default-search.net jako homepage
Napsal: 13 črc 2014 19:47
Dobrý den,
vím, že už to tady někdo před časem řešil, snažil jsem se aplikovat návod na sebe, ale daleko jsem se sám nedostal. PC před pár dny někde chytlo tzv. prohlížeč únosce, konkrétně default-search.net jako podstrčenou homepage . Která vás sleduje, přesměrovává atd a nejde zrušit. Vygooglovaná rada na SpyHunter vždycky končila nějakou mastnou registrací
To raději pak v závěru zasponzoruju zdejší fórum, kde vám aspoň věřím. (Avastu ani CCcleaneru to default search nevadí - grrr, nově ten YAC to též neodstranil). Rada odstranit default search jako odinstalovat v seznamu programů nepomohla, protože to tam není. Používám hlavně explorer, zda to vlezlo i do mozily nevím. ...Zde je RSIT, děkuji : 
---------------------------------------------------------------------------------------------------------------------------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Radim at 2014-07-13 20:13:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 62 GB (41%) free of 152 GB
Total RAM: 2046 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:14:59, on 13.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iSafe\iSafeTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Users\Radim\Desktop\RSIT.exe
C:\Program Files\trend micro\Radim.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.seznam.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... 04065E0&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... 04065E0&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.seznam.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (file missing)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 10 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.10.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files\iSafe\iSafeSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Update DoughGo - Unknown owner - C:\Program Files\DoughGo\updateDoughGo.exe (file missing)
--
End of file - 7992 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default
prefs.js - "extensions.enabledItems" - "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16, {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1416, avg@toolbar:9.0.0.18.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.25"
prefs.js - "keyword.URL" - "http://search.certified-toolbar.com?si= ... 04065E0&q="
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "browser.search.useDBForOrder" - true
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"Description"=Office Live Update v1.5
"Path"=C:\Program Files\Microsoft\Office Live\npOLW.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=14]
"Description"=Google Updater
"Path"=C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
QuickTimePlugin.class
C:\Users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-13 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-01-20 6711840]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-13 4086432]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2014-01-17 421888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-07-13 20:13:36 ----D---- C:\rsit
2014-07-13 20:07:48 ----A---- C:\Windows\avastSS.scr
2014-07-13 02:44:09 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-13 02:44:09 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-07-13 02:44:09 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-07-13 02:44:08 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-13 02:44:08 ----A---- C:\Windows\system32\iernonce.dll
2014-07-13 02:44:07 ----A---- C:\Windows\system32\urlmon.dll
2014-07-13 02:44:07 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-13 02:44:07 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-13 02:44:06 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-13 02:44:06 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-13 02:44:06 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-13 02:44:06 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-13 02:44:04 ----A---- C:\Windows\system32\msrating.dll
2014-07-13 02:44:04 ----A---- C:\Windows\system32\iesetup.dll
2014-07-13 02:44:04 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-13 02:44:03 ----A---- C:\Windows\system32\wininet.dll
2014-07-13 02:44:03 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-07-13 02:44:02 ----A---- C:\Windows\system32\ieui.dll
2014-07-13 02:44:02 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-13 02:44:01 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-13 02:44:01 ----A---- C:\Windows\system32\ieframe.dll
2014-07-13 02:44:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-07-13 02:44:00 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-07-13 02:43:59 ----A---- C:\Windows\system32\jscript9diag.dll
2014-07-13 02:43:59 ----A---- C:\Windows\system32\iertutil.dll
2014-07-13 02:43:58 ----A---- C:\Windows\system32\mshtml.dll
2014-07-13 02:43:57 ----A---- C:\Windows\system32\vbscript.dll
2014-07-13 02:43:57 ----A---- C:\Windows\system32\jscript9.dll
2014-07-13 02:43:43 ----A---- C:\Windows\system32\win32k.sys
2014-07-13 02:43:42 ----A---- C:\Windows\system32\osk.exe
2014-07-13 02:42:02 ----A---- C:\Windows\system32\qedit.dll
2014-07-13 02:40:55 ----A---- C:\Windows\system32\schannel.dll
2014-07-13 02:40:55 ----A---- C:\Windows\system32\kerberos.dll
2014-07-13 02:40:54 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-13 02:40:53 ----A---- C:\Windows\system32\wdigest.dll
2014-07-13 02:40:53 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-13 02:40:52 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-13 02:40:50 ----A---- C:\Windows\system32\credssp.dll
2014-07-13 02:39:50 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-13 02:39:40 ----A---- C:\Windows\system32\aepdu.dll
2014-07-13 02:39:30 ----A---- C:\Windows\system32\aeinv.dll
2014-07-13 02:39:18 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-13 00:46:54 ----D---- C:\Users\Radim\AppData\Roaming\eCyber
2014-07-13 00:45:44 ----A---- C:\Windows\system32\drivers\iSafeKrnlBoot.sys
2014-07-13 00:45:42 ----D---- C:\Program Files\iSafe
2014-07-13 00:45:30 ----D---- C:\Users\Radim\AppData\Roaming\iSafe
2014-07-13 00:09:17 ----A---- C:\Windows\system32\drivers\{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw.sys
2014-07-12 12:08:52 ----D---- C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-07-12 10:42:33 ----D---- C:\Program Files\DoughGo
2014-07-12 00:40:09 ----D---- C:\Program Files\Enigma Software Group
2014-07-12 00:38:38 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2014-07-10 16:56:22 ----D---- C:\ProgramData\systemk
2014-06-28 07:10:41 ----D---- C:\ProgramData\Apple Computer
2014-06-28 07:10:41 ----D---- C:\Program Files\QuickTime
2014-06-21 15:44:57 ----D---- C:\Users\Radim\AppData\Roaming\Windows Live Writer
2014-06-20 23:29:25 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2014-06-18 12:14:55 ----D---- C:\Program Files\Mozilla Firefox
2014-06-17 00:07:54 ----D---- C:\Program Files\EUcasino
======List of files/folders modified in the last 1 month======
2014-07-13 20:13:49 ----D---- C:\Windows\Prefetch
2014-07-13 20:13:40 ----D---- C:\Program Files\trend micro
2014-07-13 20:13:38 ----D---- C:\Windows\Temp
2014-07-13 20:11:46 ----D---- C:\Windows\inf
2014-07-13 20:10:01 ----D---- C:\Windows\system32\drivers
2014-07-13 20:10:01 ----D---- C:\Windows
2014-07-13 20:08:03 ----D---- C:\Windows\system32\Tasks
2014-07-13 20:07:48 ----A---- C:\Windows\system32\aswBoot.exe
2014-07-13 20:07:06 ----SHD---- C:\System Volume Information
2014-07-13 03:32:18 ----D---- C:\Windows\System32
2014-07-13 03:32:13 ----D---- C:\Windows\system32\LogFiles
2014-07-13 03:32:13 ----D---- C:\Windows\system32\catroot2
2014-07-13 03:32:13 ----D---- C:\Windows\debug
2014-07-13 03:24:37 ----D---- C:\Windows\winsxs
2014-07-13 03:24:01 ----D---- C:\Windows\system32\config
2014-07-13 03:21:21 ----D---- C:\Program Files\Windows Journal
2014-07-13 03:21:20 ----D---- C:\Windows\system32\en-US
2014-07-13 03:21:20 ----D---- C:\Program Files\Internet Explorer
2014-07-13 03:21:19 ----SD---- C:\Windows\system32\CompatTel
2014-07-13 03:21:19 ----D---- C:\Windows\system32\Dism
2014-07-13 03:21:19 ----D---- C:\Windows\system32\cs-CZ
2014-07-13 03:21:19 ----D---- C:\Windows\ehome
2014-07-13 03:21:11 ----D---- C:\Windows\system32\DriverStore
2014-07-13 03:07:53 ----D---- C:\Windows\system32\MRT
2014-07-13 03:07:47 ----A---- C:\Windows\system32\MRT.exe
2014-07-13 03:07:04 ----SHD---- C:\Windows\Installer
2014-07-13 03:06:22 ----D---- C:\Config.Msi
2014-07-13 03:06:21 ----D---- C:\ProgramData\Microsoft Help
2014-07-13 02:36:39 ----D---- C:\Windows\system32\catroot
2014-07-13 02:23:26 ----D---- C:\Program Files\VideoLAN
2014-07-13 02:19:43 ----A---- C:\Windows\win.ini
2014-07-13 02:05:08 ----D---- C:\Users\Radim\AppData\Roaming\vlc
2014-07-13 02:05:05 ----D---- C:\Windows\Panther
2014-07-13 00:45:42 ----D---- C:\Program Files
2014-07-13 00:41:07 ----SD---- C:\Users\Radim\AppData\Roaming\Microsoft
2014-07-12 00:38:38 ----D---- C:\Program Files\Common Files
2014-07-10 16:56:22 ----HD---- C:\ProgramData
2014-07-09 19:21:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-09 11:24:11 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-07-03 23:59:58 ----D---- C:\Program Files\ABBYY FineReader 10
2014-07-03 23:49:46 ----D---- C:\Program Files\CCleaner
2014-06-18 16:22:11 ----D---- C:\Program Files\Mozilla Maintenance Service
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-13 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-13 192352]
R0 Lbd;Lbd; C:\Windows\system32\DRIVERS\Lbd.sys [2010-06-18 64288]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 {735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw;{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw; C:\Windows\system32\drivers\{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw.sys [2014-07-08 52920]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-13 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-13 414520]
R1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Settings Manager\systemk\systemkmgrc2.cfg [2014-07-09 34192]
R1 iSafeKrnl;iSafeKrnl; \??\C:\Program Files\iSafe\iSafeKrnl.sys [2014-06-27 213888]
R1 iSafeKrnlKit;iSafeKrnl Kit Driver; \??\C:\Program Files\iSafe\iSafeKrnlKit.sys [2014-06-27 64512]
R1 iSafeKrnlR3;iSafeKrnl Ring3 Driver; \??\C:\Program Files\iSafe\iSafeKrnlR3.sys [2014-06-27 36992]
R1 iSafeNetFilter;iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [2014-06-03 40280]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-01-20 2317536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2007-08-20 27672]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 iSafeKrnlBoot;iSafeKrnl Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys [2014-06-27 40064]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 ZSMC301b;Look 312P; C:\Windows\System32\Drivers\usbVM31b.sys [2004-03-19 90968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2010-07-22 814344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-13 50344]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-03-11 136120]
R2 iSafeService;iSafeService; C:\Program Files\iSafe\iSafeSvc.exe [2014-06-27 118048]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-15 135664]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 Update DoughGo;Update DoughGo; C:\Program Files\DoughGo\updateDoughGo.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-15 135664]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-19 108032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-18 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------
vím, že už to tady někdo před časem řešil, snažil jsem se aplikovat návod na sebe, ale daleko jsem se sám nedostal. PC před pár dny někde chytlo tzv. prohlížeč únosce, konkrétně default-search.net jako podstrčenou homepage . Která vás sleduje, přesměrovává atd a nejde zrušit. Vygooglovaná rada na SpyHunter vždycky končila nějakou mastnou registrací


---------------------------------------------------------------------------------------------------------------------------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Radim at 2014-07-13 20:13:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 62 GB (41%) free of 152 GB
Total RAM: 2046 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:14:59, on 13.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iSafe\iSafeTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Users\Radim\Desktop\RSIT.exe
C:\Program Files\trend micro\Radim.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.seznam.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... 04065E0&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... 04065E0&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.seznam.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... 04065E0&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (file missing)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 10 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.10.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files\iSafe\iSafeSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Update DoughGo - Unknown owner - C:\Program Files\DoughGo\updateDoughGo.exe (file missing)
--
End of file - 7992 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default
prefs.js - "extensions.enabledItems" - "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16, {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1416, avg@toolbar:9.0.0.18.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.25"
prefs.js - "keyword.URL" - "http://search.certified-toolbar.com?si= ... 04065E0&q="
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "browser.search.useDBForOrder" - true
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"Description"=Office Live Update v1.5
"Path"=C:\Program Files\Microsoft\Office Live\npOLW.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=14]
"Description"=Google Updater
"Path"=C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
QuickTimePlugin.class
C:\Users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\twue63jj.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-13 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-01-20 6711840]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-13 4086432]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2014-01-17 421888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-07-13 20:13:36 ----D---- C:\rsit
2014-07-13 20:07:48 ----A---- C:\Windows\avastSS.scr
2014-07-13 02:44:09 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-13 02:44:09 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-07-13 02:44:09 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-07-13 02:44:08 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-13 02:44:08 ----A---- C:\Windows\system32\iernonce.dll
2014-07-13 02:44:07 ----A---- C:\Windows\system32\urlmon.dll
2014-07-13 02:44:07 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-13 02:44:07 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-13 02:44:06 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-13 02:44:06 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-13 02:44:06 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-13 02:44:06 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-13 02:44:04 ----A---- C:\Windows\system32\msrating.dll
2014-07-13 02:44:04 ----A---- C:\Windows\system32\iesetup.dll
2014-07-13 02:44:04 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-13 02:44:03 ----A---- C:\Windows\system32\wininet.dll
2014-07-13 02:44:03 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-07-13 02:44:02 ----A---- C:\Windows\system32\ieui.dll
2014-07-13 02:44:02 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-13 02:44:01 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-13 02:44:01 ----A---- C:\Windows\system32\ieframe.dll
2014-07-13 02:44:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-07-13 02:44:00 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-07-13 02:43:59 ----A---- C:\Windows\system32\jscript9diag.dll
2014-07-13 02:43:59 ----A---- C:\Windows\system32\iertutil.dll
2014-07-13 02:43:58 ----A---- C:\Windows\system32\mshtml.dll
2014-07-13 02:43:57 ----A---- C:\Windows\system32\vbscript.dll
2014-07-13 02:43:57 ----A---- C:\Windows\system32\jscript9.dll
2014-07-13 02:43:43 ----A---- C:\Windows\system32\win32k.sys
2014-07-13 02:43:42 ----A---- C:\Windows\system32\osk.exe
2014-07-13 02:42:02 ----A---- C:\Windows\system32\qedit.dll
2014-07-13 02:40:55 ----A---- C:\Windows\system32\schannel.dll
2014-07-13 02:40:55 ----A---- C:\Windows\system32\kerberos.dll
2014-07-13 02:40:54 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-13 02:40:53 ----A---- C:\Windows\system32\wdigest.dll
2014-07-13 02:40:53 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-13 02:40:52 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-13 02:40:50 ----A---- C:\Windows\system32\credssp.dll
2014-07-13 02:39:50 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-13 02:39:40 ----A---- C:\Windows\system32\aepdu.dll
2014-07-13 02:39:30 ----A---- C:\Windows\system32\aeinv.dll
2014-07-13 02:39:18 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-13 00:46:54 ----D---- C:\Users\Radim\AppData\Roaming\eCyber
2014-07-13 00:45:44 ----A---- C:\Windows\system32\drivers\iSafeKrnlBoot.sys
2014-07-13 00:45:42 ----D---- C:\Program Files\iSafe
2014-07-13 00:45:30 ----D---- C:\Users\Radim\AppData\Roaming\iSafe
2014-07-13 00:09:17 ----A---- C:\Windows\system32\drivers\{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw.sys
2014-07-12 12:08:52 ----D---- C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-07-12 10:42:33 ----D---- C:\Program Files\DoughGo
2014-07-12 00:40:09 ----D---- C:\Program Files\Enigma Software Group
2014-07-12 00:38:38 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2014-07-10 16:56:22 ----D---- C:\ProgramData\systemk
2014-06-28 07:10:41 ----D---- C:\ProgramData\Apple Computer
2014-06-28 07:10:41 ----D---- C:\Program Files\QuickTime
2014-06-21 15:44:57 ----D---- C:\Users\Radim\AppData\Roaming\Windows Live Writer
2014-06-20 23:29:25 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2014-06-18 12:14:55 ----D---- C:\Program Files\Mozilla Firefox
2014-06-17 00:07:54 ----D---- C:\Program Files\EUcasino
======List of files/folders modified in the last 1 month======
2014-07-13 20:13:49 ----D---- C:\Windows\Prefetch
2014-07-13 20:13:40 ----D---- C:\Program Files\trend micro
2014-07-13 20:13:38 ----D---- C:\Windows\Temp
2014-07-13 20:11:46 ----D---- C:\Windows\inf
2014-07-13 20:10:01 ----D---- C:\Windows\system32\drivers
2014-07-13 20:10:01 ----D---- C:\Windows
2014-07-13 20:08:03 ----D---- C:\Windows\system32\Tasks
2014-07-13 20:07:48 ----A---- C:\Windows\system32\aswBoot.exe
2014-07-13 20:07:06 ----SHD---- C:\System Volume Information
2014-07-13 03:32:18 ----D---- C:\Windows\System32
2014-07-13 03:32:13 ----D---- C:\Windows\system32\LogFiles
2014-07-13 03:32:13 ----D---- C:\Windows\system32\catroot2
2014-07-13 03:32:13 ----D---- C:\Windows\debug
2014-07-13 03:24:37 ----D---- C:\Windows\winsxs
2014-07-13 03:24:01 ----D---- C:\Windows\system32\config
2014-07-13 03:21:21 ----D---- C:\Program Files\Windows Journal
2014-07-13 03:21:20 ----D---- C:\Windows\system32\en-US
2014-07-13 03:21:20 ----D---- C:\Program Files\Internet Explorer
2014-07-13 03:21:19 ----SD---- C:\Windows\system32\CompatTel
2014-07-13 03:21:19 ----D---- C:\Windows\system32\Dism
2014-07-13 03:21:19 ----D---- C:\Windows\system32\cs-CZ
2014-07-13 03:21:19 ----D---- C:\Windows\ehome
2014-07-13 03:21:11 ----D---- C:\Windows\system32\DriverStore
2014-07-13 03:07:53 ----D---- C:\Windows\system32\MRT
2014-07-13 03:07:47 ----A---- C:\Windows\system32\MRT.exe
2014-07-13 03:07:04 ----SHD---- C:\Windows\Installer
2014-07-13 03:06:22 ----D---- C:\Config.Msi
2014-07-13 03:06:21 ----D---- C:\ProgramData\Microsoft Help
2014-07-13 02:36:39 ----D---- C:\Windows\system32\catroot
2014-07-13 02:23:26 ----D---- C:\Program Files\VideoLAN
2014-07-13 02:19:43 ----A---- C:\Windows\win.ini
2014-07-13 02:05:08 ----D---- C:\Users\Radim\AppData\Roaming\vlc
2014-07-13 02:05:05 ----D---- C:\Windows\Panther
2014-07-13 00:45:42 ----D---- C:\Program Files
2014-07-13 00:41:07 ----SD---- C:\Users\Radim\AppData\Roaming\Microsoft
2014-07-12 00:38:38 ----D---- C:\Program Files\Common Files
2014-07-10 16:56:22 ----HD---- C:\ProgramData
2014-07-09 19:21:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-09 11:24:11 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-07-03 23:59:58 ----D---- C:\Program Files\ABBYY FineReader 10
2014-07-03 23:49:46 ----D---- C:\Program Files\CCleaner
2014-06-18 16:22:11 ----D---- C:\Program Files\Mozilla Maintenance Service
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-13 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-13 192352]
R0 Lbd;Lbd; C:\Windows\system32\DRIVERS\Lbd.sys [2010-06-18 64288]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 {735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw;{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw; C:\Windows\system32\drivers\{735c7dda-e3b7-44f2-8521-a39cc0d289b2}Gw.sys [2014-07-08 52920]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-13 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-13 779536]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-13 414520]
R1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Settings Manager\systemk\systemkmgrc2.cfg [2014-07-09 34192]
R1 iSafeKrnl;iSafeKrnl; \??\C:\Program Files\iSafe\iSafeKrnl.sys [2014-06-27 213888]
R1 iSafeKrnlKit;iSafeKrnl Kit Driver; \??\C:\Program Files\iSafe\iSafeKrnlKit.sys [2014-06-27 64512]
R1 iSafeKrnlR3;iSafeKrnl Ring3 Driver; \??\C:\Program Files\iSafe\iSafeKrnlR3.sys [2014-06-27 36992]
R1 iSafeNetFilter;iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [2014-06-03 40280]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-13 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-13 67824]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-13 71944]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-01-20 2317536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2007-08-20 27672]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 iSafeKrnlBoot;iSafeKrnl Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys [2014-06-27 40064]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 ZSMC301b;Look 312P; C:\Windows\System32\Drivers\usbVM31b.sys [2004-03-19 90968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2010-07-22 814344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-13 50344]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-03-11 136120]
R2 iSafeService;iSafeService; C:\Program Files\iSafe\iSafeSvc.exe [2014-06-27 118048]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-15 135664]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 Update DoughGo;Update DoughGo; C:\Program Files\DoughGo\updateDoughGo.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-15 135664]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-19 108032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-18 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------