Stránka 1 z 1

Prosím o kontrolu ntb

Napsal: 13 říj 2014 15:13
od Dawood
Dobrý den,chtěl bych vás poprosit o preventivní kontrolu ntb.

Logfile of random's system information tool 1.10 (written by random/random)
Run by David at 2014-10-13 16:09:48
Microsoft Windows 8.1 Pro
System drive C: has 719 GB (79%) free of 905 GB
Total RAM: 8048 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:10:12, on 13. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\David\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Hearthstone\Hearthstone.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\David.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\David\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\David\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll,C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6872 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {05b421c1-ef2b-4ede-954dc0032b62435e}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss cf191b16-b6b3-494c-864b-aac6ad25280f 1
\??\C:\WINDOWS\system32\conhost.exe 0x4

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"


C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
szndesktop.exe default start
"C:\Users\David\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe"
"C:\Program Files (x86)\Hearthstone\Hearthstone.exe" -launch -uid hs_beta
"C:\Program Files\Realtek\Audio\HDA\FMAPP.exe" -START
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2476.0.374867062\1304863352" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17 --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.2932 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_46/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="2476.1.1806036678\1424080086" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_46/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="2476.2.599220824\1972239308" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_46/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="2476.3.154714350\611796633" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_46/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="2476.4.1680936231\1512371443" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_46/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="2476.6.1269197042\1438124961" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_46/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="2476.8.267949294\1841369562" /prefetch:673131151
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe245_ Global\UsGthrCtrlFltPipeMssGthrPipe245 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\Users\David\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\RunDll32.exe" "C:\WINDOWS\system32\WerConCpl.dll", LaunchErcApp -responsepester

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-26 13213840]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-10-29 1234064]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-08-27 6334096]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-27 2916152]
"SynLenovoGestureMgr"=C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [2012-08-27 665400]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2463552]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-10-04 2800296]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"cz.seznam.software.autoupdate"=C:\Users\David\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\David\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-13 16:09:50 ----D---- C:\Program Files\trend micro
2014-10-06 16:27:09 ----D---- C:\Program Files (x86)\osu!
2014-10-05 17:21:03 ----D---- C:\Users\David\AppData\Roaming\vlc
2014-10-05 17:19:55 ----D---- C:\Program Files (x86)\VideoLAN
2014-10-02 21:41:19 ----D---- C:\Users\David\AppData\Roaming\Might & Magic Heroes VI
2014-10-02 17:49:53 ----D---- C:\Program Files (x86)\directx
2014-09-27 20:33:49 ----D---- C:\Users\David\AppData\Roaming\Skype
2014-09-27 20:33:43 ----RD---- C:\Program Files (x86)\Skype
2014-09-27 20:33:38 ----D---- C:\ProgramData\Skype
2014-09-20 23:28:17 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-09-20 23:28:17 ----D---- C:\WINDOWS\system32\NV
2014-09-19 19:43:33 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-09-19 19:42:57 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvopencl.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvdispgenco6434411.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvdispco6434411.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvcuda.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2014-09-19 19:07:22 ----A---- C:\WINDOWS\SYSWOW64\nvaudcap32v.dll
2014-09-19 19:07:22 ----A---- C:\WINDOWS\system32\drivers\nvvad64v.sys
2014-09-15 16:18:43 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 16:18:42 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 16:18:41 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 16:18:39 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 16:18:38 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 16:18:36 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 16:18:35 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 16:18:35 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 16:18:34 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 16:18:34 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 16:18:19 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 16:18:18 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 16:18:17 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 16:18:16 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 16:18:15 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 16:18:14 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 16:18:13 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 16:18:13 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 16:18:12 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 16:18:12 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 16:18:12 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 16:18:07 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 16:18:07 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 16:18:06 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 16:18:06 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 16:18:06 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 16:18:05 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 16:18:05 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 16:18:04 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 16:18:03 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 16:18:03 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 16:18:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 16:18:02 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 16:18:02 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 16:18:02 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 16:18:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 16:18:01 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 16:18:00 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 16:18:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 16:17:59 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 16:17:59 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 16:17:58 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 16:17:58 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 16:17:57 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 16:17:57 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 16:17:56 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 16:17:55 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 16:17:55 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 16:17:54 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 16:17:54 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 16:17:53 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 16:17:53 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 16:17:53 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 16:17:53 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 16:17:52 ----AC---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 16:17:52 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 16:17:52 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 16:17:52 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 16:17:52 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 16:17:52 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 16:17:51 ----AC---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 16:17:51 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 16:17:51 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 16:17:51 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 16:17:51 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 16:17:51 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 16:17:51 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 16:17:50 ----AC---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 16:17:50 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 16:17:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 16:17:50 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 16:17:50 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 16:17:49 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 16:17:49 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 16:17:49 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 16:17:49 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 16:17:49 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 16:17:49 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 16:17:48 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 16:17:48 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 16:17:48 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 16:17:47 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 16:17:47 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 16:17:47 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 16:17:46 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 16:17:46 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 16:17:45 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 16:17:45 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 16:17:45 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 16:17:44 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 16:17:44 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 16:17:44 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 16:17:44 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 16:17:43 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 16:17:43 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 16:17:43 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 16:17:43 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 16:17:42 ----AC---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 16:17:42 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 16:17:41 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 16:17:40 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 16:17:40 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 16:17:40 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 16:17:40 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 16:17:39 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 16:17:39 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 16:17:38 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 16:17:38 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 16:17:38 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 16:17:37 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 16:17:37 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 16:17:37 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 16:17:37 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 16:17:36 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 16:17:36 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 16:17:36 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 16:17:36 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 16:17:35 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 16:17:35 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 16:17:35 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 16:17:35 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 16:17:34 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 16:17:34 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 16:17:34 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 16:17:34 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 16:17:33 ----AC---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 16:17:33 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 16:17:33 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 16:17:33 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 16:17:33 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 16:17:33 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 16:17:32 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 16:17:32 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 16:17:32 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 16:17:32 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 16:17:32 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 16:17:32 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 16:17:31 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 16:17:31 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 16:17:30 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 16:17:30 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 16:17:30 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 16:17:30 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 16:17:30 ----A---- C:\WINDOWS\system32\ppcsnap.dll
2014-09-15 16:17:30 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 16:17:29 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 16:17:29 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 16:17:29 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 16:17:29 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 16:17:29 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 16:17:28 ----AC---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 16:17:28 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 16:17:28 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 16:17:28 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 16:17:28 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 16:17:27 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 16:17:27 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 16:17:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 16:17:27 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 16:17:27 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 16:17:27 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 16:17:26 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 16:17:26 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 16:17:26 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 16:17:26 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 16:17:26 ----A---- C:\WINDOWS\system32\pmcsnap.dll
2014-09-15 16:17:25 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 16:17:25 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 16:17:25 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 16:17:25 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 16:17:25 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 16:17:24 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 16:17:24 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 16:17:24 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 16:17:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 16:17:23 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 16:17:23 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 16:17:22 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 16:17:22 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 16:17:22 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 16:17:22 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 16:17:22 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 16:17:21 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 16:17:21 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 16:17:20 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 16:17:19 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 16:17:19 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 16:17:19 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 16:17:19 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 16:17:19 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 16:17:18 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 16:17:18 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 16:17:18 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 16:17:18 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 16:17:18 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 16:17:18 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 16:17:17 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 16:17:17 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 16:17:17 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 16:17:17 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 16:17:17 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 16:17:14 ----AC---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 16:17:14 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 16:17:14 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 16:17:14 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 16:17:14 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 16:17:14 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 16:17:14 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 16:17:13 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 16:17:13 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 16:17:13 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 16:17:13 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 16:17:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 16:17:12 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 16:17:12 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 16:17:12 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 16:17:11 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 16:17:11 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 16:17:11 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 16:17:11 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 16:09:04 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 12:33:00 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2014-09-14 12:33:00 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2014-09-14 12:33:00 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2014-09-14 12:33:00 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2014-09-14 12:32:59 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2014-09-14 12:32:59 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2014-09-14 12:23:03 ----D---- C:\hry

======List of files/folders modified in the last 1 month======

2014-10-13 16:09:54 ----D---- C:\WINDOWS\Prefetch
2014-10-13 16:09:50 ----RD---- C:\Program Files
2014-10-13 16:08:28 ----D---- C:\Users\David\AppData\Roaming\uTorrent
2014-10-13 16:01:55 ----D---- C:\Users\David\AppData\Roaming\Seznam.cz
2014-10-13 16:00:00 ----D---- C:\WINDOWS\system32\sru
2014-10-13 15:59:47 ----RD---- C:\WINDOWS\System32
2014-10-13 15:59:47 ----D---- C:\WINDOWS\Inf
2014-10-13 15:59:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-13 15:56:46 ----D---- C:\WINDOWS\Temp
2014-10-13 15:56:43 ----D---- C:\WINDOWS\AppReadiness
2014-10-12 21:28:19 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-12 11:33:09 ----D---- C:\ProgramData\TmForever
2014-10-12 10:52:01 ----D---- C:\ProgramData\Origin
2014-10-12 10:51:42 ----D---- C:\Program Files (x86)\Origin
2014-10-10 20:43:42 ----D---- C:\WINDOWS\system32\NDF
2014-10-10 18:20:16 ----D---- C:\ProgramData\NVIDIA
2014-10-10 15:54:49 ----HD---- C:\Program Files\WindowsApps
2014-10-09 20:47:19 ----D---- C:\WINDOWS\SysWOW64
2014-10-08 19:34:48 ----D---- C:\Program Files (x86)\Battle.net
2014-10-08 17:49:02 ----D---- C:\WINDOWS\system32\DriverStore
2014-10-08 17:48:39 ----SHD---- C:\System Volume Information
2014-10-06 16:27:25 ----SHD---- C:\WINDOWS\Installer
2014-10-06 16:27:24 ----SHD---- C:\Config.Msi
2014-10-06 16:27:09 ----RD---- C:\Program Files (x86)
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2014-10-02 21:49:25 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-02 21:27:30 ----RSD---- C:\WINDOWS\assembly
2014-10-02 21:25:50 ----D---- C:\Program Files (x86)\Ubisoft
2014-10-02 18:40:55 ----D---- C:\Program Files (x86)\3DO
2014-10-02 17:56:47 ----D---- C:\WINDOWS\SYSWOW64\directx
2014-10-02 17:56:39 ----HD---- C:\WINDOWS\msdownld.tmp
2014-10-02 17:54:10 ----D---- C:\WINDOWS\System
2014-10-02 17:22:21 ----D---- C:\Program Files (x86)\Common Files
2014-09-28 16:59:34 ----D---- C:\WINDOWS\system32\config
2014-09-28 11:21:47 ----D---- C:\WINDOWS\rescache
2014-09-27 20:33:38 ----HD---- C:\ProgramData
2014-09-27 19:25:29 ----D---- C:\Users\David\AppData\Roaming\Mumble
2014-09-27 14:11:55 ----D---- C:\ProgramData\PMB Files
2014-09-25 13:06:36 ----D---- C:\WINDOWS\CbsTemp
2014-09-25 13:06:35 ----D---- C:\WINDOWS\WinSxS
2014-09-25 13:06:33 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-25 13:06:33 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-23 20:04:32 ----D---- C:\Windows
2014-09-23 14:18:29 ----D---- C:\Program Files (x86)\Hearthstone
2014-09-22 08:42:39 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2014-09-19 19:43:33 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-09-19 19:40:56 ----D---- C:\WINDOWS\system32\drivers
2014-09-19 19:40:50 ----D---- C:\WINDOWS\system32\catroot2
2014-09-19 19:08:14 ----D---- C:\Program Files\NVIDIA Corporation
2014-09-17 13:24:29 ----RD---- C:\WINDOWS\ToastData
2014-09-17 13:24:15 ----D---- C:\WINDOWS\WinStore
2014-09-17 13:24:15 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-17 13:24:15 ----D---- C:\Program Files\Windows Journal
2014-09-17 13:24:14 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-17 13:24:12 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-17 13:24:12 ----D---- C:\WINDOWS\system32\wbem
2014-09-17 13:24:12 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-17 13:24:12 ----D---- C:\WINDOWS\system32\Boot
2014-09-17 13:24:12 ----D---- C:\WINDOWS\PolicyDefinitions
2014-09-17 13:24:11 ----D---- C:\WINDOWS\system32\setup
2014-09-17 13:24:11 ----D---- C:\WINDOWS\system32\oobe
2014-09-17 13:24:07 ----RSD---- C:\WINDOWS\Fonts
2014-09-17 13:24:05 ----D---- C:\WINDOWS\apppatch
2014-09-17 13:24:03 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-17 13:24:03 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-17 13:24:03 ----D---- C:\WINDOWS\system32\migration
2014-09-14 12:42:20 ----D---- C:\WINDOWS\system32\wdi
2014-09-14 01:48:03 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2014-09-14 01:48:03 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2014-09-14 01:48:03 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2014-09-14 01:48:03 ----A---- C:\WINDOWS\system32\nvumdshimx.dll
2014-09-14 01:48:03 ----A---- C:\WINDOWS\system32\nvinitx.dll
2014-09-14 01:48:03 ----A---- C:\WINDOWS\system32\nvapi64.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2014-09-14 32576]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 157016]
R1 dtsoftbus01;@oem99.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-09-08 283064]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 ACPIVPC;@oem40.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2012-12-19 33560]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-08-29 857472]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-08-06 68136]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2012-12-13 5353888]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-30 4201104]
R3 IntcDAud;@oem29.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 MEIx64;@oem59.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 NETwNe64;@oem47.inf,%NIC_Service_DispName_WIN8_64%;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [2013-10-08 3345376]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-09-14 13157696]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 20288]
R3 nvvad_WaveExtensible;@oem43.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 rtsuvc;@oem8.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-27 8227216]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-27 43832]
R3 SynTP;@oem32.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-27 448312]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem1.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
S3 RSUSBVSTOR;@oem58.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2012-06-13 315536]
S3 ssudmdm;@oem71.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\system32\DRIVERS\WinUsb.sys [2013-08-22 78848]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1149760]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1796928]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19440960]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-09-13 934216]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-09-13 411968]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-18 116648]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-11 1050904]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2012-12-19 277640]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-18 116648]

-----------------EOF-----------------

Re: Prosím o kontrolu ntb

Napsal: 14 říj 2014 08:57
od Márty84
Zdravim :)

:arrow: Pokud nepouzivate, odinstalujte Seznam Software.

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.

Re: Prosím o kontrolu ntb

Napsal: 14 říj 2014 12:46
od Dawood
# AdwCleaner v4.000 - Report created 14/10/2014 at 13:43:44
# DB v2014-10-13.5
# Updated 12/10/2014 by Xplode
# Operating System : Windows 8.1 Pro (64 bits)
# Username : David - DAVID-PC
# Running from : C:\Users\David\Downloads\adwcleaner_4.000.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\374311380
Folder Deleted : C:\Users\David\Documents\Optimizer Pro

***** [ Scheduled Tasks ] *****

Task Deleted : LaunchSignup

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17278


-\\ Google Chrome v37.0.2062.124


*************************

AdwCleaner[R0].txt - [1395 octets] - [14/10/2014 13:42:38]
AdwCleaner[S0].txt - [1135 octets] - [14/10/2014 13:43:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1195 octets] ##########

Re: Prosím o kontrolu ntb

Napsal: 14 říj 2014 18:13
od Márty84
:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Prosím o kontrolu ntb

Napsal: 18 říj 2014 07:12
od Dawood
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 18. 10. 2014
Scan Time: 4:35:37
Logfile: p.txt
Administrator: Yes

Version: 0.00.0.0000
Malware Database: v2014.10.18.02
Rootkit Database: v2014.10.17.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: David

Scan Type: Custom Scan
Result: Completed
Objects Scanned: 486375
Time Elapsed: 1 hr, 50 min, 12 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Re: Prosím o kontrolu ntb

Napsal: 18 říj 2014 09:26
od Márty84
:???: Je to ciste jen prvence, nebo je i nejaky problem?

:arrow: MBAM odinstalujte

:arrow: Dejte novy log z RSIT

Re: Prosím o kontrolu ntb

Napsal: 18 říj 2014 12:56
od Dawood
Jedná se o čistou prevenci.

Logfile of random's system information tool 1.10 (written by random/random)
Run by David at 2014-10-18 13:55:59
Microsoft Windows 8.1 Pro
System drive C: has 717 GB (79%) free of 905 GB
Total RAM: 8048 MB (83% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:56:07, on 18. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\trend micro\David.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll, C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6724 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
dashost.exe {0460c869-23b4-4a24-a2cc15c4f36c6913}
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss cf191b16-b6b3-494c-864b-aac6ad25280f 1
\??\C:\WINDOWS\system32\conhost.exe 0x4

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\KMSpico\Service_KMS.exe"
C:\WINDOWS\system32\WerFault.exe -u -p 2104 -s 1504
C:\WINDOWS\System32\svchost.exe -k AppReadiness
C:\WINDOWS\Explorer.EXE

taskeng.exe {CD974234-496F-4BAF-A1EB-D47CF5A38D9C}
taskhostex.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a50d9468-86de-4848-891a-b09d13d34003 -SystemEventPortName:HostProcess-d83b6998-4bce-495d-a221-e29a6b15f994 -IoCancelEventPortName:HostProcess-e2d65b10-ed37-4ac8-9721-c4882505e836 -NonStateChangingEventPortName:HostProcess-61b758da-f9ba-4ffd-80fd-b3a4e8a14cfb -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:40fa3ac5-6806-4210-9867-e48d09024518 -DeviceGroupId:WudfDefaultDevicePool
"C:\Program Files\Windows Media Player\wmpnetwk.exe"

"C:\Users\David\Downloads\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
C:\WINDOWS\System32\wsqmcons.exe
rundll32.exe WSClient.dll,RefreshBannedAppsList

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-26 13213840]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-10-29 1234064]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-08-27 6334096]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-27 2916152]
"SynLenovoGestureMgr"=C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [2012-08-27 665400]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2463552]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-10-04 2800296]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-17 15:36:28 ----D---- C:\ProgramData\Malwarebytes
2014-10-16 12:58:57 ----A---- C:\WINDOWS\system32\win32k.sys
2014-10-16 12:58:54 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-10-16 12:58:54 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-10-16 12:58:52 ----A---- C:\WINDOWS\system32\winbici.dll
2014-10-16 12:58:30 ----A---- C:\WINDOWS\SYSWOW64\packager.dll
2014-10-16 12:58:30 ----A---- C:\WINDOWS\system32\packager.dll
2014-10-16 12:57:24 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-10-16 12:57:23 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-10-16 12:57:18 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-10-16 12:57:17 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-10-16 12:57:16 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-10-16 12:57:14 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-10-16 12:57:13 ----A---- C:\WINDOWS\system32\wininet.dll
2014-10-16 12:57:13 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-10-16 12:57:12 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-10-16 12:57:12 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-10-16 12:57:12 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-10-16 12:57:11 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-10-16 12:57:11 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-10-16 12:57:10 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-10-16 12:57:09 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-10-16 12:57:09 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-10-16 12:57:09 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-10-16 12:57:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-10-16 12:57:07 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-10-16 12:57:06 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-10-16 12:56:01 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2014-10-16 12:56:01 ----A---- C:\WINDOWS\system32\rastls.dll
2014-10-16 12:55:58 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-10-16 12:55:58 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-10-16 12:55:58 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wups2.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wups.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-10-16 12:55:57 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-10-16 12:55:14 ----A---- C:\WINDOWS\system32\shell32.dll
2014-10-16 12:55:12 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-10-16 12:55:12 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-10-16 12:55:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-10-16 12:55:08 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-10-16 12:55:07 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-10-16 12:55:07 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-10-16 12:55:07 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-10-16 12:55:04 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-10-16 12:55:04 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-10-16 12:55:04 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-10-16 12:55:03 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-10-16 12:55:02 ----A---- C:\WINDOWS\system32\propsys.dll
2014-10-16 12:55:01 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-10-16 12:55:00 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-10-16 12:55:00 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-10-16 12:55:00 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-10-16 12:55:00 ----A---- C:\WINDOWS\system32\Wldap32.dll
2014-10-16 12:55:00 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-10-16 12:54:59 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2014-10-16 12:54:59 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-10-16 12:54:59 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-10-16 12:54:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-10-16 12:54:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\ProximityService.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\pcsvDevice.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-10-16 12:54:58 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-10-16 12:54:39 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2014-10-16 12:54:39 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-10-16 12:54:39 ----A---- C:\WINDOWS\system32\msi.dll
2014-10-16 12:54:39 ----A---- C:\WINDOWS\system32\authui.dll
2014-10-16 12:54:39 ----A---- C:\WINDOWS\system32\appinfo.dll
2014-10-15 13:47:27 ----D---- C:\Program Files (x86)\Microsoft Works
2014-10-15 13:46:58 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2014-10-15 13:46:07 ----D---- C:\WINDOWS\PCHEALTH
2014-10-15 13:44:39 ----D---- C:\Program Files\Microsoft Office
2014-10-15 13:44:33 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2014-10-15 13:43:47 ----D---- C:\ProgramData\Microsoft Help
2014-10-15 13:43:47 ----D---- C:\Program Files (x86)\Microsoft Office
2014-10-14 13:42:36 ----D---- C:\AdwCleaner
2014-10-13 16:09:50 ----D---- C:\Program Files\trend micro
2014-10-06 16:27:09 ----D---- C:\Program Files (x86)\osu!
2014-10-05 17:21:03 ----D---- C:\Users\David\AppData\Roaming\vlc
2014-10-05 17:19:55 ----D---- C:\Program Files (x86)\VideoLAN
2014-10-02 21:41:19 ----D---- C:\Users\David\AppData\Roaming\Might & Magic Heroes VI
2014-10-02 17:49:53 ----D---- C:\Program Files (x86)\directx
2014-09-27 20:33:49 ----D---- C:\Users\David\AppData\Roaming\Skype
2014-09-27 20:33:43 ----RD---- C:\Program Files (x86)\Skype
2014-09-27 20:33:38 ----D---- C:\ProgramData\Skype
2014-09-20 23:28:17 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-09-20 23:28:17 ----D---- C:\WINDOWS\system32\NV
2014-09-19 19:43:33 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-09-19 19:42:57 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvopencl.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvdispgenco6434411.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvdispco6434411.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvcuda.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2014-09-19 19:39:29 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2014-09-19 19:07:22 ----A---- C:\WINDOWS\SYSWOW64\nvaudcap32v.dll
2014-09-19 19:07:22 ----A---- C:\WINDOWS\system32\drivers\nvvad64v.sys

======List of files/folders modified in the last 1 month======

2014-10-18 13:55:42 ----RD---- C:\Program Files (x86)
2014-10-18 13:55:41 ----D---- C:\WINDOWS\system32\drivers
2014-10-18 13:55:41 ----D---- C:\WINDOWS\Prefetch
2014-10-18 13:55:31 ----D---- C:\WINDOWS\Temp
2014-10-18 13:53:54 ----D---- C:\WINDOWS\system32\config
2014-10-18 13:53:50 ----D---- C:\WINDOWS\WinSxS
2014-10-18 13:53:05 ----D---- C:\ProgramData\NVIDIA
2014-10-18 13:53:03 ----D---- C:\WINDOWS\Inf
2014-10-18 13:51:34 ----D---- C:\WINDOWS\CbsTemp
2014-10-18 13:50:03 ----RD---- C:\WINDOWS\System32
2014-10-18 13:50:03 ----D---- C:\WINDOWS\SysWOW64
2014-10-18 13:50:03 ----D---- C:\WINDOWS\MediaViewer
2014-10-18 13:50:03 ----D---- C:\WINDOWS\FileManager
2014-10-18 13:50:03 ----D---- C:\WINDOWS\Camera
2014-10-18 13:50:02 ----RD---- C:\WINDOWS\ToastData
2014-10-18 13:50:02 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-10-18 13:50:02 ----D---- C:\WINDOWS\system32\cs-CZ
2014-10-18 13:50:02 ----D---- C:\Program Files\Internet Explorer
2014-10-18 13:50:02 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-18 13:49:59 ----D---- C:\WINDOWS\WinStore
2014-10-18 13:49:56 ----D---- C:\WINDOWS\system32\DriverStore
2014-10-18 13:48:08 ----D---- C:\Users\David\AppData\Roaming\uTorrent
2014-10-18 13:00:01 ----D---- C:\WINDOWS\system32\sru
2014-10-18 08:14:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-18 03:47:04 ----SHD---- C:\System Volume Information
2014-10-18 03:38:02 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-17 21:58:53 ----RSD---- C:\WINDOWS\assembly
2014-10-17 15:36:28 ----HD---- C:\ProgramData
2014-10-16 18:50:57 ----D---- C:\ProgramData\PMB Files
2014-10-16 15:19:15 ----D---- C:\Program Files (x86)\Battle.net
2014-10-16 13:19:18 ----D---- C:\WINDOWS\system32\MRT
2014-10-16 13:19:15 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-16 12:54:16 ----D---- C:\WINDOWS\system32\catroot2
2014-10-15 13:57:32 ----SD---- C:\Users\David\AppData\Roaming\Microsoft
2014-10-15 13:48:10 ----SHD---- C:\WINDOWS\Installer
2014-10-15 13:48:10 ----SHD---- C:\Config.Msi
2014-10-15 13:47:17 ----D---- C:\Program Files (x86)\MSBuild
2014-10-15 13:46:58 ----D---- C:\Program Files (x86)\Common Files
2014-10-15 13:46:56 ----D---- C:\WINDOWS\ShellNew
2014-10-15 13:46:18 ----RSD---- C:\WINDOWS\Fonts
2014-10-15 13:46:07 ----SD---- C:\ProgramData\Microsoft
2014-10-15 13:46:07 ----D---- C:\Windows
2014-10-15 13:46:07 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-10-15 13:45:29 ----D---- C:\Program Files\Common Files\microsoft shared
2014-10-15 13:44:39 ----RD---- C:\Program Files
2014-10-15 13:44:11 ----A---- C:\WINDOWS\win.ini
2014-10-15 13:34:50 ----D---- C:\WINDOWS\Tasks
2014-10-14 13:41:35 ----D---- C:\Users\David\AppData\Roaming\Seznam.cz
2014-10-14 13:41:31 ----D---- C:\Program Files (x86)\Seznam.cz
2014-10-13 15:56:43 ----D---- C:\WINDOWS\AppReadiness
2014-10-12 11:33:09 ----D---- C:\ProgramData\TmForever
2014-10-12 10:52:01 ----D---- C:\ProgramData\Origin
2014-10-12 10:51:42 ----D---- C:\Program Files (x86)\Origin
2014-10-10 20:43:42 ----D---- C:\WINDOWS\system32\NDF
2014-10-10 15:54:49 ----HD---- C:\Program Files\WindowsApps
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2014-10-02 21:49:25 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-02 21:25:50 ----D---- C:\Program Files (x86)\Ubisoft
2014-10-02 18:40:55 ----D---- C:\Program Files (x86)\3DO
2014-10-02 17:56:47 ----D---- C:\WINDOWS\SYSWOW64\directx
2014-10-02 17:56:39 ----HD---- C:\WINDOWS\msdownld.tmp
2014-10-02 17:54:10 ----D---- C:\WINDOWS\System
2014-09-30 00:45:58 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-28 11:21:47 ----D---- C:\WINDOWS\rescache
2014-09-27 19:25:29 ----D---- C:\Users\David\AppData\Roaming\Mumble
2014-09-23 14:18:29 ----D---- C:\Program Files (x86)\Hearthstone
2014-09-22 08:42:39 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2014-09-19 19:43:33 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-09-19 19:08:14 ----D---- C:\Program Files\NVIDIA Corporation

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2014-09-14 32576]
R1 dtsoftbus01;@oem99.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-09-08 283064]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 ACPIVPC;@oem40.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2012-12-19 33560]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-08-29 857472]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-08-06 68136]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2012-12-13 5353888]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-30 4201104]
R3 IntcDAud;@oem29.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys []
R3 MEIx64;@oem59.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 NETwNe64;@oem47.inf,%NIC_Service_DispName_WIN8_64%;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [2013-10-08 3345376]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-09-14 13157696]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 20288]
R3 nvvad_WaveExtensible;@oem43.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 rtsuvc;@oem8.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-27 8227216]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-27 43832]
R3 SynTP;@oem32.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-27 448312]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem1.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
S3 RSUSBVSTOR;@oem58.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2012-06-13 315536]
S3 ssudmdm;@oem71.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\system32\DRIVERS\WinUsb.sys [2013-08-22 78848]
S4 WinDivert1.1;WinDivert1.1; \??\C:\Program Files\KMSpico\WinDivert.sys [2014-08-27 35376]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1149760]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1796928]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19440960]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-09-13 934216]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-09-13 411968]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-18 116648]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-11 1050904]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2012-12-19 277640]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-18 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: Prosím o kontrolu ntb

Napsal: 18 říj 2014 13:11
od Márty84
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe a ulozte nejlepe na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[CreateRestorePoint]

:services
MBAMSwissArmy
gupdate
SkypeUpdate
gupdatem

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
C:\ProgramData\Malwarebytes

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)

Re: Prosím o kontrolu ntb

Napsal: 19 říj 2014 14:35
od Dawood
All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: David
->Temp folder emptied: 775210116 bytes
->Temporary Internet Files folder emptied: 109920642 bytes
->Google Chrome cache emptied: 393936673 bytes
->Flash cache emptied: 1129 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 15523307 bytes
RecycleBin emptied: 28736 bytes

Total Files Cleaned = 1 235,00 mb


[EMPTYFLASH]

User: All Users

User: David
->Flash cache emptied: 0 bytes

User: Default

User: Default User

User: Public

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTM Restore Point
========== SERVICES/DRIVERS ==========
Service MBAMSwissArmy stopped successfully!
Service MBAMSwissArmy deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service SkypeUpdate stopped successfully!
Service SkypeUpdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Quarantine folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration folder moved successfully.
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware folder moved successfully.
C:\ProgramData\Malwarebytes folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 10192014_153045

Files moved on Reboot...
File move failed. C:\Users\David\AppData\Local\Microsoft\Windows\INetCache\counters.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Prosím o kontrolu ntb

Napsal: 19 říj 2014 18:08
od Márty84
:!: Vsechny tyto programy - vcetne pripadne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)

:arrow:
vyosek píše: :arrow: T-Cleaner http://tharifas.sweb.cz/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry mohou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.

:arrow: Stahnete Ccleaner http://www.filehippo.com/download_ccleaner a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!
(Pokud je v pc vice uzivatelskych uctu, pouzijte program i v nich)

:arrow: Defragmentujte disk(y) (SSD Disky ne!)
Stahnete program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak je na tom pc. Pokud bude vse v poradku, mame hotovo.




10.11. pro neaktivitu :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975