Stránka 1 z 2

otravné reklamy atď.

Napsal: 31 říj 2014 22:18
od sammy19
Ahojte, prosim o pomoc. PC uz nejaky cas vyhadzuje rôzne reklamy "odveci", v poslednom case nam stale ponuka nejaky IQ test a casto nas presmeruje na nejaku uplne inu stranku (online kasina, rôzne hry, atd.).
vopred dakujem za radu!

Prikladam log

Logfile of random's system information tool 1.10 (written by random/random)
Run by Tomáš at 2014-10-31 22:11:52
Microsoft Windows 8
System drive C: has 348 GB (77%) free of 450 GB
Total RAM: 4044 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:13:03, on 31.10.2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17116)
Boot mode: Normal

Running processes:
C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
C:\Windows\jmesoft\hotkey.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\PROGRA~2\MICROS~1\Office14\OIS.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Tomáš.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchinweb.info/?pid= ... K&unqvl=47
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchinweb.info/?pid= ... K&unqvl=47
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [LVT] C:\Program Files\Lenovo\LVT\LJYZ.exe 1
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [LiveSupport] "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
O4 - HKUS\S-1-5-21-3194863872-3879588589-1328743588-1004\..\RunOnce: [Lenovo.ShowBand] C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe /show (User 'Samko')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: ALFA plus - rýchle spustenie.lnk = C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (ExentInf1 Class) -
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - KROS_20400 (FirebirdServerKROS_20400) - Firebird Project - C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LSCWinService - Unknown owner - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.9 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12941 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\windows\system32\nvvsvc.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
dashost.exe {354e504d-d6a2-4712-97094416c80fc42d}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe" -s KROS_20400
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\jmesoft\Service.exe
"C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe"
C:\windows\SysWOW64\NLSSRV32.EXE
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\windows\system32\conhost.exe 0x4
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler64.exe"
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\windows\system32\rundll32.exe C:\windows\system32\pla.dll,PlaHost "LSC Memory" "0x1bac_0x1628_0x14404fca226"
taskeng.exe {9D543A27-E775-41EB-829E-B45071DFBED4}
"C:\Program Files (x86)\AVG Security Toolbar\AVG-Secure-Search-Update_0814tb.exe" --RELAUNCH=1 --CMPID=0814tb
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\windows\system32\nvvsvc.exe -session
taskhostex.exe
C:\windows\Explorer.EXE
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
szndesktop.exe default start
"C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
"C:\Windows\System32\spool\drivers\x64\3\E_YATIHFE.EXE" /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
\??\C:\windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe" /StartUp
"C:\Windows\jmesoft\hotkey.exe"
"C:\Windows\jmesoft\JME_LOAD.exe"
"C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"C:\PROGRA~2\MICROS~1\Office14\OIS.EXE" /shellOpen "C:\Users\Tomáš\Documents\MAJKA\Skeny\img007.jpg"
C:\windows\splwow64.exe 8192
C:\windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ddae7a5e-d780-4077-8a64-1aafb763e7df -SystemEventPortName:HostProcess-9a589307-6af3-4b2b-894d-97d1520ebd67 -IoCancelEventPortName:HostProcess-33dc72ff-69cc-40d7-a2ac-05c9f4e56ba8 -NonStateChangingEventPortName:HostProcess-426f87e8-087a-4fcc-b5db-aa2536c2591c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:87f9d8fb-eb9d-453d-a543-d4596d2a8ec6 -DeviceGroupId:WpdFsGroup
C:\windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3184.0.1258097316\109359847" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16,44 --gpu-vendor-id=0x10de --gpu-device-id=0x1049 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1193 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3184.1.683501852\256321527" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3184.2.1125976491\536799094" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3184.5.644616480\1706498885" --ppapi-flash-args=enable_hw_video_decode=1 --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3184.8.756161780\641223310" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/PasswordManagerUI/Bubble/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3184.26.1091214081\148779339" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/PasswordManagerUI/Bubble/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3184.27.256818442\1027731535" /prefetch:673131151

"C:\Users\Tomáš\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore1cf2c139eab0200.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA1cf8bf9b850a917.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B38BB0AE-338B-FE8E-B91E-4385EF188116}]
greatsaivEr - C:\Program Files (x86)\greatsaivEr\XU5T.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDD16753-D902-2AC1-C748-13C3CFA21B9B}]
SNT - C:\Program Files (x86)\SNT\7zyNVMBc02.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-01-12 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-01-12 171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-09-25 13196432]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"cz.seznam.software.autoupdate"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"LiveSupport"=C:\Program Files (x86)\LiveSupport\LiveSupport.exe /noshow /log []
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"EPLTarget\P0000000000000000"=C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE [2012-07-12 241280]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2013-07-24 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-08-17 28672]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"LVT"=C:\Program Files\Lenovo\LVT\LJYZ.exe [2011-11-24 886112]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]
"CLMLServer"=C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [2009-12-05 103720]
"UpdateP2GoShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2011-12-07 214312]
"mobilegeni daemon"=C:\Program Files (x86)\Mobogenie\DaemonProcess.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2014-08-25 2640408]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"FUFAXRCV"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [2012-07-09 502952]
"FUFAXSTM"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [2012-07-09 863400]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ALFA plus - rýchle spustenie.lnk - C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe

C:\Users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe]
"Debugger="tasklist.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-31 22:11:52 ----D---- C:\rsit
2014-10-31 22:11:52 ----D---- C:\Program Files\trend micro
2014-10-29 08:09:59 ----D---- C:\windows\system32\AutoUpdateLicense
2014-10-29 07:10:10 ----A---- C:\windows\SYSWOW64\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\WinSetupUI.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\Windows.ApplicationModel.Store.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\NotificationUI.exe
2014-10-29 07:10:10 ----A---- C:\windows\system32\AutoUpdate.exe
2014-10-29 07:10:09 ----A---- C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 07:22:56 ----A---- C:\windows\system32\FNTCACHE.DAT
2014-10-17 06:52:07 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-10-15 07:24:32 ----A---- C:\windows\SYSWOW64\packager.dll
2014-10-15 07:24:32 ----A---- C:\windows\system32\packager.dll
2014-10-15 07:24:24 ----A---- C:\windows\system32\mstscax.dll
2014-10-15 07:24:23 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-10-15 07:24:23 ----A---- C:\windows\system32\termsrv.dll
2014-10-15 07:24:23 ----A---- C:\windows\system32\rdpcorets.dll
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\aaclient.dll
2014-10-15 07:24:22 ----A---- C:\windows\system32\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\system32\mstsc.exe
2014-10-15 07:24:20 ----A---- C:\windows\system32\generaltel.dll
2014-10-15 07:24:20 ----A---- C:\windows\system32\aepdu.dll
2014-10-15 07:24:20 ----A---- C:\windows\system32\aeinv.dll
2014-10-15 07:24:19 ----A---- C:\windows\SYSWOW64\rastls.dll
2014-10-15 07:24:19 ----A---- C:\windows\system32\rastls.dll
2014-10-15 07:24:08 ----A---- C:\windows\system32\ntdll.dll
2014-10-15 07:24:07 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2014-10-15 07:24:07 ----A---- C:\windows\SYSWOW64\ntdll.dll
2014-10-15 07:24:07 ----A---- C:\windows\system32\schannel.dll
2014-10-15 07:24:07 ----A---- C:\windows\system32\localspl.dll
2014-10-15 07:24:06 ----A---- C:\windows\SYSWOW64\schannel.dll
2014-10-15 07:24:06 ----A---- C:\windows\system32\WMVDECOD.DLL
2014-10-15 07:24:06 ----A---- C:\windows\system32\storagewmi.dll
2014-10-15 07:24:06 ----A---- C:\windows\system32\d3d10warp.dll
2014-10-15 07:24:05 ----A---- C:\windows\system32\wcmsvc.dll
2014-10-15 07:24:02 ----A---- C:\windows\system32\winload.exe
2014-10-15 07:24:01 ----A---- C:\windows\SYSWOW64\dwmapi.dll
2014-10-15 07:24:01 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2014-10-15 07:24:00 ----A---- C:\windows\SYSWOW64\storagewmi.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\wcmcsp.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\profsvc.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\dwmapi.dll
2014-10-15 07:23:59 ----A---- C:\windows\SYSWOW64\KBDRUM.DLL
2014-10-15 07:23:59 ----A---- C:\windows\system32\win32spl.dll
2014-10-15 07:23:59 ----A---- C:\windows\system32\KBDRUM.DLL
2014-10-15 07:23:59 ----A---- C:\windows\system32\drivers\volsnap.sys
2014-10-15 07:23:59 ----A---- C:\windows\system32\defragsvc.dll
2014-10-15 07:23:59 ----A---- C:\windows\system32\Defrag.exe
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDBASH.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDBASH.DLL
2014-10-15 07:23:34 ----A---- C:\windows\system32\mshtml.dll
2014-10-15 07:23:31 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-10-15 07:23:28 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\wininet.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\iertutil.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\ieframe.dll
2014-10-15 07:23:27 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\iesysprep.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\uxtheme.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\mshtmled.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\uxtheme.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jscript9.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iesysprep.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\ie4uinit.exe
2014-10-15 07:23:25 ----A---- C:\windows\system32\dxtmsft.dll
2014-10-15 07:23:09 ----A---- C:\windows\system32\win32k.sys
2014-10-15 07:23:00 ----A---- C:\windows\SYSWOW64\user32.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\user32.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\srvsvc.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\msdtctm.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\USBHUB3.SYS
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\srvnet.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\srv2.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2014-10-15 07:22:59 ----A---- C:\windows\SYSWOW64\sscore.dll
2014-10-15 07:22:59 ----A---- C:\windows\system32\sscore.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\twinui.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\msi.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\actxprxy.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\twinui.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\msi.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\actxprxy.dll
2014-10-15 07:22:49 ----A---- C:\windows\SYSWOW64\authui.dll
2014-10-15 07:22:49 ----A---- C:\windows\system32\authui.dll
2014-10-05 18:56:56 ----D---- C:\Program Files\Common Files\EPSON
2014-10-05 18:55:34 ----RA---- C:\windows\system32\drivers\TMUSB64.sys
2014-10-05 18:54:39 ----D---- C:\Program Files (x86)\EpsonNet
2014-10-05 18:53:38 ----A---- C:\windows\system32\enspres.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\ensppui.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\ensppmon.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enpres.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enppui.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enppmon.dll
2014-10-05 18:53:37 ----D---- C:\Program Files\EpsonNet
2014-10-05 18:53:23 ----A---- C:\windows\system32\E_YLMHFE.DLL
2014-10-05 18:53:23 ----A---- C:\windows\system32\E_GCINST.DLL
2014-10-05 18:53:22 ----A---- C:\windows\system32\E_YD4BHFE.DLL
2014-10-05 18:53:13 ----A---- C:\windows\system32\esxw2ud.dll
2014-10-05 18:53:13 ----A---- C:\windows\system32\esxcdev.dll
2014-10-05 18:53:13 ----A---- C:\windows\system32\esdevapp.exe
2014-10-05 18:37:19 ----D---- C:\Users\Tomáš\AppData\Roaming\Epson
2014-10-05 18:36:13 ----D---- C:\Program Files (x86)\EPSON Software
2014-10-05 18:35:59 ----D---- C:\ProgramData\EPSON
2014-10-05 18:35:45 ----D---- C:\Program Files (x86)\epson

======List of files/folders modified in the last 1 month======

2014-10-31 22:11:52 ----RD---- C:\Program Files
2014-10-31 22:11:19 ----D---- C:\windows\Temp
2014-10-31 21:02:00 ----D---- C:\windows\system32\sru
2014-10-31 16:48:15 ----D---- C:\windows\Prefetch
2014-10-31 09:08:22 ----D---- C:\windows\Microsoft.NET
2014-10-31 07:11:04 ----D---- C:\Users\Tomáš\AppData\Roaming\Seznam.cz
2014-10-31 07:07:04 ----SHD---- C:\windows\Installer
2014-10-31 07:06:29 ----D---- C:\ProgramData\firebird
2014-10-31 07:00:56 ----D---- C:\windows\system32\config
2014-10-30 22:17:58 ----D---- C:\windows\system32\FxsTmp
2014-10-30 22:17:57 ----D---- C:\Users\Tomáš\AppData\Roaming\Nitro PDF
2014-10-30 10:44:48 ----D---- C:\windows\WinSxS
2014-10-30 08:25:56 ----D---- C:\windows\system32\catroot2
2014-10-29 08:10:00 ----D---- C:\windows\WinStore
2014-10-29 08:09:59 ----D---- C:\windows\SysWOW64
2014-10-29 08:09:59 ----AD---- C:\windows\System32
2014-10-29 08:09:37 ----D---- C:\windows\CbsTemp
2014-10-29 08:09:28 ----SHD---- C:\System Volume Information
2014-10-24 19:53:16 ----D---- C:\windows\system32\NDF
2014-10-22 06:39:29 ----D---- C:\Program Files (x86)\KROS
2014-10-19 07:56:02 ----RD---- C:\Program Files (x86)
2014-10-19 07:55:52 ----D---- C:\windows\Tasks
2014-10-17 11:17:06 ----D---- C:\windows\system32\wdi
2014-10-17 09:47:03 ----RSD---- C:\windows\assembly
2014-10-17 09:40:39 ----D---- C:\windows\rescache
2014-10-17 06:58:50 ----D---- C:\windows\system32\catroot
2014-10-17 06:53:48 ----D---- C:\windows\Inf
2014-10-16 21:57:44 ----SD---- C:\windows\system32\CompatTel
2014-10-16 21:57:42 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-10-16 21:57:41 ----D---- C:\windows\SYSWOW64\en-US
2014-10-16 21:57:41 ----D---- C:\windows\system32\en-US
2014-10-16 21:57:41 ----D---- C:\windows\system32\cs-CZ
2014-10-16 21:57:33 ----D---- C:\windows\SYSWOW64\wbem
2014-10-16 21:57:32 ----D---- C:\windows\system32\wbem
2014-10-16 21:57:32 ----D---- C:\windows\system32\Boot
2014-10-16 21:57:30 ----RSD---- C:\windows\Fonts
2014-10-16 21:57:24 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-16 21:57:22 ----D---- C:\Program Files\Internet Explorer
2014-10-16 21:57:14 ----D---- C:\windows\system32\drivers\en-US
2014-10-16 21:57:14 ----D---- C:\windows\system32\drivers\cs-CZ
2014-10-16 21:57:13 ----D---- C:\windows\system32\Drivers
2014-10-16 21:57:12 ----RD---- C:\windows\ToastData
2014-10-16 21:57:09 ----D---- C:\windows\system32\DriverStore
2014-10-16 21:57:00 ----D---- C:\windows\system32\MRT
2014-10-16 21:48:53 ----A---- C:\windows\system32\MRT.exe
2014-10-05 18:56:56 ----D---- C:\Program Files\Common Files
2014-10-05 18:54:38 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-05 18:53:35 ----SD---- C:\Users\Tomáš\AppData\Roaming\Microsoft
2014-10-05 18:53:22 ----HD---- C:\ProgramData
2014-10-05 18:53:05 ----D---- C:\windows\twain_32
2014-10-03 06:29:15 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-10-02 16:03:45 ----AD---- C:\Windows

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2013-01-31 652784]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2014-08-11 50976]
R1 dtsoftbus01;@oem14.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\windows\System32\drivers\dtsoftbus01.sys [2013-12-17 283064]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2012-07-26 64000]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2012-10-02 4159760]
R3 MEIx64;@oem9.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\System32\drivers\HECIx64.sys [2013-01-23 64624]
R3 NVHDA;@oem2.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda64v.sys [2013-02-25 194848]
R3 nvlddmkm;nvlddmkm; C:\windows\system32\DRIVERS\nvlddmkm.sys [2013-07-08 11105568]
R3 RSUSBVSTOR;@oem3.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2012-06-15 315536]
R3 RTL8168;@oem11.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2012-12-27 760032]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1iexpress;@net1ic64.inf,%E1IExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2012-06-02 333824]
S3 h643331;h643331; C:\windows\system32\drivers\h643331.sys [2008-05-19 63552]
S3 hid3331;hid3331; C:\windows\system32\drivers\hid3331.sys []
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-06-24 15283200]
S3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys [2012-06-02 8604672]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-07-05 210560]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2012-07-26 57344]
S3 WSDPrintDevice;@WSDPrint.Inf,%WSDPrintDevice.SVCDESC%;WSD Print Support; C:\windows\System32\drivers\WSDPrint.sys [2012-07-26 21504]
S3 WSDScan;@sti.inf,%WSDScan.SvcDesc%;Podpora skenování WSD; C:\windows\system32\DRIVERS\WSDScan.sys [2013-09-17 23552]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 FirebirdServerKROS_20400;Firebird Server - KROS_20400; C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe [2011-10-11 3764224]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-07-13 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-30 167736]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-08-17 32768]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-30 364856]
R2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [2013-05-24 230408]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\windows\SysWOW64\NLSSRV32.EXE [2013-05-24 70152]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2013-07-08 884512]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2013-05-14 390632]
R2 vToolbarUpdater18.1.9;vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [2014-08-11 1820184]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2012-07-26 43616]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 LSCWinService;LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [2014-02-19 1662424]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]

-----------------EOF-----------------

Re: otravné reklamy atď.

Napsal: 31 říj 2014 22:23
od Rudy
Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: otravné reklamy atď.

Napsal: 31 říj 2014 22:33
od sammy19
DAKUJEM, urobila som tak. Vkladam log

# AdwCleaner v3.311 - Report created 31/10/2014 at 22:27:53
# Updated 30/09/2014 by Xplode
# Operating System : Windows 8 (64 bits)
# Username : Tomáš - TOMAS
# Running from : C:\Users\Tomáš\Downloads\adwcleaner_3.311.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Secure Search
[#] Folder Deleted : C:\ProgramData\BitGuard
[#] Folder Deleted : C:\ProgramData\Browser Manager
[#] Folder Deleted : C:\ProgramData\BrowserProtect
Folder Deleted : C:\ProgramData\House Of Soft
Folder Deleted : C:\ProgramData\SetApp
Folder Deleted : C:\ProgramData\SNT
Folder Deleted : C:\ProgramData\greatsaivEr
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\Amazon\ABB
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\AVG Security Toolbar
Folder Deleted : C:\Program Files (x86)\iMesh
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\Music Toolbar
Folder Deleted : C:\Program Files (x86)\SNT
Folder Deleted : C:\Program Files (x86)\greatsaivEr
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Samko\AppData\Local\torch
Folder Deleted : C:\Users\Tomáš\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Tomáš\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Tomáš\AppData\Local\Popajar
Folder Deleted : C:\Users\Tomáš\AppData\Local\torch
Folder Deleted : C:\Users\Tomáš\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Tomáš\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\Tomáš\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Tomáš\Documents\Mobogenie
Folder Deleted : C:\Users\Tomáš\Documents\Optimizer Pro
Folder Deleted : C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcojmlidolamkenemlmbkdhkdkgganon
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgklklllogjglhfabfcldanbgolkggmn
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
[!] Folder Deleted : C:\Users\Samko\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnolidanjnbpamhmmkodnfbkcolmapdk
File Deleted : C:\Users\Tomáš\daemonprocess.txt
File Deleted : C:\Users\Tomáš\AppData\Roaming\LiveSupport.exe_log.txt
File Deleted : C:\Users\Tomáš\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_continuetosave.info_0.localstorage
File Deleted : C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_continuetosave.info_0.localstorage-journal
File Deleted : C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
File Deleted : C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [livesupport]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GameTreatWidget.GameTreatWidget
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44D07CAA-4FC4-5A84-9951-A485AD808D0E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{103DFC4E-147A-5606-9B4E-1C216DF227A1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{282B0E54-8981-49EB-9193-5910A1F6FD33}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{44D07CAA-4FC4-5A84-9951-A485AD808D0E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{282B0E54-8981-49EB-9193-5910A1F6FD33}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\LiveSupport
Key Deleted : HKCU\Software\Popajar
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\SmileysWeLove
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.17116

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v38.0.2125.111

[ File : C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [20458 octets] - [31/10/2014 22:25:49]
AdwCleaner[S0].txt - [18066 octets] - [31/10/2014 22:27:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18127 octets] ##########

Re: otravné reklamy atď.

Napsal: 01 lis 2014 08:18
od sammy19
tak zatiaľ sme sa ponuky na "IQ test" nezbavili :( stále to tu vyskakuje. Ďakujem za každú radu.

Re: otravné reklamy atď.

Napsal: 01 lis 2014 11:18
od Rudy
Dejte nový log RSIT.

Re: otravné reklamy atď.

Napsal: 01 lis 2014 12:08
od sammy19
posielam novy log, dakujem


Logfile of random's system information tool 1.10 (written by random/random)
Run by Tomáš at 2014-11-01 12:07:27
Microsoft Windows 8
System drive C: has 351 GB (78%) free of 450 GB
Total RAM: 4044 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:07:32, on 1.11.2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17116)
Boot mode: Normal

Running processes:
C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Windows\jmesoft\hotkey.exe
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Tomáš\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Tomáš.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [LVT] C:\Program Files\Lenovo\LVT\LJYZ.exe 1
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: ALFA plus - rýchle spustenie.lnk = C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (ExentInf1 Class) -
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - KROS_20400 (FirebirdServerKROS_20400) - Firebird Project - C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LSCWinService - Unknown owner - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.9 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11879 bytes

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore1cf2c139eab0200.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA1cf8bf9b850a917.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-01-12 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-01-12 171424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2013-07-24 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-08-17 28672]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"LVT"=C:\Program Files\Lenovo\LVT\LJYZ.exe [2011-11-24 886112]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]
"CLMLServer"=C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [2009-12-05 103720]
"UpdateP2GoShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2011-12-07 214312]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"FUFAXRCV"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [2012-07-09 502952]
"FUFAXSTM"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [2012-07-09 863400]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"cz.seznam.software.autoupdate"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"EPLTarget\P0000000000000000"=C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE [2012-07-12 241280]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ALFA plus - rýchle spustenie.lnk - C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe

C:\Users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"vidc.cvid"=iccvid.dll
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-01 12:07:28 ----D---- C:\Program Files (x86)\trend micro
2014-10-31 23:36:26 ----SHD---- C:\Config.Msi
2014-10-31 22:26:39 ----A---- C:\windows\SysWOW64\sqlite3.dll
2014-10-31 22:11:52 ----D---- C:\rsit
2014-10-29 07:10:10 ----A---- C:\windows\SysWOW64\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-17 06:52:07 ----A---- C:\windows\SysWOW64\FlashPlayerApp.exe
2014-10-15 07:24:32 ----A---- C:\windows\SysWOW64\packager.dll
2014-10-15 07:24:23 ----A---- C:\windows\SysWOW64\mstscax.dll
2014-10-15 07:24:22 ----A---- C:\windows\SysWOW64\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\SysWOW64\mstsc.exe
2014-10-15 07:24:22 ----A---- C:\windows\SysWOW64\aaclient.dll
2014-10-15 07:24:19 ----A---- C:\windows\SysWOW64\rastls.dll
2014-10-15 07:24:07 ----A---- C:\windows\SysWOW64\WMVDECOD.DLL
2014-10-15 07:24:07 ----A---- C:\windows\SysWOW64\ntdll.dll
2014-10-15 07:24:06 ----A---- C:\windows\SysWOW64\schannel.dll
2014-10-15 07:24:01 ----A---- C:\windows\SysWOW64\dwmapi.dll
2014-10-15 07:24:01 ----A---- C:\windows\SysWOW64\d3d10warp.dll
2014-10-15 07:24:00 ----A---- C:\windows\SysWOW64\storagewmi.dll
2014-10-15 07:23:59 ----A---- C:\windows\SysWOW64\KBDRUM.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SysWOW64\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SysWOW64\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SysWOW64\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SysWOW64\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SysWOW64\KBDBASH.DLL
2014-10-15 07:23:31 ----A---- C:\windows\SysWOW64\mshtml.dll
2014-10-15 07:23:28 ----A---- C:\windows\SysWOW64\ieframe.dll
2014-10-15 07:23:27 ----A---- C:\windows\SysWOW64\iertutil.dll
2014-10-15 07:23:26 ----A---- C:\windows\SysWOW64\wininet.dll
2014-10-15 07:23:26 ----A---- C:\windows\SysWOW64\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\SysWOW64\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\SysWOW64\jscript9.dll
2014-10-15 07:23:26 ----A---- C:\windows\SysWOW64\iesysprep.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\uxtheme.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\mshtmled.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SysWOW64\dxtmsft.dll
2014-10-15 07:23:00 ----A---- C:\windows\SysWOW64\user32.dll
2014-10-15 07:22:59 ----A---- C:\windows\SysWOW64\sscore.dll
2014-10-15 07:22:51 ----A---- C:\windows\SysWOW64\twinui.dll
2014-10-15 07:22:51 ----A---- C:\windows\SysWOW64\msi.dll
2014-10-15 07:22:51 ----A---- C:\windows\SysWOW64\actxprxy.dll
2014-10-15 07:22:49 ----A---- C:\windows\SysWOW64\authui.dll
2014-10-05 18:54:39 ----D---- C:\Program Files (x86)\EpsonNet
2014-10-05 18:37:19 ----D---- C:\Users\Tomáš\AppData\Roaming\Epson
2014-10-05 18:36:13 ----D---- C:\Program Files (x86)\EPSON Software
2014-10-05 18:35:59 ----D---- C:\ProgramData\EPSON
2014-10-05 18:35:45 ----D---- C:\Program Files (x86)\epson

======List of files/folders modified in the last 1 month======

2014-11-01 12:07:28 ----RD---- C:\Program Files (x86)
2014-11-01 12:07:21 ----D---- C:\windows\Temp
2014-11-01 11:52:21 ----D---- C:\windows\Prefetch
2014-11-01 10:50:00 ----D---- C:\windows\Microsoft.NET
2014-11-01 10:49:09 ----SHD---- C:\System Volume Information
2014-11-01 07:28:01 ----D---- C:\Users\Tomáš\AppData\Roaming\Seznam.cz
2014-11-01 07:23:54 ----D---- C:\ProgramData\firebird
2014-11-01 07:23:32 ----SHD---- C:\windows\Installer
2014-10-31 23:36:57 ----RSD---- C:\windows\assembly
2014-10-31 23:36:54 ----D---- C:\Users\Tomáš\AppData\Roaming\LSC
2014-10-31 23:35:43 ----D---- C:\windows\Downloaded Installations
2014-10-31 23:24:17 ----D---- C:\Users\Tomáš\AppData\Roaming\Nitro PDF
2014-10-31 22:36:30 ----D---- C:\windows\System32
2014-10-31 22:36:30 ----D---- C:\windows\Inf
2014-10-31 22:27:54 ----HD---- C:\ProgramData
2014-10-31 22:26:39 ----D---- C:\windows\SysWOW64
2014-10-31 22:11:52 ----RD---- C:\Program Files
2014-10-30 10:44:48 ----D---- C:\windows\WinSxS
2014-10-29 08:10:18 ----D---- C:\windows\CbsTemp
2014-10-29 08:10:00 ----D---- C:\windows\WinStore
2014-10-22 06:39:29 ----D---- C:\Program Files (x86)\KROS
2014-10-19 07:55:52 ----D---- C:\windows\Tasks
2014-10-17 09:40:39 ----D---- C:\windows\rescache
2014-10-16 21:57:42 ----D---- C:\windows\SysWOW64\cs-CZ
2014-10-16 21:57:41 ----D---- C:\windows\SysWOW64\en-US
2014-10-16 21:57:33 ----D---- C:\windows\SysWOW64\wbem
2014-10-16 21:57:30 ----RSD---- C:\windows\Fonts
2014-10-16 21:57:24 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-16 21:57:12 ----RD---- C:\windows\ToastData
2014-10-05 18:54:38 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-05 18:53:35 ----SD---- C:\Users\Tomáš\AppData\Roaming\Microsoft
2014-10-05 18:53:05 ----D---- C:\windows\twain_32
2014-10-02 16:03:45 ----AD---- C:\Windows

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\windows\system32\DRIVERS\edevmon.sys []
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys []
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys []
R1 dtsoftbus01;@oem14.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\windows\System32\drivers\dtsoftbus01.sys []
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys []
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys []
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys []
R3 MEIx64;@oem9.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\System32\drivers\HECIx64.sys []
R3 NVHDA;@oem2.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda64v.sys []
R3 nvlddmkm;nvlddmkm; C:\windows\system32\DRIVERS\nvlddmkm.sys []
R3 RSUSBVSTOR;@oem3.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys []
R3 RTL8168;@oem11.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys []
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudbus.sys []
S3 e1iexpress;@net1ic64.inf,%E1IExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys []
S3 h643331;h643331; C:\windows\system32\drivers\h643331.sys []
S3 hid3331;hid3331; C:\windows\system32\drivers\hid3331.sys [2008-05-19 41336]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys []
S3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys []
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudmdm.sys []
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys []
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys []
S3 WSDPrintDevice;@WSDPrint.Inf,%WSDPrintDevice.SVCDESC%;WSD Print Support; C:\windows\System32\drivers\WSDPrint.sys []
S3 WSDScan;@sti.inf,%WSDScan.SvcDesc%;Podpora skenování WSD; C:\windows\system32\DRIVERS\WSDScan.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 FirebirdServerKROS_20400;Firebird Server - KROS_20400; C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe [2011-10-11 3764224]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-07-13 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-30 167736]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-08-17 32768]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-30 364856]
R2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [2013-05-24 230408]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\windows\SysWOW64\NLSSRV32.EXE [2013-05-24 70152]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe []
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2013-05-14 390632]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S2 vToolbarUpdater18.1.9;vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe []
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2012-07-26 43616]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 LSCWinService;LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [2014-10-16 272776]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]

-----------------EOF-----------------

Re: otravné reklamy atď.

Napsal: 01 lis 2014 12:16
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\windows\tasks\GoogleUpdateTaskMachineCore1cf2c139eab0200.job
C:\windows\tasks\GoogleUpdateTaskMachineUA1cf8bf9b850a917.job

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: otravné reklamy atď.

Napsal: 01 lis 2014 13:10
od sammy19
tak som urobila podla postupu vsetko a vkladam novy log RSIT

Logfile of random's system information tool 1.10 (written by random/random)
Run by Tomáš at 2014-11-01 13:09:43
Microsoft Windows 8
System drive C: has 352 GB (78%) free of 450 GB
Total RAM: 4044 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:09:46, on 1.11.2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17116)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
C:\Windows\jmesoft\hotkey.exe
C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Program Files\trend micro\Tomáš.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [LVT] C:\Program Files\Lenovo\LVT\LJYZ.exe 1
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: ALFA plus - rýchle spustenie.lnk = C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (ExentInf1 Class) -
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - KROS_20400 (FirebirdServerKROS_20400) - Firebird Project - C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LSCWinService - Unknown owner - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.9 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11238 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\windows\system32\nvvsvc.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
"dwm.exe"
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\windows\system32\nvvsvc.exe -session -first
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
dashost.exe {9edbcb9f-3393-4e79-8ac74ce0736ba293}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe" -s KROS_20400
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\jmesoft\Service.exe
"C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe"
C:\windows\SysWOW64\NLSSRV32.EXE
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
taskhostex.exe
taskeng.exe {0B2ADCFD-C773-43A4-A291-57462B9D8223}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler64.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Windows\System32\spool\drivers\x64\3\E_YATIHFE.EXE" /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
"C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe" /StartUp
"C:\Windows\jmesoft\hotkey.exe"
szndesktop.exe default start
"C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
"C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\windows\system32\conhost.exe 0x4
"C:\Windows\jmesoft\JME_LOAD.exe"
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe"
"C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe" /showasync
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\rundll32.exe C:\windows\system32\pla.dll,PlaHost "LSC Memory" "0xe8c_0x170_0x7fb0f343"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
taskhost.exe $(Arg0)
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 556 572 584 65536 580

"C:\Users\Tomáš\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B38BB0AE-338B-FE8E-B91E-4385EF188116}]
greatsaivEr - C:\Program Files (x86)\greatsaivEr\XU5T.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDD16753-D902-2AC1-C748-13C3CFA21B9B}]
SNT - C:\Program Files (x86)\SNT\7zyNVMBc02.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-01-12 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-01-12 171424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-09-25 13196432]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"cz.seznam.software.autoupdate"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"EPLTarget\P0000000000000000"=C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE [2012-07-12 241280]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2013-07-24 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-08-17 28672]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"LVT"=C:\Program Files\Lenovo\LVT\LJYZ.exe [2011-11-24 886112]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]
"CLMLServer"=C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [2009-12-05 103720]
"UpdateP2GoShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2011-12-07 214312]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"FUFAXRCV"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [2012-07-09 502952]
"FUFAXSTM"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [2012-07-09 863400]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ALFA plus - rýchle spustenie.lnk - C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe

C:\Users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-01 12:18:56 ----D---- C:\_OTM
2014-11-01 12:07:28 ----D---- C:\Program Files (x86)\trend micro
2014-10-31 23:36:26 ----SHD---- C:\Config.Msi
2014-10-31 22:26:39 ----A---- C:\windows\SYSWOW64\sqlite3.dll
2014-10-31 22:11:52 ----D---- C:\rsit
2014-10-31 22:11:52 ----D---- C:\Program Files\trend micro
2014-10-29 08:09:59 ----D---- C:\windows\system32\AutoUpdateLicense
2014-10-29 07:10:10 ----A---- C:\windows\SYSWOW64\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\WinSetupUI.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\Windows.ApplicationModel.Store.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\NotificationUI.exe
2014-10-29 07:10:10 ----A---- C:\windows\system32\AutoUpdate.exe
2014-10-29 07:10:09 ----A---- C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 07:22:56 ----A---- C:\windows\system32\FNTCACHE.DAT
2014-10-17 06:52:07 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-10-15 07:24:32 ----A---- C:\windows\SYSWOW64\packager.dll
2014-10-15 07:24:32 ----A---- C:\windows\system32\packager.dll
2014-10-15 07:24:24 ----A---- C:\windows\system32\mstscax.dll
2014-10-15 07:24:23 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-10-15 07:24:23 ----A---- C:\windows\system32\termsrv.dll
2014-10-15 07:24:23 ----A---- C:\windows\system32\rdpcorets.dll
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\aaclient.dll
2014-10-15 07:24:22 ----A---- C:\windows\system32\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\system32\mstsc.exe
2014-10-15 07:24:20 ----A---- C:\windows\system32\generaltel.dll
2014-10-15 07:24:20 ----A---- C:\windows\system32\aepdu.dll
2014-10-15 07:24:20 ----A---- C:\windows\system32\aeinv.dll
2014-10-15 07:24:19 ----A---- C:\windows\SYSWOW64\rastls.dll
2014-10-15 07:24:19 ----A---- C:\windows\system32\rastls.dll
2014-10-15 07:24:08 ----A---- C:\windows\system32\ntdll.dll
2014-10-15 07:24:07 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2014-10-15 07:24:07 ----A---- C:\windows\SYSWOW64\ntdll.dll
2014-10-15 07:24:07 ----A---- C:\windows\system32\schannel.dll
2014-10-15 07:24:07 ----A---- C:\windows\system32\localspl.dll
2014-10-15 07:24:06 ----A---- C:\windows\SYSWOW64\schannel.dll
2014-10-15 07:24:06 ----A---- C:\windows\system32\WMVDECOD.DLL
2014-10-15 07:24:06 ----A---- C:\windows\system32\storagewmi.dll
2014-10-15 07:24:06 ----A---- C:\windows\system32\d3d10warp.dll
2014-10-15 07:24:05 ----A---- C:\windows\system32\wcmsvc.dll
2014-10-15 07:24:02 ----A---- C:\windows\system32\winload.exe
2014-10-15 07:24:01 ----A---- C:\windows\SYSWOW64\dwmapi.dll
2014-10-15 07:24:01 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2014-10-15 07:24:00 ----A---- C:\windows\SYSWOW64\storagewmi.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\wcmcsp.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\profsvc.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\dwmapi.dll
2014-10-15 07:23:59 ----A---- C:\windows\SYSWOW64\KBDRUM.DLL
2014-10-15 07:23:59 ----A---- C:\windows\system32\win32spl.dll
2014-10-15 07:23:59 ----A---- C:\windows\system32\KBDRUM.DLL
2014-10-15 07:23:59 ----A---- C:\windows\system32\drivers\volsnap.sys
2014-10-15 07:23:59 ----A---- C:\windows\system32\defragsvc.dll
2014-10-15 07:23:59 ----A---- C:\windows\system32\Defrag.exe
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDBASH.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDBASH.DLL
2014-10-15 07:23:34 ----A---- C:\windows\system32\mshtml.dll
2014-10-15 07:23:31 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-10-15 07:23:28 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\wininet.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\iertutil.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\ieframe.dll
2014-10-15 07:23:27 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\iesysprep.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\uxtheme.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\mshtmled.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\uxtheme.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jscript9.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iesysprep.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\ie4uinit.exe
2014-10-15 07:23:25 ----A---- C:\windows\system32\dxtmsft.dll
2014-10-15 07:23:09 ----A---- C:\windows\system32\win32k.sys
2014-10-15 07:23:00 ----A---- C:\windows\SYSWOW64\user32.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\user32.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\srvsvc.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\msdtctm.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\USBHUB3.SYS
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\srvnet.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\srv2.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2014-10-15 07:22:59 ----A---- C:\windows\SYSWOW64\sscore.dll
2014-10-15 07:22:59 ----A---- C:\windows\system32\sscore.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\twinui.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\msi.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\actxprxy.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\twinui.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\msi.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\actxprxy.dll
2014-10-15 07:22:49 ----A---- C:\windows\SYSWOW64\authui.dll
2014-10-15 07:22:49 ----A---- C:\windows\system32\authui.dll
2014-10-05 18:56:56 ----D---- C:\Program Files\Common Files\EPSON
2014-10-05 18:55:34 ----RA---- C:\windows\system32\drivers\TMUSB64.sys
2014-10-05 18:54:39 ----D---- C:\Program Files (x86)\EpsonNet
2014-10-05 18:53:38 ----A---- C:\windows\system32\enspres.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\ensppui.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\ensppmon.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enpres.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enppui.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enppmon.dll
2014-10-05 18:53:37 ----D---- C:\Program Files\EpsonNet
2014-10-05 18:53:23 ----A---- C:\windows\system32\E_YLMHFE.DLL
2014-10-05 18:53:23 ----A---- C:\windows\system32\E_GCINST.DLL
2014-10-05 18:53:22 ----A---- C:\windows\system32\E_YD4BHFE.DLL
2014-10-05 18:53:13 ----A---- C:\windows\system32\esxw2ud.dll
2014-10-05 18:53:13 ----A---- C:\windows\system32\esxcdev.dll
2014-10-05 18:53:13 ----A---- C:\windows\system32\esdevapp.exe
2014-10-05 18:37:19 ----D---- C:\Users\Tomáš\AppData\Roaming\Epson
2014-10-05 18:36:13 ----D---- C:\Program Files (x86)\EPSON Software
2014-10-05 18:35:59 ----D---- C:\ProgramData\EPSON
2014-10-05 18:35:45 ----D---- C:\Program Files (x86)\epson

======List of files/folders modified in the last 1 month======

2014-11-01 13:08:26 ----D---- C:\windows\Prefetch
2014-11-01 13:00:09 ----D---- C:\windows\system32\sru
2014-11-01 12:51:12 ----D---- C:\windows\rescache
2014-11-01 12:36:15 ----D---- C:\windows\Temp
2014-11-01 12:32:05 ----D---- C:\Users\Tomáš\AppData\Roaming\Seznam.cz
2014-11-01 12:29:20 ----D---- C:\windows\Inf
2014-11-01 12:29:20 ----AD---- C:\windows\System32
2014-11-01 12:29:20 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-11-01 12:28:49 ----D---- C:\ProgramData\firebird
2014-11-01 12:28:19 ----SHD---- C:\System Volume Information
2014-11-01 12:27:48 ----SHD---- C:\windows\Installer
2014-11-01 12:18:58 ----D---- C:\windows\Tasks
2014-11-01 12:07:28 ----RD---- C:\Program Files (x86)
2014-11-01 10:50:00 ----D---- C:\windows\Microsoft.NET
2014-10-31 23:36:57 ----RSD---- C:\windows\assembly
2014-10-31 23:36:54 ----D---- C:\Users\Tomáš\AppData\Roaming\LSC
2014-10-31 23:36:45 ----D---- C:\Program Files\Lenovo
2014-10-31 23:35:43 ----D---- C:\windows\Downloaded Installations
2014-10-31 23:24:17 ----D---- C:\Users\Tomáš\AppData\Roaming\Nitro PDF
2014-10-31 22:33:37 ----D---- C:\windows\system32\FxsTmp
2014-10-31 22:27:54 ----HD---- C:\ProgramData
2014-10-31 22:26:39 ----D---- C:\windows\SysWOW64
2014-10-31 22:11:52 ----RD---- C:\Program Files
2014-10-31 07:00:56 ----D---- C:\windows\system32\config
2014-10-30 10:44:48 ----D---- C:\windows\WinSxS
2014-10-30 08:25:56 ----D---- C:\windows\system32\catroot2
2014-10-29 08:10:18 ----D---- C:\windows\CbsTemp
2014-10-29 08:10:00 ----D---- C:\windows\WinStore
2014-10-24 19:53:16 ----D---- C:\windows\system32\NDF
2014-10-22 06:39:29 ----D---- C:\Program Files (x86)\KROS
2014-10-17 11:17:06 ----D---- C:\windows\system32\wdi
2014-10-17 06:58:50 ----D---- C:\windows\system32\catroot
2014-10-16 21:57:44 ----SD---- C:\windows\system32\CompatTel
2014-10-16 21:57:42 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-10-16 21:57:41 ----D---- C:\windows\SYSWOW64\en-US
2014-10-16 21:57:41 ----D---- C:\windows\system32\en-US
2014-10-16 21:57:41 ----D---- C:\windows\system32\cs-CZ
2014-10-16 21:57:33 ----D---- C:\windows\SYSWOW64\wbem
2014-10-16 21:57:32 ----D---- C:\windows\system32\wbem
2014-10-16 21:57:32 ----D---- C:\windows\system32\Boot
2014-10-16 21:57:30 ----RSD---- C:\windows\Fonts
2014-10-16 21:57:24 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-16 21:57:22 ----D---- C:\Program Files\Internet Explorer
2014-10-16 21:57:14 ----D---- C:\windows\system32\drivers\en-US
2014-10-16 21:57:14 ----D---- C:\windows\system32\drivers\cs-CZ
2014-10-16 21:57:13 ----D---- C:\windows\system32\Drivers
2014-10-16 21:57:12 ----RD---- C:\windows\ToastData
2014-10-16 21:57:09 ----D---- C:\windows\system32\DriverStore
2014-10-16 21:57:00 ----D---- C:\windows\system32\MRT
2014-10-16 21:48:53 ----A---- C:\windows\system32\MRT.exe
2014-10-05 18:56:56 ----D---- C:\Program Files\Common Files
2014-10-05 18:54:38 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-05 18:53:35 ----SD---- C:\Users\Tomáš\AppData\Roaming\Microsoft
2014-10-05 18:53:05 ----D---- C:\windows\twain_32
2014-10-02 16:03:45 ----AD---- C:\Windows

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2013-01-31 652784]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2014-08-11 50976]
R1 dtsoftbus01;@oem14.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\windows\System32\drivers\dtsoftbus01.sys [2013-12-17 283064]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2012-07-26 64000]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2012-10-02 4159760]
R3 MEIx64;@oem9.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\System32\drivers\HECIx64.sys [2013-01-23 64624]
R3 NVHDA;@oem2.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda64v.sys [2013-02-25 194848]
R3 nvlddmkm;nvlddmkm; C:\windows\system32\DRIVERS\nvlddmkm.sys [2013-07-08 11105568]
R3 RSUSBVSTOR;@oem3.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2012-06-15 315536]
R3 RTL8168;@oem11.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2012-12-27 760032]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1iexpress;@net1ic64.inf,%E1IExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2012-06-02 333824]
S3 h643331;h643331; C:\windows\system32\drivers\h643331.sys [2008-05-19 63552]
S3 hid3331;hid3331; C:\windows\system32\drivers\hid3331.sys []
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-06-24 15283200]
S3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys [2012-06-02 8604672]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-07-05 210560]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2012-07-26 57344]
S3 WSDPrintDevice;@WSDPrint.Inf,%WSDPrintDevice.SVCDESC%;WSD Print Support; C:\windows\System32\drivers\WSDPrint.sys [2012-07-26 21504]
S3 WSDScan;@sti.inf,%WSDScan.SvcDesc%;Podpora skenování WSD; C:\windows\system32\DRIVERS\WSDScan.sys [2013-09-17 23552]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 FirebirdServerKROS_20400;Firebird Server - KROS_20400; C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe [2011-10-11 3764224]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-07-13 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-30 167736]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-08-17 32768]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-30 364856]
R2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [2013-05-24 230408]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\windows\SysWOW64\NLSSRV32.EXE [2013-05-24 70152]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2013-07-08 884512]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2013-05-14 390632]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S2 vToolbarUpdater18.1.9;vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe []
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2012-07-26 43616]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 LSCWinService;LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [2014-10-16 272776]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]

-----------------EOF-----------------

Re: otravné reklamy atď.

Napsal: 01 lis 2014 18:18
od Rudy
Log je již OK. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?

Re: otravné reklamy atď.

Napsal: 01 lis 2014 18:44
od sammy19
Dakujem moc za rady, urobila som ten cleanup, ale stale mi tu tie reklamy zostali:( Od dnes sa dokonca objavuje okienko s tym, ze treba update Java a rovno ma to hodi na nejaku stranku, aj ked kliknem na krizik. Proste tu zrejme stale nieco je. A take tie reklamy, akoze "Mate 1 dolezitu spravu, vyhrali ste, a bla-bla" a blika to na obrazovke ako sialene.

Prikladam novy log RSIT uz po tom cleanupe.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Tomáš at 2014-11-01 18:39:51
Microsoft Windows 8
System drive C: has 351 GB (78%) free of 450 GB
Total RAM: 4044 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:39:54, on 1.11.2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17116)
Boot mode: Normal

Running processes:
C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\jmesoft\hotkey.exe
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Tomáš.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [LVT] C:\Program Files\Lenovo\LVT\LJYZ.exe 1
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: ALFA plus - rýchle spustenie.lnk = C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4FF78044-96B4-4312-A5B7-FDA3CB328095} (ExentInf1 Class) -
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - KROS_20400 (FirebirdServerKROS_20400) - Firebird Project - C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LSCWinService - Unknown owner - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.9 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11602 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\windows\system32\nvvsvc.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
"dwm.exe"
C:\windows\system32\svchost.exe -k LocalService
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\windows\system32\nvvsvc.exe -session -first
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {7e68543e-4526-4cb1-86349d9eece3433a}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe" -s KROS_20400
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\jmesoft\Service.exe
"C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe"
C:\windows\SysWOW64\NLSSRV32.EXE
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
taskhostex.exe
taskeng.exe {781A3700-3026-4E62-8224-C81BE6CC2B61}
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler64.exe"
C:\windows\Explorer.EXE
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
szndesktop.exe default start
"C:\Windows\System32\spool\drivers\x64\3\E_YATIHFE.EXE" /EPT "EPLTarget\P0000000000000000" /M "WP-4525 Series"
"C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\windows\system32\conhost.exe 0x4

"C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Windows\jmesoft\hotkey.exe"
"C:\Windows\jmesoft\JME_LOAD.exe"
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4560.0.61505728\1099144213" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16,44 --gpu-vendor-id=0x10de --gpu-device-id=0x1049 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1193 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe"
"C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="4560.1.295778950\2095358313" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="4560.2.412930951\319412325" /prefetch:673131151
C:\windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4560.4.1573187947\1556287201" --ppapi-flash-args=enable_hw_video_decode=1 --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
C:\windows\system32\msiexec.exe /V
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="4560.6.1249689376\257109677" /prefetch:673131151
"C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe" /showasync
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="4560.15.252880576\1550231791" /prefetch:673131151
"C:\windows\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_25/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="4560.16.1033298337\248104243" /prefetch:673131151

"C:\Users\Tomáš\Downloads\RSITx64 (1).exe"
C:\windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B38BB0AE-338B-FE8E-B91E-4385EF188116}]
greatsaivEr - C:\Program Files (x86)\greatsaivEr\XU5T.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDD16753-D902-2AC1-C748-13C3CFA21B9B}]
SNT - C:\Program Files (x86)\SNT\7zyNVMBc02.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-01-12 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-01-12 171424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-09-25 13196432]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"cz.seznam.software.autoupdate"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Tomáš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"EPLTarget\P0000000000000000"=C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHFE.EXE [2012-07-12 241280]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2013-07-24 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-08-17 28672]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"LVT"=C:\Program Files\Lenovo\LVT\LJYZ.exe [2011-11-24 886112]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]
"CLMLServer"=C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [2009-12-05 103720]
"UpdateP2GoShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2011-12-07 214312]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"FUFAXRCV"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [2012-07-09 502952]
"FUFAXSTM"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [2012-07-09 863400]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ALFA plus - rýchle spustenie.lnk - C:\Program Files (x86)\KROS\ALFA plus\!System\ALFAplus.exe

C:\Users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-01 18:39:51 ----D---- C:\rsit
2014-11-01 12:07:28 ----D---- C:\Program Files (x86)\trend micro
2014-10-31 22:26:39 ----A---- C:\windows\SYSWOW64\sqlite3.dll
2014-10-31 22:11:52 ----D---- C:\Program Files\trend micro
2014-10-29 08:09:59 ----D---- C:\windows\system32\AutoUpdateLicense
2014-10-29 07:10:10 ----A---- C:\windows\SYSWOW64\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\WSShared.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\WinSetupUI.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\Windows.ApplicationModel.Store.dll
2014-10-29 07:10:10 ----A---- C:\windows\system32\NotificationUI.exe
2014-10-29 07:10:10 ----A---- C:\windows\system32\AutoUpdate.exe
2014-10-29 07:10:09 ----A---- C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-22 07:22:56 ----A---- C:\windows\system32\FNTCACHE.DAT
2014-10-17 06:52:07 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-10-15 07:24:32 ----A---- C:\windows\SYSWOW64\packager.dll
2014-10-15 07:24:32 ----A---- C:\windows\system32\packager.dll
2014-10-15 07:24:24 ----A---- C:\windows\system32\mstscax.dll
2014-10-15 07:24:23 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-10-15 07:24:23 ----A---- C:\windows\system32\termsrv.dll
2014-10-15 07:24:23 ----A---- C:\windows\system32\rdpcorets.dll
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-10-15 07:24:22 ----A---- C:\windows\SYSWOW64\aaclient.dll
2014-10-15 07:24:22 ----A---- C:\windows\system32\winsta.dll
2014-10-15 07:24:22 ----A---- C:\windows\system32\mstsc.exe
2014-10-15 07:24:20 ----A---- C:\windows\system32\generaltel.dll
2014-10-15 07:24:20 ----A---- C:\windows\system32\aepdu.dll
2014-10-15 07:24:20 ----A---- C:\windows\system32\aeinv.dll
2014-10-15 07:24:19 ----A---- C:\windows\SYSWOW64\rastls.dll
2014-10-15 07:24:19 ----A---- C:\windows\system32\rastls.dll
2014-10-15 07:24:08 ----A---- C:\windows\system32\ntdll.dll
2014-10-15 07:24:07 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2014-10-15 07:24:07 ----A---- C:\windows\SYSWOW64\ntdll.dll
2014-10-15 07:24:07 ----A---- C:\windows\system32\schannel.dll
2014-10-15 07:24:07 ----A---- C:\windows\system32\localspl.dll
2014-10-15 07:24:06 ----A---- C:\windows\SYSWOW64\schannel.dll
2014-10-15 07:24:06 ----A---- C:\windows\system32\WMVDECOD.DLL
2014-10-15 07:24:06 ----A---- C:\windows\system32\storagewmi.dll
2014-10-15 07:24:06 ----A---- C:\windows\system32\d3d10warp.dll
2014-10-15 07:24:05 ----A---- C:\windows\system32\wcmsvc.dll
2014-10-15 07:24:02 ----A---- C:\windows\system32\winload.exe
2014-10-15 07:24:01 ----A---- C:\windows\SYSWOW64\dwmapi.dll
2014-10-15 07:24:01 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2014-10-15 07:24:00 ----A---- C:\windows\SYSWOW64\storagewmi.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\wcmcsp.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\profsvc.dll
2014-10-15 07:24:00 ----A---- C:\windows\system32\dwmapi.dll
2014-10-15 07:23:59 ----A---- C:\windows\SYSWOW64\KBDRUM.DLL
2014-10-15 07:23:59 ----A---- C:\windows\system32\win32spl.dll
2014-10-15 07:23:59 ----A---- C:\windows\system32\KBDRUM.DLL
2014-10-15 07:23:59 ----A---- C:\windows\system32\drivers\volsnap.sys
2014-10-15 07:23:59 ----A---- C:\windows\system32\defragsvc.dll
2014-10-15 07:23:59 ----A---- C:\windows\system32\Defrag.exe
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\SYSWOW64\KBDBASH.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDYAK.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDTAT.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDRU1.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDRU.DLL
2014-10-15 07:23:58 ----A---- C:\windows\system32\KBDBASH.DLL
2014-10-15 07:23:34 ----A---- C:\windows\system32\mshtml.dll
2014-10-15 07:23:31 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-10-15 07:23:28 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\wininet.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\iertutil.dll
2014-10-15 07:23:28 ----A---- C:\windows\system32\ieframe.dll
2014-10-15 07:23:27 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-10-15 07:23:26 ----A---- C:\windows\SYSWOW64\iesysprep.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\uxtheme.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\urlmon.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\mshtmled.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\msfeeds.dll
2014-10-15 07:23:26 ----A---- C:\windows\system32\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\uxtheme.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-10-15 07:23:25 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\UXInit.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\msrating.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jsproxy.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jscript9.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\jscript.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iesysprep.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iesetup.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iernonce.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\iedkcs32.dll
2014-10-15 07:23:25 ----A---- C:\windows\system32\ie4uinit.exe
2014-10-15 07:23:25 ----A---- C:\windows\system32\dxtmsft.dll
2014-10-15 07:23:09 ----A---- C:\windows\system32\win32k.sys
2014-10-15 07:23:00 ----A---- C:\windows\SYSWOW64\user32.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\user32.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\srvsvc.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\msdtctm.dll
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\USBHUB3.SYS
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\srvnet.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\srv2.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2014-10-15 07:23:00 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2014-10-15 07:22:59 ----A---- C:\windows\SYSWOW64\sscore.dll
2014-10-15 07:22:59 ----A---- C:\windows\system32\sscore.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\twinui.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\msi.dll
2014-10-15 07:22:51 ----A---- C:\windows\SYSWOW64\actxprxy.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\twinui.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\msi.dll
2014-10-15 07:22:50 ----A---- C:\windows\system32\actxprxy.dll
2014-10-15 07:22:49 ----A---- C:\windows\SYSWOW64\authui.dll
2014-10-15 07:22:49 ----A---- C:\windows\system32\authui.dll
2014-10-05 18:56:56 ----D---- C:\Program Files\Common Files\EPSON
2014-10-05 18:55:34 ----RA---- C:\windows\system32\drivers\TMUSB64.sys
2014-10-05 18:54:39 ----D---- C:\Program Files (x86)\EpsonNet
2014-10-05 18:53:38 ----A---- C:\windows\system32\enspres.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\ensppui.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\ensppmon.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enpres.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enppui.dll
2014-10-05 18:53:38 ----A---- C:\windows\system32\enppmon.dll
2014-10-05 18:53:37 ----D---- C:\Program Files\EpsonNet
2014-10-05 18:53:23 ----A---- C:\windows\system32\E_YLMHFE.DLL
2014-10-05 18:53:23 ----A---- C:\windows\system32\E_GCINST.DLL
2014-10-05 18:53:22 ----A---- C:\windows\system32\E_YD4BHFE.DLL
2014-10-05 18:53:13 ----A---- C:\windows\system32\esxw2ud.dll
2014-10-05 18:53:13 ----A---- C:\windows\system32\esxcdev.dll
2014-10-05 18:53:13 ----A---- C:\windows\system32\esdevapp.exe
2014-10-05 18:37:19 ----D---- C:\Users\Tomáš\AppData\Roaming\Epson
2014-10-05 18:36:13 ----D---- C:\Program Files (x86)\EPSON Software
2014-10-05 18:35:59 ----D---- C:\ProgramData\EPSON
2014-10-05 18:35:45 ----D---- C:\Program Files (x86)\epson

======List of files/folders modified in the last 1 month======

2014-11-01 18:39:46 ----D---- C:\windows\Temp
2014-11-01 18:38:13 ----D---- C:\windows\Inf
2014-11-01 18:38:13 ----D---- C:\Users\Tomáš\AppData\Roaming\Seznam.cz
2014-11-01 18:38:13 ----AD---- C:\windows\System32
2014-11-01 18:38:13 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-11-01 18:36:16 ----D---- C:\windows\Prefetch
2014-11-01 18:36:09 ----SHD---- C:\windows\Installer
2014-11-01 18:35:14 ----D---- C:\ProgramData\firebird
2014-11-01 18:35:12 ----D---- C:\windows\SysWOW64
2014-11-01 18:34:13 ----SHD---- C:\System Volume Information
2014-11-01 18:00:00 ----D---- C:\windows\system32\sru
2014-11-01 12:51:12 ----D---- C:\windows\rescache
2014-11-01 12:18:58 ----D---- C:\windows\Tasks
2014-11-01 12:07:28 ----RD---- C:\Program Files (x86)
2014-11-01 10:50:00 ----D---- C:\windows\Microsoft.NET
2014-10-31 23:36:57 ----RSD---- C:\windows\assembly
2014-10-31 23:36:54 ----D---- C:\Users\Tomáš\AppData\Roaming\LSC
2014-10-31 23:36:45 ----D---- C:\Program Files\Lenovo
2014-10-31 23:35:43 ----D---- C:\windows\Downloaded Installations
2014-10-31 23:24:17 ----D---- C:\Users\Tomáš\AppData\Roaming\Nitro PDF
2014-10-31 22:33:39 ----D---- C:\windows\system32\FxsTmp
2014-10-31 22:27:54 ----HD---- C:\ProgramData
2014-10-31 22:11:52 ----RD---- C:\Program Files
2014-10-31 07:00:56 ----D---- C:\windows\system32\config
2014-10-30 10:44:48 ----D---- C:\windows\WinSxS
2014-10-30 08:25:56 ----D---- C:\windows\system32\catroot2
2014-10-29 08:10:18 ----D---- C:\windows\CbsTemp
2014-10-29 08:10:00 ----D---- C:\windows\WinStore
2014-10-24 19:53:16 ----D---- C:\windows\system32\NDF
2014-10-22 06:39:29 ----D---- C:\Program Files (x86)\KROS
2014-10-17 11:17:06 ----D---- C:\windows\system32\wdi
2014-10-17 06:58:50 ----D---- C:\windows\system32\catroot
2014-10-16 21:57:44 ----SD---- C:\windows\system32\CompatTel
2014-10-16 21:57:42 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-10-16 21:57:41 ----D---- C:\windows\SYSWOW64\en-US
2014-10-16 21:57:41 ----D---- C:\windows\system32\en-US
2014-10-16 21:57:41 ----D---- C:\windows\system32\cs-CZ
2014-10-16 21:57:33 ----D---- C:\windows\SYSWOW64\wbem
2014-10-16 21:57:32 ----D---- C:\windows\system32\wbem
2014-10-16 21:57:32 ----D---- C:\windows\system32\Boot
2014-10-16 21:57:30 ----RSD---- C:\windows\Fonts
2014-10-16 21:57:24 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-16 21:57:22 ----D---- C:\Program Files\Internet Explorer
2014-10-16 21:57:14 ----D---- C:\windows\system32\drivers\en-US
2014-10-16 21:57:14 ----D---- C:\windows\system32\drivers\cs-CZ
2014-10-16 21:57:13 ----D---- C:\windows\system32\Drivers
2014-10-16 21:57:12 ----RD---- C:\windows\ToastData
2014-10-16 21:57:09 ----D---- C:\windows\system32\DriverStore
2014-10-16 21:57:00 ----D---- C:\windows\system32\MRT
2014-10-16 21:48:53 ----A---- C:\windows\system32\MRT.exe
2014-10-05 18:56:56 ----D---- C:\Program Files\Common Files
2014-10-05 18:54:38 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-05 18:53:35 ----SD---- C:\Users\Tomáš\AppData\Roaming\Microsoft
2014-10-05 18:53:05 ----D---- C:\windows\twain_32
2014-10-02 16:03:45 ----AD---- C:\Windows

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2013-01-31 652784]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2014-08-11 50976]
R1 dtsoftbus01;@oem14.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\windows\System32\drivers\dtsoftbus01.sys [2013-12-17 283064]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2012-07-26 64000]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2012-10-02 4159760]
R3 MEIx64;@oem9.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\System32\drivers\HECIx64.sys [2013-01-23 64624]
R3 NVHDA;@oem2.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda64v.sys [2013-02-25 194848]
R3 nvlddmkm;nvlddmkm; C:\windows\system32\DRIVERS\nvlddmkm.sys [2013-07-08 11105568]
R3 RSUSBVSTOR;@oem3.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2012-06-15 315536]
R3 RTL8168;@oem11.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2012-12-27 760032]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1iexpress;@net1ic64.inf,%E1IExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2012-06-02 333824]
S3 h643331;h643331; C:\windows\system32\drivers\h643331.sys [2008-05-19 63552]
S3 hid3331;hid3331; C:\windows\system32\drivers\hid3331.sys []
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-06-24 15283200]
S3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys [2012-06-02 8604672]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-07-05 210560]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2012-07-26 57344]
S3 WSDPrintDevice;@WSDPrint.Inf,%WSDPrintDevice.SVCDESC%;WSD Print Support; C:\windows\System32\drivers\WSDPrint.sys [2012-07-26 21504]
S3 WSDScan;@sti.inf,%WSDScan.SvcDesc%;Podpora skenování WSD; C:\windows\system32\DRIVERS\WSDScan.sys [2013-09-17 23552]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 FirebirdServerKROS_20400;Firebird Server - KROS_20400; C:\Program Files (x86)\KROS\KROS FBServer\Firebird001\bin\fbserver.exe [2011-10-11 3764224]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-07-13 2451456]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-30 167736]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-08-17 32768]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-30 364856]
R2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [2013-05-24 230408]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\windows\SysWOW64\NLSSRV32.EXE [2013-05-24 70152]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2013-07-08 884512]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2013-05-14 390632]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S2 vToolbarUpdater18.1.9;vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe []
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2012-07-26 43616]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-17 116648]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 LSCWinService;LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [2014-10-16 272776]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

-----------------EOF-----------------

Re: otravné reklamy atď.

Napsal: 01 lis 2014 20:04
od Rudy
Ještě spusťte toto:

Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Ulozte nejlepe na plochu
Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
Probehne vytvoreni zalohy a nasledne prohledavani
Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

Re: otravné reklamy atď.

Napsal: 01 lis 2014 20:11
od sammy19
Naozaj dakujem za vas cas! Urobila som, co ste napisali a vkladam teda log.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.5 (10.31.2014:1)
OS: Windows 8 x64
Ran by Tom ç on so 01.11.2014 at 20:07:00,78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{91902173-602D-496E-8175-1DB74EFFA459}



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared

Re: otravné reklamy atď.

Napsal: 01 lis 2014 20:24
od Rudy
Změnilo se něco?

Re: otravné reklamy atď.

Napsal: 01 lis 2014 20:56
od sammy19
zial, stale mi to vyhadzuje ponuku na java update a potom ma to hodi na uplne inu stranku, toto pisem uz tretikrat, vzdy ma to presmeruje :(

Re: otravné reklamy atď.

Napsal: 01 lis 2014 21:05
od sammy19
v prilohe posielam, ako to vyzera