Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

do počítače se mi nainstalovaly pochybné programy

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

do počítače se mi nainstalovaly pochybné programy

#1 Příspěvek od zorttan »

Dobrý den, potřeboval bych poradit co mam dělat když se mi nainstalovali do pc programy shopper pro,youtube accelerator.Sense, atd. :(
Bohužel to byla moje vina protože jsme poslechl známého který mi doporučil jedny stránky s možností stažení a aktivováni antiviru AVG a dalších produktu od této značky.
bohužel jsem ho poslechl a nainstaloval jsem to jenže pak se začali dít věci :( všude mi skákaly reklamy to jsme naštěstí vyřešil odinstalováním Sense ale odinstalace ostatních programu se nepovedla. Počítač je strašně zabržděný a i google chrome pracuje o dost pomaleji než předtím.
Předem děkuji za pomoc.
Na vašich stránkách jsem se dočetl že mam vložit FRST tak snad je to ono nejsem moc zdatný co se týká hlubší manipulace s pc.



Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:19-07-2014
Ran by Lenovo (administrator) on LENOVO-NTB on 20-07-2014 11:30:53
Running from C:\Users\Lenovo\Desktop
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(ShopperPro) C:\Program Files\Common Files\ShopperPro\spbiu.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Ricoh co.,Ltd.) C:\Program Files\RotateImage\RCIMGDIR.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo Group Limited) C:\Program Files\ThinkPad\Utilities\SCHTASK.EXE
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Logitech Inc.) C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files\Intel\AMT\LMS.exe
(Intel Corporation) C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
(Lenovo) C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(PENDA s.r.o.) C:\Program Files\tisknulevne\ql-printer\QL-Printer.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Lenovo\Desktop\FRSTLauncher (3).exe


==================== Registry (Whitelisted) ==================

HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [93696 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [93696 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.199\jsdrv.exe

HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: E - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {4c16a250-3952-11e3-8048-001c259d602a} - D:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {4c16a30f-3952-11e3-8048-001c259d602a} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {5553bc57-07fe-11e4-a33c-00234df621aa} - E:\Windows\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {a5300530-adaa-11e3-a9dd-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {aecfbf8c-fc34-11e3-a8d8-00234df621aa} - E:\laucher.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {bf47cb32-b4bb-11e3-bdc7-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {de1e54b0-4390-11e3-9334-00234df621aa} - E:\AutoRun.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {de1e54b9-4390-11e3-9334-00234df621aa} - F:\AutoRun.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {f6775ab0-ab4c-11e3-99c0-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
Startup: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ql-printer.lnk
ShortcutTarget: ql-printer.lnk -> C:\Program Files\tisknulevne\ql-printer\QL-Printer.exe (PENDA s.r.o.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?pc=UP97&ocid=UP97DHP
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs-cz
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=17087
BHO: Sense -> {11111111-1111-1111-1111-110411821192} -> C:\Program Files\Sense\Sense-bho.dll No File
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: YTAHelper -> {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} -> C:\ProgramData\YTAHelper\YTAHelper.dll (Goobzo Ltd.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 02 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 03 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 04 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 16 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{013CD172-B340-4B4F-A38F-EED50107BF7E}: [NameServer]217.77.165.81 217.77.161.131
Tcpip\..\Interfaces\{B0DD6A44-2750-4DC0-B393-BBC189367765}: [NameServer]217.77.165.81 217.77.161.131
Tcpip\..\Interfaces\{C5B57B3B-D24E-4A12-BD7C-B212454CCB39}: [NameServer]217.77.165.81 217.77.161.131

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @photodex.com/PhotodexPresenter - C:\Program Files\Photodex Presenter\npPxPlay.dll ( )
FF Plugin: @staging.google.com/globalUpdate Update;version=10 - C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 - C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @VideoDownloadConverter_ScriptHelper.com/Plugin - C:\Program Files\VideoDownloadConverter\npVDCPlugin.dll No File
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Lenovo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

Chrome:
=======
CHR Extension: (Dokumenty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-15]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-15]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-15]
CHR Extension: (Vyhledávání Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-15]
CHR Extension: (AdBlock) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-07-19]
CHR Extension: (Peněženka Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-15]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-15]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
CHR HKLM\...\Chrome\Extension: [ojhagnahfpegocdhlopgljpaafeogmcc] - C:\Program Files\ShopperPro\ShopperPro.crx [2014-04-11]

========================== Services (Whitelisted) =================

S2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-19] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-19] (globalUpdate) [File not signed]
S2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [127072 2012-08-24] (Lenovo Group Limited)
S3 PwmEWSvc; C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE [1664808 2013-06-14] (Lenovo Group Limited)
R2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe [1812992 2014-07-16] (ShopperPro) [File not signed]
R2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [116216 2013-05-23] (Lenovo Group Limited)
R2 UNS; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2010-02-04] (Intel Corporation)
R2 VmbService; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2012-03-20] (Vodafone) [File not signed]
S4 YouTubeAcceleratorService; C:\Program Files\YouTube Accelerator\YouTubeAcceleratorService.exe [1510248 2014-07-19] (GOOBZO)

==================== Drivers (Whitelisted) ====================

R3 5U875UVC; C:\Windows\System32\DRIVERS\RCUVCMNP.sys [187776 2009-10-23] (Ricoh co.,Ltd.)
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [199960 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [197400 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2012-03-16] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [193536 2012-03-16] (Huawei Technologies Co., Ltd.)
R3 intelkmd; C:\Windows\System32\DRIVERS\igdpmd32.sys [9037312 2011-10-13] (Intel Corporation)
R3 LenovoRd; C:\Windows\System32\Drivers\LenovoRd.sys [88832 2009-05-11] (Lenovo)
S3 scvad_simple; C:\Windows\System32\drivers\SplitCamAudio.sys [18944 2013-11-01] (Windows (R) Win 7 DDK provider)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [38768 2013-05-29] (Synaptics Incorporated)
R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [25600 2014-07-16] () [File not signed]
S3 splitcam_hd_driver; C:\Windows\System32\DRIVERS\splitcam_hd_driver.sys [36984 2013-12-16] (Windows (R) Win 7 DDK provider)
S2 SPDRIVER_1.37.0.199; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys [X]
S3 SPLITCAM; system32\DRIVERS\splitcam.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-20 11:30 - 2014-07-20 11:31 - 00014696 _____ () C:\Users\Lenovo\Desktop\FRST.txt
2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\FRST
2014-07-20 11:29 - 2014-07-20 11:29 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Downloads\Nepotvrzeno 603823.crdownload
2014-07-20 11:29 - 2014-07-20 11:29 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Desktop\FRSTLauncher (3).exe
2014-07-20 11:21 - 2014-07-20 11:21 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Downloads\Nepotvrzeno 995094.crdownload
2014-07-20 11:21 - 2014-07-20 11:21 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Downloads\Nepotvrzeno 892490.crdownload
2014-07-20 11:19 - 2014-07-20 11:19 - 01079808 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST.exe
2014-07-20 10:23 - 2014-07-20 10:23 - 00000000 ____D () C:\Intel
2014-07-20 10:22 - 2014-07-20 10:22 - 00000000 ____D () C:\Users\Public\Documents\GOOBZO
2014-07-19 22:56 - 2014-07-20 08:50 - 00000168 _____ () C:\Windows\setupact.log
2014-07-19 22:56 - 2014-07-19 22:56 - 00000598 _____ () C:\Windows\PFRO.log
2014-07-19 22:56 - 2014-07-19 22:56 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-19 18:44 - 2014-07-19 18:44 - 44464139 _____ () C:\Users\Lenovo\Downloads\Spyhunter version 4 cracked.zip
2014-07-19 17:35 - 2014-07-19 17:35 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-07-19 17:26 - 2014-07-19 17:26 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Lenovo\Downloads\sh-remover.exe
2014-07-19 17:20 - 2014-07-19 20:33 - 00000334 _____ () C:\Windows\Tasks\Health-Check-deep.job
2014-07-19 17:20 - 2014-07-19 17:20 - 00002269 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO 11.lnk
2014-07-19 17:20 - 2014-07-19 17:20 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Innovative Solutions
2014-07-19 17:20 - 2014-07-19 17:20 - 00000000 ____D () C:\ProgramData\Innovative Solutions
2014-07-19 17:20 - 2014-07-19 17:20 - 00000000 ____D () C:\Program Files\Common Files\Innovative Solutions
2014-07-19 17:20 - 2014-03-07 09:25 - 00042496 _____ () C:\Windows\system32\AdvUninstCPL.cpl
2014-07-19 17:17 - 2014-07-19 17:18 - 16532896 _____ (Innovative Solutions ) C:\Users\Lenovo\Downloads\Advanced_Uninstaller11.exe
2014-07-19 16:10 - 2014-07-19 16:12 - 00007168 ___SH () C:\Users\Lenovo\Thumbs.db
2014-07-19 12:02 - 2014-07-19 16:00 - 00002394 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job
2014-07-19 12:02 - 2014-07-19 16:00 - 00001738 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job
2014-07-19 12:02 - 2014-07-19 16:00 - 00001736 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job
2014-07-19 12:02 - 2014-07-19 16:00 - 00001694 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job
2014-07-19 12:02 - 2014-07-19 16:00 - 00001674 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job
2014-07-19 12:02 - 2014-07-19 16:00 - 00001580 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job
2014-07-19 12:02 - 2014-07-19 15:29 - 00001674 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job
2014-07-19 12:01 - 2014-07-19 16:00 - 00004122 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job
2014-07-19 12:01 - 2014-07-19 16:00 - 00002752 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job
2014-07-19 11:53 - 2014-07-20 10:11 - 00000898 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-07-19 11:53 - 2014-07-20 08:50 - 00000894 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-07-19 11:53 - 2014-07-19 11:53 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\globalUpdate
2014-07-19 11:53 - 2014-07-19 11:53 - 00000000 ____D () C:\Program Files\globalUpdate
2014-07-19 11:52 - 2014-07-20 10:22 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-19 11:52 - 2014-07-19 20:32 - 00000000 ____D () C:\Program Files\YouTube Accelerator
2014-07-19 11:52 - 2014-07-19 11:52 - 00000000 ____D () C:\ProgramData\YTAHelper
2014-07-19 11:51 - 2014-07-19 20:33 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro
2014-07-19 11:51 - 2014-07-19 20:32 - 00000000 ____D () C:\ProgramData\ShopperPro
2014-07-19 11:51 - 2014-07-19 11:51 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\CrashRpt
2014-07-19 11:50 - 2014-07-19 15:45 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Seznam.cz
2014-07-19 10:53 - 2014-07-19 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-16 17:36 - 2014-07-16 17:36 - 00000704 _____ () C:\Users\Lenovo\Documents\ddd.scset
2014-07-16 17:24 - 2014-07-16 17:24 - 00276480 _____ () C:\Users\Lenovo\Documents\f.avi
2014-07-16 17:16 - 2013-11-01 11:12 - 00810496 _____ () C:\Windows\system32\xvidcore.dll
2014-07-16 17:16 - 2013-11-01 11:12 - 00183808 _____ () C:\Windows\system32\xvidvfw.dll
2014-07-16 17:16 - 2013-11-01 11:12 - 00112640 _____ () C:\Windows\system32\ff_vfw.dll
2014-07-16 17:16 - 2013-11-01 11:12 - 00000590 _____ () C:\Windows\system32\ff_vfw.dll.manifest
2014-07-14 18:48 - 2003-03-19 11:14 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\MSVCP71.dll
2014-07-14 18:48 - 2003-02-21 18:42 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\MSVCR71.dll
2014-07-14 18:48 - 1997-03-25 05:02 - 00229888 _____ (Borland International) C:\Windows\system32\bc520rtl.dll
2014-07-13 19:16 - 2014-07-13 19:16 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Conexant
2014-07-13 19:16 - 2014-07-13 19:16 - 00000000 ____D () C:\ProgramData\Conexant
2014-07-13 19:11 - 2009-11-24 14:36 - 00022408 _____ (camPoint AG) C:\Windows\system32\Drivers\camboxdrv.sys
2014-07-13 19:11 - 2007-05-03 18:56 - 00152560 _____ (GigaCodes GmbH) C:\Windows\system32\VXBox.dll
2014-07-13 18:06 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-13 18:06 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-13 18:06 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-13 18:06 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-13 18:06 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-13 18:06 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-13 18:06 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-13 18:06 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-13 18:06 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-13 18:06 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-13 18:06 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-13 18:06 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-13 18:06 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-13 18:06 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-13 18:06 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-13 18:06 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-13 18:06 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-13 18:06 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-13 18:06 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-13 18:06 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-13 18:06 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-13 18:06 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-13 18:06 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-13 18:06 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-13 18:06 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-13 18:06 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-13 18:06 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-13 18:06 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-13 18:06 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-13 18:06 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-13 18:05 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-13 18:05 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-13 18:04 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-13 18:03 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 21:44 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-07 11:51 - 2014-07-10 14:54 - 00000000 ____D () C:\Users\Lenovo\Documents\tady
2014-07-06 11:43 - 2014-05-08 11:06 - 02742784 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-07-06 11:43 - 2014-05-08 11:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-06 11:15 - 2014-07-06 11:15 - 00000037 ___SH () C:\Users\Lenovo\AppData\Local\20986331705021ca58edc424.96250074
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\icsxml
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Letasoft
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Letasoft Sound Booster
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 ____D () C:\Program Files\Letasoft Sound Booster
2014-07-05 22:38 - 2014-07-05 22:38 - 00000456 _____ () C:\Users\Lenovo\Documents\cc_20140705_223800.reg
2014-07-04 11:34 - 2014-07-04 11:34 - 00011366 _____ () C:\Users\Lenovo\Documents\cc_20140704_113413.reg
2014-07-04 09:28 - 2014-07-04 09:28 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\AVG
2014-07-04 09:28 - 2014-07-04 09:28 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\AVG
2014-07-04 09:23 - 2014-07-19 12:37 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-07-04 09:23 - 2014-07-04 09:28 - 00000000 ____D () C:\ProgramData\AVG
2014-07-04 09:20 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-07-04 09:20 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-04 09:20 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-04 09:20 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-07-04 09:20 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-07-04 09:20 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-07-04 09:20 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-07-04 09:20 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-07-04 09:20 - 2013-10-02 01:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-07-04 09:20 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-07-04 09:20 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-07-04 09:20 - 2013-10-01 22:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-07-04 09:20 - 2012-08-23 16:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-07-04 09:20 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-07-04 09:20 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-07-04 09:16 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-07-04 09:16 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-07-04 09:15 - 2014-06-08 10:48 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-04 09:15 - 2014-06-08 10:43 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-03 22:49 - 2014-07-03 22:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-07-03 22:47 - 2014-07-16 16:55 - 00000000 ____D () C:\Program Files\LiveJasmin.com
2014-07-03 15:26 - 2014-07-03 15:26 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Unity
2014-07-03 13:29 - 2014-07-03 13:29 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Unity
2014-07-01 22:07 - 2014-07-01 22:07 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Logitech® Webcam Software
2014-07-01 22:03 - 2014-07-01 22:03 - 00007475 _____ () C:\Windows\system32\lvcoinst.log
2014-07-01 22:03 - 2014-07-01 22:03 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Leadertech
2014-07-01 22:03 - 2014-07-01 22:03 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-07-01 22:01 - 2014-07-01 22:04 - 00000000 ____D () C:\Program Files\Common Files\LogiShrd
2014-07-01 22:01 - 2014-07-01 22:03 - 00000000 ____D () C:\Program Files\Logitech
2014-07-01 22:01 - 2014-07-01 22:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-07-01 18:30 - 2014-07-01 18:30 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Macromedia
2014-07-01 17:55 - 2014-07-20 10:37 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-01 17:54 - 2014-07-19 22:30 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-01 17:54 - 2014-07-19 22:30 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-01 17:54 - 2014-07-01 17:54 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-01 17:52 - 2014-07-01 17:52 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\EmieUserList
2014-07-01 17:52 - 2014-07-01 17:52 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\EmieSiteList
2014-07-01 16:49 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-07-01 16:49 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-07-01 16:49 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-07-01 16:49 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-07-01 16:49 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-07-01 16:49 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-07-01 16:49 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-07-01 16:49 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-07-01 16:49 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-07-01 16:49 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-07-01 16:49 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-01 16:48 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-07-01 16:48 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-07-01 16:48 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-07-01 16:48 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-07-01 16:48 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-07-01 16:48 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-07-01 16:45 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-07-01 16:44 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-07-01 15:49 - 2014-07-01 15:49 - 00001302 _____ () C:\Users\Lenovo\Desktop\Skyrim - Legendary Edition.lnk
2014-07-01 15:49 - 2014-07-01 15:49 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Skyrim - Legendary Edition
2014-07-01 15:49 - 2014-07-01 15:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2014-07-01 15:48 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2014-07-01 15:48 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2014-07-01 15:48 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-07-01 15:48 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-07-01 15:48 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-07-01 15:48 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-07-01 14:55 - 2014-07-01 14:55 - 00000000 ____D () C:\Users\Lenovo\Documents\My Games
2014-07-01 14:55 - 2014-07-01 14:55 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Skyrim
2014-07-01 14:06 - 2014-07-01 14:06 - 00000000 ____D () C:\Program Files\R.G. Mechanics
2014-07-01 09:51 - 2014-07-01 12:55 - 00000000 ____D () C:\Users\Lenovo\Downloads\[R.G. Mechanics] The Elder Scrolls V - Skyrim - Legendary Edition
2014-07-01 09:51 - 2014-06-29 12:39 - 00026626 ____N () C:\Users\Lenovo\[R.G. Mechanics] The Elder Scrolls V - Skyrim - Legendary Edition.torrent

==================== One Month Modified Files and Folders =======

2014-07-20 11:31 - 2014-07-20 11:30 - 00014696 _____ () C:\Users\Lenovo\Desktop\FRST.txt
2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\FRST
2014-07-20 11:29 - 2014-07-20 11:29 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Downloads\Nepotvrzeno 603823.crdownload
2014-07-20 11:29 - 2014-07-20 11:29 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Desktop\FRSTLauncher (3).exe
2014-07-20 11:23 - 2013-10-25 09:21 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Skype
2014-07-20 11:21 - 2014-07-20 11:21 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Downloads\Nepotvrzeno 995094.crdownload
2014-07-20 11:21 - 2014-07-20 11:21 - 00112640 _____ (forum.viry.cz) C:\Users\Lenovo\Downloads\Nepotvrzeno 892490.crdownload
2014-07-20 11:19 - 2014-07-20 11:19 - 01079808 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST.exe
2014-07-20 11:19 - 2013-10-15 11:24 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-20 10:53 - 2013-09-13 09:12 - 00179667 _____ () C:\Windows\WindowsUpdate.log
2014-07-20 10:37 - 2014-07-01 17:55 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-20 10:23 - 2014-07-20 10:23 - 00000000 ____D () C:\Intel
2014-07-20 10:22 - 2014-07-20 10:22 - 00000000 ____D () C:\Users\Public\Documents\GOOBZO
2014-07-20 10:22 - 2014-07-19 11:52 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-20 10:11 - 2014-07-19 11:53 - 00000898 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-07-20 09:27 - 2013-10-16 12:26 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-20 08:57 - 2009-07-14 06:34 - 00028528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-20 08:57 - 2009-07-14 06:34 - 00028528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-20 08:50 - 2014-07-19 22:56 - 00000168 _____ () C:\Windows\setupact.log
2014-07-20 08:50 - 2014-07-19 11:53 - 00000894 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-07-20 08:50 - 2013-10-15 11:24 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-20 08:50 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-19 22:56 - 2014-07-19 22:56 - 00000598 _____ () C:\Windows\PFRO.log
2014-07-19 22:56 - 2014-07-19 22:56 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-19 22:32 - 2013-10-16 12:30 - 00000000 ____D () C:\Program Files\AVG
2014-07-19 22:30 - 2014-07-01 17:54 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-19 22:30 - 2014-07-01 17:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-19 20:33 - 2014-07-19 17:20 - 00000334 _____ () C:\Windows\Tasks\Health-Check-deep.job
2014-07-19 20:33 - 2014-07-19 11:51 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro
2014-07-19 20:33 - 2013-09-13 09:20 - 00000000 ____D () C:\Users\Lenovo
2014-07-19 20:33 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2014-07-19 20:32 - 2014-07-19 11:52 - 00000000 ____D () C:\Program Files\YouTube Accelerator
2014-07-19 20:32 - 2014-07-19 11:51 - 00000000 ____D () C:\ProgramData\ShopperPro
2014-07-19 20:32 - 2010-11-21 03:24 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-07-19 20:32 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-19 20:32 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2014-07-19 20:26 - 2013-10-27 15:26 - 00000000 ____D () C:\Users\Lenovo\Desktop\eretko
2014-07-19 19:28 - 2014-01-25 18:06 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\newnext.me
2014-07-19 18:44 - 2014-07-19 18:44 - 44464139 _____ () C:\Users\Lenovo\Downloads\Spyhunter version 4 cracked.zip
2014-07-19 17:35 - 2014-07-19 17:35 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-07-19 17:26 - 2014-07-19 17:26 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Lenovo\Downloads\sh-remover.exe
2014-07-19 17:20 - 2014-07-19 17:20 - 00002269 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO 11.lnk
2014-07-19 17:20 - 2014-07-19 17:20 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Innovative Solutions
2014-07-19 17:20 - 2014-07-19 17:20 - 00000000 ____D () C:\ProgramData\Innovative Solutions
2014-07-19 17:20 - 2014-07-19 17:20 - 00000000 ____D () C:\Program Files\Common Files\Innovative Solutions
2014-07-19 17:18 - 2014-07-19 17:17 - 16532896 _____ (Innovative Solutions ) C:\Users\Lenovo\Downloads\Advanced_Uninstaller11.exe
2014-07-19 17:18 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-07-19 16:12 - 2014-07-19 16:10 - 00007168 ___SH () C:\Users\Lenovo\Thumbs.db
2014-07-19 16:05 - 2010-11-20 23:01 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-19 16:00 - 2014-07-19 12:02 - 00002394 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job
2014-07-19 16:00 - 2014-07-19 12:02 - 00001738 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job
2014-07-19 16:00 - 2014-07-19 12:02 - 00001736 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job
2014-07-19 16:00 - 2014-07-19 12:02 - 00001694 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job
2014-07-19 16:00 - 2014-07-19 12:02 - 00001674 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job
2014-07-19 16:00 - 2014-07-19 12:02 - 00001580 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job
2014-07-19 16:00 - 2014-07-19 12:01 - 00004122 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job
2014-07-19 16:00 - 2014-07-19 12:01 - 00002752 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job
2014-07-19 15:45 - 2014-07-19 11:50 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Seznam.cz
2014-07-19 15:29 - 2014-07-19 12:02 - 00001674 _____ () C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job
2014-07-19 12:37 - 2014-07-04 09:23 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-07-19 11:53 - 2014-07-19 11:53 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\globalUpdate
2014-07-19 11:53 - 2014-07-19 11:53 - 00000000 ____D () C:\Program Files\globalUpdate
2014-07-19 11:52 - 2014-07-19 11:52 - 00000000 ____D () C:\ProgramData\YTAHelper
2014-07-19 11:51 - 2014-07-19 11:51 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\CrashRpt
2014-07-19 10:53 - 2014-07-19 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-18 18:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-07-18 00:33 - 2013-10-15 11:25 - 00002129 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-16 17:36 - 2014-07-16 17:36 - 00000704 _____ () C:\Users\Lenovo\Documents\ddd.scset
2014-07-16 17:24 - 2014-07-16 17:24 - 00276480 _____ () C:\Users\Lenovo\Documents\f.avi
2014-07-16 16:55 - 2014-07-03 22:47 - 00000000 ____D () C:\Program Files\LiveJasmin.com
2014-07-14 16:10 - 2013-10-09 08:38 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\vlc
2014-07-13 19:16 - 2014-07-13 19:16 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Conexant
2014-07-13 19:16 - 2014-07-13 19:16 - 00000000 ____D () C:\ProgramData\Conexant
2014-07-13 18:57 - 2014-02-14 10:01 - 00000000 ____D () C:\Program Files\AVG Secure Search
2014-07-13 18:52 - 2013-09-13 10:57 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-07-13 18:31 - 2013-09-13 09:20 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\VirtualStore
2014-07-13 18:17 - 2009-07-14 06:33 - 00271424 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-13 18:14 - 2010-11-21 03:25 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-13 18:12 - 2013-10-22 09:03 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-13 18:07 - 2013-10-22 09:03 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-13 18:02 - 2013-09-13 10:57 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-07-10 14:54 - 2014-07-07 11:51 - 00000000 ____D () C:\Users\Lenovo\Documents\tady
2014-07-10 14:52 - 2014-02-24 11:08 - 00000000 ____D () C:\Users\Lenovo\Downloads\QL-Printer-Install
2014-07-10 14:50 - 2014-01-25 17:54 - 00076651 _____ () C:\Users\Lenovo\resume.dat.old
2014-07-10 14:50 - 2014-01-25 17:54 - 00065366 _____ () C:\Users\Lenovo\resume.dat
2014-07-10 14:50 - 2014-01-25 17:54 - 00001856 _____ () C:\Users\Lenovo\dht.dat
2014-07-10 14:50 - 2014-01-25 17:54 - 00000099 _____ () C:\Users\Lenovo\rss.dat
2014-07-10 14:50 - 2014-01-25 17:53 - 00006488 _____ () C:\Users\Lenovo\settings.dat
2014-07-10 14:32 - 2014-01-25 17:53 - 00006487 _____ () C:\Users\Lenovo\settings.dat.old
2014-07-06 11:33 - 2014-01-25 18:06 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\genienext
2014-07-06 11:15 - 2014-07-06 11:15 - 00000037 ___SH () C:\Users\Lenovo\AppData\Local\20986331705021ca58edc424.96250074
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\icsxml
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Letasoft
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Letasoft Sound Booster
2014-07-06 11:15 - 2014-07-06 11:15 - 00000000 ____D () C:\Program Files\Letasoft Sound Booster
2014-07-05 22:38 - 2014-07-05 22:38 - 00000456 _____ () C:\Users\Lenovo\Documents\cc_20140705_223800.reg
2014-07-04 11:34 - 2014-07-04 11:34 - 00011366 _____ () C:\Users\Lenovo\Documents\cc_20140704_113413.reg
2014-07-04 11:33 - 2014-03-27 10:06 - 00000000 ____D () C:\Windows\Minidump
2014-07-04 10:24 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-04 09:36 - 2014-01-25 17:53 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2014-07-04 09:36 - 2013-10-20 08:46 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Downloaded Installations
2014-07-04 09:28 - 2014-07-04 09:28 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\AVG
2014-07-04 09:28 - 2014-07-04 09:28 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\AVG
2014-07-04 09:28 - 2014-07-04 09:23 - 00000000 ____D () C:\ProgramData\AVG
2014-07-04 09:19 - 2014-05-01 08:59 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-03 22:49 - 2014-07-03 22:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2014-07-03 22:49 - 2014-05-19 09:34 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-07-03 22:49 - 2014-05-19 09:34 - 00000000 ____D () C:\Program Files\Adobe
2014-07-03 22:49 - 2013-10-15 15:38 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Adobe
2014-07-03 15:26 - 2014-07-03 15:26 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Unity
2014-07-03 13:29 - 2014-07-03 13:29 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Unity
2014-07-01 22:32 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-07-01 22:07 - 2014-07-01 22:07 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Logitech® Webcam Software
2014-07-01 22:04 - 2014-07-01 22:01 - 00000000 ____D () C:\Program Files\Common Files\LogiShrd
2014-07-01 22:03 - 2014-07-01 22:03 - 00007475 _____ () C:\Windows\system32\lvcoinst.log
2014-07-01 22:03 - 2014-07-01 22:03 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Leadertech
2014-07-01 22:03 - 2014-07-01 22:03 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-07-01 22:03 - 2014-07-01 22:01 - 00000000 ____D () C:\Program Files\Logitech
2014-07-01 22:03 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\twain_32
2014-07-01 22:01 - 2014-07-01 22:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-07-01 21:50 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-07-01 18:30 - 2014-07-01 18:30 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Macromedia
2014-07-01 17:54 - 2014-07-01 17:54 - 00000000 ____D () C:\Windows\system32\Macromed
2014-07-01 17:52 - 2014-07-01 17:52 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\EmieUserList
2014-07-01 17:52 - 2014-07-01 17:52 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\EmieSiteList
2014-07-01 15:49 - 2014-07-01 15:49 - 00001302 _____ () C:\Users\Lenovo\Desktop\Skyrim - Legendary Edition.lnk
2014-07-01 15:49 - 2014-07-01 15:49 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Skyrim - Legendary Edition
2014-07-01 15:49 - 2014-07-01 15:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2014-07-01 14:55 - 2014-07-01 14:55 - 00000000 ____D () C:\Users\Lenovo\Documents\My Games
2014-07-01 14:55 - 2014-07-01 14:55 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Skyrim
2014-07-01 14:18 - 2014-02-24 11:45 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\tisknulevne
2014-07-01 14:06 - 2014-07-01 14:06 - 00000000 ____D () C:\Program Files\R.G. Mechanics
2014-07-01 14:06 - 2014-01-25 17:54 - 00004118 _____ () C:\Users\Lenovo\dht.dat.old
2014-07-01 14:06 - 2014-01-25 17:54 - 00000099 _____ () C:\Users\Lenovo\rss.dat.old
2014-07-01 12:55 - 2014-07-01 09:51 - 00000000 ____D () C:\Users\Lenovo\Downloads\[R.G. Mechanics] The Elder Scrolls V - Skyrim - Legendary Edition
2014-06-29 12:39 - 2014-07-01 09:51 - 00026626 ____N () C:\Users\Lenovo\[R.G. Mechanics] The Elder Scrolls V - Skyrim - Legendary Edition.torrent
2014-06-20 21:39 - 2014-07-13 18:06 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll

Files to move or delete:
====================
C:\Users\Lenovo\dht.dat
C:\Users\Lenovo\resume.dat
C:\Users\Lenovo\rss.dat
C:\Users\Lenovo\settings.dat
C:\Users\Lenovo\utorrent.exe


Some content of TEMP:
====================
C:\Users\Lenovo\AppData\Local\Temp\appshat_generic.exe
C:\Users\Lenovo\AppData\Local\Temp\cabex.dll
C:\Users\Lenovo\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Lenovo\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Lenovo\AppData\Local\Temp\PartnerInstaller_smtyc.exe
C:\Users\Lenovo\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Lenovo\AppData\Local\Temp\setup.exe
C:\Users\Lenovo\AppData\Local\Temp\SHSetup.exe
C:\Users\Lenovo\AppData\Local\Temp\unelevate.exe
C:\Users\Lenovo\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-18 18:00




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:148.95 GB) (Free:78.76 GB) NTFS

Available physical RAM: 780.05 MB
Total physical RAM: 2518.02 MB
Percentage of memory in use: 69%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 8D7289FC)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job => C:\Program Files\Sense\Sense-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job => C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job => C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job => C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job => C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job => C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job => C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job => C:\Program Files\Sense\Sense-novainstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job => C:\Program Files\Sense\Sense-nova.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Health-Check-deep.job => C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\healthcheck.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\ProgramData\TEMP:56E2E879

==================== Security Center ==================

AV: AVG Internet Security 2014 (Disabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security 2014 (Disabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2014 (Disabled) {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Lenovo\Desktop" je 18 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119544
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: do počítače se mi nainstalovaly pochybné programy

#2 Příspěvek od Rudy »

Zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: E - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {4c16a250-3952-11e3-8048-001c259d602a} - D:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {4c16a30f-3952-11e3-8048-001c259d602a} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {5553bc57-07fe-11e4-a33c-00234df621aa} - E:\Windows\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {a5300530-adaa-11e3-a9dd-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {aecfbf8c-fc34-11e3-a8d8-00234df621aa} - E:\laucher.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {bf47cb32-b4bb-11e3-bdc7-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {de1e54b0-4390-11e3-9334-00234df621aa} - E:\AutoRun.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {de1e54b9-4390-11e3-9334-00234df621aa} - F:\AutoRun.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {f6775ab0-ab4c-11e3-99c0-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=17087
BHO: Sense -> {11111111-1111-1111-1111-110411821192} -> C:\Program Files\Sense\Sense-bho.dll No File
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
C:\Program Files\Sense
C:\ProgramData\ShopperPro
C:\Program Files\Skype\Toolbars
Winsock: Catalog9 01 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 02 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 03 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 04 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 16 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
FF Plugin: @microsoft.com/GENUINE - disabled No File
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
CHR HKLM\...\Chrome\Extension: [ojhagnahfpegocdhlopgljpaafeogmcc] - C:\Program Files\ShopperPro\ShopperPro.crx [2014-04-11]
S3 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [25600 2014-07-16] () [File not signed]
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
C:\Program Files\YouTube Accelerator
C:\ProgramData\YTAHelper
C:\Program Files\Common Files\ShopperPro
C:\ProgramData\ShopperPro
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Users\Public\Documents\GOOBZO
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Program Files\Common Files\ShopperPro
C:\Users\Lenovo\dht.dat
C:\Users\Lenovo\resume.dat
C:\Users\Lenovo\rss.dat
C:\Users\Lenovo\settings.dat
C:\Users\Lenovo\utorrent.exe
C:\Users\Lenovo\AppData\Local\Temp
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
End
Uložte na plochu jako fixlist.txt. Pak znovu spusťte FRST a klikněte na >Fix<. Zkopírujte sem pak log, který se na závěr vytvoří.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#3 Příspěvek od zorttan »

tak jsem to udělal ale počítač se mi teď odmítá připojit k internetu a po diagnostice sítě mi to napsalo sys. win. se nepodařilo automaticky zjistit nastavení proxy serveru sítě :( vůbec nevím co s tím tuto zprávu píšu z jiného pc

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#4 Příspěvek od zorttan »

Report Fixlog:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:20-07-2014
Ran by Lenovo at 2014-07-20 13:06:42 Run:1
Running from C:\Users\Lenovo\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: E - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {4c16a250-3952-11e3-8048-001c259d602a} - D:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {4c16a30f-3952-11e3-8048-001c259d602a} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {5553bc57-07fe-11e4-a33c-00234df621aa} - E:\Windows\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {a5300530-adaa-11e3-a9dd-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {aecfbf8c-fc34-11e3-a8d8-00234df621aa} - E:\laucher.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {bf47cb32-b4bb-11e3-bdc7-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {de1e54b0-4390-11e3-9334-00234df621aa} - E:\AutoRun.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {de1e54b9-4390-11e3-9334-00234df621aa} - F:\AutoRun.exe
HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\...\MountPoints2: {f6775ab0-ab4c-11e3-99c0-00234df621aa} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=17087
BHO: Sense -> {11111111-1111-1111-1111-110411821192} -> C:\Program Files\Sense\Sense-bho.dll No File
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
C:\Program Files\Sense
C:\ProgramData\ShopperPro
C:\Program Files\Skype\Toolbars
Winsock: Catalog9 01 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 02 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 03 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 04 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 16 C:\Program Files\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
FF Plugin: @microsoft.com/GENUINE - disabled No File
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
CHR HKLM\...\Chrome\Extension: [ojhagnahfpegocdhlopgljpaafeogmcc] - C:\Program Files\ShopperPro\ShopperPro.crx [2014-04-11]
S3 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [25600 2014-07-16] () [File not signed]
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
C:\Program Files\YouTube Accelerator
C:\ProgramData\YTAHelper
C:\Program Files\Common Files\ShopperPro
C:\ProgramData\ShopperPro
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Users\Public\Documents\GOOBZO
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Program Files\Common Files\ShopperPro
C:\Users\Lenovo\dht.dat
C:\Users\Lenovo\resume.dat
C:\Users\Lenovo\rss.dat
C:\Users\Lenovo\settings.dat
C:\Users\Lenovo\utorrent.exe
C:\Users\Lenovo\AppData\Local\Temp
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
End
*****************

'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-3104639505-3165122878-2294490742-1000'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c16a250-3952-11e3-8048-001c259d602a}' => Key deleted successfully.
'HKCR\CLSID\{4c16a250-3952-11e3-8048-001c259d602a}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c16a30f-3952-11e3-8048-001c259d602a}' => Key deleted successfully.
'HKCR\CLSID\{4c16a30f-3952-11e3-8048-001c259d602a}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5553bc57-07fe-11e4-a33c-00234df621aa} - E:\Windows\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}'=> Key not found.
'HKCR\CLSID\{5553bc57-07fe-11e4-a33c-00234df621aa} - E:\Windows\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A01B06 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a5300530-adaa-11e3-a9dd-00234df621aa}' => Key deleted successfully.
'HKCR\CLSID\{a5300530-adaa-11e3-a9dd-00234df621aa}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aecfbf8c-fc34-11e3-a8d8-00234df621aa}' => Key deleted successfully.
'HKCR\CLSID\{aecfbf8c-fc34-11e3-a8d8-00234df621aa}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf47cb32-b4bb-11e3-bdc7-00234df621aa}' => Key deleted successfully.
'HKCR\CLSID\{bf47cb32-b4bb-11e3-bdc7-00234df621aa}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{de1e54b0-4390-11e3-9334-00234df621aa}' => Key deleted successfully.
'HKCR\CLSID\{de1e54b0-4390-11e3-9334-00234df621aa}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{de1e54b9-4390-11e3-9334-00234df621aa}' => Key deleted successfully.
'HKCR\CLSID\{de1e54b9-4390-11e3-9334-00234df621aa}'=> Key not found.
'HKU\S-1-5-21-3104639505-3165122878-2294490742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f6775ab0-ab4c-11e3-99c0-00234df621aa}' => Key deleted successfully.
'HKCR\CLSID\{f6775ab0-ab4c-11e3-99c0-00234df621aa}'=> Key not found.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}' => Key deleted successfully.
'HKCR\CLSID\{11111111-1111-1111-1111-110411821192}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}' => Key deleted successfully.
'HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}' => Key deleted successfully.
'HKCR\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}' => Key deleted successfully.
"C:\Program Files\Sense" => File/Directory not found.
C:\ProgramData\ShopperPro => Moved successfully.
C:\Program Files\Skype\Toolbars => Moved successfully.
'HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001' => Key deleted successfully.
'HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002' => Key deleted successfully.
'HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003' => Key deleted successfully.
'HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004' => Key deleted successfully.
'HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016' => Key deleted successfully.
'HKLM\Software\MozillaPlugins\FF Plugin: @microsoft.com/GENUINE - disabled No File'=> Key not found.
FF Plugin: @microsoft.com/GENUINE - disabled No File not found.
'HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl' => Key deleted successfully.
"C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx" => File/Directory not found.
'HKLM\SOFTWARE\Google\Chrome\Extensions\ojhagnahfpegocdhlopgljpaafeogmcc' => Key deleted successfully.
"C:\Program Files\ShopperPro\ShopperPro.crx" => File/Directory not found.
c2cautoupdatesvc => Service deleted successfully.
c2cpnrsvc => Service deleted successfully.
SPBIUpdd => Unable to stop service
SPBIUpdd => Service deleted successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job => Moved successfully.
C:\Windows\Tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully.
C:\Program Files\YouTube Accelerator => Moved successfully.
C:\ProgramData\YTAHelper => Moved successfully.
C:\Program Files\Common Files\ShopperPro => Moved successfully.
"C:\ProgramData\ShopperPro" => File/Directory not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Users\Public\Documents\GOOBZO => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
"C:\Program Files\Common Files\ShopperPro" => File/Directory not found.
C:\Users\Lenovo\dht.dat => Moved successfully.
C:\Users\Lenovo\resume.dat => Moved successfully.
C:\Users\Lenovo\rss.dat => Moved successfully.
C:\Users\Lenovo\settings.dat => Moved successfully.
C:\Users\Lenovo\utorrent.exe => Moved successfully.

"C:\Users\Lenovo\AppData\Local\Temp" directory move:

C:\Users\Lenovo\AppData\Local\Temp\2014-7-19_20-44-18-249.xml => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\31683B8D-A5CC-4537-8DB4-1730123AD0BC.Diagnose.0.etl => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\About YouTube Accelerator.url => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\appshat_generic.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\autoexec.bat.bk => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\avg-824cc94f-c94e-4570-9f6e-501871464d75.tmp.html => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\avginfo.id => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AvgRep.xml => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\c8bfb247f1 => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\cabex.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\catalog0 => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\DseShExt-x86.dll => Moved successfully.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\etilqs_chNKzdHGB30fjDf" => Scheduled to move on reboot.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\etilqs_JN51wJfQuUt2tJm" => Scheduled to move on reboot.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\FXSAPIDebugLogFile.txt" => Scheduled to move on reboot.
C:\Users\Lenovo\AppData\Local\Temp\hosts.bk => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\info_log.txt => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Lang_cs-CZ.msi => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\log3 => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LuUpdater.log => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LWSDebugOut.txt => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\MSI65f9c.LOG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\MSI77bc4.LOG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\MSIf0905.LOG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\PartnerInstaller_smtyc.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SDShelEx-win32.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\setup.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SHSetup.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\system.ini.bk => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TemplateHtml.html => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TUMB09D.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TUMB224.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TUMC111.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TUMCBAC.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TUME331.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\TUME489.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\tuneupmsi.7z => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\unelevate.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\win.ini.bk => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\~7FED.bat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\~7FED.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\~98F7.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\~C5D0.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\~D1A5.tmp => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\~nsu.tmp\Au_.exe => Moved successfully.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-54LBuk1ezgfcjiHGYdo6I3HG" => Scheduled to move on reboot.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-eGAhlkLiPMogl7FrSDMyIXBR" => Scheduled to move on reboot.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-gcmVXRNPONmS4GftN9sjvNZl" => Scheduled to move on reboot.
Could not move "C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-QfkNNbAYTtmvDhzHExxnLtmS" => Scheduled to move on reboot.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\AniGIF.ocx => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\blank.html => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\Cancel.gif => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\comtest.gif => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\engine.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\helper.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\ipc.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\LangPackU.cab => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\lspinst.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\lspinst2.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\OK.gif => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\progbar.gif => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\Res.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\SA.CAB => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\sporder.Dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\testlsp.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\unelevate.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\updater.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\varemove_page1.mht => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\varemove_page2.mht => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\xmldb.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\YouTubeAccelerator.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\YouTubeAcceleratorService.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\YTAHelper.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\YTAHUninstall.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\ytalsp.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\ytauninstall.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\SAINST\YTAuninstall.mht => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VADEU.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAENG.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAESM.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAFAR.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAFIL.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAFRA.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAIDN.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAITA.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAJPN.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VANLD.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAPOL.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAPTB.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VAROM.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VASRB.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\LocalesU\VATRK.LNG => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Install_4501\iwebar.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Install_21735\sense.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Install_14968\shopperpro.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Install_14968\yta.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\GoogleCrashHandler.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\GoogleUpdate.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\GoogleUpdateBroker.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\GoogleUpdateHelper.msi => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\GoogleUpdateOnDemand.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\goopdate.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\goopdateres_en.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\npGoogleUpdate4.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\psmachine.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.472053\psuser.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\GoogleCrashHandler.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\GoogleUpdate.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\GoogleUpdateBroker.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\GoogleUpdateHelper.msi => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\GoogleUpdateOnDemand.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\goopdate.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\goopdateres_en.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\npGoogleUpdate4.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\psmachine.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.426134\psuser.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\GoogleCrashHandler.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\GoogleUpdate.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\GoogleUpdateBroker.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\GoogleUpdateHelper.msi => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\GoogleUpdateOnDemand.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\goopdate.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\goopdateres_en.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\npGoogleUpdate4.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\psmachine.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\comh.258734\psuser.dll => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\AVG_ResetAccess.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\utils\reset_acess.bat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\utils\SetACL32.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\utils\SetACL64.exe => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\accept_cz_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\accept_cz_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\accept_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\accept_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\AVG_default.ico => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\AVG_ResetAccess.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\cancel_cz_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\cancel_cz_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\cancel_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\cancel_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\continue_cz_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\continue_cz_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\continue_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\continue_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\decline_cz_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\decline_cz_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\decline_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\decline_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\end.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\end_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\end_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\min.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\min_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\min_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\no_cz_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\no_cz_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\no_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\no_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\ok_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\ok_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\yes_cz_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\yes_cz_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\yes_h.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\pics\yes_n.jpg => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\eula\license_cz.htm => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\AVG_ResetAccess\eula\license_us.htm => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\installer\boot.dat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\installer\installer-config.dat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\installer\installer.dat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\installer\new-screen.dat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\installer\sandbox-boot.dat => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\images\loader.gif => Moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\125a6a81\images\progressbar.gif => Moved successfully.
Could not move "C:\Users\Lenovo\AppData\Local\Temp" directory. => Scheduled to move on reboot.

C:\ProgramData\TEMP => ":56E2E879" ADS removed successfully.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-07-20 13:14:13)<=

C:\Users\Lenovo\AppData\Local\Temp\etilqs_chNKzdHGB30fjDf => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\etilqs_JN51wJfQuUt2tJm => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\FXSAPIDebugLogFile.txt => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-54LBuk1ezgfcjiHGYdo6I3HG => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-eGAhlkLiPMogl7FrSDMyIXBR => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-gcmVXRNPONmS4GftN9sjvNZl => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp\Skype\DbTemp\temp-QfkNNbAYTtmvDhzHExxnLtmS => Is moved successfully.
C:\Users\Lenovo\AppData\Local\Temp => Moved successfully.

==== End of Fixlog ====

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#5 Příspěvek od zorttan »

musel jsem použít obnovení systému nechtělo mi to vůbec pracovat :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119544
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: do počítače se mi nainstalovaly pochybné programy

#6 Příspěvek od Rudy »

On tam byl mezi jiným rootkit, mohlo to způsobit jeho odstranění. Jak to vypadá nyní.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#7 Příspěvek od zorttan »

po tom co jsem udělal obnovu systému to zatím pracuje ale je to porad zabržděné a ty programy tam jsou porad jak mam tedy postupovat dál ? mam tedy udělat znova ten FIX podle toho jak jste mi to poslal poprvé ?

omlouvám se že píšu s prodlevami ale jsme v práci

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119544
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: do počítače se mi nainstalovaly pochybné programy

#8 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#9 Příspěvek od zorttan »

RSIT:



Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2014-07-20 18:31:07
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 78 GB (51%) free of 153 GB
Total RAM: 2518 MB (28% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:31:55, on 20.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\RotateImage\RCIMGDIR.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\AVG\AVG2014\avgui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Lenovo\Desktop\RSIT.exe
C:\Program Files\trend micro\Lenovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=17087
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: CrossriderApp0048292 - {11111111-1111-1111-1111-110411821192} - (no file)
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [RotateImage] C:\Program Files\RotateImage\RCIMGDIR.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [picon] "C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe"
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: ql-printer.lnk = C:\Program Files\tisknulevne\ql-printer\QL-Printer.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{013CD172-B340-4B4F-A38F-EED50107BF7E}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{B0DD6A44-2750-4DC0-B393-BBC189367765}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B57B3B-D24E-4A12-BD7C-B212454CCB39}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CS1\Services\Tcpip\..\{013CD172-B340-4B4F-A38F-EED50107BF7E}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CS2\Services\Tcpip\..\{013CD172-B340-4B4F-A38F-EED50107BF7E}: NameServer = 217.77.165.81 217.77.161.131
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Lenovo PM Service (IBMPMSVC) - Lenovo. - C:\Windows\system32\ibmpmsvc.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Power Manager Service (Power Manager DBC Service) - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe

--
End of file - 8811 bytes

======Scheduled tasks folder======

C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job - C:\Program Files\Sense\Sense-codedownloader.exe /KAgOeO /GhMcgT=task /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /UfsKgx=1.34.7.1 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /AhPGcayf=http://js.genstatsnet.com /INsFsII=ch /xzZla='Sense' /CuesV=http://js.clientdemocloud.com /JTyUet /TGNMdcyOR='{"asw":[1, 1, 0]}' /zYPeaB='http://update.genstatsnet.com/ie_code_a ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-11.exe /QarKDhFPz=X+PjJ+sI4p/tWJVb2P9gH7HaKIv2v7DrFz61D0w+w6LCURprFSpFquxiaBaoJwByhWIFrbMmPVjCAgrFntH8Mwy2V+zq6/eVHDSafEoL/tXw6sgDM9GqQRJHWRsQfNGA3wzZMZkzSM4YuiQ42Uuy4xnXdjd7hjIiq0gfGEPPdCF9g83ECt6Jm+rwODb2TgAKruxEu7RmnqJ3yXRsh+kIscL8QVDCqClRunu96o8unpU350qYNVsQSqCPJH3kOxv+R+HoJ7LhBkFg+LkgQC5hXNcDO2spVi77XhzFQg1NYkH7VCQGLu1MKOej5QRWYNZdIDFUoZ1fdyEeS4x4Mz5rzRuJA640bpldtPuPiRPPBtxmGHyQZtuaoqRCE8Mey+YPcsA0ZcU0ZMgUWi7Rn4xP4hUUh+bqSQb10wldCJ8PEWE3gPusexDHegN2ywKBXzB+ESC9XYpogByI3qCE33QXZvlYRbLOUvT5WVlQLK2e+9w/OdnWxuzDOkrrCmd7I5OiG4DDOHa6tSbjjTuOCIZ5ikiR1C+ekbfKUrE3tQOROplgi5SIodbEV0E9WzraWeeTSKV+V2mVt06PqHHkEB8OvYajL3y0RnMI39ttxngpbjp1bk0PLXEJoC+Ey9DzHMgnXz3UYl2qWezxt4sVQ1NxyYlb8FI7nvOWeXOJjwtCULoH6fvFWtb6hI1nyEO9+HtHQeeWz7Rh2jPEeow5MwrKo0QqnpELrU5R4uMe9fFfo4Z+ovrfVzU2cNRo5up9PJjkBcaP6f/0M9o3KuH9aORhGb7IcUrONvr15pSfs0X9pvb5DUkapaQG0NELS7ahPUkbhFoKFnzQMsnBlftC092enTyipg0qGb4sQUbO5R4G4j2uorfDt2AtMUmlLSueBSMB3ehNYsBq/tIgbm2OSphKdFF42fn9rbUISV59QXOrqorqGIb+af5z4+KYD+6rPyPyO17XZ/U8sNAIsWpjKl8L2Oquy9q2yJTyS6XUzZL32cOEpu0e9feAFV+iBzz58kyIqgmc14b7smTJSDM95Y+7qMb16A1X1BzxraT6z/hTDLEIccJNZjcnsGBBITGTD46It2UNRvBkyQsbiVvwEfcz0utJb5GLBX9X2EkGFcEj80u1cgJqV2badOVuGtTBVA9mQRjbKqsK1cVTJJy9fz/4rgko5+AHD4f/Mv6k2wS7H7iT5HuN8t5o2kp+r7lOc5zUzG3WvOQg+JRL6+BftZdG3ol1fPKjXrwocxF+q8ftpYkKy+wLnpgFoACytoNEzhf8RRXK9muKK+euMzrftSOmVBxxVx2XVuRBVd5T8KoGrOEoyFNCLBzsGRGpove6+yHSqeMyOQ4iirO+9zp7ZwSq/sd6y8O93n8pBIbD9U5q+Ase0pxLc+JUBsi5WfRBj/Z6rySTrng6qYxpn1mLRbiUeyeeVFSHmpx2YEnbwK9x+bm+4tT32gB9PSziyx9J1g3Mh+9l0beq4Ndx/hFs57kMqrUmfdzV2Ow6Y+4RjEliPkLUqzGZJeMey4auYcqWoyNoJKiqVI9PBw6mtGMNvBhi2i2mDmqdiTlaBgFDY8HBRLIRsg9W0sGO2uodO7WITZGIvehnDl2Abbc6hEMdPpq9JYdBB5FyVthfKExvVy9EOFmNpCZbtJd73NiS7pFJQPThSFEy0PhsmYtl9bMq8nduMds6nc2JyI6MFfyBY+NZOSxYxljpV003wX6NNyN8awbcxCTFJNFPYbsrGQh9g4dePGnK4r//ncbgQ8o5p6kFqCJ1mA3BpZIIhjI7Xe9/9IiUq6lpMGLvFBzU3zJo2WCDDlU6Jvf6V7ezSoHeQRNPIbjzxoDb3z9jDjW0tiSK1qXW5/BmdjyuPG5vo/grmKWsiA==
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-2.exe /jspKGKwKB /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /JwbBPdbM=11111111-1111-1111-1111-110411821192 /INsFsII=ch /JTyUet /zYPeaB='http://update.genstatsnet.com/ie_enable ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-3.exe /QarKDhFPz=lS3+17Yn1AX79iibVqsUbg0GBIecNsvd0niuICz+zonSxEczbyxEwRD3TkbXf1Jyi9By1XQIoR2jqKk83BPa8bQmobwUhr+sXhJwdkhCozSC6RrzZUT9hmlRdKVKllHn64AgkzdNUraGjUtJIk24BMDyDZYqBjdk+9+a6hJaWlYrobeXChBKyFP4SIMjAwu6V3gVnfApsfioj3oSNxlhMGCOV4jUJtuCNlREteT0VMWeh9Qy62+ER/REjsRk5uCiEJ1Pi8v71jpZ68fQTVke8ZqcrZHg6FPpF71dxdfWAhPtOdP3ryfWhO3R4XMIT29oRrSrXPL4PLDSFjF/WguIuUrYogFAyEEXnnMrV/gpU3nf4sDd6JBnJt5iqLUrR4DeZmUKoDFGn3BXM1e79gHNrvSmcctqOeZ1O7oC7gceiwb+6nG359Ky8WENTY6Pd1qBBgz8vH+AotjhTUlkxUVNL6KZ45OlrOoZIptryHvuumtIUWynKQ208EhCY9GgkcdaIu2881IaiD0GEnYu56Lii+SHplgFHvyDjGd+Kea1N1MWDxcuVL9DDWDZ+xlqIvI1aW9ehjjhdzCof6a4NALSSDISFW0uzLC3jzou/nH6h3UqMnfQMyi5B8N7WCStSJ+T86aAd7i3PJ4m1qLSlKqfO849FQKyJL15X1W34OJ2/33H8FCjrBFi/hOZo55dke8S6pgToEdKCsEHff09Bz3t7guwRn0wPTlZn9ZobRblacQGkzvN9yuwF/8sWQcPr/oEJzytVNl3ZHrZPgGiAyGSk534DV8+4LXEq+OH1c2d9p6RwLIcfeG54sxUGUfiaWPHsHvYVvVV3dfm6hIufdRp3JzaOVO4j+vDVRfukD1jivhgmLIpQpe/I1AMZtk0Gewf7SEaIvGWNKXEiZ9XHY5RVm5GJIL0OJvwy0JVE7kYbqwfF4hFlqxNcWRohMTftRTVAsY3xMapbzc6LWsEtqqxV9V3UaurBuENO1EhigjpYiQeIJ0LvR8Y9msmv+IfZDYkQTJJoEmXaLgaBBNe3Fh68RMdZQYv9npVDK3Rxq+IcKvTRUlHFt6CTtrUXdlhHQoNK5h3kjUIm4eqGpcJ+iQe08vdPo61tHDE14IXozt3+RIpsk2YGht3kA7ixlRir+LoVnDo7h6Z5IZCHulIXE6nB1RwNnzQnI7jWpHJfdFlu9I=
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-4.exe /cCZMfeSA /EULsgStB='Sense' /RanEoJ='C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965.xpi' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /UfsKgx=1.34.7.1 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /EiEqtOy=300 /pwecmz=143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com /QLZumaMwy=0.95 /zZXXloF=a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292 /zorOFLDxT=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /48292.rdf /aAiVVgDmZ='Sense' /qPdhclo='.' /eVbrN='Object Browser' /INsFsII=ch /TGNMdcyOR='{"asw":[1, 1, 0]}' /JTyUet /cSPRk /lDxORFfy /zYPeaB='http://update.genstatsnet.com/ff_agent_ ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-5.exe /mVplONyK /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /MZHYN=http://ipgeoapi.com/ /oTFDipXNf=http://update.genstatsnet.com /qZJmRCsNG=2 /KMXAB=http://logs.genstatsnet.com /zYPeaB='http://update.genstatsnet.com/updater_a ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-5.exe /mVplONyK /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /MZHYN=http://ipgeoapi.com/ /oTFDipXNf=http://update.genstatsnet.com /qZJmRCsNG=2 /KMXAB=http://logs.genstatsnet.com /zYPeaB='http://update.genstatsnet.com/updater_a ... pdate.json' /hBjbnpVl /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job - C:\Program Files\Sense\Sense-novainstaller.exe /ZTOZUA /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /UfsKgx=1.34.7.1 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /AhPGcayf=http://js.genstatsnet.com /INsFsII=ch /tehGl /xzZla=Sense /EEeUwdO='nova' /CuesV=http://js.clientdemocloud.com /TGNMdcyOR='{"asw":[1, 1, 0]}' /GhMcgT=task /zYPeaB='http://update.genstatsnet.com/novacode/ ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job - C:\Program Files\Sense\Sense-nova.exe /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /UfsKgx=1.34.7.1 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /AhPGcayf=http://js.genstatsnet.com /INsFsII=ch /tehGl /xzZla=Sense /EEeUwdO='nova' /CuesV=http://js.clientdemocloud.com /TGNMdcyOR='{"asw":[1, 1, 0]}' /zYPeaB='http://update.genstatsnet.com/novarun/{ ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Health-Check-deep.job - C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\healthcheck.exe -deepscan

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro.dll [2014-07-16 418664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper.dll [2014-06-15 434024]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PWMTRV"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor []
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"RotateImage"=C:\Program Files\RotateImage\RCIMGDIR.exe [2008-10-30 31744]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-10-13 138008]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-10-13 171288]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-10-13 172824]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-05-04 98304]
"picon"=C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe [2010-02-04 111640]
"MobileBroadband"=C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2012-03-20 69632]
"LWS"=C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2012-09-13 204136]
"AVG_UI"=C:\Program Files\AVG\AVG2014\avgui.exe [2014-06-17 5179408]

C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
ql-printer.lnk - C:\Program Files\tisknulevne\ql-printer\QL-Printer.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-10-13 228864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mobilebroadband.exe]
"Debugger=""C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe]
"Debugger=""C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\teamviewer.exe]
"Debugger=""C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-20 18:31:09 ----D---- C:\Program Files\trend micro
2014-07-20 18:31:07 ----D---- C:\rsit
2014-07-20 11:30:17 ----D---- C:\FRST
2014-07-20 10:23:31 ----D---- C:\Intel
2014-07-19 17:20:42 ----D---- C:\Windows\fonts\AdvUninstal
2014-07-19 17:20:38 ----D---- C:\ProgramData\Innovative Solutions
2014-07-19 17:20:36 ----D---- C:\Program Files\Common Files\Innovative Solutions
2014-07-19 17:20:33 ----D---- C:\Program Files\Innovative Solutions
2014-07-19 11:53:19 ----D---- C:\Program Files\globalUpdate
2014-07-19 11:52:31 ----D---- C:\ProgramData\YTAHelper
2014-07-19 11:52:13 ----AD---- C:\ProgramData\TEMP
2014-07-19 11:52:04 ----D---- C:\Program Files\YouTube Accelerator
2014-07-19 11:51:48 ----D---- C:\ProgramData\ShopperPro
2014-07-19 11:51:47 ----D---- C:\Program Files\Common Files\ShopperPro
2014-07-19 11:50:44 ----D---- C:\Users\Lenovo\AppData\Roaming\Seznam.cz
2014-07-19 11:45:51 ----A---- C:\Windows\system32\TURegOpt.exe
2014-07-19 11:45:50 ----A---- C:\Windows\system32\authuitu.dll
2014-07-16 17:16:09 ----A---- C:\Windows\system32\xvidvfw.dll
2014-07-16 17:16:09 ----A---- C:\Windows\system32\xvidcore.dll
2014-07-16 17:16:09 ----A---- C:\Windows\system32\ff_vfw.dll
2014-07-14 18:48:03 ----A---- C:\Windows\system32\MSVCP71.dll
2014-07-14 18:48:03 ----A---- C:\Windows\system32\bc520rtl.dll
2014-07-14 18:48:02 ----A---- C:\Windows\system32\MSVCR71.dll
2014-07-13 19:16:47 ----D---- C:\ProgramData\Conexant
2014-07-13 19:11:48 ----A---- C:\Windows\system32\VXBox.dll
2014-07-13 19:11:48 ----A---- C:\Windows\system32\drivers\camboxdrv.sys
2014-07-13 18:06:41 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-13 18:06:41 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-07-13 18:06:41 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-07-13 18:06:40 ----A---- C:\Windows\system32\urlmon.dll
2014-07-13 18:06:40 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-13 18:06:40 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-13 18:06:40 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-13 18:06:40 ----A---- C:\Windows\system32\iernonce.dll
2014-07-13 18:06:40 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-13 18:06:39 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-13 18:06:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-13 18:06:39 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-13 18:06:37 ----A---- C:\Windows\system32\msrating.dll
2014-07-13 18:06:37 ----A---- C:\Windows\system32\iesetup.dll
2014-07-13 18:06:37 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-13 18:06:36 ----A---- C:\Windows\system32\wininet.dll
2014-07-13 18:06:36 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-07-13 18:06:36 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-13 18:06:35 ----A---- C:\Windows\system32\ieui.dll
2014-07-13 18:06:35 ----A---- C:\Windows\system32\ieframe.dll
2014-07-13 18:06:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-07-13 18:06:34 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-13 18:06:34 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-07-13 18:06:33 ----A---- C:\Windows\system32\jscript9diag.dll
2014-07-13 18:06:33 ----A---- C:\Windows\system32\iertutil.dll
2014-07-13 18:06:32 ----A---- C:\Windows\system32\mshtml.dll
2014-07-13 18:06:31 ----A---- C:\Windows\system32\vbscript.dll
2014-07-13 18:06:31 ----A---- C:\Windows\system32\jscript9.dll
2014-07-13 18:05:51 ----A---- C:\Windows\system32\win32k.sys
2014-07-13 18:05:50 ----A---- C:\Windows\system32\osk.exe
2014-07-13 18:04:22 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-13 18:03:55 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-10 21:44:48 ----A---- C:\Windows\system32\qedit.dll
2014-07-06 11:43:43 ----A---- C:\Windows\system32\rdpcorets.dll
2014-07-06 11:43:42 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-06 11:15:16 ----D---- C:\Users\Lenovo\AppData\Roaming\Letasoft
2014-07-06 11:15:11 ----D---- C:\Program Files\Letasoft Sound Booster
2014-07-04 09:28:02 ----D---- C:\Users\Lenovo\AppData\Roaming\AVG
2014-07-04 09:23:40 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-07-04 09:23:37 ----D---- C:\ProgramData\AVG
2014-07-04 09:20:53 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2014-07-04 09:20:51 ----A---- C:\Windows\system32\rdpudd.dll
2014-07-04 09:20:51 ----A---- C:\Windows\system32\rdpendp_winip.dll
2014-07-04 09:20:29 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-04 09:20:29 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-07-04 09:20:28 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-07-04 09:20:27 ----A---- C:\Windows\system32\wksprtPS.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\wksprt.exe
2014-07-04 09:20:27 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-07-04 09:20:27 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\tsgqec.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-07-04 09:20:26 ----A---- C:\Windows\system32\mstscax.dll
2014-07-04 09:20:26 ----A---- C:\Windows\system32\mstsc.exe
2014-07-04 09:16:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-07-04 09:16:37 ----A---- C:\Windows\system32\qdvd.dll
2014-07-04 09:15:57 ----A---- C:\Windows\system32\aepdu.dll
2014-07-04 09:15:57 ----A---- C:\Windows\system32\aeinv.dll
2014-07-03 22:47:10 ----D---- C:\Program Files\LiveJasmin.com
2014-07-03 15:26:26 ----D---- C:\Users\Lenovo\AppData\Roaming\Unity
2014-07-01 22:03:50 ----D---- C:\ProgramData\LogiShrd
2014-07-01 22:03:24 ----D---- C:\Users\Lenovo\AppData\Roaming\Leadertech
2014-07-01 22:01:31 ----D---- C:\Program Files\Logitech
2014-07-01 22:01:31 ----D---- C:\Program Files\Common Files\LogiShrd
2014-07-01 18:30:18 ----D---- C:\Users\Lenovo\AppData\Roaming\Macromedia
2014-07-01 17:54:59 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-07-01 17:54:56 ----D---- C:\Windows\system32\Macromed
2014-07-01 16:49:15 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-07-01 16:49:14 ----A---- C:\Windows\system32\kerberos.dll
2014-07-01 16:49:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-07-01 16:49:12 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-01 16:49:11 ----A---- C:\Windows\system32\winlogon.exe
2014-07-01 16:49:11 ----A---- C:\Windows\system32\objsel.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\wdigest.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\KernelBase.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\dimsroam.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\schannel.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-07-01 16:49:09 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\cngprovider.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\capiprovider.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\adprovider.dll
2014-07-01 16:49:08 ----A---- C:\Windows\system32\wincredprovider.dll
2014-07-01 16:49:08 ----A---- C:\Windows\system32\sspicli.dll
2014-07-01 16:49:08 ----A---- C:\Windows\system32\lsass.exe
2014-07-01 16:49:08 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-07-01 16:49:08 ----A---- C:\Windows\system32\credssp.dll
2014-07-01 16:49:07 ----A---- C:\Windows\system32\sspisrv.dll
2014-07-01 16:49:07 ----A---- C:\Windows\system32\secur32.dll
2014-07-01 16:48:26 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-07-01 16:48:26 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-07-01 16:48:24 ----A---- C:\Windows\system32\msxml6.dll
2014-07-01 16:48:23 ----A---- C:\Windows\system32\msxml3.dll
2014-07-01 16:48:22 ----A---- C:\Windows\system32\msxml6r.dll
2014-07-01 16:48:22 ----A---- C:\Windows\system32\msxml3r.dll
2014-07-01 16:45:06 ----A---- C:\Windows\system32\usp10.dll
2014-07-01 16:44:17 ----A---- C:\Windows\system32\shell32.dll
2014-07-01 15:49:36 ----D---- C:\Users\Lenovo\AppData\Roaming\Skyrim - Legendary Edition
2014-07-01 15:48:54 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-07-01 15:48:54 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-07-01 15:48:52 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-07-01 15:48:50 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-07-01 15:48:46 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-07-01 15:48:40 ----A---- C:\Windows\system32\xinput1_3.dll
2014-07-01 14:06:30 ----D---- C:\Program Files\R.G. Mechanics

======List of files/folders modified in the last 1 month======

2014-07-20 18:31:09 ----RD---- C:\Program Files
2014-07-20 18:30:35 ----D---- C:\Windows\Temp
2014-07-20 18:20:18 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2014-07-20 17:27:52 ----D---- C:\ProgramData\MFAData
2014-07-20 17:11:43 ----A---- C:\Windows\system32\log.txt
2014-07-20 17:09:43 ----D---- C:\Windows\inf
2014-07-20 17:09:26 ----D---- C:\Windows
2014-07-20 17:07:42 ----D---- C:\Windows\system32\config
2014-07-20 14:46:35 ----D---- C:\Program Files\AVG
2014-07-20 14:45:21 ----SHD---- C:\Windows\Installer
2014-07-20 14:45:11 ----SHD---- C:\System Volume Information
2014-07-20 14:31:02 ----D---- C:\Windows\system32\Tasks
2014-07-20 14:31:01 ----D---- C:\Windows\System32
2014-07-20 14:30:58 ----D---- C:\Windows\Tasks
2014-07-20 14:24:46 ----HD---- C:\ProgramData
2014-07-20 14:18:08 ----D---- C:\Windows\system32\wfp
2014-07-20 14:18:07 ----RSD---- C:\Windows\Fonts
2014-07-20 14:18:03 ----D---- C:\Windows\system32\wbem
2014-07-20 14:16:43 ----D---- C:\Windows\system32\DriverStore
2014-07-20 14:16:42 ----D---- C:\Windows\winsxs
2014-07-20 14:16:42 ----D---- C:\Windows\system32\NDF
2014-07-20 14:16:42 ----D---- C:\Windows\system32\drivers\etc
2014-07-20 14:16:42 ----D---- C:\Windows\system32\drivers
2014-07-20 14:16:42 ----D---- C:\Windows\system32\CodeIntegrity
2014-07-20 14:16:42 ----D---- C:\Windows\system32\catroot2
2014-07-20 14:16:42 ----D---- C:\Program Files\Internet Explorer
2014-07-20 14:16:39 ----D---- C:\Users\Lenovo\AppData\Roaming\tisknulevne
2014-07-20 14:16:32 ----RD---- C:\Program Files\Skype
2014-07-20 14:16:32 ----D---- C:\Program Files\Common Files\InstallShield
2014-07-20 14:16:32 ----D---- C:\Program Files\Common Files
2014-07-20 14:16:17 ----D---- C:\Windows\registration
2014-07-20 14:16:04 ----D---- C:\Windows\system32\catroot
2014-07-20 14:16:01 ----D---- C:\Windows\Microsoft.NET
2014-07-20 14:15:54 ----RSD---- C:\Windows\assembly
2014-07-20 14:15:40 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2014-07-20 14:15:07 ----D---- C:\Program Files\Vodafone
2014-07-20 13:27:35 ----D---- C:\ProgramData\Vodafone
2014-07-19 22:28:59 ----D---- C:\Windows\SoftwareDistribution
2014-07-19 20:47:42 ----D---- C:\Windows\debug
2014-07-19 20:34:32 ----D---- C:\Windows\Logs
2014-07-19 19:28:51 ----D---- C:\Users\Lenovo\AppData\Roaming\newnext.me
2014-07-19 17:18:26 ----D---- C:\Windows\system32\LogFiles
2014-07-19 16:41:04 ----SD---- C:\ProgramData\Microsoft
2014-07-19 16:05:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-19 12:06:11 ----D---- C:\Windows\Prefetch
2014-07-18 18:07:25 ----D---- C:\Windows\rescache
2014-07-14 16:10:38 ----D---- C:\Users\Lenovo\AppData\Roaming\vlc
2014-07-13 18:57:00 ----D---- C:\Program Files\AVG Secure Search
2014-07-13 18:14:29 ----D---- C:\Windows\system32\en-US
2014-07-13 18:14:29 ----D---- C:\Program Files\Windows Journal
2014-07-13 18:14:26 ----D---- C:\Windows\ehome
2014-07-13 18:12:37 ----D---- C:\Windows\system32\MRT
2014-07-13 18:07:49 ----A---- C:\Windows\system32\MRT.exe
2014-07-13 18:02:42 ----HD---- C:\Program Files\InstallShield Installation Information
2014-07-04 11:33:37 ----D---- C:\Windows\Minidump
2014-07-04 10:20:46 ----D---- C:\Windows\system32\cs-CZ
2014-07-04 10:20:46 ----D---- C:\Windows\PolicyDefinitions
2014-07-04 10:20:45 ----D---- C:\Windows\system32\drivers\en-US
2014-07-04 10:20:43 ----D---- C:\Windows\system32\drivers\UMDF
2014-07-04 09:19:13 ----SD---- C:\Windows\system32\CompatTel
2014-07-03 22:49:06 ----D---- C:\Users\Lenovo\AppData\Roaming\Adobe
2014-07-03 22:49:05 ----D---- C:\Program Files\Common Files\Adobe
2014-07-03 22:49:05 ----D---- C:\Program Files\Adobe
2014-07-01 22:03:04 ----D---- C:\Windows\twain_32
2014-07-01 21:50:13 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2014-06-17 147736]
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2014-06-17 241944]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2014-06-17 98584]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2014-06-17 27416]
R0 DozeHDD;DozeHDD; C:\Windows\System32\DRIVERS\DozeHDD.sys [2013-06-14 25416]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2014-06-17 121624]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2014-06-17 199960]
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2014-06-17 21272]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2014-06-17 188696]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2014-06-17 197400]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr32v.sys [2013-06-14 19712]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-09-07 48128]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-09-15 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2009-09-15 38400]
R3 5U875UVC;Integrated Camera; C:\Windows\system32\DRIVERS\RCUVCMNP.sys [2009-10-23 187776]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-05-05 6574080]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-05-04 229888]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2009-10-05 460800]
R3 e1yexpress;Ovladač gigabitových síťových připojení Intel(R); C:\Windows\system32\DRIVERS\e1y6032.sys [2009-07-14 214016]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-06-23 40832]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2012-03-16 73984]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2014-02-27 45880]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd32.sys [2011-10-13 9037312]
R3 LenovoRd;LenovoRd; C:\Windows\System32\Drivers\LenovoRd.sys [2009-05-11 88832]
R3 NETw5s32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 32 Bit; C:\Windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2013-05-29 38768]
R3 SPBIUpdd;ShopperPro UpdateD; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys [2014-07-16 25600]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-05-29 347888]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S2 SPDRIVER_1.37.0.199;SPDRIVER_1.37.0.199; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-05-05 6574080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2012-03-16 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2012-03-16 11136]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2012-03-16 89856]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2012-03-16 26624]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2012-03-16 193536]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-10-13 9037312]
S3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2012-09-21 310504]
S3 LVUVC;Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc.sys [2012-09-21 4261224]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 scvad_simple;SplitCam Virtual Microphone (WDM); C:\Windows\system32\drivers\SplitCamAudio.sys [2013-11-01 18944]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SPLITCAM;Splitcam, WDM Camera Stream Splitter; C:\Windows\system32\DRIVERS\splitcam.sys []
S3 splitcam_hd_driver;SplitCam Virtual Video Driver; C:\Windows\system32\DRIVERS\splitcam_hd_driver.sys [2013-12-16 36984]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 WinUsb;Ovladač WinUSB; C:\Windows\system32\drivers\WinUSB.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-05-04 176128]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [2014-06-17 289328]
R2 IBMPMSVC;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2014-02-27 56664]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2010-02-04 174616]
R2 SPBIUpd;ShopperPro Update; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2014-07-16 1812992]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2013-05-23 116216]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2012-12-04 125504]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2010-02-04 2058776]
R3 Power Manager DBC Service;Power Manager Service; C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [2013-06-14 1668904]
S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [2014-06-27 3241488]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-07-19 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-15 116648]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2012-08-24 127072]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-17 262320]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S3 DozeSvc;Lenovo Doze Mode Service; C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE [2013-06-14 280640]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-07-19 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-15 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-19 108032]
S3 PwmEWSvc;Cisco EnergyWise Enabler; C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE [2013-06-14 1664808]
S3 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-15 1343400]
S4 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
S4 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TeamViewer9;TeamViewer 9; C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
S4 VmbService;Vodafone Mobile Connect Service; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2012-03-20 8704]

-----------------EOF-----------------

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#10 Příspěvek od zorttan »

a ještě my vyběhlo tohle :



info.txt logfile of random's system information tool 1.10 2014-07-20 18:32:02

======MBR======

0x33C08ED0BC007C8EC08ED8BE007CBF0006B90002FCF3A450681C06CBFBB90400BDBE07807E00007C0B0F850E0183C510E2F1CD1888560055C6461105C6461000B441BBAA55CD135D720F81FB55AA7509F7C101007403FE46106660807E1000742666680000000066FF760868000068007C680100681000B4428A56008BF4CD139F83C4109EEB14B80102BB007C8A56008A76018A4E028A6E03CD136661731CFE4E11750C807E00800F848A00B280EB845532E48A5600CD135DEB9E813EFE7D55AA756EFF7600E88D007517FAB0D1E664E88300B0DFE660E87C00B0FFE664E87500FBB800BBCD1A6623C0753B6681FB54435041753281F90201722C666807BB00006668000200006668080000006653665366556668000000006668007C0000666168000007CD1A5A32F6EA007C0000CD18A0B707EB08A0B607EB03A0B50732E40500078BF0AC3C007409BB0700B40ECD10EBF2F4EBFD2BC9E464EB002402E0F82402C3496E76616C696420706172746974696F6E207461626C65004572726F72206C6F6164696E67206F7065726174696E672073797374656D004D697373696E67206F7065726174696E672073797374656D000000637B9AFC89728D00008020210007EFFFFF000800000020030000A3140D07EFFFFF0028030000709E12000000000000000000000000000000000000000000000000000000000000000055AA

======Uninstall list======

-->C:\Program Files\Conexant\SAII\SETUP.EXE -U -ISAII -SM=SmartAudio.EXE,1801
Adobe Flash Media Live Encoder 3.2-->MsiExec.exe /I{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}
Adobe Flash Player 14 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil32_14_0_0_145_ActiveX.exe -maintain activex
Adobe Flash Player 14 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil32_14_0_0_145_Plugin.exe -maintain plugin
Adobe Reader XI (11.0.07) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AB0000000001}
ATI Catalyst Install Manager-->msiexec /q/x{C4C8EFCE-D59D-BF96-3EBF-22E396E02B88} REBOOT=ReallySuppress
ATI Uninstaller-->C:\Program Files\ATI\CIM\Bin\Atisetup.exe -uninstall all
AVG 2014-->"C:\Program Files\AVG\AVG2014\avgmfapx.exe" /AppMode=SETUP /Uninstall
AVG 2014-->MsiExec.exe /I{B78FB576-8BB4-4799-B612-A02B74BA0DF0}
AVG 2014-->MsiExec.exe /I{C330C4F4-FD7C-4821-A210-F8058E1FB81C}
CameraHelperMsi-->MsiExec.exe /I{15634701-BACE-4449-8B25-1567DA8C9FD3}
Catalyst Control Center - Branding-->MsiExec.exe /I{2C4FD7D3-6F3A-45C2-AAAD-929B40346E3F}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Conexant 20561 SmartAudio HD-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -ITPUNHERx.INF
erLT-->MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
Google Chrome-->"C:\Program Files\Google\Chrome\Application\36.0.1985.125\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Integrated Camera Driver Installer Package Ver.1.32.500.0-->"C:\Program Files\InstallShield Installation Information\{82EB6CEA-749A-410F-8AD2-372A286BA3BE}\setup.exe" -runfromtemp -l0x0009 anything -removeonly
Intel(R) Management Engine Interface-->C:\Windows\system32\heciudlg.exe -uninstall
Intel® Active Management Technology-->C:\Windows\system32\mesoludlg.exe -uninstall
Lenovo Patch Utility-->MsiExec.exe /X{AD32F5E9-6BDD-480A-8B7B-95571D04691C}
Lenovo Power Management Driver-->RunDll32.exe tpinspm.dll,Uninstall
Lenovo System Interface Driver-->RunDll32.exe setupapi.dll,InstallHinfSection DefaultUninstall.NTx86 130 C:\Program Files\Lenovo\SMIIF\lnvsmi.inf
Letasoft Sound Booster version 1.2-->"C:\Program Files\Letasoft Sound Booster\unins000.exe"
Logitech Webcam Software-->"C:\Program Files\Common Files\LogiShrd\Installer\{D40EB009-0499-459c-A8AF-C9C110766215}\setup.exe" /lang=ENU /guid="{D40EB009-0499-459c-A8AF-C9C110766215}"
LWS Facebook-->MsiExec.exe /I{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}
LWS Gallery-->MsiExec.exe /I{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}
LWS Help_main-->MsiExec.exe /I{1651216E-E7AD-4250-92A1-FB8ED61391C9}
LWS Launcher-->MsiExec.exe /I{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}
LWS Motion Detection-->MsiExec.exe /I{71E66D3F-A009-44AB-8784-75E2819BA4BA}
LWS Pictures And Video-->MsiExec.exe /I{08610298-29AE-445B-B37D-EFBE05802967}
LWS Twitter-->MsiExec.exe /I{174A3B31-4C43-43DD-866F-73C9DB887B48}
LWS Webcam Software-->MsiExec.exe /I{8937D274-C281-42E4-8CDB-A0B2DF979189}
LWS WLM Plugin-->MsiExec.exe /I{9DAEA76B-E50F-4272-A595-0124E826553D}
LWS YouTube Plugin-->MsiExec.exe /I{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}
Microsoft .NET Framework 4.5.1 (CSY)-->MsiExec.exe /X{123F4E9B-80E6-3A84-BDD4-3CB3AC59ABF0}
Microsoft .NET Framework 4.5.1 (čeština)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\CSY\\Setup.exe /repair /x86 /lcid 1029
Microsoft .NET Framework 4.5.1-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\\Setup.exe /repair /x86
Microsoft .NET Framework 4.5.1-->MsiExec.exe /X{4903D172-DCCB-392F-93A3-34CA9D47FE3D}
Microsoft Report Viewer 2012 Runtime-->MsiExec.exe /I{421B88F8-D7C9-44CB-8B73-166D65B18DCC}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft System CLR Types for SQL Server 2012-->MsiExec.exe /I{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
On Screen Display-->rundll32.exe "C:\Program Files\Lenovo\HOTKEY\cleanup.dll",InfUninstallEx DefaultUninstall.LH C:\Program Files\Lenovo\HOTKEY\tphk_tp.inf
Photodex Presenter-->C:\Program Files\Photodex Presenter\remove.exe
Power Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.exe" -l0x9 -AddRemove
RICOH R5U8xx Media Driver ver.3.64.02-->"C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -runfromtemp -l0x0005 anything -removeonly
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\setup.exe /uninstallpatch {8086EDC0-3409-3560-B108-44FC46882443}
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\setup.exe /uninstallpatch {FED9B2BC-E6D7-3409-B4C9-99AF8AC65725}
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\v4.5.50938\setup.exe /uninstallpatch {054F96E9-E89B-3DDB-AA70-A65194B921B4}
Skype Click to Call-->MsiExec.exe /X{BB285C9F-C821-4770-8970-56C4AB52C87E}
Skype™ 6.16-->MsiExec.exe /X{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}
Skyrim - Legendary Edition-->"C:\Users\Lenovo\AppData\Roaming\Skyrim - Legendary Edition\Uninstall\unins000.exe"
TeamViewer 9-->C:\Program Files\TeamViewer\Version9\uninstall.exe
ThinkPad FullScreen Magnifier-->rundll32.exe "C:\Program Files\Lenovo\ZOOM\cleanup.dll",InfUninstall DefaultUninstall 132 C:\Program Files\Lenovo\Zoom\TpScrex.inf
ThinkPad UltraNav Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Visual Studio 2012 x86 Redistributables-->MsiExec.exe /I{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}
VLC media player 2.0.8-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Vodafone Mobile Broadband-->MsiExec.exe /I{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}
WinRAR 4.20 (32-bit)-->C:\Program Files\WinRAR\uninstall.exe

======System event log======

Computer Name: Lenovo-NTB
Event Code: 5005
Message:
Record Number: 144027
Source Name: netw5v32
Time Written: 20140615145841.856443-000
Event Type: Informace
User:

Computer Name: Lenovo-NTB
Event Code: 5005
Message:
Record Number: 144026
Source Name: netw5v32
Time Written: 20140615145841.856443-000
Event Type: Informace
User:

Computer Name: Lenovo-NTB
Event Code: 5005
Message:
Record Number: 144025
Source Name: netw5v32
Time Written: 20140615145841.856443-000
Event Type: Informace
User:

Computer Name: Lenovo-NTB
Event Code: 5005
Message:
Record Number: 144024
Source Name: netw5v32
Time Written: 20140615145841.856443-000
Event Type: Informace
User:

Computer Name: Lenovo-NTB
Event Code: 5005
Message:
Record Number: 144023
Source Name: netw5v32
Time Written: 20140615145841.856443-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247F27-08
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPDriverNotFound
Reakce: Není k dispozici
ID souboru CAB: 0

Podpis problému:
P1: x86
P2: PCI\VEN_8086&DEV_2A47&SUBSYS_20EC17AA&REV_07
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

Připojené soubory:
C:\Windows\Temp\DMI5B29.tmp.log.xml

Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_196fccb6e4aeb7e0fafda911412d388fce59a_cab_05ee5b96

Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: c40318c5-1c43-11e3-b104-ee126eaee066
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20130913071153.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20130913071042.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20130913071036.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20130913071032.322526-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247F27-08
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20130913071032.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: 37L4247F27-08
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130913071013.134492-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247F27-08$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x1c0
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130913071013.134492-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x2623c
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130913071006.754081-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130913071004.320477-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130913071004.273676-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=1706
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119544
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: do počítače se mi nainstalovaly pochybné programy

#11 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\ProgramData\ShopperPro
C:\Program Files\Skype\Toolbars
C:\ProgramData\YTAHelper
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-1.job
C:\Windows\tasks\850-b76e515bd84a965-11.job
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-7.job
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files\Common Files\ShopperPro

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]

:services
c2cautoupdatesvc
c2cpnrsvc

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#12 Příspěvek od zorttan »

tak sem to udělal,



Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2014-07-20 19:41:48
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 78 GB (51%) free of 153 GB
Total RAM: 2518 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:42:19, on 20.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\RotateImage\RCIMGDIR.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVG\AVG2014\avgui.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
C:\Users\Lenovo\Desktop\RSIT.exe
C:\Program Files\trend micro\Lenovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=17087
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [RotateImage] C:\Program Files\RotateImage\RCIMGDIR.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [picon] "C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe"
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: ql-printer.lnk = C:\Program Files\tisknulevne\ql-printer\QL-Printer.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{013CD172-B340-4B4F-A38F-EED50107BF7E}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{B0DD6A44-2750-4DC0-B393-BBC189367765}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5B57B3B-D24E-4A12-BD7C-B212454CCB39}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CS1\Services\Tcpip\..\{013CD172-B340-4B4F-A38F-EED50107BF7E}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CS2\Services\Tcpip\..\{013CD172-B340-4B4F-A38F-EED50107BF7E}: NameServer = 217.77.165.81 217.77.161.131
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Lenovo PM Service (IBMPMSVC) - Lenovo. - C:\Windows\system32\ibmpmsvc.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Power Manager Service (Power Manager DBC Service) - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: ShopperPro Update (SPBIUpd) - Unknown owner - C:\Program Files\Common Files\ShopperPro\spbiu.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe

--
End of file - 8358 bytes

======Scheduled tasks folder======

C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-11.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-11.exe /QarKDhFPz=X+PjJ+sI4p/tWJVb2P9gH7HaKIv2v7DrFz61D0w+w6LCURprFSpFquxiaBaoJwByhWIFrbMmPVjCAgrFntH8Mwy2V+zq6/eVHDSafEoL/tXw6sgDM9GqQRJHWRsQfNGA3wzZMZkzSM4YuiQ42Uuy4xnXdjd7hjIiq0gfGEPPdCF9g83ECt6Jm+rwODb2TgAKruxEu7RmnqJ3yXRsh+kIscL8QVDCqClRunu96o8unpU350qYNVsQSqCPJH3kOxv+R+HoJ7LhBkFg+LkgQC5hXNcDO2spVi77XhzFQg1NYkH7VCQGLu1MKOej5QRWYNZdIDFUoZ1fdyEeS4x4Mz5rzRuJA640bpldtPuPiRPPBtxmGHyQZtuaoqRCE8Mey+YPcsA0ZcU0ZMgUWi7Rn4xP4hUUh+bqSQb10wldCJ8PEWE3gPusexDHegN2ywKBXzB+ESC9XYpogByI3qCE33QXZvlYRbLOUvT5WVlQLK2e+9w/OdnWxuzDOkrrCmd7I5OiG4DDOHa6tSbjjTuOCIZ5ikiR1C+ekbfKUrE3tQOROplgi5SIodbEV0E9WzraWeeTSKV+V2mVt06PqHHkEB8OvYajL3y0RnMI39ttxngpbjp1bk0PLXEJoC+Ey9DzHMgnXz3UYl2qWezxt4sVQ1NxyYlb8FI7nvOWeXOJjwtCULoH6fvFWtb6hI1nyEO9+HtHQeeWz7Rh2jPEeow5MwrKo0QqnpELrU5R4uMe9fFfo4Z+ovrfVzU2cNRo5up9PJjkBcaP6f/0M9o3KuH9aORhGb7IcUrONvr15pSfs0X9pvb5DUkapaQG0NELS7ahPUkbhFoKFnzQMsnBlftC092enTyipg0qGb4sQUbO5R4G4j2uorfDt2AtMUmlLSueBSMB3ehNYsBq/tIgbm2OSphKdFF42fn9rbUISV59QXOrqorqGIb+af5z4+KYD+6rPyPyO17XZ/U8sNAIsWpjKl8L2Oquy9q2yJTyS6XUzZL32cOEpu0e9feAFV+iBzz58kyIqgmc14b7smTJSDM95Y+7qMb16A1X1BzxraT6z/hTDLEIccJNZjcnsGBBITGTD46It2UNRvBkyQsbiVvwEfcz0utJb5GLBX9X2EkGFcEj80u1cgJqV2badOVuGtTBVA9mQRjbKqsK1cVTJJy9fz/4rgko5+AHD4f/Mv6k2wS7H7iT5HuN8t5o2kp+r7lOc5zUzG3WvOQg+JRL6+BftZdG3ol1fPKjXrwocxF+q8ftpYkKy+wLnpgFoACytoNEzhf8RRXK9muKK+euMzrftSOmVBxxVx2XVuRBVd5T8KoGrOEoyFNCLBzsGRGpove6+yHSqeMyOQ4iirO+9zp7ZwSq/sd6y8O93n8pBIbD9U5q+Ase0pxLc+JUBsi5WfRBj/Z6rySTrng6qYxpn1mLRbiUeyeeVFSHmpx2YEnbwK9x+bm+4tT32gB9PSziyx9J1g3Mh+9l0beq4Ndx/hFs57kMqrUmfdzV2Ow6Y+4RjEliPkLUqzGZJeMey4auYcqWoyNoJKiqVI9PBw6mtGMNvBhi2i2mDmqdiTlaBgFDY8HBRLIRsg9W0sGO2uodO7WITZGIvehnDl2Abbc6hEMdPpq9JYdBB5FyVthfKExvVy9EOFmNpCZbtJd73NiS7pFJQPThSFEy0PhsmYtl9bMq8nduMds6nc2JyI6MFfyBY+NZOSxYxljpV003wX6NNyN8awbcxCTFJNFPYbsrGQh9g4dePGnK4r//ncbgQ8o5p6kFqCJ1mA3BpZIIhjI7Xe9/9IiUq6lpMGLvFBzU3zJo2WCDDlU6Jvf6V7ezSoHeQRNPIbjzxoDb3z9jDjW0tiSK1qXW5/BmdjyuPG5vo/grmKWsiA==
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-2.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-2.exe /jspKGKwKB /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /JwbBPdbM=11111111-1111-1111-1111-110411821192 /INsFsII=ch /JTyUet /zYPeaB='http://update.genstatsnet.com/ie_enable ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-3.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-3.exe /QarKDhFPz=lS3+17Yn1AX79iibVqsUbg0GBIecNsvd0niuICz+zonSxEczbyxEwRD3TkbXf1Jyi9By1XQIoR2jqKk83BPa8bQmobwUhr+sXhJwdkhCozSC6RrzZUT9hmlRdKVKllHn64AgkzdNUraGjUtJIk24BMDyDZYqBjdk+9+a6hJaWlYrobeXChBKyFP4SIMjAwu6V3gVnfApsfioj3oSNxlhMGCOV4jUJtuCNlREteT0VMWeh9Qy62+ER/REjsRk5uCiEJ1Pi8v71jpZ68fQTVke8ZqcrZHg6FPpF71dxdfWAhPtOdP3ryfWhO3R4XMIT29oRrSrXPL4PLDSFjF/WguIuUrYogFAyEEXnnMrV/gpU3nf4sDd6JBnJt5iqLUrR4DeZmUKoDFGn3BXM1e79gHNrvSmcctqOeZ1O7oC7gceiwb+6nG359Ky8WENTY6Pd1qBBgz8vH+AotjhTUlkxUVNL6KZ45OlrOoZIptryHvuumtIUWynKQ208EhCY9GgkcdaIu2881IaiD0GEnYu56Lii+SHplgFHvyDjGd+Kea1N1MWDxcuVL9DDWDZ+xlqIvI1aW9ehjjhdzCof6a4NALSSDISFW0uzLC3jzou/nH6h3UqMnfQMyi5B8N7WCStSJ+T86aAd7i3PJ4m1qLSlKqfO849FQKyJL15X1W34OJ2/33H8FCjrBFi/hOZo55dke8S6pgToEdKCsEHff09Bz3t7guwRn0wPTlZn9ZobRblacQGkzvN9yuwF/8sWQcPr/oEJzytVNl3ZHrZPgGiAyGSk534DV8+4LXEq+OH1c2d9p6RwLIcfeG54sxUGUfiaWPHsHvYVvVV3dfm6hIufdRp3JzaOVO4j+vDVRfukD1jivhgmLIpQpe/I1AMZtk0Gewf7SEaIvGWNKXEiZ9XHY5RVm5GJIL0OJvwy0JVE7kYbqwfF4hFlqxNcWRohMTftRTVAsY3xMapbzc6LWsEtqqxV9V3UaurBuENO1EhigjpYiQeIJ0LvR8Y9msmv+IfZDYkQTJJoEmXaLgaBBNe3Fh68RMdZQYv9npVDK3Rxq+IcKvTRUlHFt6CTtrUXdlhHQoNK5h3kjUIm4eqGpcJ+iQe08vdPo61tHDE14IXozt3+RIpsk2YGht3kA7ixlRir+LoVnDo7h6Z5IZCHulIXE6nB1RwNnzQnI7jWpHJfdFlu9I=
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-4.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-4.exe /cCZMfeSA /EULsgStB='Sense' /RanEoJ='C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965.xpi' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /UfsKgx=1.34.7.1 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /EiEqtOy=300 /pwecmz=143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com /QLZumaMwy=0.95 /zZXXloF=a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292 /zorOFLDxT=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /48292.rdf /aAiVVgDmZ='Sense' /qPdhclo='.' /eVbrN='Object Browser' /INsFsII=ch /TGNMdcyOR='{"asw":[1, 1, 0]}' /JTyUet /cSPRk /lDxORFfy /zYPeaB='http://update.genstatsnet.com/ff_agent_ ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-5.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-5.exe /mVplONyK /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /MZHYN=http://ipgeoapi.com/ /oTFDipXNf=http://update.genstatsnet.com /qZJmRCsNG=2 /KMXAB=http://logs.genstatsnet.com /zYPeaB='http://update.genstatsnet.com/updater_a ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-5_user.job - C:\Program Files\Sense\728eebb7-649d-4850-b76e-8515bd84a965-5.exe /mVplONyK /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /MZHYN=http://ipgeoapi.com/ /oTFDipXNf=http://update.genstatsnet.com /qZJmRCsNG=2 /KMXAB=http://logs.genstatsnet.com /zYPeaB='http://update.genstatsnet.com/updater_a ... pdate.json' /hBjbnpVl /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\728eebb7-649d-4850-b76e-8515bd84a965-6.job - C:\Program Files\Sense\Sense-novainstaller.exe /ZTOZUA /EULsgStB='Sense' /qZerxEp=48292 /LAGNHump='000805' /zlGDEpa='0' /HVzXtNy='eyJkYXRhIjp7ImRhdGUiOiJFN0p3c210eWNsMSwzYzZkNmNiYS02N2E4LTQzZTQtYTQ3Ni1kNmM1ODYzNWIxYTksIiwidW5xIjoiM2M2ZDZjYmEtNjdhOC00M2U0LWE0NzYtZDZjNTg2MzViMWE5In19' /ggHcsUA=4A0F9FB630F04EE8B8474D320D299781IE /aMfofmGBR=0bf9d1b88defc2e8bc5efa6e8622326a /ZYSIh=1_34_07_01 /UfsKgx=1.34.7.1 /oPfzFlAg=1405764108 /HVFDO=http://stats.genstatsnet.com /aSYWFrS=http://errors.genstatsnet.com /AhPGcayf=http://js.genstatsnet.com /INsFsII=ch /tehGl /xzZla=Sense /EEeUwdO='nova' /CuesV=http://js.clientdemocloud.com /TGNMdcyOR='{"asw":[1, 1, 0]}' /GhMcgT=task /zYPeaB='http://update.genstatsnet.com/novacode/ ... pdate.json' /GhMcgT='task' /zbHxiQt=''
C:\Windows\tasks\Health-Check-deep.job - C:\Program Files\Innovative Solutions\Advanced Uninstaller PRO\healthcheck.exe -deepscan

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PWMTRV"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor []
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"RotateImage"=C:\Program Files\RotateImage\RCIMGDIR.exe [2008-10-30 31744]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-10-13 138008]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-10-13 171288]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-10-13 172824]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-05-04 98304]
"picon"=C:\Program Files\Common Files\Intel\Privacy Icon\PIconStartup.exe [2010-02-04 111640]
"MobileBroadband"=C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2012-03-20 69632]
"LWS"=C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2012-09-13 204136]
"AVG_UI"=C:\Program Files\AVG\AVG2014\avgui.exe [2014-06-17 5179408]

C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
ql-printer.lnk - C:\Program Files\tisknulevne\ql-printer\QL-Printer.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-10-13 228864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mobilebroadband.exe]
"Debugger=""C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe]
"Debugger=""C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\teamviewer.exe]
"Debugger=""C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-20 19:38:13 ----D---- C:\_OTM
2014-07-20 18:31:09 ----D---- C:\Program Files\trend micro
2014-07-20 18:31:07 ----D---- C:\rsit
2014-07-20 11:30:17 ----D---- C:\FRST
2014-07-20 10:23:31 ----D---- C:\Intel
2014-07-19 17:20:42 ----D---- C:\Windows\fonts\AdvUninstal
2014-07-19 17:20:38 ----D---- C:\ProgramData\Innovative Solutions
2014-07-19 17:20:36 ----D---- C:\Program Files\Common Files\Innovative Solutions
2014-07-19 17:20:33 ----D---- C:\Program Files\Innovative Solutions
2014-07-19 11:53:19 ----D---- C:\Program Files\globalUpdate
2014-07-19 11:52:13 ----AD---- C:\ProgramData\TEMP
2014-07-19 11:52:04 ----D---- C:\Program Files\YouTube Accelerator
2014-07-19 11:50:44 ----D---- C:\Users\Lenovo\AppData\Roaming\Seznam.cz
2014-07-19 11:45:51 ----A---- C:\Windows\system32\TURegOpt.exe
2014-07-19 11:45:50 ----A---- C:\Windows\system32\authuitu.dll
2014-07-16 17:16:09 ----A---- C:\Windows\system32\xvidvfw.dll
2014-07-16 17:16:09 ----A---- C:\Windows\system32\xvidcore.dll
2014-07-16 17:16:09 ----A---- C:\Windows\system32\ff_vfw.dll
2014-07-14 18:48:03 ----A---- C:\Windows\system32\MSVCP71.dll
2014-07-14 18:48:03 ----A---- C:\Windows\system32\bc520rtl.dll
2014-07-14 18:48:02 ----A---- C:\Windows\system32\MSVCR71.dll
2014-07-13 19:16:47 ----D---- C:\ProgramData\Conexant
2014-07-13 19:11:48 ----A---- C:\Windows\system32\VXBox.dll
2014-07-13 19:11:48 ----A---- C:\Windows\system32\drivers\camboxdrv.sys
2014-07-13 18:06:41 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-13 18:06:41 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-07-13 18:06:41 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-07-13 18:06:40 ----A---- C:\Windows\system32\urlmon.dll
2014-07-13 18:06:40 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-13 18:06:40 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-13 18:06:40 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-13 18:06:40 ----A---- C:\Windows\system32\iernonce.dll
2014-07-13 18:06:40 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-13 18:06:39 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-13 18:06:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-13 18:06:39 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-13 18:06:37 ----A---- C:\Windows\system32\msrating.dll
2014-07-13 18:06:37 ----A---- C:\Windows\system32\iesetup.dll
2014-07-13 18:06:37 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-13 18:06:36 ----A---- C:\Windows\system32\wininet.dll
2014-07-13 18:06:36 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-07-13 18:06:36 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-13 18:06:35 ----A---- C:\Windows\system32\ieui.dll
2014-07-13 18:06:35 ----A---- C:\Windows\system32\ieframe.dll
2014-07-13 18:06:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-07-13 18:06:34 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-13 18:06:34 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-07-13 18:06:33 ----A---- C:\Windows\system32\jscript9diag.dll
2014-07-13 18:06:33 ----A---- C:\Windows\system32\iertutil.dll
2014-07-13 18:06:32 ----A---- C:\Windows\system32\mshtml.dll
2014-07-13 18:06:31 ----A---- C:\Windows\system32\vbscript.dll
2014-07-13 18:06:31 ----A---- C:\Windows\system32\jscript9.dll
2014-07-13 18:05:51 ----A---- C:\Windows\system32\win32k.sys
2014-07-13 18:05:50 ----A---- C:\Windows\system32\osk.exe
2014-07-13 18:04:22 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-13 18:03:55 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-10 21:44:48 ----A---- C:\Windows\system32\qedit.dll
2014-07-06 11:43:43 ----A---- C:\Windows\system32\rdpcorets.dll
2014-07-06 11:43:42 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-07-06 11:15:16 ----D---- C:\Users\Lenovo\AppData\Roaming\Letasoft
2014-07-06 11:15:11 ----D---- C:\Program Files\Letasoft Sound Booster
2014-07-04 09:28:02 ----D---- C:\Users\Lenovo\AppData\Roaming\AVG
2014-07-04 09:23:40 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-07-04 09:23:37 ----D---- C:\ProgramData\AVG
2014-07-04 09:20:53 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2014-07-04 09:20:51 ----A---- C:\Windows\system32\rdpudd.dll
2014-07-04 09:20:51 ----A---- C:\Windows\system32\rdpendp_winip.dll
2014-07-04 09:20:29 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-07-04 09:20:29 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-07-04 09:20:28 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-07-04 09:20:27 ----A---- C:\Windows\system32\wksprtPS.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\wksprt.exe
2014-07-04 09:20:27 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-07-04 09:20:27 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\tsgqec.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-07-04 09:20:27 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-07-04 09:20:26 ----A---- C:\Windows\system32\mstscax.dll
2014-07-04 09:20:26 ----A---- C:\Windows\system32\mstsc.exe
2014-07-04 09:16:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-07-04 09:16:37 ----A---- C:\Windows\system32\qdvd.dll
2014-07-04 09:15:57 ----A---- C:\Windows\system32\aepdu.dll
2014-07-04 09:15:57 ----A---- C:\Windows\system32\aeinv.dll
2014-07-03 22:47:10 ----D---- C:\Program Files\LiveJasmin.com
2014-07-03 15:26:26 ----D---- C:\Users\Lenovo\AppData\Roaming\Unity
2014-07-01 22:03:50 ----D---- C:\ProgramData\LogiShrd
2014-07-01 22:03:24 ----D---- C:\Users\Lenovo\AppData\Roaming\Leadertech
2014-07-01 22:01:31 ----D---- C:\Program Files\Logitech
2014-07-01 22:01:31 ----D---- C:\Program Files\Common Files\LogiShrd
2014-07-01 18:30:18 ----D---- C:\Users\Lenovo\AppData\Roaming\Macromedia
2014-07-01 17:54:59 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-07-01 17:54:56 ----D---- C:\Windows\system32\Macromed
2014-07-01 16:49:15 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-07-01 16:49:14 ----A---- C:\Windows\system32\kerberos.dll
2014-07-01 16:49:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-07-01 16:49:12 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-01 16:49:11 ----A---- C:\Windows\system32\winlogon.exe
2014-07-01 16:49:11 ----A---- C:\Windows\system32\objsel.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\wdigest.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\KernelBase.dll
2014-07-01 16:49:10 ----A---- C:\Windows\system32\dimsroam.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\schannel.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-07-01 16:49:09 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\cngprovider.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\capiprovider.dll
2014-07-01 16:49:09 ----A---- C:\Windows\system32\adprovider.dll
2014-07-01 16:49:08 ----A---- C:\Windows\system32\wincredprovider.dll
2014-07-01 16:49:08 ----A---- C:\Windows\system32\sspicli.dll
2014-07-01 16:49:08 ----A---- C:\Windows\system32\lsass.exe
2014-07-01 16:49:08 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-07-01 16:49:08 ----A---- C:\Windows\system32\credssp.dll
2014-07-01 16:49:07 ----A---- C:\Windows\system32\sspisrv.dll
2014-07-01 16:49:07 ----A---- C:\Windows\system32\secur32.dll
2014-07-01 16:48:26 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-07-01 16:48:26 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-07-01 16:48:24 ----A---- C:\Windows\system32\msxml6.dll
2014-07-01 16:48:23 ----A---- C:\Windows\system32\msxml3.dll
2014-07-01 16:48:22 ----A---- C:\Windows\system32\msxml6r.dll
2014-07-01 16:48:22 ----A---- C:\Windows\system32\msxml3r.dll
2014-07-01 16:45:06 ----A---- C:\Windows\system32\usp10.dll
2014-07-01 16:44:17 ----A---- C:\Windows\system32\shell32.dll
2014-07-01 15:49:36 ----D---- C:\Users\Lenovo\AppData\Roaming\Skyrim - Legendary Edition
2014-07-01 15:48:54 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-07-01 15:48:54 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-07-01 15:48:52 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-07-01 15:48:50 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-07-01 15:48:46 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-07-01 15:48:40 ----A---- C:\Windows\system32\xinput1_3.dll
2014-07-01 14:06:30 ----D---- C:\Program Files\R.G. Mechanics

======List of files/folders modified in the last 1 month======

2014-07-20 19:41:37 ----D---- C:\Windows\Temp
2014-07-20 19:38:56 ----D---- C:\Windows\system32\config
2014-07-20 19:38:56 ----A---- C:\Windows\system32\log.txt
2014-07-20 19:38:16 ----RD---- C:\Program Files\Skype
2014-07-20 19:38:16 ----HD---- C:\ProgramData
2014-07-20 19:38:16 ----D---- C:\Windows\Tasks
2014-07-20 19:38:16 ----D---- C:\Program Files\Common Files
2014-07-20 19:26:55 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2014-07-20 18:31:09 ----RD---- C:\Program Files
2014-07-20 17:27:52 ----D---- C:\ProgramData\MFAData
2014-07-20 17:09:43 ----D---- C:\Windows\inf
2014-07-20 17:09:26 ----D---- C:\Windows
2014-07-20 14:46:35 ----D---- C:\Program Files\AVG
2014-07-20 14:45:21 ----SHD---- C:\Windows\Installer
2014-07-20 14:45:11 ----SHD---- C:\System Volume Information
2014-07-20 14:31:02 ----D---- C:\Windows\system32\Tasks
2014-07-20 14:31:01 ----D---- C:\Windows\System32
2014-07-20 14:18:08 ----D---- C:\Windows\system32\wfp
2014-07-20 14:18:07 ----RSD---- C:\Windows\Fonts
2014-07-20 14:18:03 ----D---- C:\Windows\system32\wbem
2014-07-20 14:16:43 ----D---- C:\Windows\system32\DriverStore
2014-07-20 14:16:42 ----D---- C:\Windows\winsxs
2014-07-20 14:16:42 ----D---- C:\Windows\system32\NDF
2014-07-20 14:16:42 ----D---- C:\Windows\system32\drivers\etc
2014-07-20 14:16:42 ----D---- C:\Windows\system32\drivers
2014-07-20 14:16:42 ----D---- C:\Windows\system32\CodeIntegrity
2014-07-20 14:16:42 ----D---- C:\Windows\system32\catroot2
2014-07-20 14:16:42 ----D---- C:\Program Files\Internet Explorer
2014-07-20 14:16:39 ----D---- C:\Users\Lenovo\AppData\Roaming\tisknulevne
2014-07-20 14:16:32 ----D---- C:\Program Files\Common Files\InstallShield
2014-07-20 14:16:17 ----D---- C:\Windows\registration
2014-07-20 14:16:04 ----D---- C:\Windows\system32\catroot
2014-07-20 14:16:01 ----D---- C:\Windows\Microsoft.NET
2014-07-20 14:15:54 ----RSD---- C:\Windows\assembly
2014-07-20 14:15:40 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2014-07-20 14:15:07 ----D---- C:\Program Files\Vodafone
2014-07-20 13:27:35 ----D---- C:\ProgramData\Vodafone
2014-07-19 22:28:59 ----D---- C:\Windows\SoftwareDistribution
2014-07-19 20:47:42 ----D---- C:\Windows\debug
2014-07-19 20:34:32 ----D---- C:\Windows\Logs
2014-07-19 19:28:51 ----D---- C:\Users\Lenovo\AppData\Roaming\newnext.me
2014-07-19 17:18:26 ----D---- C:\Windows\system32\LogFiles
2014-07-19 16:41:04 ----SD---- C:\ProgramData\Microsoft
2014-07-19 16:05:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-19 12:06:11 ----D---- C:\Windows\Prefetch
2014-07-18 18:07:25 ----D---- C:\Windows\rescache
2014-07-14 16:10:38 ----D---- C:\Users\Lenovo\AppData\Roaming\vlc
2014-07-13 18:57:00 ----D---- C:\Program Files\AVG Secure Search
2014-07-13 18:14:29 ----D---- C:\Windows\system32\en-US
2014-07-13 18:14:29 ----D---- C:\Program Files\Windows Journal
2014-07-13 18:14:26 ----D---- C:\Windows\ehome
2014-07-13 18:12:37 ----D---- C:\Windows\system32\MRT
2014-07-13 18:07:49 ----A---- C:\Windows\system32\MRT.exe
2014-07-13 18:02:42 ----HD---- C:\Program Files\InstallShield Installation Information
2014-07-04 11:33:37 ----D---- C:\Windows\Minidump
2014-07-04 10:20:46 ----D---- C:\Windows\system32\cs-CZ
2014-07-04 10:20:46 ----D---- C:\Windows\PolicyDefinitions
2014-07-04 10:20:45 ----D---- C:\Windows\system32\drivers\en-US
2014-07-04 10:20:43 ----D---- C:\Windows\system32\drivers\UMDF
2014-07-04 09:19:13 ----SD---- C:\Windows\system32\CompatTel
2014-07-03 22:49:06 ----D---- C:\Users\Lenovo\AppData\Roaming\Adobe
2014-07-03 22:49:05 ----D---- C:\Program Files\Common Files\Adobe
2014-07-03 22:49:05 ----D---- C:\Program Files\Adobe
2014-07-01 22:03:04 ----D---- C:\Windows\twain_32
2014-07-01 21:50:13 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2014-06-17 147736]
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2014-06-17 241944]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2014-06-17 98584]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2014-06-17 27416]
R0 DozeHDD;DozeHDD; C:\Windows\System32\DRIVERS\DozeHDD.sys [2013-06-14 25416]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2014-06-17 121624]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2014-06-17 199960]
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2014-06-17 21272]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2014-06-17 188696]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2014-06-17 197400]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr32v.sys [2013-06-14 19712]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-09-07 48128]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-09-15 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2009-09-15 38400]
R3 5U875UVC;Integrated Camera; C:\Windows\system32\DRIVERS\RCUVCMNP.sys [2009-10-23 187776]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-05-05 6574080]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-05-04 229888]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2009-10-05 460800]
R3 e1yexpress;Ovladač gigabitových síťových připojení Intel(R); C:\Windows\system32\DRIVERS\e1y6032.sys [2009-07-14 214016]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-06-23 40832]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2012-03-16 73984]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2014-02-27 45880]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd32.sys [2011-10-13 9037312]
R3 LenovoRd;LenovoRd; C:\Windows\System32\Drivers\LenovoRd.sys [2009-05-11 88832]
R3 NETw5s32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 32 Bit; C:\Windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2013-05-29 38768]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-05-29 347888]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S2 SPDRIVER_1.37.0.199;SPDRIVER_1.37.0.199; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-05-05 6574080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2012-03-16 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2012-03-16 11136]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2012-03-16 89856]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2012-03-16 26624]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2012-03-16 193536]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-10-13 9037312]
S3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2012-09-21 310504]
S3 LVUVC;Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc.sys [2012-09-21 4261224]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 scvad_simple;SplitCam Virtual Microphone (WDM); C:\Windows\system32\drivers\SplitCamAudio.sys [2013-11-01 18944]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SPBIUpdd;ShopperPro UpdateD; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys []
S3 SPLITCAM;Splitcam, WDM Camera Stream Splitter; C:\Windows\system32\DRIVERS\splitcam.sys []
S3 splitcam_hd_driver;SplitCam Virtual Video Driver; C:\Windows\system32\DRIVERS\splitcam_hd_driver.sys [2013-12-16 36984]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 WinUsb;Ovladač WinUSB; C:\Windows\system32\drivers\WinUSB.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-05-04 176128]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [2014-06-17 289328]
R2 IBMPMSVC;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2014-02-27 56664]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2013-05-23 116216]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2012-12-04 125504]
S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [2014-06-27 3241488]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-07-19 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-15 116648]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2012-08-24 127072]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2010-02-04 174616]
S2 SPBIUpd;ShopperPro Update; C:\Program Files\Common Files\ShopperPro\spbiu.exe /service []
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2010-02-04 2058776]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-17 262320]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S3 DozeSvc;Lenovo Doze Mode Service; C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE [2013-06-14 280640]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-07-19 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-15 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-19 108032]
S3 Power Manager DBC Service;Power Manager Service; C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [2013-06-14 1668904]
S3 PwmEWSvc;Cisco EnergyWise Enabler; C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE [2013-06-14 1664808]
S3 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-15 1343400]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TeamViewer9;TeamViewer 9; C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
S4 VmbService;Vodafone Mobile Connect Service; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2012-03-20 8704]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119544
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: do počítače se mi nainstalovaly pochybné programy

#13 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#14 Příspěvek od zorttan »

No super změna ne o sto ale o tisíc procent, :D .
Ani nevím jak poděkovat, takže mockrát děkuji :) .

zorttan
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 20 črc 2014 09:49
Bydliště: Praha

Re: do počítače se mi nainstalovaly pochybné programy

#15 Příspěvek od zorttan »

I když ted sem koukal do program files a porad to tady mam :( ale počítač běží rychlejc i po restartu to nabehlo podstatně rychleji a ve správci úloh je to taky v záložce služby ale je to tam jakoby nespuštěny

Zamčeno