Stránka 1 z 2

Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 15:49
od sexkula
Zdravíčko, mám problém stím, že mi při práci na internetu vyskakují internetové stránky všeho možného.. Vypršela mi platnost antiviráku a než jsem stihl stáhnout a aktivovat plnou verzi tak jsem chytil tenhle vir.. Prosím o pomoc.. děkuji..

LOG RSIT:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Patrikovo at 2014-09-13 16:41:27
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 36 GB (47%) free of 76 GB
Total RAM: 2038 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:42:03, on 13.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\AVG\AVG2014\avgui.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\AVG Web TuneUp\vprot.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Patrikovo\Downloads\RSIT.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Program Files\trend micro\Patrikovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.creativetoolbars.com/?src ... martbar&g=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: SmartBar Helper Object - {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: SmartBar Toolbar - {0CFBE80D-5608-4309-A0F5-3B1414833432} - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\smartbarTlbr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Web TuneUp\vprot.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: vToolbarUpdater3.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe

--
End of file - 7368 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS\AutoKMS.exe
C:\Windows\tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-1.job - C:\Program Files\Shop_an_Upi_1.6\Shop_an_Upi_1.6-codedownloader.exe /lVhSU /rcbYrfph=task /ZpBCgxxtc='Shop_an_Upi_1.6' /opKZNk=42822 /CjftjJ='001310' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=FA7AAEFA3EDF47CEAD8F4BB653D0A983IE /TRIdwDGm=252705edb3b732a45ed4995c5c83440b /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1410521493 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jpelGLu=http://js.democlientnet.com /tQQrCEVl=ff /VLUYScLFK=http://js.clientdemocloud.com /JKizC /bOpFcHBjn='{"asw":[1, 4, 0]}' /JGGFP='http://update.democlientnet.com/ie_code ... pdate.json' /rcbYrfph='task' /XeUwvLgUe=''
C:\Windows\tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-10.job - C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-10.exe /ZpBCgxxtc='Shop_an_Upi_1.6' /opKZNk=42822 /CjftjJ='001310' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=FA7AAEFA3EDF47CEAD8F4BB653D0A983IE /TRIdwDGm=252705edb3b732a45ed4995c5c83440b /vxIZPlGJu=1_34_06_10 /nkaOBMRBi=1410521493 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /cIstfpesq='Shop_an_Upi_1.6' /apuODrS=1000 /arxkuY=http://logs.democlientnet.com /rcbYrfph='task' /XeUwvLgUe=''
C:\Windows\tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-11.job - C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-11.exe /fazRMXi=hx77lIYbAXVOdIq3zEuluxGjTwXOm5SpnUyWaczrFvyfOYgDJcrEMDaYzG1uuGF8XOgpotFMbNlaApxh8SBLM8wEFV4/Ha6MixlpBBvBiOPCOEU5E6fiWUN1SBrEQMqMXTtvR48DG30n8NNedEMDJzORol7Gg0AJA2CeezYo+DG1jRMQEpKdSS+31wRTpjmVXstII5tqDjOZCtrDYMI7JnTpz1I9vYdzYc4zVQPvkVkgwFwYyrffBdbARt3E0T3eqbp2C3HWyQuWgFTUbwS8+lPhzJnFP3E0MyGUKAlDCFeuVr+e3ORYO3nf+IbMRdMDeTzpOccglK692BnVlXxUpouzinGN60538Cfn2vWKU1CIXUl3tmhdcc1VpW5U87ITcwsEMDM4fPcYBDq7GV06PYkg5/+xEfnn1VlFj2WroEHxYc7wnL9OwVzgNPkZK/GHAJSWA+E4U2afoQ+kg1sw7eeVNnObSxMLWo/Wk9sY2vW0kW+kkfwoW254/TxfLQnXseZlPjGeH5xAUMBRGr+P0sc3lME8KJGb4StcjSl3UgXAIVE7vQ/tbNZuu40UpniXogIOr2IbUQfCfs7gaLP4+Krd9hxVllsWHmBs0R8i9S0C0/5W8kSwCOHSEEeXI3caVNfIBcwjpOqu0m1+dy7h+tOtbTAMFLFqFcvq/8UZAgVJxEy3bRc25+iqtQVVwDabbIxvS8sXoD5jKZaHsLATg02xmn0DcoAlNXRm2PohQAC2X0k0WJ2+MsjTSF3gRgNfhYjkZBa3ypyY8U6VPU7gB36HSgIhGVwbwyuJ+qM/iINI1VGoA5C720h90vPIwqMAW44ZpsUAIB3v9ESoh3RdVLBh/ZbEXCzk/OzneI2SRA8t9sB2vF8GnIPP7DDK3iec14PS5+VLqznVuXWhkkBxxRAbx7NxBq+bUSCKyMvXHrqcuRCgN4ee4eCiXfmQvHliqKOLnrKxFc4niTROO9Cp9AKt/7PsxCs+KO5SVHV1Kwf8xsZE5qrEU336l/Wc47KZDMPqT+PFTkzm6jTGeBkyOAeewNAhqlLlk0pm77nOh5s2bMn1WUOm6VLFNDly+83zCJbNqL+1N9fz910ZeoDKMn1ToM9WqFvgdeGm+kq2ivEGD77XEdGEPeDczi9x7GBfulw+vIIECaLpO4QWVkpB4jdQt3xtwEj3JLGfzdyhg3euWwcDVMWBbl0tvFoMnMvX1nILzpaeJKQHtWU57IN6oMGwK2QRZhP+8ZHjnZ59q7CAnZlQkEBSBRkJmwqwDIkbc3YwKpIgTBpBT3lagkIVwKDouQ9dlelAUqfOId3zFrGrg0GdW81i1/Fx6mHIK5EyA7HdlDAehkdOKw0fFthbCsL5FhwCsbGhQH4KZ83xrA2BTpT1TgXk3MhT2lo0iNQEY+14TylTgnDDi6TnTZlHshAtbEhkMkmxCRFXRHiEtwAhfBGLVRJe2Wsywie6/4iABBfuEdpRZXScW4zraX+rsVSZD4qt4jDL+/eMQB0+yAx3rMyQPOSrz5I/lWo0PkhbEKRZ9FgIwv7w2ntFtxLssa9RTCEhj97p+m9zGgThaipLcOX9lKhI5QyJO5SgVMC3xyzPkk0KS/iVKHG1FRUGyChVDZHnZ3VK5ndHwShGb0DSUhxghDhYdzjZZbr8fbfO6sO/aywhBqoTM6pBpAyiv3iuODRLOBxD5xLl4H1+5k8=
C:\Windows\tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-4.job - C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-4.exe /yiYpEh /ZpBCgxxtc='Shop_an_Upi_1.6' /fekQtsK='C:\Program Files\Shop_an_Upi_1.6\42822.xpi' /opKZNk=42822 /CjftjJ='001310' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=FA7AAEFA3EDF47CEAD8F4BB653D0A983IE /TRIdwDGm=252705edb3b732a45ed4995c5c83440b /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1410521493 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jTZPGdj=300 /iHOqOSqX=a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1de-4b29-8f70-c0a27f6ca2b8.com /CIoZrUwqh=0.94 /rWNAvk=aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822 /DSfhfiuz=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /42822.rdf /cIstfpesq='Shop_an_Upi_1.6' /xpLdKr='Shop-Up' /kRdSKzd='Winportal' /tQQrCEVl=ff /bOpFcHBjn='{"asw":[1, 4, 0]}' /JKizC /SaWjDhp /eyWjDj /JGGFP='http://update.democlientnet.com/ff_agen ... pdate.json' /rcbYrfph='task' /XeUwvLgUe=''
C:\Windows\tasks\d8f74118-7758-4a73-8216-f3d5e66779f5-5.job - C:\Program Files\Shop_an_Upi_1.6\d8f74118-7758-4a73-8216-f3d5e66779f5-5.exe /ysprChJRm /ZpBCgxxtc='Shop_an_Upi_1.6' /opKZNk=42822 /CjftjJ='001310' /JlFutVD='0' /xsGyTcGOL='0' /uEdfKzwvS=FA7AAEFA3EDF47CEAD8F4BB653D0A983IE /TRIdwDGm=252705edb3b732a45ed4995c5c83440b /vxIZPlGJu=1_34_06_10 /nkaOBMRBi=1410521493 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /VHNSLo=http://ipgeoapi.com/ /rjhDfWc=http://update.democlientnet.com /mOikl=2 /arxkuY=http://logs.democlientnet.com /JGGFP='http://update.democlientnet.com/updater ... pdate.json' /rcbYrfph='task' /XeUwvLgUe=''
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://mysearch.avg.com?pid=wtu&sg=&ci ... A33&sap=hp"
prefs.js - "keyword.URL" - "http://search.creativetoolbars.com/resu ... tbar&g=&q="

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\3.2.0\\npsitesafety.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\extensions\
a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1de-4b29-8f70-c0a27f6ca2b8.com
avg@toolbar

C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\searchplugins\
avg-secure-search.xml
smartbar.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}]
SmartBar Helper Object - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll [2013-01-13 247704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0CFBE80D-5608-4309-A0F5-3B1414833432} - SmartBar Toolbar - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\smartbarTlbr.dll [2013-01-13 321944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AVG_UI"=C:\Program Files\AVG\AVG2014\avgui.exe [2014-08-25 5188112]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []
"vProt"=C:\Program Files\AVG Web TuneUp\vprot.exe [2014-09-10 2680344]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\steam.exe [2014-08-28 1939136]
"Sony PC Companion"=C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [2014-07-30 467680]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-13 14:35:10 ----D---- C:\Program Files\Mozilla Firefox
2014-09-13 14:21:23 ----HD---- C:\Program Files\InstallShield Installation Information
2014-09-13 14:21:23 ----D---- C:\ProgramData\Sony
2014-09-13 14:21:23 ----D---- C:\Program Files\Sony
2014-09-12 18:41:28 ----D---- C:\Program Files\MyRealGames.com
2014-09-12 13:32:36 ----D---- C:\ProgramData\BlueStacksSetup
2014-09-12 13:31:44 ----D---- C:\Program Files\globalUpdate
2014-09-12 13:31:42 ----D---- C:\Program Files\Shop_an_Upi_1.6
2014-09-12 13:29:49 ----D---- C:\Program Files\Bechiro S.L
2014-09-11 13:17:17 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 13:17:16 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 13:17:15 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 13:17:15 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 13:17:13 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 13:17:12 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 13:17:11 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 13:17:11 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 13:17:11 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 13:17:08 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 13:17:08 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 13:17:07 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 13:17:07 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 13:17:04 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 13:17:03 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 13:14:37 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 10:57:10 ----D---- C:\Users\Patrikovo\AppData\Roaming\AVG2014
2014-09-11 10:50:12 ----D---- C:\ProgramData\AVG2014
2014-09-11 10:42:50 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 10:42:50 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 10:42:28 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 10:42:23 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 10:42:20 ----A---- C:\Windows\system32\aepdu.dll
2014-09-11 10:42:20 ----A---- C:\Windows\system32\aeinv.dll
2014-09-11 10:36:48 ----D---- C:\Users\Patrikovo\AppData\Roaming\VSO
2014-09-11 10:36:48 ----D---- C:\ProgramData\VSO
2014-09-11 10:36:19 ----D---- C:\Program Files\VSO ConvertXtoDVD 5.0.0.33 Final - CRACK
2014-09-11 10:35:56 ----AS---- C:\Windows\system32\lcpmncdjdw.exe
2014-09-11 10:35:56 ----AS---- C:\Windows\system32\dcgmncdjdw.exe
2014-09-11 10:35:55 ----D---- C:\Windows\system32\bitstreams
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\zlib1.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\ssleay32.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\pthreadVC2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\pthreadGC2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libssh2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\librtmp.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libidn-11.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libeay32.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libcurl-4.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\cudart32_50_35.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\acumncdjdw.exe
2014-08-29 17:32:41 ----D---- C:\ProgramData\AVG Security Toolbar
2014-08-29 17:32:26 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2014-08-29 17:32:20 ----D---- C:\ProgramData\AVG Secure Search
2014-08-29 17:32:18 ----D---- C:\Program Files\Common Files\AVG Secure Search
2014-08-29 17:32:07 ----D---- C:\Program Files\AVG Web TuneUp
2014-08-29 17:32:06 ----D---- C:\ProgramData\AVG Web TuneUp
2014-08-27 21:45:32 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 21:45:32 ----A---- C:\Windows\system32\gdi32.dll
2014-08-27 21:40:52 ----D---- C:\Users\Patrikovo\AppData\Roaming\HpUpdate
2014-08-27 21:38:38 ----D---- C:\Windows\Hewlett-Packard
2014-08-14 04:30:55 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-14 04:30:51 ----A---- C:\Windows\system32\icardres.dll
2014-08-14 04:30:46 ----A---- C:\Windows\system32\icardagt.exe
2014-08-14 04:30:43 ----A---- C:\Windows\system32\TsWpfWrp.exe

======List of files/folders modified in the last 1 month======

2014-09-13 16:42:01 ----D---- C:\Program Files\trend micro
2014-09-13 16:39:38 ----D---- C:\Program Files\Steam
2014-09-13 16:38:35 ----D---- C:\Windows\Temp
2014-09-13 16:32:25 ----D---- C:\Windows\inf
2014-09-13 16:32:25 ----D---- C:\Windows\debug
2014-09-13 16:32:25 ----D---- C:\Windows
2014-09-13 16:28:15 ----D---- C:\rsit
2014-09-13 16:01:35 ----D---- C:\ProgramData\MFAData
2014-09-13 15:50:37 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-09-13 15:50:37 ----D---- C:\Program Files
2014-09-13 15:11:56 ----D---- C:\Windows\Microsoft.NET
2014-09-13 15:06:57 ----RSD---- C:\Windows\assembly
2014-09-13 15:03:47 ----D---- C:\Windows\system32\config
2014-09-13 14:36:39 ----D---- C:\Windows\system32\catroot
2014-09-13 14:36:38 ----D---- C:\Windows\system32\DriverStore
2014-09-13 14:33:18 ----SHD---- C:\System Volume Information
2014-09-13 14:26:15 ----D---- C:\Windows\system32\catroot2
2014-09-13 14:21:23 ----HD---- C:\ProgramData
2014-09-13 14:03:04 ----D---- C:\Windows\system32\drivers
2014-09-13 14:02:46 ----D---- C:\Windows\system32\drivers\UMDF
2014-09-13 14:02:46 ----D---- C:\Windows\System32
2014-09-13 13:56:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-12 14:11:55 ----SHD---- C:\Windows\Installer
2014-09-12 14:11:55 ----HD---- C:\Config.Msi
2014-09-12 13:33:02 ----SD---- C:\Users\Patrikovo\AppData\Roaming\Microsoft
2014-09-12 13:32:46 ----D---- C:\Windows\system32\Tasks
2014-09-12 13:32:45 ----D---- C:\Windows\Tasks
2014-09-11 21:20:33 ----D---- C:\Windows\AutoKMS
2014-09-11 16:13:41 ----D---- C:\Windows\winsxs
2014-09-11 16:10:51 ----D---- C:\Windows\system32\en-US
2014-09-11 16:10:48 ----D---- C:\Program Files\Internet Explorer
2014-09-11 13:15:59 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 13:14:34 ----D---- C:\Windows\system32\MRT
2014-09-11 13:07:05 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 13:06:38 ----SD---- C:\Windows\system32\CompatTel
2014-09-11 11:00:08 ----D---- C:\ProgramData\AVG2013
2014-09-11 10:56:52 ----HD---- C:\$AVG
2014-09-11 10:49:56 ----D---- C:\Program Files\AVG
2014-09-11 10:30:37 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-29 17:32:18 ----D---- C:\Program Files\Common Files
2014-08-27 21:41:36 ----D---- C:\Program Files\HP
2014-08-27 21:38:29 ----D---- C:\Windows\Prefetch
2014-08-18 15:40:46 ----D---- C:\Program Files\Volkswagen GTI Racing
2014-08-18 12:30:51 ----D---- C:\Windows\rescache
2014-08-15 15:41:01 ----D---- C:\Windows\PolicyDefinitions
2014-08-15 15:41:01 ----D---- C:\Windows\ehome
2014-08-15 15:41:00 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 15:40:18 ----RSD---- C:\Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2014-06-17 147736]
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2014-06-17 241944]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2014-08-06 98584]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2014-06-17 27416]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2014-06-30 121624]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2013-09-26 47928]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2014-07-21 200984]
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2014-06-17 21272]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2014-06-17 188696]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2014-06-17 197400]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2014-08-29 42784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2014\avgfws.exe [2014-08-25 1417160]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [2014-08-25 3242000]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [2014-08-25 289328]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 vToolbarUpdater3.2.0;vToolbarUpdater3.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe [2014-08-29 1843736]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-09-12 68608]
S2 ProtectMonitor;Protect Monitor; C:\Program Files\PCDApp\StartHelp.exe [2014-05-09 97232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-11 267440]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2014-09-12 68608]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-18 108032]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-13 114288]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-11-19 489256]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-11 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 18:16
od Rudy
Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 20:59
od sexkula
Už jsem to pročistil AVG a našlo to něco a odstranilo a zatím mě nic nevyskakuje, ale buhví jestli je to pryč... pač internet je nějaký lenivější. Tady je Log:

# AdwCleaner v3.310 - Report created 13/09/2014 at 21:53:22
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Patrikovo - SP-SWEET
# Running from : C:\Users\Patrikovo\Desktop\adwcleaner_3.310.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : ProtectMonitor

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\HulaToo
Folder Deleted : C:\Program Files\PCDApp
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Patrikovo\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\Extensions\Avg@toolbar
File Deleted : C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\searchplugins\smartbar.xml
File Deleted : C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\user.js

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : d8f74118-7758-4a73-8216-f3d5e66779f5-1
Task Deleted : d8f74118-7758-4a73-8216-f3d5e66779f5-10
Task Deleted : d8f74118-7758-4a73-8216-f3d5e66779f5-11
Task Deleted : d8f74118-7758-4a73-8216-f3d5e66779f5-4
Task Deleted : d8f74118-7758-4a73-8216-f3d5e66779f5-5

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\flcjcajklmlbpmgckpcmnampagbhhmcp
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\b
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0CFBE80D-5608-4309-A0F5-3B1414833432}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{596EAA89-F3D2-4174-9BD9-F7D79C744CDA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0CFBE80D-5608-4309-A0F5-3B1414833432}]
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\HulaToo
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\HulaToo
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartBar

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

-\\ Mozilla Firefox v32.0.1 (x86 cs)

[ File : C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\prefs.js ]

Line Deleted : user_pref("avg.wtu.ext.setting_hp_list", "[{\"name\":\"AVG Secure Search\",\"value\":\"hxxp://mysearch.avg.com\"},{\"name\":\"Google\",\"value\":\"hxxp://www.google.com\"},{\"name\":\"Yahoo\",\"value\[...]
Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Deleted : user_pref("browser.search.order.1", "Search the web (CT)");
Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Line Deleted : user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.c[...]
Line Deleted : user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Line Deleted : user_pref("extensions.crossrider.bic", "14869abde093ed9579360c50c053c97e");
Line Deleted : user_pref("extensions.smartbar.admin", false);
Line Deleted : user_pref("extensions.smartbar.aflt", "orgnl");
Line Deleted : user_pref("extensions.smartbar.appId", "{C5E5951A-4ADD-4402-8A8E-EF97DCB9D8EC}");
Line Deleted : user_pref("extensions.smartbar.autoRvrt", "false");
Line Deleted : user_pref("extensions.smartbar.dfltLng", "");
Line Deleted : user_pref("extensions.smartbar.dfltSrch", true);
Line Deleted : user_pref("extensions.smartbar.dnsErr", true);
Line Deleted : user_pref("extensions.smartbar.excTlbr", false);
Line Deleted : user_pref("extensions.smartbar.hmpg", true);
Line Deleted : user_pref("extensions.smartbar.hmpgUrl", "hxxp://search.creativetoolbars.com/?src=hp&id=smartbar&g=");
Line Deleted : user_pref("extensions.smartbar.hpOld0", "hxxps://mysearch.avg.com?pid=wtu&sg=&cid=%7B49888620-2362-4c5d-9b1e-0d6e7129e81e%7D&mid=efcf84b6112f47d28327d1527e315037-b4102d0160691a636314cf4967dea079796ea3[...]
Line Deleted : user_pref("extensions.smartbar.id", "864bc76c000000000000001f3a66599b");
Line Deleted : user_pref("extensions.smartbar.instlDay", "16325");
Line Deleted : user_pref("extensions.smartbar.instlRef", "");
Line Deleted : user_pref("extensions.smartbar.kw_url", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");
Line Deleted : user_pref("extensions.smartbar.newTab", true);
Line Deleted : user_pref("extensions.smartbar.newTabUrl", "hxxp://search.creativetoolbars.com/?src=nt&id=smartbar&g=");
Line Deleted : user_pref("extensions.smartbar.prdct", "smartbar");
Line Deleted : user_pref("extensions.smartbar.prtnrId", "bechiro");
Line Deleted : user_pref("extensions.smartbar.rvrt", "false");
Line Deleted : user_pref("extensions.smartbar.smplGrp", "mm");
Line Deleted : user_pref("extensions.smartbar.srchPrvdr", "Search the web (CT)");
Line Deleted : user_pref("extensions.smartbar.tlbrId", "smartbar");
Line Deleted : user_pref("extensions.smartbar.tlbrSrchUrl", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");
Line Deleted : user_pref("extensions.smartbar.vrsn", "1.8.8.12");
Line Deleted : user_pref("extensions.smartbar.vrsnTs", "1.8.8.1213:29:52");
Line Deleted : user_pref("extensions.smartbar.vrsni", "1.8.8.12");
Line Deleted : user_pref("keyword.URL", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");

*************************

AdwCleaner[R0].txt - [13676 octets] - [13/09/2014 21:50:21]
AdwCleaner[S0].txt - [13812 octets] - [13/09/2014 21:53:22]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13873 octets] ##########

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 21:39
od Rudy
Dejte nový log RSIT.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 21:54
od sexkula
Logfile of random's system information tool 1.10 (written by random/random)
Run by Patrikovo at 2014-09-13 22:51:13
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 35 GB (46%) free of 76 GB
Total RAM: 2038 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:52:07, on 13.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG2014\avgui.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Patrikovo\Downloads\RSIT.exe
C:\Program Files\trend micro\Patrikovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: SmartBar Helper Object - {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: vToolbarUpdater3.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe (file missing)

--
End of file - 6210 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS\AutoKMS.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://mysearch.avg.com?pid=wtu&sg=&ci ... A33&sap=hp"

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\extensions\
a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1de-4b29-8f70-c0a27f6ca2b8.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}]
SmartBar Helper Object - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll [2013-01-13 247704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AVG_UI"=C:\Program Files\AVG\AVG2014\avgui.exe [2014-08-25 5188112]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\steam.exe [2014-08-28 1939136]
"Sony PC Companion"=C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [2014-07-30 467680]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-13 21:50:19 ----D---- C:\AdwCleaner
2014-09-13 14:35:10 ----D---- C:\Program Files\Mozilla Firefox
2014-09-13 14:21:23 ----HD---- C:\Program Files\InstallShield Installation Information
2014-09-13 14:21:23 ----D---- C:\ProgramData\Sony
2014-09-13 14:21:23 ----D---- C:\Program Files\Sony
2014-09-12 18:41:28 ----D---- C:\Program Files\MyRealGames.com
2014-09-12 13:32:36 ----D---- C:\ProgramData\BlueStacksSetup
2014-09-12 13:31:42 ----D---- C:\Program Files\Shop_an_Upi_1.6
2014-09-12 13:29:49 ----D---- C:\Program Files\Bechiro S.L
2014-09-11 13:17:17 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 13:17:16 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 13:17:15 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 13:17:15 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 13:17:13 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 13:17:12 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 13:17:11 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 13:17:11 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 13:17:11 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 13:17:08 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 13:17:08 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 13:17:07 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 13:17:07 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 13:17:04 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 13:17:03 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 13:14:37 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 10:57:10 ----D---- C:\Users\Patrikovo\AppData\Roaming\AVG2014
2014-09-11 10:50:12 ----D---- C:\ProgramData\AVG2014
2014-09-11 10:42:50 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 10:42:50 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 10:42:28 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 10:42:23 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 10:42:20 ----A---- C:\Windows\system32\aepdu.dll
2014-09-11 10:42:20 ----A---- C:\Windows\system32\aeinv.dll
2014-09-11 10:36:48 ----D---- C:\Users\Patrikovo\AppData\Roaming\VSO
2014-09-11 10:36:48 ----D---- C:\ProgramData\VSO
2014-09-11 10:36:19 ----D---- C:\Program Files\VSO ConvertXtoDVD 5.0.0.33 Final - CRACK
2014-09-11 10:35:55 ----D---- C:\Windows\system32\bitstreams
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\zlib1.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\ssleay32.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\pthreadVC2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\pthreadGC2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libssh2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\librtmp.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libidn-11.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libeay32.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libcurl-4.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\cudart32_50_35.dll
2014-08-29 17:32:26 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2014-08-29 17:32:07 ----D---- C:\Program Files\AVG Web TuneUp
2014-08-29 17:32:06 ----D---- C:\ProgramData\AVG Web TuneUp
2014-08-27 21:45:32 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 21:45:32 ----A---- C:\Windows\system32\gdi32.dll
2014-08-27 21:40:52 ----D---- C:\Users\Patrikovo\AppData\Roaming\HpUpdate
2014-08-27 21:38:38 ----D---- C:\Windows\Hewlett-Packard
2014-08-14 04:30:55 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-14 04:30:51 ----A---- C:\Windows\system32\icardres.dll
2014-08-14 04:30:46 ----A---- C:\Windows\system32\icardagt.exe
2014-08-14 04:30:43 ----A---- C:\Windows\system32\TsWpfWrp.exe

======List of files/folders modified in the last 1 month======

2014-09-13 22:51:18 ----D---- C:\Program Files\trend micro
2014-09-13 22:46:10 ----D---- C:\Windows\Temp
2014-09-13 22:11:49 ----D---- C:\Windows\system32\config
2014-09-13 22:02:05 ----D---- C:\ProgramData\MFAData
2014-09-13 21:57:43 ----D---- C:\Program Files\Steam
2014-09-13 21:55:35 ----D---- C:\Windows
2014-09-13 21:53:32 ----D---- C:\Windows\Tasks
2014-09-13 21:53:31 ----D---- C:\Windows\system32\Tasks
2014-09-13 21:53:26 ----D---- C:\Program Files\Common Files
2014-09-13 21:53:26 ----D---- C:\Program Files
2014-09-13 21:53:25 ----HD---- C:\ProgramData
2014-09-13 18:47:23 ----D---- C:\Windows\system32\NDF
2014-09-13 18:28:42 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-09-13 18:24:14 ----D---- C:\Windows\inf
2014-09-13 18:01:27 ----D---- C:\Windows\System32
2014-09-13 16:32:25 ----D---- C:\Windows\debug
2014-09-13 16:28:15 ----D---- C:\rsit
2014-09-13 15:11:56 ----D---- C:\Windows\Microsoft.NET
2014-09-13 15:06:57 ----RSD---- C:\Windows\assembly
2014-09-13 14:36:39 ----D---- C:\Windows\system32\catroot
2014-09-13 14:36:38 ----D---- C:\Windows\system32\DriverStore
2014-09-13 14:33:18 ----SHD---- C:\System Volume Information
2014-09-13 14:26:15 ----D---- C:\Windows\system32\catroot2
2014-09-13 14:03:04 ----D---- C:\Windows\system32\drivers
2014-09-13 14:02:46 ----D---- C:\Windows\system32\drivers\UMDF
2014-09-13 13:56:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-12 14:11:55 ----SHD---- C:\Windows\Installer
2014-09-12 14:11:55 ----HD---- C:\Config.Msi
2014-09-12 13:33:02 ----SD---- C:\Users\Patrikovo\AppData\Roaming\Microsoft
2014-09-11 21:20:33 ----D---- C:\Windows\AutoKMS
2014-09-11 16:13:41 ----D---- C:\Windows\winsxs
2014-09-11 16:10:51 ----D---- C:\Windows\system32\en-US
2014-09-11 16:10:48 ----D---- C:\Program Files\Internet Explorer
2014-09-11 13:15:59 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 13:14:34 ----D---- C:\Windows\system32\MRT
2014-09-11 13:07:05 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 13:06:38 ----SD---- C:\Windows\system32\CompatTel
2014-09-11 11:00:08 ----D---- C:\ProgramData\AVG2013
2014-09-11 10:56:52 ----HD---- C:\$AVG
2014-09-11 10:49:56 ----D---- C:\Program Files\AVG
2014-09-11 10:30:37 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-27 21:41:36 ----D---- C:\Program Files\HP
2014-08-27 21:38:29 ----D---- C:\Windows\Prefetch
2014-08-18 15:40:46 ----D---- C:\Program Files\Volkswagen GTI Racing
2014-08-18 12:30:51 ----D---- C:\Windows\rescache
2014-08-15 15:41:01 ----D---- C:\Windows\PolicyDefinitions
2014-08-15 15:41:01 ----D---- C:\Windows\ehome
2014-08-15 15:41:00 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 15:40:18 ----RSD---- C:\Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2014-06-17 147736]
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2014-06-17 241944]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2014-08-06 98584]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2014-06-17 27416]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2014-06-30 121624]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2013-09-26 47928]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2014-07-21 200984]
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2014-06-17 21272]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2014-06-17 188696]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2014-06-17 197400]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2014-08-29 42784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2014\avgfws.exe [2014-08-25 1417160]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [2014-08-25 3242000]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [2014-08-25 289328]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 vToolbarUpdater3.2.0;vToolbarUpdater3.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-11 267440]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-18 108032]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-13 114288]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-11-19 489256]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-11 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 22:00
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Bechiro S.L
C:\Windows\tasks\AutoKMS.job
C:\Windows\AutoKMS\AutoKMS.exe

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 22:14
od sexkula
Logfile of random's system information tool 1.10 (written by random/random)
Run by Patrikovo at 2014-09-13 23:10:37
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 35 GB (47%) free of 76 GB
Total RAM: 2038 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:11:33, on 13.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG2014\avgui.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Patrikovo\Downloads\RSIT.exe
C:\Program Files\trend micro\Patrikovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: SmartBar Helper Object - {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll (file missing)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: vToolbarUpdater3.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe (file missing)

--
End of file - 6225 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://mysearch.avg.com?pid=wtu&sg=&ci ... A33&sap=hp"

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\Patrikovo\AppData\Roaming\Mozilla\Firefox\Profiles\zz9yc8st.default-1399796473521\extensions\
a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1de-4b29-8f70-c0a27f6ca2b8.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD36FEBE-DBA1-4597-9DD1-B13794B92F68}]
SmartBar Helper Object - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AVG_UI"=C:\Program Files\AVG\AVG2014\avgui.exe [2014-08-25 5188112]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\steam.exe [2014-08-28 1939136]
"Sony PC Companion"=C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [2014-07-30 467680]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-13 23:04:37 ----D---- C:\_OTM
2014-09-13 21:50:19 ----D---- C:\AdwCleaner
2014-09-13 14:35:10 ----D---- C:\Program Files\Mozilla Firefox
2014-09-13 14:21:23 ----HD---- C:\Program Files\InstallShield Installation Information
2014-09-13 14:21:23 ----D---- C:\ProgramData\Sony
2014-09-13 14:21:23 ----D---- C:\Program Files\Sony
2014-09-12 18:41:28 ----D---- C:\Program Files\MyRealGames.com
2014-09-12 13:32:36 ----D---- C:\ProgramData\BlueStacksSetup
2014-09-12 13:31:42 ----D---- C:\Program Files\Shop_an_Upi_1.6
2014-09-11 13:17:17 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 13:17:16 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 13:17:15 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 13:17:15 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 13:17:14 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 13:17:13 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 13:17:13 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 13:17:12 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 13:17:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 13:17:11 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 13:17:11 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 13:17:11 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 13:17:08 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 13:17:08 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 13:17:07 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 13:17:07 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 13:17:04 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 13:17:03 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 13:14:37 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 10:57:10 ----D---- C:\Users\Patrikovo\AppData\Roaming\AVG2014
2014-09-11 10:50:12 ----D---- C:\ProgramData\AVG2014
2014-09-11 10:42:50 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 10:42:50 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 10:42:28 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 10:42:23 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 10:42:20 ----A---- C:\Windows\system32\aepdu.dll
2014-09-11 10:42:20 ----A---- C:\Windows\system32\aeinv.dll
2014-09-11 10:36:48 ----D---- C:\Users\Patrikovo\AppData\Roaming\VSO
2014-09-11 10:36:48 ----D---- C:\ProgramData\VSO
2014-09-11 10:36:19 ----D---- C:\Program Files\VSO ConvertXtoDVD 5.0.0.33 Final - CRACK
2014-09-11 10:35:55 ----D---- C:\Windows\system32\bitstreams
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\zlib1.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\ssleay32.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\pthreadVC2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\pthreadGC2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libssh2.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\librtmp.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libidn-11.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libeay32.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\libcurl-4.dll
2014-09-11 10:35:55 ----AS---- C:\Windows\system32\cudart32_50_35.dll
2014-08-29 17:32:26 ----A---- C:\Windows\system32\drivers\avgtpx86.sys
2014-08-29 17:32:07 ----D---- C:\Program Files\AVG Web TuneUp
2014-08-29 17:32:06 ----D---- C:\ProgramData\AVG Web TuneUp
2014-08-27 21:45:32 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 21:45:32 ----A---- C:\Windows\system32\gdi32.dll
2014-08-27 21:40:52 ----D---- C:\Users\Patrikovo\AppData\Roaming\HpUpdate
2014-08-27 21:38:38 ----D---- C:\Windows\Hewlett-Packard
2014-08-14 04:30:55 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-14 04:30:51 ----A---- C:\Windows\system32\icardres.dll
2014-08-14 04:30:46 ----A---- C:\Windows\system32\icardagt.exe
2014-08-14 04:30:43 ----A---- C:\Windows\system32\TsWpfWrp.exe

======List of files/folders modified in the last 1 month======

2014-09-13 23:10:42 ----D---- C:\Program Files\trend micro
2014-09-13 23:09:17 ----D---- C:\Program Files\Steam
2014-09-13 23:07:47 ----D---- C:\Windows\Temp
2014-09-13 23:05:42 ----D---- C:\Windows\system32\config
2014-09-13 23:04:38 ----D---- C:\Windows\Tasks
2014-09-13 23:04:38 ----D---- C:\Program Files
2014-09-13 22:02:05 ----D---- C:\ProgramData\MFAData
2014-09-13 21:55:35 ----D---- C:\Windows
2014-09-13 21:53:31 ----D---- C:\Windows\system32\Tasks
2014-09-13 21:53:26 ----D---- C:\Program Files\Common Files
2014-09-13 21:53:25 ----HD---- C:\ProgramData
2014-09-13 18:47:23 ----D---- C:\Windows\system32\NDF
2014-09-13 18:28:42 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-09-13 18:24:14 ----D---- C:\Windows\inf
2014-09-13 18:01:27 ----D---- C:\Windows\System32
2014-09-13 16:32:25 ----D---- C:\Windows\debug
2014-09-13 16:28:15 ----D---- C:\rsit
2014-09-13 15:11:56 ----D---- C:\Windows\Microsoft.NET
2014-09-13 15:06:57 ----RSD---- C:\Windows\assembly
2014-09-13 14:36:39 ----D---- C:\Windows\system32\catroot
2014-09-13 14:36:38 ----D---- C:\Windows\system32\DriverStore
2014-09-13 14:33:18 ----SHD---- C:\System Volume Information
2014-09-13 14:26:15 ----D---- C:\Windows\system32\catroot2
2014-09-13 14:03:04 ----D---- C:\Windows\system32\drivers
2014-09-13 14:02:46 ----D---- C:\Windows\system32\drivers\UMDF
2014-09-13 13:56:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-12 14:11:55 ----SHD---- C:\Windows\Installer
2014-09-12 14:11:55 ----HD---- C:\Config.Msi
2014-09-12 13:33:02 ----SD---- C:\Users\Patrikovo\AppData\Roaming\Microsoft
2014-09-11 21:20:33 ----D---- C:\Windows\AutoKMS
2014-09-11 16:13:41 ----D---- C:\Windows\winsxs
2014-09-11 16:10:51 ----D---- C:\Windows\system32\en-US
2014-09-11 16:10:48 ----D---- C:\Program Files\Internet Explorer
2014-09-11 13:15:59 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 13:14:34 ----D---- C:\Windows\system32\MRT
2014-09-11 13:07:05 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 13:06:38 ----SD---- C:\Windows\system32\CompatTel
2014-09-11 11:00:08 ----D---- C:\ProgramData\AVG2013
2014-09-11 10:56:52 ----HD---- C:\$AVG
2014-09-11 10:49:56 ----D---- C:\Program Files\AVG
2014-09-11 10:30:37 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-27 21:41:36 ----D---- C:\Program Files\HP
2014-08-27 21:38:29 ----D---- C:\Windows\Prefetch
2014-08-18 15:40:46 ----D---- C:\Program Files\Volkswagen GTI Racing
2014-08-18 12:30:51 ----D---- C:\Windows\rescache
2014-08-15 15:41:01 ----D---- C:\Windows\PolicyDefinitions
2014-08-15 15:41:01 ----D---- C:\Windows\ehome
2014-08-15 15:41:00 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 15:40:18 ----RSD---- C:\Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2014-06-17 147736]
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2014-06-17 241944]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2014-08-06 98584]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2014-06-17 27416]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2014-06-30 121624]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2013-09-26 47928]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2014-07-21 200984]
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2014-06-17 21272]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2014-06-17 188696]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2014-06-17 197400]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2014-08-29 42784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2014\avgfws.exe [2014-08-25 1417160]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [2014-08-25 3242000]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [2014-08-25 289328]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 vToolbarUpdater3.2.0;vToolbarUpdater3.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-11 267440]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-18 108032]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-13 114288]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-11-19 489256]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-11 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 22:16
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Patrikovo.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O2 - BHO: SmartBar Helper Object - {FD36FEBE-DBA1-4597-9DD1-B13794B92F68} - C:\Program Files\Bechiro S.L\smartbar\1.8.8.12\bh\smartbar.dll (file missing)

Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 13 zář 2014 22:35
od sexkula
Pořád dokola.. a mám takový pocit že mám snad na každé stránce reklamy v menších oknech, i na této vaší mám blbosti o hubnutí atd. Jo a neustále mě AVG zabraňuje tomuhle:
This link on prize6.com is safe for browsing

http://w.prize6.com/media/cz/iphone5s/a ... var4..1688

Re: Spamování, vyskakování Internet. stránek..

Napsal: 14 zář 2014 10:36
od Rudy
Na tom webu je infiltrace. Hlásí to i Eset a Avast. V jakém se to děje prohlížeči?

Re: Spamování, vyskakování Internet. stránek..

Napsal: 14 zář 2014 10:57
od sexkula
Firefox.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 14 zář 2014 11:04
od Rudy
FF zazálohujte pomocí MozBackUp: http://www.stahuj.centrum.cz/utility_a_ ... mozbackup/ . Pak FF odinstalujte vč. jeho profilu. Znovu nainstalujte a zpět ze zálohy nakopírujte pouze záložky, příp. hesla.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 14 zář 2014 12:44
od sexkula
udělal sem vše podle návodu a stále to přetrvává.. To je trest.. :/

Re: Spamování, vyskakování Internet. stránek..

Napsal: 14 zář 2014 16:18
od Rudy
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: Spamování, vyskakování Internet. stránek..

Napsal: 14 zář 2014 19:49
od sexkula
log RSIT ? jinak, mám pocit, že po vyčištění už se to ztratilo, protože už ani ty malé reklamy tady u vás na stránkách nemám :)