-----w- c:\programdata\AVAST Software
2014-06-16 20:02 . 2014-06-23 08:03 20435 ----a-w- c:\windows\cscmondump.bin
2014-06-16 19:14 . 2014-06-16 19:14 -------- d-----w- c:\program files\COMODO
2014-06-16 19:14 . 2014-06-16 19:14 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2014-06-16 19:14 . 2014-06-16 19:14 1700352 ----a-w- c:\windows\SysWow64\gdiplus.dll
2014-06-16 19:14 . 2014-06-16 19:14 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2014-06-16 19:12 . 2014-06-16 19:12 -------- d-----w- c:\program files (x86)\USBTest
2014-06-16 19:08 . 2014-06-16 19:08 -------- d-----w- c:\users\Petra\AppData\Roaming\ArcSoft
2014-06-16 18:54 . 2014-06-16 18:54 -------- d-----w- c:\users\Petra\AppData\Local\Hewlett-Packard_Developme
2014-06-12 09:02 . 2014-06-08 09:13 506368 ----a-w- c:\windows\system32\aepdu.dll
2014-06-12 09:02 . 2014-06-08 09:08 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-05-28 12:56 . 2014-05-28 12:56 -------- d-----w- c:\users\Petra\AppData\Roaming\AVG
2014-05-28 12:56 . 2014-05-28 12:56 -------- d-----w- c:\users\Petra\AppData\Local\AVG
2014-05-28 12:56 . 2014-05-31 22:35 -------- d-----w- c:\users\Petra\AppData\Local\Diagnostics
2014-05-28 12:49 . 2014-05-28 12:49 -------- d-sh--w- c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-05-28 12:49 . 2014-05-28 12:49 -------- d--h--w- c:\programdata\Common Files
2014-05-28 12:48 . 2014-05-28 12:48 -------- d-----w- c:\windows\SysWow64\C2MP
2014-05-28 12:45 . 2014-05-28 12:45 -------- d-----w- c:\programdata\VistaCodecs
2014-05-26 20:05 . 2014-05-26 20:05 -------- d-----w- c:\users\Petra\AppData\Local\Kolor
2014-05-26 20:05 . 2014-05-26 20:05 -------- d-----w- c:\program files\Kolor
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-22 12:34 . 2014-05-11 13:22 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-05-20 13:03 . 2014-05-20 13:03 45384 ----a-w- c:\windows\SysWow64\DiscHandler.exe
2014-05-19 10:40 . 2014-05-19 10:40 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2014-05-19 10:40 . 2014-05-19 10:40 708200 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2014-05-19 10:40 . 2011-05-12 00:30 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2014-05-19 10:28 . 2014-05-19 10:28 175928 ----a-w- c:\windows\system32\drivers\jmcr.sys
2014-05-19 10:26 . 2014-05-19 10:26 672256 ------w- c:\windows\system32\stapi64.dll
2014-05-19 10:26 . 2014-05-19 10:26 543744 ----a-w- c:\windows\system32\drivers\stwrt64.sys
2014-05-19 10:26 . 2014-05-19 10:26 499200 ----a-w- c:\windows\system32\stcplx64.dll
2014-05-19 10:26 . 2014-05-19 10:26 255488 ----a-w- c:\windows\system32\st646428.dll
2014-05-19 10:26 . 2014-05-19 10:26 2188800 ----a-w- c:\windows\system32\stapo64.dll
2014-05-19 10:26 . 2014-04-14 10:18 8013312 ----a-w- c:\windows\system32\IDTNHP.dll
2014-05-19 10:26 . 2014-04-14 10:18 8003072 ----a-w- c:\windows\system32\IDTNGUI.exe
2014-05-19 10:26 . 2014-04-14 10:18 253952 ----a-w- c:\windows\system32\IDTNJ.exe
2014-05-19 10:26 . 2014-04-14 10:18 2214912 ----a-w- c:\windows\system32\IDTNX.dll
2014-05-19 10:26 . 2014-04-14 10:18 1664000 ----a-w- c:\windows\sttray64.exe
2014-05-19 10:26 . 2014-04-14 10:18 6102016 ----a-w- c:\windows\system32\stlang64.dll
2014-05-19 10:26 . 2014-04-14 10:18 74336 ----a-w- c:\windows\system32\AESTAR64.dll
2014-05-19 10:26 . 2014-04-14 10:18 442368 ----a-w- c:\windows\system32\AESTEC64.dll
2014-05-19 10:26 . 2014-04-14 10:18 224256 ----a-w- c:\windows\system32\HPToneCtrls64.dll
2014-05-19 10:26 . 2014-04-14 10:18 200288 ----a-w- c:\windows\system32\AESTAC64.dll
2014-05-19 10:26 . 2014-04-14 10:18 90624 ----a-w- c:\windows\system32\AESTCo64.dll
2014-05-19 10:26 . 2014-04-14 10:18 1821184 ----a-w- c:\windows\system32\IDTNC64.cpl
2014-05-19 10:21 . 2014-05-19 10:21 1795952 ----a-w- c:\windows\system32\WdfCoInstaller01011.dll
2014-05-19 10:21 . 2014-05-19 10:21 92 ----a-w- c:\windows\system32\calibration.bin
2014-05-16 21:17 . 2014-04-15 21:29 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-16 21:17 . 2014-04-15 21:29 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-13 15:05 . 2014-05-13 15:05 4009984 ----a-w- c:\windows\system32\ffmpeg.dll
2014-05-13 15:05 . 2014-05-13 15:05 474624 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2014-05-13 15:05 . 2014-05-13 15:05 127488 ----a-w- c:\windows\system32\ff_vfw.dll
2014-05-13 15:05 . 2014-05-13 15:05 4374528 ----a-w- c:\windows\system32\ffdshow.ax
2014-05-13 15:04 . 2014-05-13 15:04 631296 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2014-05-13 15:04 . 2014-05-13 15:04 222720 ----a-w- c:\windows\system32\ff_libdts.dll
2014-05-13 15:04 . 2014-05-13 15:04 156672 ----a-w- c:\windows\system32\ff_libmad.dll
2014-05-13 15:04 . 2014-05-13 15:04 116224 ----a-w- c:\windows\system32\ff_liba52.dll
2014-05-13 15:04 . 2014-05-13 15:04 114688 ----a-w- c:\windows\system32\ff_wmv9.dll
2014-05-13 15:04 . 2014-05-13 15:04 190464 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2014-05-13 15:04 . 2014-05-13 15:04 183296 ----a-w- c:\windows\system32\ff_unrar.dll
2014-05-13 15:04 . 2014-05-13 15:04 1532928 ----a-w- c:\windows\system32\ff_samplerate.dll
2014-05-13 15:02 . 2014-05-13 15:02 3916288 ----a-w- c:\windows\SysWow64\ffmpeg.dll
2014-05-13 15:01 . 2014-05-13 15:01 112640 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2014-05-13 15:01 . 2014-05-13 15:01 3502592 ----a-w- c:\windows\SysWow64\ffdshow.ax
2014-05-13 15:01 . 2014-05-13 15:01 271360 ----a-w- c:\windows\SysWow64\TomsMoComp_ff.dll
2014-05-13 15:00 . 2014-05-13 15:00 99840 ----a-w- c:\windows\SysWow64\ff_wmv9.dll
2014-05-13 15:00 . 2014-05-13 15:00 157184 ----a-w- c:\windows\SysWow64\ff_unrar.dll
2014-05-13 15:00 . 2014-05-13 15:00 211968 ----a-w- c:\windows\SysWow64\ff_libdts.dll
2014-05-13 15:00 . 2014-05-13 15:00 1525760 ----a-w- c:\windows\SysWow64\ff_samplerate.dll
2014-05-13 15:00 . 2014-05-13 15:00 147456 ----a-w- c:\windows\SysWow64\ff_libmad.dll
2014-05-13 15:00 . 2014-05-13 15:00 114688 ----a-w- c:\windows\SysWow64\ff_liba52.dll
2014-05-13 15:00 . 2014-05-13 15:00 136704 ----a-w- c:\windows\SysWow64\libmpeg2_ff.dll
2014-04-30 23:20 . 2014-05-23 13:31 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2ECD638F-86FE-43DE-8982-0D93D5FB624A}\mpengine.dll
2014-04-20 12:42 . 2014-04-20 12:42 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-04-20 12:42 . 2014-04-20 12:42 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-04-20 12:42 . 2014-04-20 12:42 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-04-20 12:42 . 2014-04-20 12:42 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-04-20 12:42 . 2014-04-20 12:42 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-04-20 12:42 . 2014-04-20 12:42 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-04-20 12:42 . 2014-04-20 12:42 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-04-20 12:42 . 2014-04-20 12:42 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-04-20 12:42 . 2014-04-20 12:42 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-04-20 12:42 . 2014-04-20 12:42 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-04-20 12:42 . 2014-04-20 12:42 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-04-20 12:42 . 2014-04-20 12:42 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-04-20 12:42 . 2014-04-20 12:42 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-04-20 12:42 . 2014-04-20 12:42 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-20 12:42 . 2014-04-20 12:42 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-20 12:42 . 2014-04-20 12:42 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-04-20 12:42 . 2014-04-20 12:42 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-04-20 12:42 . 2014-04-20 12:42 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-20 12:42 . 2014-04-20 12:42 81408 ----a-w- c:\windows\system32\icardie.dll
2014-04-20 12:42 . 2014-04-20 12:42 774144 ----a-w- c:\windows\system32\jscript.dll
2014-04-20 12:42 . 2014-04-20 12:42 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-04-20 12:42 . 2014-04-20 12:42 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-04-20 12:42 . 2014-04-20 12:42 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-04-20 12:42 . 2014-04-20 12:42 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-04-20 12:42 . 2014-04-20 12:42 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-04-20 12:42 . 2014-04-20 12:42 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-04-20 12:42 . 2014-04-20 12:42 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-20 12:42 . 2014-04-20 12:42 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-04-20 12:42 . 2014-04-20 12:42 413696 ----a-w- c:\windows\system32\html.iec
2014-04-20 12:42 . 2014-04-20 12:42 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-20 12:42 . 2014-04-20 12:42 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-04-20 12:42 . 2014-04-20 12:42 247808 ----a-w- c:\windows\system32\msls31.dll
2014-04-20 12:42 . 2014-04-20 12:42 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-04-20 12:42 . 2014-04-20 12:42 235520 ----a-w- c:\windows\system32\url.dll
2014-04-20 12:42 . 2014-04-20 12:42 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-04-20 12:42 . 2014-04-20 12:42 147968 ----a-w- c:\windows\system32\occache.dll
2014-04-20 12:42 . 2014-04-20 12:42 143872 ----a-w- c:\windows\system32\wextract.exe
2014-04-20 12:42 . 2014-04-20 12:42 13824 ----a-w- c:\windows\system32\mshta.exe
2014-04-20 12:42 . 2014-04-20 12:42 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-04-20 12:42 . 2014-04-20 12:42 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-04-20 12:42 . 2014-04-20 12:42 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-20 12:42 . 2014-04-20 12:42 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-04-20 12:42 . 2014-04-20 12:42 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-20 12:42 . 2014-04-20 12:42 101376 ----a-w- c:\windows\system32\inseng.dll
2014-04-18 01:32 . 2014-04-18 01:32 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-04-18 01:32 . 2014-04-18 01:32 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 299576]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-28 336384]
"HP HD Webcam [Fixed]_Monitor"="c:\program files (x86)\HP HD Webcam [Fixed]\monitor.exe" [2010-11-26 11:31 267128]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-06-16 3890208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 ioperm;ioperm support for Cygwin driver;c:\cmospwd-5.0\windows\ioperm.sys;c:\cmospwd-5.0\windows\ioperm.sys [x]
R2 XobniService;XobniService;c:\program files (x86)\Xobni\XobniService.exe;c:\program files (x86)\Xobni\XobniService.exe [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 MfeEpePc;MfeEpePc; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRMD.sys [x]
S1 CFRPD;CFRPD;c:\windows\system32\DRIVERS\CFRPD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRPD.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [x]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [x]
S2 McNeelUpdate;McNeel Update Service 5.0;c:\program files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe;c:\program files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [x]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe;c:\windows\SYSNATIVE\vcsFPService.exe [x]
S2 VRLService;VRLService;c:\progra~3\ASGVIS\DONGLE~1\STARTV~1.EXE;c:\progra~3\ASGVIS\DONGLE~1\STARTV~1.EXE [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftVCapture.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SPUVCbv;SPUVCb Driver Service;c:\windows\system32\Drivers\SPUVCbv_x64.sys;c:\windows\SYSNATIVE\Drivers\SPUVCbv_x64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-16 20:48 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-15 21:17]
.
2014-06-18 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2014-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 20:45]
.
2014-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16 20:45]
.
2014-06-22 c:\windows\Tasks\HPCeeScheduleForPETRA-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 02:43]
.
2014-06-22 c:\windows\Tasks\HPCeeScheduleForPetra.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 02:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-06-16 20:45 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-27 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-27 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-27 418328]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-01-06 615584]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-01-06 379040]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2014-05-19 1664000]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 10.10.11.1 192.168.0.1
TCP: Interfaces\{2A0B24E1-768D-4D85-A52F-B1A8AF054611}\6596275737: NameServer = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\yglywmtp.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Celkový čas: 2014-06-23 10:10:46 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-06-23 08:10
ComboFix2.txt 2014-06-22 18:54
.
Před spuštěním: Volných bajtů: 537 467 486 208
Po spuštění: Volných bajtů: 537 332 510 720
.
- - End Of File - - 75A6504AA5D99D6796E7DC00A6F8AE57

Re: BSOD, explorer.exe po loginu dlouho nacita

Napsal: 23 čer 2014 16:19
od Rudy
Smazáno. CF odinstalujte pomocí T-Cleaneru: http://vyosek.tym.cz/pro_usery/T-Cleaner.exe . Nastala nějaká změna?