Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problémy s psaním háčků a čárek

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Problémy s psaním háčků a čárek

#1 Příspěvek od Dragonsired1 »

Dobrý den. Vím že tenhle problém se tu řešil už několikrát, ale aˇˇt dělám jakýkoliv postup tady zmíněný vůbec mi to nepomahá, a už ani nevím co stáhnout. Klávesnici mám sice starší, ale klávesnicí ti není, dělá to jak na mé externí tak na notebooku. Prosím poradte jak se toho svináka zbavit. Dokonce, jsem musel odstranit oprávnění pro Trustedinstaller ve system32, vzal mi oprávnění a nic jsem nemohl dělat. Každopádně problém s háčky a čárkami stále přetrvává.

prosím porˇˇdte.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:01, on 5.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Users\Martin\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\WhatPulse2\whatpulse.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Windows\AsScrPro.exe
C:\Users\Martin\AppData\Roaming\synchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Martin\Downloads\hijackthis.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - D:\Program Files\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Martin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_B3FBEF5462B7ECF3CF8933E4FE9764B6] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [WhatPulse] "C:\Program Files (x86)\WhatPulse2\whatpulse.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [synchost] C:\Users\Martin\AppData\Roaming\synchost.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: register.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Se&nd to OneNote - res://D:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14776 bytes

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problémy s psaním háčků a čárek

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Dejte log z FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100 jelikoz HJT je jiz nekolik let nedostatecny
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#3 Příspěvek od Dragonsired1 »

Zdravím :)

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02
Ran by Martin (administrator) on MARTIN-PC on 05-09-2014 15:59:28
Running from C:\Users\Martin\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\ASPG.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(BitTorrent Inc.) C:\Users\Martin\AppData\Roaming\uTorrent\uTorrent.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\WhatPulse2\whatpulse.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Windows\AsScrPro.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
() C:\Users\Martin\AppData\Roaming\synchost.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Trend Micro Inc.) C:\Users\Martin\Downloads\hijackthis.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [635784 2010-01-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-06-16] (Microsoft Corporation)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21652064 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [uTorrent] => C:\Users\Martin\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-03] (BitTorrent Inc.)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22734160 2014-08-08] (Google)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [GoogleChromeAutoLaunch_B3FBEF5462B7ECF3CF8933E4FE9764B6] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-30] (Google Inc.)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [WhatPulse] => C:\Program Files (x86)\WhatPulse2\whatpulse.exe [3054592 2014-04-17] ()
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [Facebook Update] => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-07-10] (Facebook Inc.)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [synchost] => C:\Users\Martin\AppData\Roaming\synchost.exe [1654784 2014-09-05] ()
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\MountPoints2: {08fe45c8-f463-11e3-8aa7-0025d3b094f1} - G:\Start.exe
HKU\S-1-5-21-1487655845-786866156-960716543-1000\...\MountPoints2: {1e2fc684-0fda-11e4-9178-0025d3b094f1} - J:\iStudio.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\register.exe ()
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=U218DHP&pc=U218
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ASUT
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> D:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Partner BHO Class -> {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} -> C:\ProgramData\Partner\Partner64.dll (Google Inc.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> D:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 12.0 Helper -> {432dd630-7e03-4c97-9d62-b99f52df4fc2} -> D:\Program Files\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Partner BHO Class -> {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} -> C:\ProgramData\Partner\Partner.dll (Google Inc.)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Toolbar Helper -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - D:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 178.72.241.110 10.152.32.1

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> D:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: redgiant.com/RGMediaPlayer -> C:\Program Files (x86)\Red Giant\BulletProof\npRGMediaPlayer.dll (Red Giant)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox
FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox [2014-06-15]

Chrome:
=======
CHR HomePage: Default -> hxxp://search.babylon.com/?babsrc=HP_ss&affID=101434&mntrId=88da94750000000000001a4bd6aa0be5
CHR StartupUrls: Default -> "hxxp://isearch.avg.com/?cid={4F844922-18B1-4E72-BB1C-0FC85BABD218}&mid=1e5893719f0247d0a332d16c95547d02-1c27e0904dbf99beaef8dfeb7a225ce2fdbfc411&lang=en&ds=yu012&pr=sa&d=2012-05-28 22:01:10&v=11.1.0.7&sap=hp", "hxxp://www.searchnu.com/421", "https://isearch.avg.com/?cid={B232DBD8- ... 2012-09-01 18:00:19&v=12.2.0.5&sap=hp", "hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod=ASUT", "hxxp://www.claro-search.com/?affID=120129&babs ... 5b394dfb4a", "hxxp://www.google.com/", "hxxp://websearch.a-searchpage.info/?pid=1058&r=2013/06/02&hid=3528227852&lg=EN&cc=CZ&unqvl=18", "", "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP&dt=062013"
CHR DefaultSearchKeyword: Default -> 63DE02E9B4B5A24AA02A1B65192E7AFB39F164EBA8010865B311CF9BCA6388FD
CHR DefaultSearchURL: Default -> 1C8B6A1E15473AA0CA7F9B1FD84BF003E6E4005E08AA682DCB7CC6C9BC780185
CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Theme Creator) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2014-06-14]
CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-14]
CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-14]
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-14]
CHR Extension: (Google Cast) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-06-14]
CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-14]
CHR Extension: (Cesta do zěmě Oz) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgmbnhmcbgnenhcjpmgfhneiiamfijel [2014-06-14]
CHR Extension: (Skyrim: Book of the Dragonborn Theme) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioigkhgefneinlgdahhpddckbpofpnfi [2014-06-14]
CHR Extension: (Peněženka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-14]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-14]
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2014-06-15]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-10-01] (Intel Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-10-01] (Intel Corporation) [File not signed]
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-06-18] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-15] (Disc Soft Ltd)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-06-18] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-05 15:59 - 2014-09-05 16:00 - 00023093 _____ () C:\Users\Martin\Downloads\FRST.txt
2014-09-05 15:59 - 2014-09-05 15:59 - 00000000 ____D () C:\FRST
2014-09-05 15:58 - 2014-09-05 15:58 - 02104832 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe
2014-09-05 15:49 - 2014-09-05 15:55 - 00000112 _____ () C:\Windows\setupact.log
2014-09-05 15:49 - 2014-09-05 15:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-05 15:38 - 2014-09-05 15:47 - 00014778 _____ () C:\Users\Martin\Downloads\hijackthis.log
2014-09-05 15:38 - 2014-09-05 15:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Martin\Downloads\hijackthis.exe
2014-09-05 15:27 - 2014-09-05 15:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-05 15:25 - 2014-09-05 15:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-05 12:57 - 2014-09-05 12:57 - 00014290 _____ () C:\Users\Martin\Desktop\hijackthis.log
2014-09-05 12:26 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-09-05 12:26 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-09-05 12:26 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-09-05 12:25 - 2014-09-05 12:25 - 00002774 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-09-05 12:25 - 2014-09-05 12:25 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-09-05 12:25 - 2014-09-05 12:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-09-05 12:24 - 2014-09-05 12:25 - 00000000 ____D () C:\Program Files\CCleaner
2014-09-05 10:39 - 2014-09-05 12:39 - 01654784 _____ () C:\Users\Martin\AppData\Roaming\synchost.exe
2014-09-03 16:01 - 2014-09-03 16:01 - 36801106 _____ () C:\Users\Martin\Desktop\Castle3.mp4
2014-09-03 12:41 - 2014-09-03 12:41 - 36617426 _____ () C:\Users\Martin\Desktop\Castle2.mp4
2014-08-27 19:34 - 2014-08-27 19:34 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\dvdcss
2014-08-27 19:26 - 2014-08-27 19:26 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis
2014-08-27 19:26 - 2014-08-27 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis
2014-08-27 19:19 - 2014-09-05 12:39 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Windowssettings
2014-08-27 19:19 - 2014-08-27 20:27 - 00000000 ____D () C:\wintemp
2014-08-24 12:05 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-24 12:05 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-24 12:05 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-24 12:05 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-24 12:05 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-24 12:05 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-24 12:05 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-24 12:05 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-24 12:04 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-24 12:04 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-24 12:04 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-24 12:04 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-24 12:04 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-24 12:04 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-24 12:04 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-24 12:04 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-24 12:04 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-24 12:04 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-24 12:04 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-24 12:04 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-24 12:04 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-24 12:04 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-24 12:04 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-24 12:04 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-24 12:04 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-24 12:04 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-24 12:04 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-24 12:04 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-24 12:04 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-24 12:04 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-24 12:04 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-24 12:04 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-24 12:04 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-24 12:04 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-24 12:04 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-24 12:04 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-24 12:04 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-24 12:04 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-24 12:04 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-24 12:04 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-24 12:04 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-24 12:04 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-24 12:04 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-24 12:04 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-24 12:04 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-24 12:04 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-24 12:04 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-24 12:04 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-24 12:04 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-24 12:04 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-24 12:04 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-24 12:04 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-24 12:04 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-24 12:04 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-24 12:04 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-24 12:04 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-24 12:04 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-24 12:04 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-24 12:04 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-24 12:04 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-24 12:04 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-24 12:04 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-24 12:04 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-24 12:04 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-24 12:04 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-24 12:04 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-24 12:04 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-08-24 12:04 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-08-24 12:03 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-24 12:03 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-24 12:03 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-24 12:03 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-24 12:03 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-24 12:03 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-24 12:03 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-24 12:02 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-24 12:02 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-24 12:02 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-23 11:15 - 2014-08-23 11:15 - 00003662 _____ () C:\Windows\System32\Tasks\Red Giant Link
2014-08-23 11:15 - 2014-08-23 11:15 - 00000000 ____D () C:\Program Files (x86)\Red Giant Link
2014-08-23 11:04 - 2014-08-23 11:15 - 00000000 ____D () C:\ProgramData\Red Giant
2014-08-23 11:04 - 2014-08-23 11:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
2014-08-23 11:04 - 2014-08-23 11:04 - 00001183 _____ () C:\Users\Public\Desktop\BulletProof.lnk
2014-08-23 11:04 - 2014-08-23 11:04 - 00000965 _____ () C:\Users\Public\Desktop\PluralEyes 3.5.lnk
2014-08-23 11:04 - 2014-08-23 11:04 - 00000000 ____D () C:\ProgramData\RedGiant
2014-08-23 11:03 - 2014-08-23 11:14 - 00000000 ____D () C:\Program Files (x86)\Red Giant
2014-08-23 11:03 - 2014-08-23 11:03 - 00000000 ____D () C:\Program Files\Red Giant
2014-08-23 11:03 - 2014-08-13 08:14 - 00000129 _____ () C:\Users\Martin\Desktop\VR.nfo
2014-08-18 21:39 - 2014-08-19 23:59 - 00000000 ____D () C:\Users\Martin\Documents\Harry Potter II
2014-08-18 21:26 - 2014-08-18 21:26 - 00000989 _____ () C:\Users\Public\Desktop\Harry Potter and the Chamber of Secrets.lnk
2014-08-18 21:01 - 2014-08-18 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2014-08-18 21:00 - 2014-08-18 21:00 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-08-18 20:59 - 2014-08-18 20:59 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2014-08-18 20:59 - 2014-08-18 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2014-08-16 17:34 - 2014-08-16 18:44 - 02148351 _____ () C:\Users\Martin\Desktop\kongres.c4d
2014-08-16 12:35 - 2014-08-16 20:41 - 00000000 ____D () C:\Users\Martin\Desktop\illum
2014-08-16 11:46 - 2014-09-03 12:40 - 00000000 ____D () C:\Users\Martin\Desktop\Castlepic HD
2014-08-16 09:54 - 2014-08-16 09:55 - 00738471 _____ () C:\Users\Martin\Desktop\castle3.c4d
2014-08-14 21:47 - 2014-08-14 21:54 - 67519138 _____ () C:\Users\Martin\Desktop\videoplayback
2014-08-14 19:26 - 2014-08-14 19:50 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\creeperworld3
2014-08-14 19:26 - 2014-08-14 19:26 - 00000743 _____ () C:\Users\Martin\Desktop\Creeper World 3.lnk
2014-08-14 19:26 - 2014-08-14 19:26 - 00000000 ____D () C:\Users\Martin\Documents\creeperworld3
2014-08-14 19:26 - 2014-08-14 19:26 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\.mono
2014-08-14 19:14 - 2014-08-14 19:14 - 01636302 _____ () C:\Users\Martin\Desktop\Castlebou.c4d
2014-08-14 19:03 - 2014-08-14 19:03 - 00000000 ____D () C:\Users\Martin\Documents\SafeNet Sentinel
2014-08-14 19:01 - 2014-08-14 19:01 - 00002491 _____ () C:\Users\Public\Desktop\boujou 5.0.lnk
2014-08-14 19:01 - 2014-08-14 19:01 - 00000000 ____D () C:\ProgramData\SafeNet Sentinel
2014-08-14 19:01 - 2014-08-14 19:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vicon
2014-08-14 19:01 - 2014-08-14 19:01 - 00000000 ____D () C:\Program Files (x86)\Vicon
2014-08-14 16:38 - 2014-08-14 16:38 - 00000855 _____ () C:\Users\Public\Desktop\Democracy 3.lnk
2014-08-14 16:38 - 2014-08-14 16:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2014-08-14 10:54 - 2014-08-14 10:57 - 00000000 ____D () C:\Users\Martin\Desktop\Castlepic
2014-08-14 10:47 - 2014-08-16 12:55 - 00957011 _____ () C:\Users\Martin\Desktop\Castle2.c4d
2014-08-14 10:19 - 2014-08-14 10:31 - 00837388 _____ () C:\Users\Martin\Desktop\Castle.c4d
2014-08-14 09:52 - 2014-08-14 11:04 - 06929631 _____ () C:\Users\Martin\Desktop\Castle.mp4
2014-08-13 01:00 - 2014-08-13 01:00 - 04575232 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-05 16:00 - 2014-09-05 15:59 - 00023093 _____ () C:\Users\Martin\Downloads\FRST.txt
2014-09-05 15:59 - 2014-09-05 15:59 - 00000000 ____D () C:\FRST
2014-09-05 15:59 - 2014-06-14 23:29 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype
2014-09-05 15:58 - 2014-09-05 15:58 - 02104832 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe
2014-09-05 15:58 - 2014-07-02 10:29 - 00000000 ____D () C:\Users\Martin\AppData\Local\WhatPulse
2014-09-05 15:58 - 2014-06-15 10:25 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\uTorrent
2014-09-05 15:57 - 2010-04-17 07:03 - 00000966 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-05 15:55 - 2014-09-05 15:49 - 00000112 _____ () C:\Windows\setupact.log
2014-09-05 15:49 - 2014-09-05 15:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-05 15:47 - 2014-09-05 15:38 - 00014778 _____ () C:\Users\Martin\Downloads\hijackthis.log
2014-09-05 15:38 - 2014-09-05 15:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Martin\Downloads\hijackthis.exe
2014-09-05 15:27 - 2014-09-05 15:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-05 15:25 - 2014-09-05 15:25 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Martin\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-05 14:31 - 2014-07-10 20:26 - 00000932 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000UA.job
2014-09-05 13:07 - 2010-04-17 06:40 - 01324800 ____N () C:\Windows\WindowsUpdate.log
2014-09-05 12:57 - 2014-09-05 12:57 - 00014290 _____ () C:\Users\Martin\Desktop\hijackthis.log
2014-09-05 12:44 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-05 12:44 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-05 12:43 - 2009-08-03 22:00 - 00668792 _____ () C:\Windows\system32\perfh005.dat
2014-09-05 12:43 - 2009-08-03 22:00 - 00141420 _____ () C:\Windows\system32\perfc005.dat
2014-09-05 12:43 - 2009-07-14 07:13 - 01583226 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-05 12:39 - 2014-09-05 10:39 - 01654784 _____ () C:\Users\Martin\AppData\Roaming\synchost.exe
2014-09-05 12:39 - 2014-08-27 19:19 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Windowssettings
2014-09-05 12:38 - 2014-06-17 10:53 - 00000000 ___RD () C:\Users\Martin\Disk Google
2014-09-05 12:37 - 2010-04-17 07:39 - 00002103 _____ () C:\Windows\system32\AutoRunFilter.ini
2014-09-05 12:37 - 2010-04-17 07:03 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-05 12:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-05 12:37 - 2009-07-14 06:45 - 05060048 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-05 12:30 - 2014-06-15 10:13 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
2014-09-05 12:28 - 2014-07-02 10:34 - 00000000 ____D () C:\Windows\Minidump
2014-09-05 12:28 - 2014-06-30 17:40 - 00000000 ____D () C:\Users\Martin\AppData\Local\CrashDumps
2014-09-05 12:28 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther
2014-09-05 12:25 - 2014-09-05 12:25 - 00002774 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-09-05 12:25 - 2014-09-05 12:25 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-09-05 12:25 - 2014-09-05 12:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-09-05 12:25 - 2014-09-05 12:24 - 00000000 ____D () C:\Program Files\CCleaner
2014-09-04 20:31 - 2014-07-10 20:26 - 00000910 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000Core.job
2014-09-03 16:01 - 2014-09-03 16:01 - 36801106 _____ () C:\Users\Martin\Desktop\Castle3.mp4
2014-09-03 12:41 - 2014-09-03 12:41 - 36617426 _____ () C:\Users\Martin\Desktop\Castle2.mp4
2014-09-03 12:40 - 2014-08-16 11:46 - 00000000 ____D () C:\Users\Martin\Desktop\Castlepic HD
2014-09-02 21:01 - 2014-06-15 10:17 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\MAXON
2014-09-02 20:59 - 2014-06-15 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON
2014-08-28 00:38 - 2014-07-05 11:51 - 00000000 ____D () C:\Users\Martin\AppData\Local\Deployment
2014-08-27 20:27 - 2014-08-27 19:19 - 00000000 ____D () C:\wintemp
2014-08-27 19:34 - 2014-08-27 19:34 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\dvdcss
2014-08-27 19:26 - 2014-08-27 19:26 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis
2014-08-27 19:26 - 2014-08-27 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis
2014-08-27 19:21 - 2010-04-17 06:59 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-24 18:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-24 12:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-24 12:18 - 2014-06-15 14:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-24 12:12 - 2014-06-15 14:23 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-23 11:15 - 2014-08-23 11:15 - 00003662 _____ () C:\Windows\System32\Tasks\Red Giant Link
2014-08-23 11:15 - 2014-08-23 11:15 - 00000000 ____D () C:\Program Files (x86)\Red Giant Link
2014-08-23 11:15 - 2014-08-23 11:04 - 00000000 ____D () C:\ProgramData\Red Giant
2014-08-23 11:15 - 2014-08-23 11:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
2014-08-23 11:15 - 2014-06-14 23:07 - 00000000 ____D () C:\Users\Martin
2014-08-23 11:14 - 2014-08-23 11:03 - 00000000 ____D () C:\Program Files (x86)\Red Giant
2014-08-23 11:14 - 2014-06-15 12:22 - 00000000 ____D () C:\Program Files\Adobe
2014-08-23 11:04 - 2014-08-23 11:04 - 00001183 _____ () C:\Users\Public\Desktop\BulletProof.lnk
2014-08-23 11:04 - 2014-08-23 11:04 - 00000965 _____ () C:\Users\Public\Desktop\PluralEyes 3.5.lnk
2014-08-23 11:04 - 2014-08-23 11:04 - 00000000 ____D () C:\ProgramData\RedGiant
2014-08-23 11:03 - 2014-08-23 11:03 - 00000000 ____D () C:\Program Files\Red Giant
2014-08-23 04:07 - 2014-09-05 12:26 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-09-05 12:26 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-09-05 12:26 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 21:22 - 2014-06-21 18:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Synthesia
2014-08-19 23:59 - 2014-08-18 21:39 - 00000000 ____D () C:\Users\Martin\Documents\Harry Potter II
2014-08-18 21:39 - 2014-06-25 12:26 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-18 21:26 - 2014-08-18 21:26 - 00000989 _____ () C:\Users\Public\Desktop\Harry Potter and the Chamber of Secrets.lnk
2014-08-18 21:01 - 2014-08-18 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2014-08-18 21:00 - 2014-08-18 21:00 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-08-18 20:59 - 2014-08-18 20:59 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2014-08-18 20:59 - 2014-08-18 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2014-08-16 20:41 - 2014-08-16 12:35 - 00000000 ____D () C:\Users\Martin\Desktop\illum
2014-08-16 18:44 - 2014-08-16 17:34 - 02148351 _____ () C:\Users\Martin\Desktop\kongres.c4d
2014-08-16 13:58 - 2014-06-17 10:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-08-16 12:55 - 2014-08-14 10:47 - 00957011 _____ () C:\Users\Martin\Desktop\Castle2.c4d
2014-08-16 09:55 - 2014-08-16 09:54 - 00738471 _____ () C:\Users\Martin\Desktop\castle3.c4d
2014-08-14 22:02 - 2014-07-21 15:59 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\vlc
2014-08-14 21:54 - 2014-08-14 21:47 - 67519138 _____ () C:\Users\Martin\Desktop\videoplayback
2014-08-14 19:50 - 2014-08-14 19:26 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\creeperworld3
2014-08-14 19:26 - 2014-08-14 19:26 - 00000743 _____ () C:\Users\Martin\Desktop\Creeper World 3.lnk
2014-08-14 19:26 - 2014-08-14 19:26 - 00000000 ____D () C:\Users\Martin\Documents\creeperworld3
2014-08-14 19:26 - 2014-08-14 19:26 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\.mono
2014-08-14 19:14 - 2014-08-14 19:14 - 01636302 _____ () C:\Users\Martin\Desktop\Castlebou.c4d
2014-08-14 19:03 - 2014-08-14 19:03 - 00000000 ____D () C:\Users\Martin\Documents\SafeNet Sentinel
2014-08-14 19:01 - 2014-08-14 19:01 - 00002491 _____ () C:\Users\Public\Desktop\boujou 5.0.lnk
2014-08-14 19:01 - 2014-08-14 19:01 - 00000000 ____D () C:\ProgramData\SafeNet Sentinel
2014-08-14 19:01 - 2014-08-14 19:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vicon
2014-08-14 19:01 - 2014-08-14 19:01 - 00000000 ____D () C:\Program Files (x86)\Vicon
2014-08-14 16:39 - 2014-06-15 12:40 - 00000000 ____D () C:\Users\Martin\Documents\My Games
2014-08-14 16:38 - 2014-08-14 16:38 - 00000855 _____ () C:\Users\Public\Desktop\Democracy 3.lnk
2014-08-14 16:38 - 2014-08-14 16:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2014-08-14 16:38 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-14 11:04 - 2014-08-14 09:52 - 06929631 _____ () C:\Users\Martin\Desktop\Castle.mp4
2014-08-14 10:57 - 2014-08-14 10:54 - 00000000 ____D () C:\Users\Martin\Desktop\Castlepic
2014-08-14 10:31 - 2014-08-14 10:19 - 00837388 _____ () C:\Users\Martin\Desktop\Castle.c4d
2014-08-13 09:10 - 2014-06-14 23:29 - 00000000 ____D () C:\ProgramData\Skype
2014-08-13 08:14 - 2014-08-23 11:03 - 00000129 _____ () C:\Users\Martin\Desktop\VR.nfo
2014-08-13 01:00 - 2014-08-13 01:00 - 04575232 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2014-08-10 14:57 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-27 13:33

==================== End Of Log ============================

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#4 Příspěvek od Dragonsired1 »

Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

djmirente
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 27 dub 2009 13:38

Re: Problémy s psaním háčků a čárek

#5 Příspěvek od djmirente »

Dragonsired1 píše:Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"? Pretože mne to spôsoboval ten..

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#6 Příspěvek od Dragonsired1 »

djmirente píše:
Dragonsired1 píše:Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"? Pretože mne to spôsoboval ten..

To nevím jistě, ale proč mi tedy kellner.exe odebral administrátorská práva pro system32? Nebo se jedná o totéž?!
Každopádně jakým způsobem bych mohl eliminovat keylogger?

djmirente
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 27 dub 2009 13:38

Re: Problémy s psaním háčků a čárek

#7 Příspěvek od djmirente »

Dragonsired1 píše:
djmirente píše:
Dragonsired1 píše:Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"? Pretože mne to spôsoboval ten..

To nevím jistě, ale proč mi tedy kellner.exe odebral administrátorská práva pro system32? Nebo se jedná o totéž?!
Každopádně jakým způsobem bych mohl eliminovat keylogger?
Ako som písal nechcem niekomu do toho kafrať ... Keylogger je program ktorý zaznamenáva všetko čo sa týka kláves v konečnom dôsledku je to PROGRAM ale neviem so 100%nou istotou povedať, že je to ten istý problém ako som mal ja ..

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#8 Příspěvek od Dragonsired1 »

djmirente píše:
Dragonsired1 píše:
djmirente píše:
Dragonsired1 píše:Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"? Pretože mne to spôsoboval ten..

To nevím jistě, ale proč mi tedy kellner.exe odebral administrátorská práva pro system32? Nebo se jedná o totéž?!
Každopádně jakým způsobem bych mohl eliminovat keylogger?
Ako som písal nechcem niekomu do toho kafrať ... Keylogger je program ktorý zaznamenáva všetko čo sa týka kláves v konečnom dôsledku je to PROGRAM ale neviem so 100%nou istotou povedať, že je to ten istý problém ako som mal ja ..
Mám nainstalovaný WhatPulse... odinstalace nic nevyřešila

djmirente
Návštěvník
Návštěvník
Příspěvky: 127
Registrován: 27 dub 2009 13:38

Re: Problémy s psaním háčků a čárek

#9 Příspěvek od djmirente »

Dragonsired1 píše:
djmirente píše:
Dragonsired1 píše:
djmirente píše:
Dragonsired1 píše:Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"? Pretože mne to spôsoboval ten..

To nevím jistě, ale proč mi tedy kellner.exe odebral administrátorská práva pro system32? Nebo se jedná o totéž?!
Každopádně jakým způsobem bych mohl eliminovat keylogger?
Ako som písal nechcem niekomu do toho kafrať ... Keylogger je program ktorý zaznamenáva všetko čo sa týka kláves v konečnom dôsledku je to PROGRAM ale neviem so 100%nou istotou povedať, že je to ten istý problém ako som mal ja ..
Mám nainstalovaný WhatPulse... odinstalace nic nevyřešila
reštart ste skúsili?

edit: aspoň som to skúsil good luck :)

edit: užívateľ vyosek
Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"?
Naposledy upravil(a) djmirente dne 05 zář 2014 18:30, celkem upraveno 2 x.

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#10 Příspěvek od Dragonsired1 »

djmirente píše:
Dragonsired1 píše:
djmirente píše:
Dragonsired1 píše:
djmirente píše:
Dragonsired1 píše:Už si ani nevím rady, projetí antivirem nic, navíc by to trvalo neuvěřitelné hodiny. Spíše mám podezření na BadTrans, ale nevím jistě, ale pokud ano, raději nikam nebudu zadávat heslo...

Nechce sa tu starať do práce odborníkov ale nemáte náhodou nejaký "keylogger"? Pretože mne to spôsoboval ten..

To nevím jistě, ale proč mi tedy kellner.exe odebral administrátorská práva pro system32? Nebo se jedná o totéž?!
Každopádně jakým způsobem bych mohl eliminovat keylogger?
Ako som písal nechcem niekomu do toho kafrať ... Keylogger je program ktorý zaznamenáva všetko čo sa týka kláves v konečnom dôsledku je to PROGRAM ale neviem so 100%nou istotou povedať, že je to ten istý problém ako som mal ja ..
Mám nainstalovaný WhatPulse... odinstalace nic nevyřešila
reštart ste skúsili?
Restart nikterak nepomohl

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problémy s psaním háčků a čárek

#11 Příspěvek od vyosek »

:arrow: Uzivatel djmirente se tu nebude michat do reseni logu, jelikoz radi kravoviny a nesmysly - PC je plny bordelu

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#12 Příspěvek od Dragonsired1 »

Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/05/2014 07:29:06 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 activation.cloud.techsmith.com
127.0.0.1 oscount.techsmith.com

Program finished at: 09/05/2014 07:29:18 PM
Execution time: 0 hours(s), 0 minute(s), and 12 seconds(s)


ComboFix 14-09-05.01 - Martin 05.09.2014 19:33:11.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.974 [GMT 2:00]
Spuštěný z: c:\users\Martin\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\users\Martin\AppData\Local\Temp\_MEI35682\_ctypes.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\_elementtree.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\_hashlib.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\_multiprocessing.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\_socket.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\_ssl.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\hashobjs_ext.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\pyexpat.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\pysqlite2._sqlite.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\python27.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\pythoncom27.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\PyWinTypes27.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\select.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\unicodedata.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32api.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32com.shell.shell.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32crypt.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32event.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32file.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32gui.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32inet.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32pdh.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32pipe.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32process.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32profile.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32security.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\win32ts.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\windows._lib_cacheinvalidation.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._animate.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._controls_.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._core_.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._gdi_.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._html2.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._misc_.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._windows_.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wx._wizard.pyd
c:\users\Martin\AppData\Local\Temp\_MEI35682\wxbase294u_net_vc90.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\wxbase294u_vc90.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\wxmsw294u_adv_vc90.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\wxmsw294u_core_vc90.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\wxmsw294u_html_vc90.dll
c:\users\Martin\AppData\Local\Temp\_MEI35682\wxmsw294u_webview_vc90.dll
c:\users\Martin\AppData\Roaming\dclogs
c:\users\Martin\AppData\Roaming\dclogs\2014-09-05-6.dc
D:\install.exe
F:\Autorun.inf
F:\install.exe
F:\Setup.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-05 do 2014-09-05 )))))))))))))))))))))))))))))))
.
.
2014-09-05 17:50 . 2014-09-05 17:50 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{24E7D923-4367-4600-B13B-D7743EDBAE5A}\offreg.dll
2014-09-05 13:59 . 2014-09-05 14:01 -------- d-----w- C:\FRST
2014-09-05 13:34 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{24E7D923-4367-4600-B13B-D7743EDBAE5A}\mpengine.dll
2014-09-05 13:27 . 2014-09-05 13:27 -------- d-----w- c:\programdata\Malwarebytes
2014-09-05 10:49 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-09-05 10:26 . 2014-08-23 00:59 3163648 ----a-w- c:\windows\system32\win32k.sys
2014-09-05 10:26 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-09-05 10:26 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-09-05 10:24 . 2014-09-05 10:25 -------- d-----w- c:\program files\CCleaner
2014-09-05 08:39 . 2014-09-05 16:38 1654784 ----a-w- c:\users\Martin\AppData\Roaming\synchost.exe
2014-09-02 18:49 . 2014-09-02 18:49 -------- d-----w- c:\program files (x86)\Common Files\Intel
2014-08-29 08:35 . 2014-08-20 07:26 1169712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3AE55855-3C57-4AE1-ACA5-315095287B80}\gapaengine.dll
2014-08-27 17:34 . 2014-08-27 17:34 -------- d-----w- c:\users\Martin\AppData\Roaming\dvdcss
2014-08-27 17:19 . 2014-09-05 16:38 -------- d-----w- c:\users\Martin\AppData\Roaming\Windowssettings
2014-08-27 17:19 . 2014-08-27 18:27 -------- d-----w- C:\wintemp
2014-08-24 10:05 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-24 10:05 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-08-24 10:05 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-08-24 10:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-08-24 10:05 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-24 10:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-08-24 10:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-24 10:05 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-24 10:03 . 2014-06-03 10:02 3241984 ----a-w- c:\windows\system32\msi.dll
2014-08-24 10:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\SysWow64\msi.dll
2014-08-24 10:03 . 2014-06-03 10:02 112064 ----a-w- c:\windows\system32\consent.exe
2014-08-24 10:03 . 2014-06-03 10:02 504320 ----a-w- c:\windows\system32\msihnd.dll
2014-08-24 10:03 . 2014-06-03 10:02 1941504 ----a-w- c:\windows\system32\authui.dll
2014-08-24 10:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2014-08-24 10:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2014-08-24 10:02 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-08-24 10:02 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-08-24 10:02 . 2014-06-16 02:10 985536 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-08-23 09:15 . 2014-08-23 09:15 -------- d-----w- c:\program files (x86)\Red Giant Link
2014-08-23 09:04 . 2014-08-23 09:04 -------- d-----w- c:\programdata\RedGiant
2014-08-23 09:04 . 2014-08-23 09:15 -------- d-----w- c:\programdata\Red Giant
2014-08-23 09:03 . 2014-08-23 09:03 -------- d-----w- c:\program files\Red Giant
2014-08-23 09:03 . 2014-08-23 09:14 -------- d-----w- c:\program files (x86)\Red Giant
2014-08-18 19:00 . 2014-08-18 19:00 -------- d-----w- c:\program files (x86)\Electronic Arts
2014-08-18 18:58 . 2000-01-04 04:39 212992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2014-08-14 17:26 . 2014-08-14 17:26 -------- d-----w- c:\users\Martin\AppData\Roaming\.mono
2014-08-14 17:26 . 2014-08-14 17:50 -------- d-----w- c:\users\Martin\AppData\Roaming\creeperworld3
2014-08-14 17:01 . 2014-08-14 17:01 -------- d-----w- c:\programdata\SafeNet Sentinel
2014-08-14 17:01 . 2014-08-14 17:01 -------- d-----w- c:\program files (x86)\Vicon
2014-08-13 07:11 . 2014-08-13 07:11 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-08-12 23:00 . 2014-08-12 23:00 4575232 ----a-w- c:\windows\SysWow64\GPhotos.scr
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-24 10:12 . 2014-06-15 12:23 99218768 ----a-w- c:\windows\system32\MRT.exe
2014-08-20 07:26 . 2014-06-17 08:33 1169712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-06-21 17:01 . 2014-06-21 17:01 94720 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2014-06-21 16:59 . 2014-06-21 16:59 110080 ----a-w- c:\windows\system32\DelayAPO.dll
2014-06-21 11:58 . 2014-06-21 11:58 2857824 ----a-w- c:\programdata\Microsoft\VisualStudio\12.0\1033\ResourceCache.dll
2014-06-21 10:48 . 2014-06-21 10:48 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-06-21 10:48 . 2014-06-21 10:48 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-06-21 10:48 . 2014-06-21 10:48 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-06-21 10:48 . 2014-06-21 10:48 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-06-21 10:48 . 2014-06-21 10:48 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-06-21 10:48 . 2014-06-21 10:48 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-06-21 10:48 . 2014-06-21 10:48 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-06-21 10:48 . 2014-06-21 10:48 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-06-21 10:48 . 2014-06-21 10:48 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-06-21 10:48 . 2014-06-21 10:48 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-06-21 10:48 . 2014-06-21 10:48 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-06-21 10:48 . 2014-06-21 10:48 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-06-21 10:48 . 2014-06-21 10:48 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-06-21 10:48 . 2014-06-21 10:48 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-06-21 10:48 . 2014-06-21 10:48 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-06-21 10:48 . 2014-06-21 10:48 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-06-21 10:48 . 2014-06-21 10:48 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-06-21 10:48 . 2014-06-21 10:48 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-06-21 10:48 . 2014-06-21 10:48 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-06-21 10:48 . 2014-06-21 10:48 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-06-21 10:48 . 2014-06-21 10:48 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-06-21 10:48 . 2014-06-21 10:48 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-06-21 10:48 . 2014-06-21 10:48 247808 ----a-w- c:\windows\system32\msls31.dll
2014-06-21 10:48 . 2014-06-21 10:48 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-06-21 10:48 . 2014-06-21 10:48 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-06-21 10:48 . 2014-06-21 10:48 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-06-21 10:48 . 2014-06-21 10:48 81408 ----a-w- c:\windows\system32\icardie.dll
2014-06-21 10:48 . 2014-06-21 10:48 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-06-21 10:48 . 2014-06-21 10:48 413696 ----a-w- c:\windows\system32\html.iec
2014-06-21 10:48 . 2014-06-21 10:48 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-06-21 10:48 . 2014-06-21 10:48 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-06-21 10:48 . 2014-06-21 10:48 235520 ----a-w- c:\windows\system32\url.dll
2014-06-21 10:48 . 2014-06-21 10:48 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-06-21 10:48 . 2014-06-21 10:48 143872 ----a-w- c:\windows\system32\wextract.exe
2014-06-21 10:48 . 2014-06-21 10:48 101376 ----a-w- c:\windows\system32\inseng.dll
2014-06-21 10:48 . 2014-06-21 10:48 774144 ----a-w- c:\windows\system32\jscript.dll
2014-06-21 10:48 . 2014-06-21 10:48 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-06-21 10:48 . 2014-06-21 10:48 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-06-21 10:48 . 2014-06-21 10:48 147968 ----a-w- c:\windows\system32\occache.dll
2014-06-21 10:48 . 2014-06-21 10:48 13824 ----a-w- c:\windows\system32\mshta.exe
2014-06-21 10:48 . 2014-06-21 10:48 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-06-21 10:46 . 2014-06-21 10:46 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-06-21 10:46 . 2014-06-21 10:46 859648 ----a-w- c:\windows\system32\tdh.dll
2014-06-21 10:46 . 2014-06-21 10:46 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-06-21 10:46 . 2014-06-21 10:46 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-06-21 10:46 . 2014-06-21 10:46 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-06-21 10:46 . 2014-06-21 10:46 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-06-21 10:46 . 2014-06-21 10:46 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-06-21 10:46 . 2014-06-21 10:46 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-06-21 10:46 . 2014-06-21 10:46 68608 ----a-w- c:\windows\system32\taskhost.exe
2014-06-21 10:45 . 2014-06-21 10:45 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-06-21 10:45 . 2014-06-21 10:45 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2014-06-21 10:45 . 2014-06-21 10:45 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2014-06-21 10:45 . 2014-06-21 10:45 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-06-21 10:45 . 2014-06-21 10:45 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-06-21 10:45 . 2014-06-21 10:45 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-06-21 10:45 . 2014-06-21 10:45 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-06-21 10:45 . 2014-06-21 10:45 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-06-21 10:45 . 2014-06-21 10:45 296960 ----a-w- c:\windows\system32\d3d10core.dll
2014-06-21 10:45 . 2014-06-21 10:45 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2014-06-21 10:45 . 2014-06-21 10:45 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2014-06-21 10:45 . 2014-06-21 10:45 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-06-21 10:45 . 2014-06-21 10:45 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-06-21 10:45 . 2014-06-21 10:45 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2014-06-21 10:45 . 2014-06-21 10:45 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2014-06-21 10:45 . 2014-06-21 10:45 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2014-06-21 10:45 . 2014-06-21 10:45 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2014-06-21 10:45 . 2014-06-21 10:45 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2014-06-21 10:45 . 2014-06-21 10:45 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2014-06-21 10:45 . 2014-06-21 10:45 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-06-21 10:45 . 2014-06-21 10:45 1238528 ----a-w- c:\windows\system32\d3d10.dll
2014-06-21 10:45 . 2014-06-21 10:45 1175552 ----a-w- c:\windows\system32\FntCache.dll
2014-06-21 10:45 . 2014-06-21 10:45 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2014-06-21 10:43 . 2014-06-21 10:43 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-06-21 10:43 . 2014-06-21 10:43 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-06-18 18:21 . 2014-06-18 18:21 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys
2014-06-18 18:21 . 2014-06-18 18:21 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2010-04-17 05:03 433648 ----a-w- c:\programdata\Partner\Partner.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-06-03 05:35 1725128 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-06-03 05:35 1725128 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-06-03 05:35 1725128 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-07-24 21652064]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"uTorrent"="c:\users\Martin\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-03 1322832]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-08-08 22734160]
"GoogleChromeAutoLaunch_B3FBEF5462B7ECF3CF8933E4FE9764B6"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-08-30 852808]
"synchost"="c:\users\Martin\AppData\Roaming\synchost.exe" [2014-09-05 1654784]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-01-05 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888]
.
c:\users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
register.exe [2014-6-8 485376]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 c2wts;Claims to Windows Token Service;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys;c:\windows\SYSNATIVE\DRIVERS\LVUSBS64.sys [x]
S3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-04 18:57 1096520 ----a-w- c:\program files (x86)\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000Core.job
- c:\users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-07-10 18:26]
.
2014-09-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000UA.job
- c:\users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-07-10 18:26]
.
2014-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-17 05:03]
.
2014-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-04-17 05:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2010-04-17 05:03 750064 ----a-w- c:\programdata\Partner\Partner64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 18:37 2322576 ----a-w- d:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 18:37 2322576 ----a-w- d:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 18:37 2322576 ----a-w- d:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office15\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Se&nd to OneNote - d:\progra~1\MICROS~1\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 178.72.241.110 10.152.32.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
c:\windows\AsScrPro.exe
.
**************************************************************************
.
Celkový čas: 2014-09-05 20:02:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-09-05 18:02
.
Před spuštěním: Volných bajtů: 58 789 462 016
Po spuštění: Volných bajtů: 58 760 036 352
.
- - End Of File - - 25827C64F44A93453FF7F7F322D40D83

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#13 Příspěvek od Dragonsired1 »

Už umím napsat Ď! Mnohokrát Vám děkuji, sice nevím jak je to možné ale už to funguje... Jen doufám že se to nevrátí nebo že to není zalezlé, tedy že už v pc nemám nic hrozného! :( I tak mnohokrát děkuji...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problémy s psaním háčků a čárek

#14 Příspěvek od vyosek »

:arrow: Jeste docistime :James008:

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    c:\users\Martin\AppData\Roaming\synchost.exe
    c:\users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\register.exe
    
    File::
    c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000Core.job
    c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000UA.job
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Skype"=-
    "uTorrent"=-
    "synchost"=-
    "DAEMON Tools Lite"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "UpdateLBPShortCut"=-
    "QuickTime Task"=-
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Dragonsired1
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 05 zář 2014 14:42

Re: Problémy s psaním háčků a čárek

#15 Příspěvek od Dragonsired1 »

Prosím log zde:

ComboFix 14-09-05.01 - Martin 05.09.2014 21:46:48.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.832 [GMT 2:00]
Spuštěný z: c:\users\Martin\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Martin\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\register.exe
c:\users\Martin\AppData\Roaming\synchost.exe
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1487655845-786866156-960716543-1000UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-05 do 2014-09-05 )))))))))))))))))))))))))))))))
.
.
2014-09-05 19:58 . 2014-09-05 19:58 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{02219DDA-421B-4BE3-93F1-58D8950A0305}\offreg.dll
2014-09-05 19:56 . 2014-09-05 19:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-05 18:05 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{02219DDA-421B-4BE3-93F1-58D8950A0305}\mpengine.dll
2014-09-05 13:59 . 2014-09-05 14:01 -------- d-----w- C:\FRST
2014-09-05 13:27 . 2014-09-05 13:27 -------- d-----w- c:\programdata\Malwarebytes
2014-09-05 10:49 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-09-05 10:26 . 2014-08-23 00:59 3163648 ----a-w- c:\windows\system32\win32k.sys
2014-09-05 10:26 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-09-05 10:26 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-09-05 10:24 . 2014-09-05 10:25 -------- d-----w- c:\program files\CCleaner
2014-09-02 18:49 . 2014-09-02 18:49 -------- d-----w- c:\program files (x86)\Common Files\Intel
2014-08-29 08:35 . 2014-08-20 07:26 1169712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3AE55855-3C57-4AE1-ACA5-315095287B80}\gapaengine.dll
2014-08-27 17:34 . 2014-08-27 17:34 -------- d-----w- c:\users\Martin\AppData\Roaming\dvdcss
2014-08-27 17:19 . 2014-09-05 16:38 -------- d-----w- c:\users\Martin\AppData\Roaming\Windowssettings
2014-08-27 17:19 . 2014-08-27 18:27 -------- d-----w- C:\wintemp
2014-08-24 10:05 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-08-24 10:05 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-08-24 10:05 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-08-24 10:05 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-08-24 10:05 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-08-24 10:05 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-08-24 10:05 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-24 10:05 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-24 10:03 . 2014-06-03 10:02 3241984 ----a-w- c:\windows\system32\msi.dll
2014-08-24 10:03 . 2014-06-03 09:29 2363392 ----a-w- c:\windows\SysWow64\msi.dll
2014-08-24 10:03 . 2014-06-03 10:02 112064 ----a-w- c:\windows\system32\consent.exe
2014-08-24 10:03 . 2014-06-03 10:02 504320 ----a-w- c:\windows\system32\msihnd.dll
2014-08-24 10:03 . 2014-06-03 10:02 1941504 ----a-w- c:\windows\system32\authui.dll
2014-08-24 10:03 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2014-08-24 10:03 . 2014-06-03 09:29 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2014-08-24 10:02 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-08-24 10:02 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-08-24 10:02 . 2014-06-16 02:10 985536 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-08-23 09:15 . 2014-08-23 09:15 -------- d-----w- c:\program files (x86)\Red Giant Link
2014-08-23 09:04 . 2014-08-23 09:04 -------- d-----w- c:\programdata\RedGiant
2014-08-23 09:04 . 2014-08-23 09:15 -------- d-----w- c:\programdata\Red Giant
2014-08-23 09:03 . 2014-08-23 09:03 -------- d-----w- c:\program files\Red Giant
2014-08-23 09:03 . 2014-08-23 09:14 -------- d-----w- c:\program files (x86)\Red Giant
2014-08-18 19:00 . 2014-08-18 19:00 -------- d-----w- c:\program files (x86)\Electronic Arts
2014-08-18 18:58 . 2000-01-04 04:39 212992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2014-08-14 17:26 . 2014-08-14 17:26 -------- d-----w- c:\users\Martin\AppData\Roaming\.mono
2014-08-14 17:26 . 2014-08-14 17:50 -------- d-----w- c:\users\Martin\AppData\Roaming\creeperworld3
2014-08-14 17:01 . 2014-08-14 17:01 -------- d-----w- c:\programdata\SafeNet Sentinel
2014-08-14 17:01 . 2014-08-14 17:01 -------- d-----w- c:\program files (x86)\Vicon
2014-08-13 07:11 . 2014-08-13 07:11 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-08-12 23:00 . 2014-08-12 23:00 4575232 ----a-w- c:\windows\SysWow64\GPhotos.scr
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-24 10:12 . 2014-06-15 12:23 99218768 ----a-w- c:\windows\system32\MRT.exe
2014-08-20 07:26 . 2014-06-17 08:33 1169712 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-06-21 17:01 . 2014-06-21 17:01 94720 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2014-06-21 16:59 . 2014-06-21 16:59 110080 ----a-w- c:\windows\system32\DelayAPO.dll
2014-06-21 11:58 . 2014-06-21 11:58 2857824 ----a-w- c:\programdata\Microsoft\VisualStudio\12.0\1033\ResourceCache.dll
2014-06-21 10:48 . 2014-06-21 10:48 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-06-21 10:48 . 2014-06-21 10:48 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-06-21 10:48 . 2014-06-21 10:48 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-06-21 10:48 . 2014-06-21 10:48 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-06-21 10:48 . 2014-06-21 10:48 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-06-21 10:48 . 2014-06-21 10:48 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-06-21 10:48 . 2014-06-21 10:48 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-06-21 10:48 . 2014-06-21 10:48 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-06-21 10:48 . 2014-06-21 10:48 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-06-21 10:48 . 2014-06-21 10:48 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-06-21 10:48 . 2014-06-21 10:48 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-06-21 10:48 . 2014-06-21 10:48 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-06-21 10:48 . 2014-06-21 10:48 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-06-21 10:48 . 2014-06-21 10:48 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-06-21 10:48 . 2014-06-21 10:48 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-06-21 10:48 . 2014-06-21 10:48 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-06-21 10:48 . 2014-06-21 10:48 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-06-21 10:48 . 2014-06-21 10:48 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-06-21 10:48 . 2014-06-21 10:48 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-06-21 10:48 . 2014-06-21 10:48 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-06-21 10:48 . 2014-06-21 10:48 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-06-21 10:48 . 2014-06-21 10:48 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-06-21 10:48 . 2014-06-21 10:48 247808 ----a-w- c:\windows\system32\msls31.dll
2014-06-21 10:48 . 2014-06-21 10:48 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-06-21 10:48 . 2014-06-21 10:48 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-06-21 10:48 . 2014-06-21 10:48 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-06-21 10:48 . 2014-06-21 10:48 81408 ----a-w- c:\windows\system32\icardie.dll
2014-06-21 10:48 . 2014-06-21 10:48 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-06-21 10:48 . 2014-06-21 10:48 413696 ----a-w- c:\windows\system32\html.iec
2014-06-21 10:48 . 2014-06-21 10:48 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-06-21 10:48 . 2014-06-21 10:48 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-06-21 10:48 . 2014-06-21 10:48 235520 ----a-w- c:\windows\system32\url.dll
2014-06-21 10:48 . 2014-06-21 10:48 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-06-21 10:48 . 2014-06-21 10:48 143872 ----a-w- c:\windows\system32\wextract.exe
2014-06-21 10:48 . 2014-06-21 10:48 101376 ----a-w- c:\windows\system32\inseng.dll
2014-06-21 10:48 . 2014-06-21 10:48 774144 ----a-w- c:\windows\system32\jscript.dll
2014-06-21 10:48 . 2014-06-21 10:48 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-06-21 10:48 . 2014-06-21 10:48 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-06-21 10:48 . 2014-06-21 10:48 147968 ----a-w- c:\windows\system32\occache.dll
2014-06-21 10:48 . 2014-06-21 10:48 13824 ----a-w- c:\windows\system32\mshta.exe
2014-06-21 10:48 . 2014-06-21 10:48 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-06-21 10:46 . 2014-06-21 10:46 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-06-21 10:46 . 2014-06-21 10:46 859648 ----a-w- c:\windows\system32\tdh.dll
2014-06-21 10:46 . 2014-06-21 10:46 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-06-21 10:46 . 2014-06-21 10:46 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-06-21 10:46 . 2014-06-21 10:46 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-06-21 10:46 . 2014-06-21 10:46 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-06-21 10:46 . 2014-06-21 10:46 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-06-21 10:46 . 2014-06-21 10:46 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-06-21 10:46 . 2014-06-21 10:46 68608 ----a-w- c:\windows\system32\taskhost.exe
2014-06-21 10:45 . 2014-06-21 10:45 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-06-21 10:45 . 2014-06-21 10:45 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2014-06-21 10:45 . 2014-06-21 10:45 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2014-06-21 10:45 . 2014-06-21 10:45 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-21 10:45 . 2014-06-21 10:45 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-06-21 10:45 . 2014-06-21 10:45 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-06-21 10:45 . 2014-06-21 10:45 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-06-21 10:45 . 2014-06-21 10:45 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-06-21 10:45 . 2014-06-21 10:45 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-06-21 10:45 . 2014-06-21 10:45 296960 ----a-w- c:\windows\system32\d3d10core.dll
2014-06-21 10:45 . 2014-06-21 10:45 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2014-06-21 10:45 . 2014-06-21 10:45 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2014-06-21 10:45 . 2014-06-21 10:45 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-06-21 10:45 . 2014-06-21 10:45 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-06-21 10:45 . 2014-06-21 10:45 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2014-06-21 10:45 . 2014-06-21 10:45 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2014-06-21 10:45 . 2014-06-21 10:45 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2014-06-21 10:45 . 2014-06-21 10:45 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2014-06-21 10:45 . 2014-06-21 10:45 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2014-06-21 10:45 . 2014-06-21 10:45 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2014-06-21 10:45 . 2014-06-21 10:45 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-06-21 10:45 . 2014-06-21 10:45 1238528 ----a-w- c:\windows\system32\d3d10.dll
2014-06-21 10:45 . 2014-06-21 10:45 1175552 ----a-w- c:\windows\system32\FntCache.dll
2014-06-21 10:45 . 2014-06-21 10:45 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2014-06-21 10:43 . 2014-06-21 10:43 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-06-21 10:43 . 2014-06-21 10:43 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-06-18 18:21 . 2014-06-18 18:21 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys
2014-06-18 18:21 . 2014-06-18 18:21 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2010-04-17 05:03 433648 ----a-w- c:\programdata\Partner\Partner.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-06-03 05:35 1725128 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-06-03 05:35 1725128 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-06-03 05:35 1725128 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-08-08 22734160]
"GoogleChromeAutoLaunch_B3FBEF5462B7ECF3CF8933E4FE9764B6"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-08-30 852808]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-01-05 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 c2wts;Claims to Windows Token Service;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe;c:\program files\Windows Identity Foundation\v3.5\c2wtshost.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;c:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys;c:\windows\SYSNATIVE\DRIVERS\LVUSBS64.sys [x]
S3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-04 18:57 1096520 ----a-w- c:\program files (x86)\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2010-04-17 05:03 750064 ----a-w- c:\programdata\Partner\Partner64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 18:37 2322576 ----a-w- d:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 18:37 2322576 ----a-w- d:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 18:37 2322576 ----a-w- d:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-08-08 08:34 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office15\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Se&nd to OneNote - d:\progra~1\MICROS~1\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 178.72.241.110 10.152.32.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Celkový čas: 2014-09-05 22:10:59 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-09-05 20:10
ComboFix2.txt 2014-09-05 18:02
.
Před spuštěním: Volných bajtů: 58 669 678 592
Po spuštění: Volných bajtů: 58 691 084 288
.
- - End Of File - - 36D8E176D4CB2CCE3E551A9CC3AECB5A

Zamčeno