
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosim o kontrolu
Logfile of random's system information tool 1.10 (written by random/random)
Run by Milan at 2014-09-02 13:28:51
Microsoft® Windows Vista™ Home Premium
System drive C: has 50 GB (17%) free of 297 GB
Total RAM: 3007 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:29:02, on 2. 9. 2014
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Milan\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Milan.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Search App by Ask BHO - {41564952-412D-5350-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll" (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Search App by Ask - {41564952-412D-5350-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll" (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [mslpchSrv] "C:\Windows\system32\mslpch.vbe" mswaygv msjeib
O4 - HKLM\..\Run: [MSStp] C:\Windows\inf\msstp.vbe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
--
End of file - 8734 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job - C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job - C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5350-00A7-7A786E7484D7}]
Search App by Ask - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll [2014-07-31 12184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-22 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-22 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{41564952-412D-5350-00A7-7A786E7484D7} - Search App by Ask - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll [2014-07-31 12184]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-02 1004136]
"VMonitorVMUVC"=C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe [2007-12-20 135168]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-09-17 152392]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2013-07-31 2296600]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2014-08-12 751184]
"ApnTBMon"=C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2014-07-31 1957784]
"Avira Systray"=C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [2014-08-04 161584]
"mslpchSrv"=C:\Windows\system32\mslpch.vbe [2014-06-23 649]
"MSStp"=C:\Windows\inf\msstp.vbe [2014-03-05 1584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2012-06-24 1232896]
"Facebook Update"=C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 138096]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
======List of files/folders created in the last 1 month======
2014-08-29 18:22:00 ----D---- C:\Windows\system32\bitstreams
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\zlib1.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\ssleay32.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\pthreadVC2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\pthreadGC2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\libssh2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\librtmp.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\libidn-11.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\acumncebtxi.exe
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\libeay32.dll
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\libcurl-4.dll
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\cudart32_50_35.dll
2014-08-29 18:20:30 ----AS---- C:\Windows\system32\nircmdc.exe
2014-08-14 15:43:32 ----D---- C:\ProgramData\Package Cache
2014-08-11 18:02:47 ----D---- C:\Program Files\Common Files\Skype
2014-08-11 18:02:46 ----RD---- C:\Program Files\Skype
2014-08-08 10:31:03 ----D---- C:\ProgramData\AskPartnerNetwork
2014-08-08 10:31:03 ----D---- C:\Program Files\AskPartnerNetwork
2014-08-08 10:30:48 ----D---- C:\Users\Milan\AppData\Roaming\Avira
2014-08-08 10:30:38 ----D---- C:\ProgramData\APN
2014-08-08 10:28:49 ----A---- C:\Windows\system32\drivers\ssmdrv.sys
2014-08-08 10:28:41 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2014-08-08 10:28:41 ----A---- C:\Windows\system32\drivers\avipbb.sys
2014-08-08 10:28:40 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2014-08-08 10:28:38 ----D---- C:\ProgramData\Avira
2014-08-08 10:28:38 ----D---- C:\Program Files\Avira
2014-08-06 16:59:16 ----D---- C:\Program Files\ESET
2014-08-06 13:33:23 ----SHD---- C:\$RECYCLE.BIN
2014-08-06 13:29:36 ----SD---- C:\ComboFix
2014-08-06 13:29:30 ----D---- C:\Qoobox
2014-08-06 13:28:58 ----D---- C:\Windows\erdnt
2014-08-06 13:28:55 ----SD---- C:\32788R22FWJFW
2014-08-06 12:06:52 ----D---- C:\Program Files\trend micro
2014-08-06 12:06:51 ----D---- C:\rsit
2014-08-06 10:06:27 ----D---- C:\Users\Milan\AppData\Roaming\TuneUp Software
======List of files/folders modified in the last 1 month======
2014-09-02 13:29:01 ----D---- C:\Windows\Temp
2014-09-02 13:28:51 ----D---- C:\Windows\Prefetch
2014-09-02 13:17:06 ----D---- C:\Windows\System32
2014-09-02 13:17:05 ----D---- C:\Windows\inf
2014-09-02 13:17:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-02 13:12:31 ----D---- C:\Windows\system32\catroot2
2014-09-01 11:18:13 ----SHD---- C:\System Volume Information
2014-08-31 13:40:03 ----D---- C:\Users\Milan\AppData\Roaming\Skype
2014-08-29 18:31:34 ----RD---- C:\Program Files
2014-08-29 17:55:53 ----D---- C:\ProgramData\NVIDIA
2014-08-20 07:42:38 ----HD---- C:\Config.Msi
2014-08-19 17:43:49 ----SHD---- C:\Windows\Installer
2014-08-15 20:09:17 ----A---- C:\Windows\win.ini
2014-08-14 15:43:32 ----HD---- C:\ProgramData
2014-08-11 18:03:10 ----D---- C:\ProgramData\Skype
2014-08-11 18:02:47 ----D---- C:\Program Files\Common Files
2014-08-08 10:40:05 ----D---- C:\Windows\system32\catroot
2014-08-08 10:34:15 ----D---- C:\Program Files\AVG
2014-08-08 10:34:12 ----D---- C:\ProgramData\MFAData
2014-08-08 10:28:49 ----D---- C:\Windows\system32\drivers
2014-08-07 18:48:11 ----D---- C:\Windows\Tasks
2014-08-07 17:59:27 ----D---- C:\Windows\system32\Tasks
2014-08-06 13:55:16 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-06 13:32:52 ----D---- C:\Windows
2014-08-06 10:18:13 ----D---- C:\ProgramData\AVAST Software
2014-08-06 09:58:36 ----SD---- C:\Windows\system32\Microsoft
2014-08-05 19:31:45 ----D---- C:\Users\Milan\AppData\Roaming\Notepad++
2014-08-05 19:31:45 ----D---- C:\Program Files\PDFCreator
2014-08-05 19:31:14 ----D---- C:\Windows\Panther
2014-08-05 19:31:13 ----D---- C:\Windows\Minidump
2014-08-05 19:31:13 ----D---- C:\Windows\Debug
2014-08-05 19:28:26 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2014-05-09 136216]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2014-05-09 37352]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 31088]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2014-05-09 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2014-08-08 97648]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 43800]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2013-05-23 28312]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-05-15 11354944]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 30208]
R3 VMUVC;Vimicro Camera Service VMUVC; C:\Windows\System32\Drivers\VMUVC.sys [2010-01-12 252928]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC; C:\Windows\system32\drivers\vvftUVC.sys [2008-07-01 398720]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag.sys [2012-07-03 23040]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem.sys [2012-07-03 27776]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter; C:\Windows\system32\DRIVERS\lgandnetndis.sys [2012-07-04 70400]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athur.sys [2010-01-05 1387008]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2012-06-24 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2006-11-02 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-06-24 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2012-06-24 29184]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2006-11-02 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2006-11-02 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2006-11-02 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys []
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
S3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2012-09-18 39608]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2006-11-02 49664]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-01 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-01 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-01 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-01 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-01 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-01 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-01 123504]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2006-11-02 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2014-08-12 430160]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2014-08-12 430160]
R2 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2014-08-12 1021008]
R2 APNMCP;Ask Update Service; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [2014-07-31 165784]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-08-04 149296]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2013-11-18 87368]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-09-17 553288]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-16 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-06 262320]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-16 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 293144]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-17 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-08-29 79360]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
-----------------EOF-----------------
Run by Milan at 2014-09-02 13:28:51
Microsoft® Windows Vista™ Home Premium
System drive C: has 50 GB (17%) free of 297 GB
Total RAM: 3007 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:29:02, on 2. 9. 2014
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Milan\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Milan.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Search App by Ask BHO - {41564952-412D-5350-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll" (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Search App by Ask - {41564952-412D-5350-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll" (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [mslpchSrv] "C:\Windows\system32\mslpch.vbe" mswaygv msjeib
O4 - HKLM\..\Run: [MSStp] C:\Windows\inf\msstp.vbe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
--
End of file - 8734 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job - C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job - C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5350-00A7-7A786E7484D7}]
Search App by Ask - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll [2014-07-31 12184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-22 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-22 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{41564952-412D-5350-00A7-7A786E7484D7} - Search App by Ask - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll [2014-07-31 12184]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-02 1004136]
"VMonitorVMUVC"=C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe [2007-12-20 135168]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-09-17 152392]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2013-07-31 2296600]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2014-08-12 751184]
"ApnTBMon"=C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2014-07-31 1957784]
"Avira Systray"=C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [2014-08-04 161584]
"mslpchSrv"=C:\Windows\system32\mslpch.vbe [2014-06-23 649]
"MSStp"=C:\Windows\inf\msstp.vbe [2014-03-05 1584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2012-06-24 1232896]
"Facebook Update"=C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 138096]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
======List of files/folders created in the last 1 month======
2014-08-29 18:22:00 ----D---- C:\Windows\system32\bitstreams
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\zlib1.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\ssleay32.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\pthreadVC2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\pthreadGC2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\libssh2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\librtmp.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\libidn-11.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\acumncebtxi.exe
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\libeay32.dll
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\libcurl-4.dll
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\cudart32_50_35.dll
2014-08-29 18:20:30 ----AS---- C:\Windows\system32\nircmdc.exe
2014-08-14 15:43:32 ----D---- C:\ProgramData\Package Cache
2014-08-11 18:02:47 ----D---- C:\Program Files\Common Files\Skype
2014-08-11 18:02:46 ----RD---- C:\Program Files\Skype
2014-08-08 10:31:03 ----D---- C:\ProgramData\AskPartnerNetwork
2014-08-08 10:31:03 ----D---- C:\Program Files\AskPartnerNetwork
2014-08-08 10:30:48 ----D---- C:\Users\Milan\AppData\Roaming\Avira
2014-08-08 10:30:38 ----D---- C:\ProgramData\APN
2014-08-08 10:28:49 ----A---- C:\Windows\system32\drivers\ssmdrv.sys
2014-08-08 10:28:41 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2014-08-08 10:28:41 ----A---- C:\Windows\system32\drivers\avipbb.sys
2014-08-08 10:28:40 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2014-08-08 10:28:38 ----D---- C:\ProgramData\Avira
2014-08-08 10:28:38 ----D---- C:\Program Files\Avira
2014-08-06 16:59:16 ----D---- C:\Program Files\ESET
2014-08-06 13:33:23 ----SHD---- C:\$RECYCLE.BIN
2014-08-06 13:29:36 ----SD---- C:\ComboFix
2014-08-06 13:29:30 ----D---- C:\Qoobox
2014-08-06 13:28:58 ----D---- C:\Windows\erdnt
2014-08-06 13:28:55 ----SD---- C:\32788R22FWJFW
2014-08-06 12:06:52 ----D---- C:\Program Files\trend micro
2014-08-06 12:06:51 ----D---- C:\rsit
2014-08-06 10:06:27 ----D---- C:\Users\Milan\AppData\Roaming\TuneUp Software
======List of files/folders modified in the last 1 month======
2014-09-02 13:29:01 ----D---- C:\Windows\Temp
2014-09-02 13:28:51 ----D---- C:\Windows\Prefetch
2014-09-02 13:17:06 ----D---- C:\Windows\System32
2014-09-02 13:17:05 ----D---- C:\Windows\inf
2014-09-02 13:17:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-02 13:12:31 ----D---- C:\Windows\system32\catroot2
2014-09-01 11:18:13 ----SHD---- C:\System Volume Information
2014-08-31 13:40:03 ----D---- C:\Users\Milan\AppData\Roaming\Skype
2014-08-29 18:31:34 ----RD---- C:\Program Files
2014-08-29 17:55:53 ----D---- C:\ProgramData\NVIDIA
2014-08-20 07:42:38 ----HD---- C:\Config.Msi
2014-08-19 17:43:49 ----SHD---- C:\Windows\Installer
2014-08-15 20:09:17 ----A---- C:\Windows\win.ini
2014-08-14 15:43:32 ----HD---- C:\ProgramData
2014-08-11 18:03:10 ----D---- C:\ProgramData\Skype
2014-08-11 18:02:47 ----D---- C:\Program Files\Common Files
2014-08-08 10:40:05 ----D---- C:\Windows\system32\catroot
2014-08-08 10:34:15 ----D---- C:\Program Files\AVG
2014-08-08 10:34:12 ----D---- C:\ProgramData\MFAData
2014-08-08 10:28:49 ----D---- C:\Windows\system32\drivers
2014-08-07 18:48:11 ----D---- C:\Windows\Tasks
2014-08-07 17:59:27 ----D---- C:\Windows\system32\Tasks
2014-08-06 13:55:16 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-06 13:32:52 ----D---- C:\Windows
2014-08-06 10:18:13 ----D---- C:\ProgramData\AVAST Software
2014-08-06 09:58:36 ----SD---- C:\Windows\system32\Microsoft
2014-08-05 19:31:45 ----D---- C:\Users\Milan\AppData\Roaming\Notepad++
2014-08-05 19:31:45 ----D---- C:\Program Files\PDFCreator
2014-08-05 19:31:14 ----D---- C:\Windows\Panther
2014-08-05 19:31:13 ----D---- C:\Windows\Minidump
2014-08-05 19:31:13 ----D---- C:\Windows\Debug
2014-08-05 19:28:26 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2014-05-09 136216]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2014-05-09 37352]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 31088]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2014-05-09 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2014-08-08 97648]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 43800]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2013-05-23 28312]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-05-15 11354944]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 30208]
R3 VMUVC;Vimicro Camera Service VMUVC; C:\Windows\System32\Drivers\VMUVC.sys [2010-01-12 252928]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC; C:\Windows\system32\drivers\vvftUVC.sys [2008-07-01 398720]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag.sys [2012-07-03 23040]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem.sys [2012-07-03 27776]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter; C:\Windows\system32\DRIVERS\lgandnetndis.sys [2012-07-04 70400]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athur.sys [2010-01-05 1387008]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2012-06-24 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2006-11-02 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-06-24 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2012-06-24 29184]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2006-11-02 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2006-11-02 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2006-11-02 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys []
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
S3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2012-09-18 39608]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2006-11-02 49664]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-01 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-01 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-01 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-01 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-01 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-01 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-01 123504]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2006-11-02 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2014-08-12 430160]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2014-08-12 430160]
R2 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2014-08-12 1021008]
R2 APNMCP;Ask Update Service; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [2014-07-31 165784]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-08-04 149296]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2013-11-18 87368]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-09-17 553288]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-16 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-06 262320]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-16 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 293144]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-17 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-08-29 79360]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
-----------------EOF-----------------
Re: Prosim o kontrolu
Zdravim 
Proc nemate aktualizovany windows?
Mate slusne zavirovano
Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce


Mate slusne zavirovano


Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2. 9. 2014
Scan Time: 19:01:00
Logfile: jozef.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.09.02.07
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows Vista
CPU: x86
File System: NTFS
User: Milan
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 274291
Time Elapsed: 13 min, 57 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 2
Trojan.Agent.SCR, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSStp, C:\Windows\inf\msstp.vbe, , [cb1403e592e9de580161ff0ec043ee12]
Trojan.Script, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mslpchSrv, "C:\Windows\system32\mslpch.vbe" mswaygv msjeib, , [627d00e8aecdf541735425fb50b32ed2]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 5
PUP.Optional.Bitcoin, C:\Windows\System32\acumncebtxi.exe, , [c61911d778038caad8eb4f70c73af60a],
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [cb1403e592e9de580161ff0ec043ee12],
Trojan.Script, C:\Windows\System32\msjeib.vbe, , [69769256e89337ffeed922feda29d32d],
Trojan.Script, C:\Windows\System32\mslpch.vbe, , [627d00e8aecdf541735425fb50b32ed2],
Trojan.Script, C:\Windows\System32\mswaygv.vbe, , [805f1fc93645f145a2256db3f211827e],
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 2. 9. 2014
Scan Time: 19:01:00
Logfile: jozef.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.09.02.07
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows Vista
CPU: x86
File System: NTFS
User: Milan
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 274291
Time Elapsed: 13 min, 57 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 2
Trojan.Agent.SCR, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSStp, C:\Windows\inf\msstp.vbe, , [cb1403e592e9de580161ff0ec043ee12]
Trojan.Script, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mslpchSrv, "C:\Windows\system32\mslpch.vbe" mswaygv msjeib, , [627d00e8aecdf541735425fb50b32ed2]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 5
PUP.Optional.Bitcoin, C:\Windows\System32\acumncebtxi.exe, , [c61911d778038caad8eb4f70c73af60a],
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [cb1403e592e9de580161ff0ec043ee12],
Trojan.Script, C:\Windows\System32\msjeib.vbe, , [69769256e89337ffeed922feda29d32d],
Trojan.Script, C:\Windows\System32\mslpch.vbe, , [627d00e8aecdf541735425fb50b32ed2],
Trojan.Script, C:\Windows\System32\mswaygv.vbe, , [805f1fc93645f145a2256db3f211827e],
Physical Sectors: 0
(No malicious items detected)
(end)
Re: Prosim o kontrolu
Nalezy nechte odstranit. Po restartu pc test zopakujte, ale tentokrat ho nastavte opravdu tak, jak je v navodu, aby program kontroloval cely pocitac! Napiste vysledek testu a podle toho zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 3. 9. 2014
Scan Time: 7:20:00
Logfile: jozef.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.09.03.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Milan
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 511535
Time Elapsed: 5 hr, 53 min, 2 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
Trojan.Dropper.PGen, C:\Zaloha\D\PC\staryPC\InA!talaÄ?ky a zA!loha-disk C\AcdS 9\ACDSee.v9.0.108.Photo.Manager.Incl.Keymaker-CORE.rar, , [aced6663512af2441e12401f8b75aa56],
Physical Sectors: 0
(No malicious items detected)
(end)
www.malwarebytes.org
Scan Date: 3. 9. 2014
Scan Time: 7:20:00
Logfile: jozef.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.09.03.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Milan
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 511535
Time Elapsed: 5 hr, 53 min, 2 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
Trojan.Dropper.PGen, C:\Zaloha\D\PC\staryPC\InA!talaÄ?ky a zA!loha-disk C\AcdS 9\ACDSee.v9.0.108.Photo.Manager.Incl.Keymaker-CORE.rar, , [aced6663512af2441e12401f8b75aa56],
Physical Sectors: 0
(No malicious items detected)
(end)
Re: Prosim o kontrolu


Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu
# AdwCleaner v3.309 - Report created 04/09/2014 at 09:10:04
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Milan - DOMA-PC
# Running from : C:\Users\Milan\Desktop\adwcleaner_3.309.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : APNMCP
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Users\Milan\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\Users\Milan\AppData\Local\Temp\apn
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
-\\ Google Chrome v37.0.2062.103
[ File : C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R2].txt - [1736 octets] - [04/09/2014 09:08:00]
AdwCleaner[S1].txt - [1976 octets] - [04/09/2014 09:10:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2036 octets] ##########
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Milan - DOMA-PC
# Running from : C:\Users\Milan\Desktop\adwcleaner_3.309.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : APNMCP
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Users\Milan\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\Users\Milan\AppData\Local\Temp\apn
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
-\\ Google Chrome v37.0.2062.103
[ File : C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R2].txt - [1736 octets] - [04/09/2014 09:08:00]
AdwCleaner[S1].txt - [1976 octets] - [04/09/2014 09:10:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2036 octets] ##########
Re: Prosim o kontrolu




Vypnete antivir i dalsi pripadne zabezpeceni.
Kliknete na ComboFix pravym mysidlem a levym na Spustit jako spravce
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte


Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu
ComboFix 14-08-31.01 - Milan . 09. 2014 16:12:43.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3006.2034 [GMT 2:00]
Running from: c:\users\Milan\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msxml4-KB2758694-enu.LOG
.
.
((((((((((((((((((((((((( Files Created from 2014-08-04 to 2014-09-04 )))))))))))))))))))))))))))))))
.
.
2014-09-04 14:20 . 2014-09-04 14:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-04 07:06 . 2014-09-04 07:06 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2014-09-03 14:39 . 2014-09-03 14:39 -------- d-----w- c:\program files\Defraggler
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\program files\Windows Portable Devices
2014-09-03 08:56 . 2014-09-03 08:56 -------- d-----w- c:\users\Milan\AppData\Roaming\AVG2014
2014-09-03 08:52 . 2014-09-03 08:55 -------- d-----w- c:\programdata\AVG2014
2014-09-03 08:52 . 2014-09-03 08:52 -------- d-----w- C:\$AVG
2014-09-03 08:50 . 2014-09-03 14:36 -------- d-----w- c:\users\Milan\AppData\Local\Avg2014
2014-09-03 08:28 . 2014-09-03 08:31 -------- d-----w- c:\windows\system32\MRT
2014-09-03 08:20 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-09-03 08:20 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-09-03 08:20 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-09-03 08:20 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-09-03 08:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-09-03 08:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-09-03 08:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-09-03 07:47 . 2014-09-03 07:47 -------- d-----w- c:\windows\Migration
2014-09-03 07:37 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-03 07:37 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-03 07:19 . 2014-09-03 07:19 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-09-03 07:18 . 2014-09-03 07:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-09-03 07:18 . 2014-09-03 07:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-09-03 07:18 . 2014-09-03 07:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-09-03 07:18 . 2014-09-03 07:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-09-03 07:18 . 2014-09-03 07:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-09-03 07:18 . 2014-09-03 07:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-09-03 07:18 . 2014-09-03 07:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-09-03 06:44 . 2014-07-30 00:25 304128 ----a-w- c:\program files\Internet Explorer\ieuser.exe
2014-09-03 06:40 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-09-03 06:40 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-09-03 06:40 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-09-03 06:40 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-09-03 06:40 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-09-03 06:40 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-09-03 06:40 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2014-09-03 06:40 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-09-03 06:40 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-09-03 06:40 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-09-03 06:28 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-09-03 06:22 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-09-03 06:22 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-09-03 06:21 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-09-03 06:21 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2014-09-03 06:21 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-09-03 06:21 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2014-09-03 06:21 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2014-09-03 06:21 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2014-09-03 06:21 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2014-09-03 06:21 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-09-03 06:19 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2014-09-03 06:19 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2014-09-03 06:18 . 2009-10-23 17:10 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-09-03 06:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2014-09-03 06:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2014-09-03 06:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2014-09-03 06:18 . 2012-02-01 15:10 1404928 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2014-09-03 06:18 . 2014-06-02 10:31 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-09-03 06:18 . 2014-06-02 10:30 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-09-03 06:18 . 2014-06-02 10:30 937472 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-09-03 06:18 . 2014-06-02 10:30 965120 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-09-03 06:18 . 2012-02-01 13:58 47104 ----a-w- c:\program files\Windows Journal\PDIALOG.exe
2014-09-03 06:18 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-09-03 06:18 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2014-09-03 06:17 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-09-03 06:17 . 2014-04-05 02:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-09-03 06:17 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-09-03 06:17 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-09-03 06:17 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-09-03 06:17 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-09-03 06:16 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-09-03 06:16 . 2013-07-12 09:04 73344 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2014-09-03 06:14 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-09-03 06:12 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-09-03 06:12 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-09-03 06:12 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-09-03 06:12 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-09-03 06:12 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-09-03 06:12 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-09-03 06:11 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2014-09-03 06:11 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2014-09-03 06:11 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-09-03 06:11 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-09-03 06:11 . 2013-06-26 23:01 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-09-03 06:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-09-03 06:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-09-03 06:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-09-03 06:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-09-03 06:10 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-09-03 06:10 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-09-03 06:09 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-09-03 06:09 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-09-03 06:09 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-09-03 06:09 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe
2014-09-03 06:09 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe
2014-09-03 06:09 . 2014-06-07 02:08 1305088 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-09-03 06:09 . 2014-06-07 02:08 149504 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-09-03 06:09 . 2014-06-07 02:08 114688 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-09-03 06:09 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2014-09-03 06:09 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\system32\msxml6.dll
2014-09-03 06:09 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-09-03 06:09 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-09-03 06:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2014-09-03 06:06 . 2014-07-08 00:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-03 06:06 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2014-09-03 06:06 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-09-03 06:06 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-09-03 06:06 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2014-09-03 06:06 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2014-09-03 06:06 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-09-03 06:06 . 2013-07-16 04:35 615936 ----a-w- c:\windows\system32\themeui.dll
2014-09-03 06:06 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-09-03 06:06 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-09-03 06:04 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-09-03 06:03 . 2013-06-29 02:07 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-09-03 06:03 . 2013-06-29 02:07 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-09-03 06:03 . 2013-06-29 02:07 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-09-03 06:03 . 2013-06-29 02:06 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-09-03 06:03 . 2011-05-05 13:54 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-09-03 06:03 . 2011-05-05 13:54 23552 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-09-03 06:03 . 2014-06-14 00:33 37376 ----a-w- c:\windows\system32\cdd.dll
2014-09-03 06:03 . 2014-06-14 00:44 638400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-09-03 06:03 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2014-09-03 06:03 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2014-09-03 06:03 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-03 11:41 . 2013-11-17 19:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-03 07:20 . 2014-09-03 07:20 203776 ----a-w- c:\windows\system32\webcheck.dll
2014-09-03 07:18 . 2014-09-03 07:18 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2014-09-02 19:30 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-09-02 19:30 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-08-06 11:55 . 2012-06-24 12:39 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-06 11:55 . 2012-06-24 12:39 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-30 02:11 . 2014-09-03 06:44 53760 ----a-w- c:\windows\apppatch\iebrshim.dll
2014-07-21 19:03 . 2014-07-21 19:03 200984 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-06-30 10:43 . 2014-06-30 10:43 121624 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-06-17 14:22 . 2014-06-17 14:22 188696 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-06-17 14:21 . 2014-06-17 14:21 197400 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-06-17 14:18 . 2014-06-17 14:18 241944 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-06-17 14:17 . 2014-06-17 14:17 147736 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-06-17 14:06 . 2014-06-17 14:06 27416 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-06-17 14:06 . 2014-06-17 14:06 21272 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2007-12-20 135168]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-09-17 152392]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-12-17 17:03 138096 ----atw- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-620889938-3404297717-3700568068-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-03 05:13 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 11:55]
.
2014-08-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
Toolbar-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
WebBrowser-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-{229FE254-C78E-B54C-6B45-E799F93F8BD1}_is1 - c:\program files\Zoner Photo Studio 15 Professional CZ Key kl(100% funkn
AddRemove-{7E0D648F-EDBE-983A-B91E-2BA38FAA1EF5}_is1 - c:\program files\Zoner Photo Studio 15 Professional CZ Key kl(100% funkn
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-04 16:21
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-09-04 16:23:36
ComboFix-quarantined-files.txt 2014-09-04 14:23
.
Pre-Run: 78 075 113 472 bytes free
Post-Run: 78 137 905 152 bytes free
.
- - End Of File - - 38252465BDC964619106BBEB282AD500
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3006.2034 [GMT 2:00]
Running from: c:\users\Milan\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msxml4-KB2758694-enu.LOG
.
.
((((((((((((((((((((((((( Files Created from 2014-08-04 to 2014-09-04 )))))))))))))))))))))))))))))))
.
.
2014-09-04 14:20 . 2014-09-04 14:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-04 07:06 . 2014-09-04 07:06 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2014-09-03 14:39 . 2014-09-03 14:39 -------- d-----w- c:\program files\Defraggler
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\program files\Windows Portable Devices
2014-09-03 08:56 . 2014-09-03 08:56 -------- d-----w- c:\users\Milan\AppData\Roaming\AVG2014
2014-09-03 08:52 . 2014-09-03 08:55 -------- d-----w- c:\programdata\AVG2014
2014-09-03 08:52 . 2014-09-03 08:52 -------- d-----w- C:\$AVG
2014-09-03 08:50 . 2014-09-03 14:36 -------- d-----w- c:\users\Milan\AppData\Local\Avg2014
2014-09-03 08:28 . 2014-09-03 08:31 -------- d-----w- c:\windows\system32\MRT
2014-09-03 08:20 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-09-03 08:20 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-09-03 08:20 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-09-03 08:20 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-09-03 08:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-09-03 08:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-09-03 08:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-09-03 07:47 . 2014-09-03 07:47 -------- d-----w- c:\windows\Migration
2014-09-03 07:37 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-03 07:37 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-03 07:19 . 2014-09-03 07:19 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-09-03 07:18 . 2014-09-03 07:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-09-03 07:18 . 2014-09-03 07:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-09-03 07:18 . 2014-09-03 07:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-09-03 07:18 . 2014-09-03 07:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-09-03 07:18 . 2014-09-03 07:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-09-03 07:18 . 2014-09-03 07:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-09-03 07:18 . 2014-09-03 07:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-09-03 06:44 . 2014-07-30 00:25 304128 ----a-w- c:\program files\Internet Explorer\ieuser.exe
2014-09-03 06:40 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-09-03 06:40 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-09-03 06:40 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-09-03 06:40 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-09-03 06:40 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-09-03 06:40 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-09-03 06:40 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2014-09-03 06:40 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-09-03 06:40 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-09-03 06:40 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-09-03 06:28 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-09-03 06:22 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-09-03 06:22 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-09-03 06:21 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-09-03 06:21 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2014-09-03 06:21 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-09-03 06:21 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2014-09-03 06:21 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2014-09-03 06:21 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2014-09-03 06:21 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2014-09-03 06:21 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-09-03 06:19 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2014-09-03 06:19 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2014-09-03 06:18 . 2009-10-23 17:10 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-09-03 06:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2014-09-03 06:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2014-09-03 06:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2014-09-03 06:18 . 2012-02-01 15:10 1404928 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2014-09-03 06:18 . 2014-06-02 10:31 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-09-03 06:18 . 2014-06-02 10:30 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-09-03 06:18 . 2014-06-02 10:30 937472 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-09-03 06:18 . 2014-06-02 10:30 965120 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-09-03 06:18 . 2012-02-01 13:58 47104 ----a-w- c:\program files\Windows Journal\PDIALOG.exe
2014-09-03 06:18 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-09-03 06:18 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2014-09-03 06:17 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-09-03 06:17 . 2014-04-05 02:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-09-03 06:17 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-09-03 06:17 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-09-03 06:17 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-09-03 06:17 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-09-03 06:16 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-09-03 06:16 . 2013-07-12 09:04 73344 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2014-09-03 06:14 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-09-03 06:12 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-09-03 06:12 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-09-03 06:12 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-09-03 06:12 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-09-03 06:12 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-09-03 06:12 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-09-03 06:11 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2014-09-03 06:11 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2014-09-03 06:11 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-09-03 06:11 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-09-03 06:11 . 2013-06-26 23:01 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-09-03 06:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-09-03 06:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-09-03 06:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-09-03 06:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-09-03 06:10 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-09-03 06:10 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-09-03 06:09 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-09-03 06:09 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-09-03 06:09 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-09-03 06:09 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe
2014-09-03 06:09 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe
2014-09-03 06:09 . 2014-06-07 02:08 1305088 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-09-03 06:09 . 2014-06-07 02:08 149504 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-09-03 06:09 . 2014-06-07 02:08 114688 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-09-03 06:09 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2014-09-03 06:09 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\system32\msxml6.dll
2014-09-03 06:09 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-09-03 06:09 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-09-03 06:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2014-09-03 06:06 . 2014-07-08 00:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-03 06:06 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2014-09-03 06:06 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-09-03 06:06 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-09-03 06:06 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2014-09-03 06:06 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2014-09-03 06:06 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-09-03 06:06 . 2013-07-16 04:35 615936 ----a-w- c:\windows\system32\themeui.dll
2014-09-03 06:06 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-09-03 06:06 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-09-03 06:04 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-09-03 06:03 . 2013-06-29 02:07 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-09-03 06:03 . 2013-06-29 02:07 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-09-03 06:03 . 2013-06-29 02:07 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-09-03 06:03 . 2013-06-29 02:06 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-09-03 06:03 . 2011-05-05 13:54 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-09-03 06:03 . 2011-05-05 13:54 23552 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-09-03 06:03 . 2014-06-14 00:33 37376 ----a-w- c:\windows\system32\cdd.dll
2014-09-03 06:03 . 2014-06-14 00:44 638400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-09-03 06:03 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2014-09-03 06:03 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2014-09-03 06:03 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-03 11:41 . 2013-11-17 19:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-03 07:20 . 2014-09-03 07:20 203776 ----a-w- c:\windows\system32\webcheck.dll
2014-09-03 07:18 . 2014-09-03 07:18 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2014-09-02 19:30 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-09-02 19:30 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-08-06 11:55 . 2012-06-24 12:39 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-06 11:55 . 2012-06-24 12:39 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-30 02:11 . 2014-09-03 06:44 53760 ----a-w- c:\windows\apppatch\iebrshim.dll
2014-07-21 19:03 . 2014-07-21 19:03 200984 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-06-30 10:43 . 2014-06-30 10:43 121624 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-06-17 14:22 . 2014-06-17 14:22 188696 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-06-17 14:21 . 2014-06-17 14:21 197400 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-06-17 14:18 . 2014-06-17 14:18 241944 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-06-17 14:17 . 2014-06-17 14:17 147736 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-06-17 14:06 . 2014-06-17 14:06 27416 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-06-17 14:06 . 2014-06-17 14:06 21272 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2007-12-20 135168]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-09-17 152392]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-12-17 17:03 138096 ----atw- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-620889938-3404297717-3700568068-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-03 05:13 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 11:55]
.
2014-08-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
Toolbar-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
WebBrowser-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-{229FE254-C78E-B54C-6B45-E799F93F8BD1}_is1 - c:\program files\Zoner Photo Studio 15 Professional CZ Key kl(100% funkn
AddRemove-{7E0D648F-EDBE-983A-B91E-2BA38FAA1EF5}_is1 - c:\program files\Zoner Photo Studio 15 Professional CZ Key kl(100% funkn
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-04 16:21
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-09-04 16:23:36
ComboFix-quarantined-files.txt 2014-09-04 14:23
.
Pre-Run: 78 075 113 472 bytes free
Post-Run: 78 137 905 152 bytes free
.
- - End Of File - - 38252465BDC964619106BBEB282AD500
5C616939100B85E558DA92B899A0FC36
Re: Prosim o kontrolu


Kód: Vybrat vše
KillAll::
File::
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\System32\acumncebtxi.exe
C:\Windows\inf\msstp.vbe
C:\Windows\System32\msjeib.vbe
C:\Windows\System32\mslpch.vbe
C:\Windows\System32\mswaygv.vbe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=-
"GrooveMonitor"=-
"Adobe ARM"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
Reboot::
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.


Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu
ComboFix 14-08-31.01 - Milan . 09. 2014 19:14:33.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3006.1967 [GMT 2:00]
Running from: c:\users\Milan\Desktop\ComboFix.exe
Command switches used :: c:\users\Milan\Desktop\CFScript.txt
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
FILE ::
"c:\windows\inf\msstp.vbe"
"c:\windows\System32\acumncebtxi.exe"
"c:\windows\System32\msjeib.vbe"
"c:\windows\System32\mslpch.vbe"
"c:\windows\System32\mswaygv.vbe"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((( Files Created from 2014-08-04 to 2014-09-04 )))))))))))))))))))))))))))))))
.
.
2014-09-04 17:23 . 2014-09-04 17:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-04 17:10 . 2014-09-04 17:10 -------- d-----w- c:\users\Milan\AppData\Local\AVG Web TuneUp
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Security Toolbar
2014-09-04 17:09 . 2014-09-04 17:09 42784 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Secure Search
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Web TuneUp
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\program files\AVG Web TuneUp
2014-09-04 15:48 . 2014-09-04 15:48 -------- d-----w- c:\program files\Scan Tailor
2014-09-04 07:06 . 2014-09-04 07:06 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2014-09-03 14:39 . 2014-09-03 14:39 -------- d-----w- c:\program files\Defraggler
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\program files\Windows Portable Devices
2014-09-03 08:56 . 2014-09-03 08:56 -------- d-----w- c:\users\Milan\AppData\Roaming\AVG2014
2014-09-03 08:52 . 2014-09-03 08:55 -------- d-----w- c:\programdata\AVG2014
2014-09-03 08:52 . 2014-09-03 08:52 -------- d-----w- C:\$AVG
2014-09-03 08:50 . 2014-09-03 14:36 -------- d-----w- c:\users\Milan\AppData\Local\Avg2014
2014-09-03 08:28 . 2014-09-03 08:31 -------- d-----w- c:\windows\system32\MRT
2014-09-03 08:20 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-09-03 08:20 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-09-03 08:20 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-09-03 08:20 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-09-03 08:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-09-03 08:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-09-03 08:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-09-03 07:47 . 2014-09-03 07:47 -------- d-----w- c:\windows\Migration
2014-09-03 07:37 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-03 07:37 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-03 07:19 . 2014-09-03 07:19 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-09-03 07:18 . 2014-09-03 07:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-09-03 07:18 . 2014-09-03 07:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-09-03 07:18 . 2014-09-03 07:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-09-03 07:18 . 2014-09-03 07:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-09-03 07:18 . 2014-09-03 07:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-09-03 07:18 . 2014-09-03 07:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-09-03 07:18 . 2014-09-03 07:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-09-03 06:44 . 2014-07-30 00:25 304128 ----a-w- c:\program files\Internet Explorer\ieuser.exe
2014-09-03 06:40 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-09-03 06:40 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-09-03 06:40 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-09-03 06:40 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-09-03 06:40 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-09-03 06:40 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-09-03 06:40 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2014-09-03 06:40 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-09-03 06:40 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-09-03 06:40 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-09-03 06:28 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-09-03 06:22 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-09-03 06:22 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-09-03 06:21 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-09-03 06:21 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2014-09-03 06:21 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-09-03 06:21 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2014-09-03 06:21 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2014-09-03 06:21 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2014-09-03 06:21 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2014-09-03 06:21 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-09-03 06:19 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2014-09-03 06:19 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2014-09-03 06:18 . 2009-10-23 17:10 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-09-03 06:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2014-09-03 06:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2014-09-03 06:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2014-09-03 06:18 . 2012-02-01 15:10 1404928 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2014-09-03 06:18 . 2014-06-02 10:31 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-09-03 06:18 . 2014-06-02 10:30 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-09-03 06:18 . 2014-06-02 10:30 937472 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-09-03 06:18 . 2014-06-02 10:30 965120 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-09-03 06:18 . 2012-02-01 13:58 47104 ----a-w- c:\program files\Windows Journal\PDIALOG.exe
2014-09-03 06:18 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-09-03 06:18 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2014-09-03 06:17 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-09-03 06:17 . 2014-04-05 02:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-09-03 06:17 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-09-03 06:17 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-09-03 06:17 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-09-03 06:17 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-09-03 06:16 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-09-03 06:16 . 2013-07-12 09:04 73344 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2014-09-03 06:14 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-09-03 06:12 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-09-03 06:12 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-09-03 06:12 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-09-03 06:12 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-09-03 06:12 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-09-03 06:12 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-09-03 06:11 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2014-09-03 06:11 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2014-09-03 06:11 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-09-03 06:11 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-09-03 06:11 . 2013-06-26 23:01 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-09-03 06:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-09-03 06:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-09-03 06:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-09-03 06:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-09-03 06:10 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-09-03 06:10 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-09-03 06:09 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-09-03 06:09 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-09-03 06:09 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-09-03 06:09 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe
2014-09-03 06:09 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe
2014-09-03 06:09 . 2014-06-07 02:08 1305088 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-09-03 06:09 . 2014-06-07 02:08 149504 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-09-03 06:09 . 2014-06-07 02:08 114688 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-09-03 06:09 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2014-09-03 06:09 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\system32\msxml6.dll
2014-09-03 06:09 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-09-03 06:09 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-09-03 06:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2014-09-03 06:06 . 2014-07-08 00:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-03 06:06 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2014-09-03 06:06 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-09-03 06:06 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-09-03 06:06 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2014-09-03 06:06 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2014-09-03 06:06 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-09-03 06:06 . 2013-07-16 04:35 615936 ----a-w- c:\windows\system32\themeui.dll
2014-09-03 06:06 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-09-03 06:06 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-09-03 06:04 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-09-03 06:03 . 2013-06-29 02:07 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-09-03 06:03 . 2013-06-29 02:07 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-09-03 06:03 . 2013-06-29 02:07 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-03 11:41 . 2013-11-17 19:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-03 07:20 . 2014-09-03 07:20 203776 ----a-w- c:\windows\system32\webcheck.dll
2014-09-03 07:18 . 2014-09-03 07:18 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2014-09-02 19:30 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-09-02 19:30 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-08-06 11:55 . 2012-06-24 12:39 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-06 11:55 . 2012-06-24 12:39 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-30 02:11 . 2014-09-03 06:44 53760 ----a-w- c:\windows\apppatch\iebrshim.dll
2014-07-21 19:03 . 2014-07-21 19:03 200984 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-06-30 10:43 . 2014-06-30 10:43 121624 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-06-17 14:22 . 2014-06-17 14:22 188696 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-06-17 14:21 . 2014-06-17 14:21 197400 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-06-17 14:18 . 2014-06-17 14:18 241944 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-06-17 14:17 . 2014-06-17 14:17 147736 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-06-17 14:06 . 2014-06-17 14:06 27416 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-06-17 14:06 . 2014-06-17 14:06 21272 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2007-12-20 135168]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-09-17 152392]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
"vProt"="c:\program files\AVG Web TuneUp\vprot.exe" [2014-09-04 2680344]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-620889938-3404297717-3700568068-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-03 05:13 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 11:55]
.
2014-08-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-04 19:26
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2014\avgrsx.exe
c:\program files\AVG\AVG2014\avgcsrvx.exe
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\AVG\AVG2014\avgidsagent.exe
c:\program files\AVG\AVG2014\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe
c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\loggingserver.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\windows\System32\WUDFHost.exe
c:\program files\AVG\AVG2014\avgnsx.exe
c:\program files\AVG\AVG2014\avgemcx.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2014-09-04 19:31:07 - machine was rebooted
ComboFix-quarantined-files.txt 2014-09-04 17:31
.
Pre-Run: 74 367 688 704 bytes free
Post-Run: 74 170 261 504 bytes free
.
- - End Of File - - C9A6D55563E233071CF7A4AD4A3642B4
5C616939100B85E558DA92B899A0FC36
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3006.1967 [GMT 2:00]
Running from: c:\users\Milan\Desktop\ComboFix.exe
Command switches used :: c:\users\Milan\Desktop\CFScript.txt
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
FILE ::
"c:\windows\inf\msstp.vbe"
"c:\windows\System32\acumncebtxi.exe"
"c:\windows\System32\msjeib.vbe"
"c:\windows\System32\mslpch.vbe"
"c:\windows\System32\mswaygv.vbe"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((( Files Created from 2014-08-04 to 2014-09-04 )))))))))))))))))))))))))))))))
.
.
2014-09-04 17:23 . 2014-09-04 17:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-04 17:10 . 2014-09-04 17:10 -------- d-----w- c:\users\Milan\AppData\Local\AVG Web TuneUp
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Security Toolbar
2014-09-04 17:09 . 2014-09-04 17:09 42784 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Secure Search
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Web TuneUp
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\program files\AVG Web TuneUp
2014-09-04 15:48 . 2014-09-04 15:48 -------- d-----w- c:\program files\Scan Tailor
2014-09-04 07:06 . 2014-09-04 07:06 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2014-09-03 14:39 . 2014-09-03 14:39 -------- d-----w- c:\program files\Defraggler
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\program files\Windows Portable Devices
2014-09-03 08:56 . 2014-09-03 08:56 -------- d-----w- c:\users\Milan\AppData\Roaming\AVG2014
2014-09-03 08:52 . 2014-09-03 08:55 -------- d-----w- c:\programdata\AVG2014
2014-09-03 08:52 . 2014-09-03 08:52 -------- d-----w- C:\$AVG
2014-09-03 08:50 . 2014-09-03 14:36 -------- d-----w- c:\users\Milan\AppData\Local\Avg2014
2014-09-03 08:28 . 2014-09-03 08:31 -------- d-----w- c:\windows\system32\MRT
2014-09-03 08:20 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-09-03 08:20 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-09-03 08:20 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-09-03 08:20 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-09-03 08:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-09-03 08:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-09-03 08:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-09-03 07:47 . 2014-09-03 07:47 -------- d-----w- c:\windows\Migration
2014-09-03 07:37 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-03 07:37 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-03 07:19 . 2014-09-03 07:19 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-09-03 07:18 . 2014-09-03 07:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-09-03 07:18 . 2014-09-03 07:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-09-03 07:18 . 2014-09-03 07:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-09-03 07:18 . 2014-09-03 07:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-09-03 07:18 . 2014-09-03 07:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-09-03 07:18 . 2014-09-03 07:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-09-03 07:18 . 2014-09-03 07:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-09-03 06:44 . 2014-07-30 00:25 304128 ----a-w- c:\program files\Internet Explorer\ieuser.exe
2014-09-03 06:40 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-09-03 06:40 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-09-03 06:40 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-09-03 06:40 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-09-03 06:40 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-09-03 06:40 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-09-03 06:40 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2014-09-03 06:40 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-09-03 06:40 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-09-03 06:40 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-09-03 06:28 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-09-03 06:22 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-09-03 06:22 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-09-03 06:21 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-09-03 06:21 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2014-09-03 06:21 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-09-03 06:21 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2014-09-03 06:21 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2014-09-03 06:21 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2014-09-03 06:21 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2014-09-03 06:21 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-09-03 06:19 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2014-09-03 06:19 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2014-09-03 06:18 . 2009-10-23 17:10 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-09-03 06:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2014-09-03 06:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2014-09-03 06:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2014-09-03 06:18 . 2012-02-01 15:10 1404928 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2014-09-03 06:18 . 2014-06-02 10:31 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-09-03 06:18 . 2014-06-02 10:30 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-09-03 06:18 . 2014-06-02 10:30 937472 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-09-03 06:18 . 2014-06-02 10:30 965120 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-09-03 06:18 . 2012-02-01 13:58 47104 ----a-w- c:\program files\Windows Journal\PDIALOG.exe
2014-09-03 06:18 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-09-03 06:18 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2014-09-03 06:17 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-09-03 06:17 . 2014-04-05 02:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-09-03 06:17 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-09-03 06:17 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-09-03 06:17 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-09-03 06:17 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-09-03 06:16 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-09-03 06:16 . 2013-07-12 09:04 73344 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2014-09-03 06:14 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-09-03 06:12 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-09-03 06:12 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-09-03 06:12 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-09-03 06:12 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-09-03 06:12 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-09-03 06:12 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-09-03 06:11 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2014-09-03 06:11 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2014-09-03 06:11 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-09-03 06:11 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-09-03 06:11 . 2013-06-26 23:01 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-09-03 06:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-09-03 06:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-09-03 06:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-09-03 06:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-09-03 06:10 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-09-03 06:10 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-09-03 06:09 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-09-03 06:09 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-09-03 06:09 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-09-03 06:09 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe
2014-09-03 06:09 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe
2014-09-03 06:09 . 2014-06-07 02:08 1305088 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-09-03 06:09 . 2014-06-07 02:08 149504 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-09-03 06:09 . 2014-06-07 02:08 114688 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-09-03 06:09 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2014-09-03 06:09 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\system32\msxml6.dll
2014-09-03 06:09 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-09-03 06:09 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-09-03 06:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2014-09-03 06:06 . 2014-07-08 00:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-03 06:06 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2014-09-03 06:06 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-09-03 06:06 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-09-03 06:06 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2014-09-03 06:06 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2014-09-03 06:06 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-09-03 06:06 . 2013-07-16 04:35 615936 ----a-w- c:\windows\system32\themeui.dll
2014-09-03 06:06 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-09-03 06:06 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-09-03 06:04 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-09-03 06:03 . 2013-06-29 02:07 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-09-03 06:03 . 2013-06-29 02:07 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-09-03 06:03 . 2013-06-29 02:07 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-03 11:41 . 2013-11-17 19:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-03 07:20 . 2014-09-03 07:20 203776 ----a-w- c:\windows\system32\webcheck.dll
2014-09-03 07:18 . 2014-09-03 07:18 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2014-09-02 19:30 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-09-02 19:30 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-08-06 11:55 . 2012-06-24 12:39 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-06 11:55 . 2012-06-24 12:39 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-30 02:11 . 2014-09-03 06:44 53760 ----a-w- c:\windows\apppatch\iebrshim.dll
2014-07-21 19:03 . 2014-07-21 19:03 200984 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-06-30 10:43 . 2014-06-30 10:43 121624 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-06-17 14:22 . 2014-06-17 14:22 188696 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-06-17 14:21 . 2014-06-17 14:21 197400 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-06-17 14:18 . 2014-06-17 14:18 241944 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-06-17 14:17 . 2014-06-17 14:17 147736 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-06-17 14:06 . 2014-06-17 14:06 27416 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-06-17 14:06 . 2014-06-17 14:06 21272 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2007-12-20 135168]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-09-17 152392]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
"vProt"="c:\program files\AVG Web TuneUp\vprot.exe" [2014-09-04 2680344]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-620889938-3404297717-3700568068-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-03 05:13 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 11:55]
.
2014-08-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-04 19:26
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2014\avgrsx.exe
c:\program files\AVG\AVG2014\avgcsrvx.exe
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\AVG\AVG2014\avgidsagent.exe
c:\program files\AVG\AVG2014\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe
c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\loggingserver.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\windows\System32\WUDFHost.exe
c:\program files\AVG\AVG2014\avgnsx.exe
c:\program files\AVG\AVG2014\avgemcx.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2014-09-04 19:31:07 - machine was rebooted
ComboFix-quarantined-files.txt 2014-09-04 17:31
.
Pre-Run: 74 367 688 704 bytes free
Post-Run: 74 170 261 504 bytes free
.
- - End Of File - - C9A6D55563E233071CF7A4AD4A3642B4
5C616939100B85E558DA92B899A0FC36
Re: Prosim o kontrolu

Márty84 píše:Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.

Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Prosim o kontrolu
# AdwCleaner v3.309 - Report created 04/09/2014 at 21:18:01
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Milan - DOMA-PC
# Running from : C:\Users\Milan\Desktop\adwcleaner_3.309.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
-\\ Google Chrome v37.0.2062.103
[ File : C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R3].txt - [2518 octets] - [04/09/2014 21:16:30]
AdwCleaner[S2].txt - [2483 octets] - [04/09/2014 21:18:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2543 octets] ##########
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Milan - DOMA-PC
# Running from : C:\Users\Milan\Desktop\adwcleaner_3.309.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16563
-\\ Google Chrome v37.0.2062.103
[ File : C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R3].txt - [2518 octets] - [04/09/2014 21:16:30]
AdwCleaner[S2].txt - [2483 octets] - [04/09/2014 21:18:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2543 octets] ##########
Re: Prosim o kontrolu
RSIT ma 124340 znaků takze sa neda poslat. Maximální povolený počet znaků je 100000.
Re: Prosim o kontrolu
Rozdelte ho do dvou prispevku.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).