
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o kontrolu, predem dekuji :)
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosim o kontrolu, predem dekuji :)
Logfile of random's system information tool 1.10 (written by random/random)
Run by Erutan at 2014-08-09 16:03:46
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 48 GB (42%) free of 114 GB
Total RAM: 8189 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:03:47, on 9.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Erutan.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: µTorrent.lnk = C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8090 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
atieclxx
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {96876012-4DCE-498E-9306-2F45ACCE4F43}
WLIDSvcM.exe 1652
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"D:\Download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default
prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.google.com"
prefs.js - "keyword.URL" - "http://www.google.com/search?btnG=Google+Search&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
nppluginrichmediaplayer.dll
C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\
{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-10-06 11474024]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-09-30 825184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
"uTorrent"=C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [2014-07-02 1322832]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"NUSB3MON"=C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-20 106496]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-03-28 642656]
C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
µTorrent.lnk - C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-08-01 13:21:42 ----D---- C:\Users\Erutan\AppData\Roaming\MKKE
2014-08-01 13:21:22 ----D---- C:\ProgramData\Riot Games
2014-08-01 13:20:59 ----D---- C:\Riot Games
2014-07-31 12:59:03 ----D---- C:\ProgramData\AVG Secure Search
2014-07-31 12:59:00 ----D---- C:\Users\Erutan\AppData\Roaming\Stardock
2014-07-24 07:10:53 ----D---- C:\Program Files (x86)\Windows Phone
2014-07-24 07:10:34 ----D---- C:\ProgramData\Applications
2014-07-23 21:39:14 ----D---- C:\Users\Erutan\AppData\Roaming\Day 1 Studios
2014-07-23 21:23:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-07-23 07:58:23 ----D---- C:\Program Files (x86)\GreenTree Applications
2014-07-22 17:48:38 ----D---- C:\Program Files\Defraggler
2014-07-22 12:51:08 ----D---- C:\Windows\8AAB4176A747493AA42CB63CFADFD8E3.TMP
2014-07-20 11:15:09 ----RA---- C:\Windows\SYSWOW64\tmpD165.tmp
2014-07-20 11:15:09 ----D---- C:\Program Files (x86)\BRS
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\rapture3d_oal.dll
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\mkl_blueripple.dll
2014-07-17 21:53:49 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-07-17 21:53:23 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2014-07-17 21:53:21 ----D---- C:\Users\Erutan\AppData\Roaming\Ubisoft
2014-07-13 21:52:24 ----D---- C:\Program Files (x86)\Microsoft
======List of files/folders modified in the last 1 month======
2014-08-09 16:03:47 ----D---- C:\Windows\Temp
2014-08-09 16:03:47 ----D---- C:\Windows\Prefetch
2014-08-09 16:03:47 ----D---- C:\Program Files\trend micro
2014-08-09 16:03:36 ----D---- C:\Users\Erutan\AppData\Roaming\uTorrent
2014-08-09 16:00:31 ----D---- C:\Windows\inf
2014-08-09 16:00:31 ----D---- C:\Windows
2014-08-09 16:00:31 ----D---- C:\Users\Erutan\AppData\Roaming\DAEMON Tools Lite
2014-08-09 15:52:31 ----D---- C:\Windows\system32\config
2014-08-09 15:42:08 ----D---- C:\Program Files (x86)\SpeedFan
2014-08-09 10:02:02 ----D---- C:\Users\Erutan\AppData\Roaming\Skype
2014-08-08 22:51:47 ----D---- C:\ProgramData\Origin
2014-08-08 21:13:23 ----D---- C:\Users\Erutan\AppData\Roaming\vlc
2014-08-08 19:28:22 ----D---- C:\Program Files (x86)\Origin
2014-08-07 20:41:51 ----D---- C:\Windows\Logs
2014-08-07 18:22:00 ----SHD---- C:\Windows\Installer
2014-08-07 18:21:59 ----SHD---- C:\Config.Msi
2014-08-07 18:21:52 ----SHD---- C:\System Volume Information
2014-08-07 17:50:31 ----D---- C:\Windows\Minidump
2014-08-07 17:35:39 ----D---- C:\Program Files (x86)\The KMPlayer
2014-08-07 15:38:14 ----D---- C:\Users\Erutan\AppData\Roaming\ViberPC
2014-08-06 18:41:34 ----HD---- C:\ProgramData
2014-08-06 18:41:34 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-08-06 13:30:16 ----D---- C:\Users\Erutan\AppData\Roaming\dvdcss
2014-08-06 12:12:00 ----D---- C:\Windows\system32\catroot2
2014-08-03 18:41:52 ----D---- C:\Windows\SYSWOW64\directx
2014-08-03 15:54:00 ----D---- C:\Windows\winsxs
2014-08-02 22:39:12 ----SD---- C:\ProgramData\Microsoft
2014-08-01 13:21:00 ----D---- C:\Windows\Tasks
2014-08-01 13:20:59 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2014-08-01 07:43:18 ----RD---- C:\Program Files (x86)
2014-07-31 17:13:23 ----RSD---- C:\Windows\assembly
2014-07-31 14:09:18 ----D---- C:\Windows\System32
2014-07-31 14:09:12 ----D---- C:\Windows\SysWOW64
2014-07-31 13:00:06 ----D---- C:\Windows\Microsoft.NET
2014-07-24 07:04:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-23 10:15:28 ----D---- C:\ProgramData\Codemasters
2014-07-22 17:48:38 ----RD---- C:\Program Files
2014-07-22 13:02:47 ----D---- C:\ProgramData\Ubisoft
2014-07-20 11:44:16 ----D---- C:\Windows\SoftwareDistribution
2014-07-20 11:15:09 ----D---- C:\Program Files (x86)\OpenAL
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2014-07-20 11:15:09 ----A---- C:\Windows\system32\wrap_oal.dll
2014-07-20 11:15:09 ----A---- C:\Windows\system32\OpenAL32.dll
2014-07-20 08:57:34 ----D---- C:\Program Files (x86)\iDeerApp
2014-07-13 21:52:57 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2014-07-13 21:52:14 ----D---- C:\Temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-09-07 121432]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 RzFilter;RzFilter; C:\Windows\system32\drivers\RzFilter.sys [2013-07-31 74456]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-07-14 834544]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-03-29 11658752]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-03-29 581120]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-02-14 96768]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-08-09 25640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-10-06 2511464]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 75776]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 177152]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-13 73984]
S1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg []
S3 aiwulbvf;aiwulbvf; C:\Windows\system32\drivers\aiwulbvf.sys []
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-07-14 30528]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-05-25 253728]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-03-29 241152]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-03-28 361984]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2010-09-07 72280]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-17 76888]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-23 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-07-16 542912]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2013-07-14 607048]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
-----------------EOF-----------------
Run by Erutan at 2014-08-09 16:03:46
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 48 GB (42%) free of 114 GB
Total RAM: 8189 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:03:47, on 9.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Erutan.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: µTorrent.lnk = C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8090 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
atieclxx
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {96876012-4DCE-498E-9306-2F45ACCE4F43}
WLIDSvcM.exe 1652
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"D:\Download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default
prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.google.com"
prefs.js - "keyword.URL" - "http://www.google.com/search?btnG=Google+Search&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
nppluginrichmediaplayer.dll
C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\
{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-10-06 11474024]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-09-30 825184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
"uTorrent"=C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe [2014-07-02 1322832]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"NUSB3MON"=C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-20 106496]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-03-28 642656]
C:\Users\Erutan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
µTorrent.lnk - C:\Users\Erutan\AppData\Roaming\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-08-01 13:21:42 ----D---- C:\Users\Erutan\AppData\Roaming\MKKE
2014-08-01 13:21:22 ----D---- C:\ProgramData\Riot Games
2014-08-01 13:20:59 ----D---- C:\Riot Games
2014-07-31 12:59:03 ----D---- C:\ProgramData\AVG Secure Search
2014-07-31 12:59:00 ----D---- C:\Users\Erutan\AppData\Roaming\Stardock
2014-07-24 07:10:53 ----D---- C:\Program Files (x86)\Windows Phone
2014-07-24 07:10:34 ----D---- C:\ProgramData\Applications
2014-07-23 21:39:14 ----D---- C:\Users\Erutan\AppData\Roaming\Day 1 Studios
2014-07-23 21:23:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-07-23 07:58:23 ----D---- C:\Program Files (x86)\GreenTree Applications
2014-07-22 17:48:38 ----D---- C:\Program Files\Defraggler
2014-07-22 12:51:08 ----D---- C:\Windows\8AAB4176A747493AA42CB63CFADFD8E3.TMP
2014-07-20 11:15:09 ----RA---- C:\Windows\SYSWOW64\tmpD165.tmp
2014-07-20 11:15:09 ----D---- C:\Program Files (x86)\BRS
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\rapture3d_oal.dll
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\mkl_blueripple.dll
2014-07-17 21:53:49 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-07-17 21:53:23 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2014-07-17 21:53:21 ----D---- C:\Users\Erutan\AppData\Roaming\Ubisoft
2014-07-13 21:52:24 ----D---- C:\Program Files (x86)\Microsoft
======List of files/folders modified in the last 1 month======
2014-08-09 16:03:47 ----D---- C:\Windows\Temp
2014-08-09 16:03:47 ----D---- C:\Windows\Prefetch
2014-08-09 16:03:47 ----D---- C:\Program Files\trend micro
2014-08-09 16:03:36 ----D---- C:\Users\Erutan\AppData\Roaming\uTorrent
2014-08-09 16:00:31 ----D---- C:\Windows\inf
2014-08-09 16:00:31 ----D---- C:\Windows
2014-08-09 16:00:31 ----D---- C:\Users\Erutan\AppData\Roaming\DAEMON Tools Lite
2014-08-09 15:52:31 ----D---- C:\Windows\system32\config
2014-08-09 15:42:08 ----D---- C:\Program Files (x86)\SpeedFan
2014-08-09 10:02:02 ----D---- C:\Users\Erutan\AppData\Roaming\Skype
2014-08-08 22:51:47 ----D---- C:\ProgramData\Origin
2014-08-08 21:13:23 ----D---- C:\Users\Erutan\AppData\Roaming\vlc
2014-08-08 19:28:22 ----D---- C:\Program Files (x86)\Origin
2014-08-07 20:41:51 ----D---- C:\Windows\Logs
2014-08-07 18:22:00 ----SHD---- C:\Windows\Installer
2014-08-07 18:21:59 ----SHD---- C:\Config.Msi
2014-08-07 18:21:52 ----SHD---- C:\System Volume Information
2014-08-07 17:50:31 ----D---- C:\Windows\Minidump
2014-08-07 17:35:39 ----D---- C:\Program Files (x86)\The KMPlayer
2014-08-07 15:38:14 ----D---- C:\Users\Erutan\AppData\Roaming\ViberPC
2014-08-06 18:41:34 ----HD---- C:\ProgramData
2014-08-06 18:41:34 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-08-06 13:30:16 ----D---- C:\Users\Erutan\AppData\Roaming\dvdcss
2014-08-06 12:12:00 ----D---- C:\Windows\system32\catroot2
2014-08-03 18:41:52 ----D---- C:\Windows\SYSWOW64\directx
2014-08-03 15:54:00 ----D---- C:\Windows\winsxs
2014-08-02 22:39:12 ----SD---- C:\ProgramData\Microsoft
2014-08-01 13:21:00 ----D---- C:\Windows\Tasks
2014-08-01 13:20:59 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2014-08-01 07:43:18 ----RD---- C:\Program Files (x86)
2014-07-31 17:13:23 ----RSD---- C:\Windows\assembly
2014-07-31 14:09:18 ----D---- C:\Windows\System32
2014-07-31 14:09:12 ----D---- C:\Windows\SysWOW64
2014-07-31 13:00:06 ----D---- C:\Windows\Microsoft.NET
2014-07-24 07:04:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-23 10:15:28 ----D---- C:\ProgramData\Codemasters
2014-07-22 17:48:38 ----RD---- C:\Program Files
2014-07-22 13:02:47 ----D---- C:\ProgramData\Ubisoft
2014-07-20 11:44:16 ----D---- C:\Windows\SoftwareDistribution
2014-07-20 11:15:09 ----D---- C:\Program Files (x86)\OpenAL
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2014-07-20 11:15:09 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2014-07-20 11:15:09 ----A---- C:\Windows\system32\wrap_oal.dll
2014-07-20 11:15:09 ----A---- C:\Windows\system32\OpenAL32.dll
2014-07-20 08:57:34 ----D---- C:\Program Files (x86)\iDeerApp
2014-07-13 21:52:57 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2014-07-13 21:52:14 ----D---- C:\Temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-09-07 121432]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 RzFilter;RzFilter; C:\Windows\system32\drivers\RzFilter.sys [2013-07-31 74456]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-07-14 834544]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-03-29 11658752]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-03-29 581120]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-02-14 96768]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-08-09 25640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-10-06 2511464]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2009-11-20 75776]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2009-11-20 177152]
R3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-13 73984]
S1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg []
S3 aiwulbvf;aiwulbvf; C:\Windows\system32\drivers\aiwulbvf.sys []
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-07-14 30528]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-05-25 253728]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-03-29 241152]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-03-28 361984]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2010-09-07 72280]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-17 76888]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-23 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-07-16 542912]
S3 TuneUp.Defrag;@C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe [2013-07-14 607048]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
-----------------EOF-----------------
Re: Prosim o kontrolu, predem dekuji :)
Zdravim 
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.


Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu, predem dekuji :)
# AdwCleaner v3.304 - Report created 10/08/2014 at 11:15:05
# Updated 08/08/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Erutan - ERUTAN-PC
# Running from : C:\Users\Erutan\Desktop\adwcleaner_3.304.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Service Deleted : AppleChargerSrv
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\systemk
Folder Deleted : C:\Program Files (x86)\GreenTree Applications
File Deleted : C:\Windows\System32\AppleChargerSrv.exe
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKCU\Software\df6f1d15fc6b1522ebf209e10045b79f
Key Deleted : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\SystemK
Key Deleted : HKCU\Software\AppDataLow\Software\Search Protection
Key Deleted : HKLM\Software\SystemK
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\prefs.js ]
*************************
AdwCleaner[R1].txt - [2580 octets] - [10/08/2014 11:14:17]
AdwCleaner[S1].txt - [2213 octets] - [10/08/2014 11:15:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2273 octets] ##########
# Updated 08/08/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Erutan - ERUTAN-PC
# Running from : C:\Users\Erutan\Desktop\adwcleaner_3.304.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Service Deleted : AppleChargerSrv
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\systemk
Folder Deleted : C:\Program Files (x86)\GreenTree Applications
File Deleted : C:\Windows\System32\AppleChargerSrv.exe
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKCU\Software\df6f1d15fc6b1522ebf209e10045b79f
Key Deleted : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\SystemK
Key Deleted : HKCU\Software\AppDataLow\Software\Search Protection
Key Deleted : HKLM\Software\SystemK
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\prefs.js ]
*************************
AdwCleaner[R1].txt - [2580 octets] - [10/08/2014 11:14:17]
AdwCleaner[S1].txt - [2213 octets] - [10/08/2014 11:15:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2273 octets] ##########
Re: Prosim o kontrolu, predem dekuji :)
Dekuji za pomoc.
Zajimave ze ja nemam nainstalovany zadny antivir a uz vubec ne AVG.
Tak co znamena tohle?: Folder Deleted : C:\ProgramData\AVG Secure Search
Zajimave ze ja nemam nainstalovany zadny antivir a uz vubec ne AVG.
Tak co znamena tohle?: Folder Deleted : C:\ProgramData\AVG Secure Search
Re: Prosim o kontrolu, predem dekuji :)
Nejspis jste si to nainstaloval s nejakym softem.Erutan píše:Zajimave ze ja nemam nainstalovany zadny antivir a uz vubec ne AVG.
Tak co znamena tohle?: Folder Deleted : C:\ProgramData\AVG Secure Search

Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu, predem dekuji :)
Postupoval jsem podle navodu a nic jsem neodstranil...disk F mam jen na hry(vetsina je neoriginalni takze cracky budou asi hlaseny jako viry jak jsem videl v logu)
zde je log:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 10.8.2014
Scan Time: 15:45:01
Logfile: log.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.10.03
Rootkit Database: v2014.08.04.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Erutan
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 544125
Time Elapsed: 51 min, 32 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.FreeHDSportTV.A, HKLM\SOFTWARE\WOW6432NODE\FreeHDSport TV V7.0, , [92595b697803fe388a10c13817eb0cf4],
PUP.Optional.FreeHDSportTV.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\FreeHDSport TV V7.0, , [ea01477d2c4f9a9c1c7c73860101c937],
PUP.Optional.FreeHDSportTV.A, HKU\S-1-5-21-1926684632-688041120-732502126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\FreeHDSport TV V7.0, , [11da596b2f4c6fc768308970b44ef709],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 31
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF14.dll, , [c52614b0e19a270fd027dea82bd62dd3],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF10.dll, , [44a7ba0a4d2ef73f9a5dbec83ec3659b],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF11.dll, , [a249b311b5c6fb3bf3043f4752af7a86],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF12.dll, , [8a61873dfb802d0928cf92f4d82924dc],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF13.dll, , [8a61cff5b4c74de909eeb5d1768b956b],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF15.dll, , [905b754f6615bb7b2dcadda99071c13f],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF16.dll, , [e308c00485f6c86e9265077f71906d93],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF17.dll, , [11dabc08c8b3d26454a395f1c43d8d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF18.dll, , [e308ac18e49773c3c433780ed031ee12],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF19.dll, , [ae3d863ed9a25fd7ba3d5d296b967789],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF2.dll, , [97540cb86219b086b740315516eb817f],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF20.dll, , [9e4de1e32d4e2b0b0cebc6c0a65b8d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF21.dll, , [ea01a420abd09b9b0cebc3c30df420e0],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF22.dll, , [6e7d13b15526360054a3780ef01126da],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF23.dll, , [0be0f1d31a618da97186e6a0db26847c],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF24.dll, , [64875b69b2c9e35300f7baccc839f30d],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF25.dll, , [31ba596babd0290de90e7b0bd130d32d],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF26.dll, , [32b98d37bdbe3105ce29681e33ce8d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF27.dll, , [a645ac187cff55e170878ff7b849ce32],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF28.dll, , [67849d27394291a5ce2991f50af73dc3],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF29.dll, , [c92215af512a1a1cd324295de21fa55b],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF4.dll, , [07e4c7fd91ea96a0d225d4b29e638d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF5.dll, , [d81344805922af87c82fccba3bc64cb4],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF6.dll, , [e605cafa6318092dbb3c9fe7d72abe42],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF7.dll, , [c328b50f88f36ccaef089ee845bcdd23],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF8.dll, , [b338c8fca5d69e98976090f604fd6898],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF9.dll, , [0be00db78bf01a1c8d6a097d6a977b85],
Hacktool.ChewWGA, D:\Programy-Instalacky\AktivA!tor windows.eXe, , [519a18acf98290a6caf85bfa2ad60af6],
PUP.RiskwareTool.CK, F:\Dirt3\paul.dll, , [b833358f007be94d29d6a0f608f83ac6],
Trojan.Downloader.H, F:\Dirt3\SKIDROW.dll, , [707b6361e2993204cb22cb3a2fd339c7],
Trojan.VirTool, F:\Mortal Kombat Komplete Edition\DiscContentPC\steam_api.dll, , [d4175e663348ea4c6db4bc856b97c13f],
Physical Sectors: 0
(No malicious items detected)
(end)
zde je log:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 10.8.2014
Scan Time: 15:45:01
Logfile: log.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.10.03
Rootkit Database: v2014.08.04.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Erutan
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 544125
Time Elapsed: 51 min, 32 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.FreeHDSportTV.A, HKLM\SOFTWARE\WOW6432NODE\FreeHDSport TV V7.0, , [92595b697803fe388a10c13817eb0cf4],
PUP.Optional.FreeHDSportTV.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\FreeHDSport TV V7.0, , [ea01477d2c4f9a9c1c7c73860101c937],
PUP.Optional.FreeHDSportTV.A, HKU\S-1-5-21-1926684632-688041120-732502126-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\FreeHDSport TV V7.0, , [11da596b2f4c6fc768308970b44ef709],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 31
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF14.dll, , [c52614b0e19a270fd027dea82bd62dd3],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF10.dll, , [44a7ba0a4d2ef73f9a5dbec83ec3659b],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF11.dll, , [a249b311b5c6fb3bf3043f4752af7a86],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF12.dll, , [8a61873dfb802d0928cf92f4d82924dc],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF13.dll, , [8a61cff5b4c74de909eeb5d1768b956b],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF15.dll, , [905b754f6615bb7b2dcadda99071c13f],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF16.dll, , [e308c00485f6c86e9265077f71906d93],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF17.dll, , [11dabc08c8b3d26454a395f1c43d8d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF18.dll, , [e308ac18e49773c3c433780ed031ee12],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF19.dll, , [ae3d863ed9a25fd7ba3d5d296b967789],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF2.dll, , [97540cb86219b086b740315516eb817f],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF20.dll, , [9e4de1e32d4e2b0b0cebc6c0a65b8d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF21.dll, , [ea01a420abd09b9b0cebc3c30df420e0],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF22.dll, , [6e7d13b15526360054a3780ef01126da],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF23.dll, , [0be0f1d31a618da97186e6a0db26847c],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF24.dll, , [64875b69b2c9e35300f7baccc839f30d],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF25.dll, , [31ba596babd0290de90e7b0bd130d32d],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF26.dll, , [32b98d37bdbe3105ce29681e33ce8d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF27.dll, , [a645ac187cff55e170878ff7b849ce32],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF28.dll, , [67849d27394291a5ce2991f50af73dc3],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF29.dll, , [c92215af512a1a1cd324295de21fa55b],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF4.dll, , [07e4c7fd91ea96a0d225d4b29e638d73],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF5.dll, , [d81344805922af87c82fccba3bc64cb4],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF6.dll, , [e605cafa6318092dbb3c9fe7d72abe42],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF7.dll, , [c328b50f88f36ccaef089ee845bcdd23],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF8.dll, , [b338c8fca5d69e98976090f604fd6898],
PUP.Optional.SystemK.A, C:\Users\Erutan\AppData\Roaming\Mozilla\Firefox\Profiles\7rsi9my6.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}\components\SystemKHlpFF9.dll, , [0be00db78bf01a1c8d6a097d6a977b85],
Hacktool.ChewWGA, D:\Programy-Instalacky\AktivA!tor windows.eXe, , [519a18acf98290a6caf85bfa2ad60af6],
PUP.RiskwareTool.CK, F:\Dirt3\paul.dll, , [b833358f007be94d29d6a0f608f83ac6],
Trojan.Downloader.H, F:\Dirt3\SKIDROW.dll, , [707b6361e2993204cb22cb3a2fd339c7],
Trojan.VirTool, F:\Mortal Kombat Komplete Edition\DiscContentPC\steam_api.dll, , [d4175e663348ea4c6db4bc856b97c13f],
Physical Sectors: 0
(No malicious items detected)
(end)
Re: Prosim o kontrolu, predem dekuji :)
A co ten aktivator windows?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu, predem dekuji :)
aktivator je na aktivaci windowsu (kdo ma v dnesni dobe originalni win?) resi problemy s cernou obrazovkou kdy v pravem dolnim rohu je neaky text o nelegalnim win
Re: Prosim o kontrolu, predem dekuji :)
A pravidla fora jste cetl? Hovori jasne http://forum.viry.cz/viewtopic.php?f=12&t=115512

Pomáhat NELZE:
2) Pokud stroj uživatele prokazatelně obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.), je nutné navést uživatele k nápravě, např. skrze neplacený software,
a začít řešit, až v době kdy je PC "v pořádku". V případě že uživatel nechce na pravidla přistoupit,
je nutné jej vyzvat ať fórum opustí, a vrátí se až je splní.

Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu, predem dekuji :)
to se omlouvam ale o tomhle jsem nevedel samozrejme neznalost neomlouva.
asi budu muset poridit original ( http://operacni-systemy.heureka.cz/oem- ... fqc-04646/ ) a jak se tak divam tak drahe to ani neni
az budu mit orginal jak vam muzu dokazat ze nemam piratskou verzi?
asi budu muset poridit original ( http://operacni-systemy.heureka.cz/oem- ... fqc-04646/ ) a jak se tak divam tak drahe to ani neni

az budu mit orginal jak vam muzu dokazat ze nemam piratskou verzi?
Re: Prosim o kontrolu, predem dekuji :)
Z urcitych logu se to da vycistErutan píše:az budu mit orginal jak vam muzu dokazat ze nemam piratskou verzi?

Zatim tedy


Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).