Stránka 1 z 2

Podezření na vir

Napsal: 09 úno 2015 22:41
od jirkaj44
Dobrý večer pánové.
Dneska mi syn hlásil, že prý avast detekoval nějakou hrozbu. Bohužel se mi zapomněl zmínit co to bylo. :( Tak jsem si řekl, že se radši obrátím na Vás s prosbou o kontrolu, jestli je vše OK. Velice se omlouvám, ale přidá mi to klid na duši. :) Předem děkuji všem, kdo odpoví.
  • Logfile of random's system information tool 1.10 (written by random/random)
    Run by Jirka at 2015-02-09 22:38:53
    Microsoft Windows 7 Ultimate Service Pack 1
    System drive C: has 39 GB (39%) free of 100 GB
    Total RAM: 3000 MB (35% free)

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 22:39:47, on 9.2.2015
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v11.0 (11.00.9600.17496)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
    C:\Program Files\AVAST Software\Avast\avastui.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Google\Drive\googledrivesync.exe
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
    C:\Program Files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe
    C:\Program Files\CCleaner\CCleaner.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files\Stardock\ObjectDock Plus\ObjectDock.exe
    C:\Program Files\Stardock\ObjectDock Plus\ObjectDockTray.exe
    C:\Program Files\Google\Drive\googledrivesync.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Program Files\COMODO\COMODO Internet Security\cis.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Users\Jirka\Desktop\RSIT.exe
    C:\Program Files\trend micro\Jirka.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MSOFFI~1\Office14\GROOVEEX.DLL
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
    O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MSOFFI~1\Office14\URLREDIR.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
    O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
    O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
    O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [ACPW08EN] "C:\Program Files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\MS Office\Office14\BCSSync.exe" /DelayServices
    O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
    O4 - HKCU\..\Run: [ACDSeeCommanderPro8] C:\Program Files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe
    O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - Startup: Dropbox.lnk = C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
    O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock Plus\ObjectDock.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MSOFFI~1\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MSOFFI~1\Office14\ONBttnIE.dll/105
    O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\MS Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\MS Office\Office14\ONBttnIE.dll
    O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\MS Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\MS Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MSOFFI~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0F5D245C-A2D6-415D-9437-C5A4CB9A001A}: NameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}: NameServer = 156.154.70.25,156.154.71.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0F5D245C-A2D6-415D-9437-C5A4CB9A001A}: NameServer = 192.168.1.1
    O17 - HKLM\System\CS2\Services\Tcpip\..\{0F5D245C-A2D6-415D-9437-C5A4CB9A001A}: NameServer = 192.168.1.1
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    O23 - Service: Box Sync Update Service (BoxSyncUpdateService) - Box, Inc. - C:\Program Files\Box\Box Sync\SyncUpdaterService.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    O23 - Service: Cadence License Manager - Flexera Software, Inc. - C:\Cadence\LicenseManager\lmgrd.exe
    O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
    O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
    O23 - Service: NI Citadel 4 Service (LkCitadelServer) - National Instruments, Inc. - C:\Windows\system32\lkcitdl.exe
    O23 - Service: NI PSP Service Locator (lkClassAds) - National Instruments Corporation - C:\Windows\system32\lkads.exe
    O23 - Service: NI Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\Windows\system32\lktsrv.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
    O23 - Service: NI GPIB Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\Windows\system32\nipalsm.exe
    O23 - Service: NI Application Web Server (NIApplicationWebServer) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
    O23 - Service: NI Authentication Service (niauth) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\niauth\niauth_daemon.exe
    O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\Windows\system32\nidevldu.exe
    O23 - Service: NI Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
    O23 - Service: NI LXI Discovery Service (niLXIDiscovery) - National Instruments Corporation - C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
    O23 - Service: NI mDNS Responder Service (nimDNSResponder) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
    O23 - Service: NI Network Discovery (NINetworkDiscovery) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe
    O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\Windows\system32\nipxism.exe
    O23 - Service: NI-RIO Server (NiRioRpc) - National Instruments Corporation - C:\Windows\system32\NiRioRpc.exe
    O23 - Service: NI Service Locator (NiSvcLoc) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\niSvcLoc\nisvcloc.exe
    O23 - Service: NI System Web Server (NISystemWebServer) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe
    O23 - Service: NI Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: OpcEnum - OPC Foundation - C:\Windows\system32\Opcenum.exe
    O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
    O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
    O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe

    --
    End of file - 13474 bytes

    ======Scheduled tasks folder======

    C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS.exe
    C:\Windows\tasks\AutoKMSDaily.job - C:\Windows\AutoKMS.exe
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
    Groove GFS Browser Helper - C:\PROGRA~1\MSOFFI~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-24 460712]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
    avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-28 586968]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
    Office Document Cache Handler - C:\PROGRA~1\MSOFFI~1\Office14\URLREDIR.DLL [2010-02-28 561552]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-24 172968]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
    Microsoft Web Test Recorder 10.0 Helper - C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-26 5227112]
    "COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-02-03 1243864]
    "SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
    "ACPW08EN"=C:\Program Files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe [2014-09-17 1470224]
    "IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-11-13 138784]
    "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-11-13 172064]
    "Persistence"=C:\Windows\system32\igfxpers.exe [2012-11-13 173600]
    "QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2010-02-25 287800]
    "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-17 2439920]
    "BCSSync"=C:\Program Files\MS Office\Office14\BCSSync.exe [2010-03-13 91520]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "GoogleDriveSync"=C:\Program Files\Google\Drive\googledrivesync.exe [2015-01-27 23308256]
    "ACDSeeCommanderPro8"=C:\Program Files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe [2014-09-30 2029576]
    "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-09-26 4811032]
    "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BoxSync]
    C:\Program Files\Box\Box Sync\BoxSync.exe [2014-11-13 5669176]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
    C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [2014-12-14 707496]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
    C:\Program Files\FileZilla Server\FileZilla Server Interface.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI Background Service]
    C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\niDevMon]
    C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe [2014-02-12 119120]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NIRegistrationWizard]
    C:\Program Files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [2013-04-19 847000]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-01-24 508800]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tvncontrol]
    C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe -controlservice -slave []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NI Error Reporting.lnk]
    C:\PROGRA~1\NATION~1\Shared\NIERRO~1\NIERSE~1.EXE [2014-05-20 665944]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk]
    C:\PROGRA~1\COMODO\GEEKBU~1\launcher.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Collector.lnk]
    C:\PROGRA~1\teraterm\COLLEC~1\COLLEC~1.EXE [2015-01-26 139264]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk]
    C:\Windows\system32\RunDll32.exe [2009-07-14 44544]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TeraTerm Menu.lnk]
    C:\PROGRA~1\teraterm\ttpmenu.exe [2015-01-26 94208]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    Dropbox.lnk - C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
    Mozilla Thunderbird.lnk - C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock Plus\ObjectDock.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\Windows\system32\igfxdev.dll [2012-11-13 228864]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MSOFFI~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=0
    "ConsentPromptBehaviorUser"=3
    "EnableLUA"=0
    "EnableUIADesktopToggle"=0
    "PromptOnSecureDesktop"=0
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "SoftwareSASGeneration"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
    "Debugger="C:\Program Files\COMODO\COMODO Internet Security\killswitch.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
    "vidc.mrle"=msrle32.dll
    "vidc.msvc"=msvidc32.dll
    "msacm.imaadpcm"=imaadp32.acm
    "msacm.msg711"=msg711.acm
    "msacm.msgsm610"=msgsm32.acm
    "msacm.msadpcm"=msadp32.acm
    "midimapper"=midimap.dll
    "wavemapper"=msacm32.drv
    "VIDC.UYVY"=msyuv.dll
    "VIDC.YUY2"=msyuv.dll
    "VIDC.YVYU"=msyuv.dll
    "VIDC.IYUV"=iyuv_32.dll
    "vidc.i420"=iyuv_32.dll
    "VIDC.YVU9"=tsbyuv.dll
    "msacm.l3acm"=l3codeca.acm
    "vidc.cvid"=iccvid.dll
    "MSVideo8"=VfWWDM32.dll
    "wave"=wdmaud.drv
    "midi"=wdmaud.drv
    "mixer"=wdmaud.drv
    "aux"=wdmaud.drv
    "wave1"=wdmaud.drv
    "midi1"=wdmaud.drv
    "mixer1"=wdmaud.drv
    "aux1"=wdmaud.drv
    "VIDC.LAGS"=lagarith.dll
    "VIDC.X264"=x264vfw.dll
    "VIDC.XVID"=xvidvfw.dll
    "VIDC.FFDS"=ff_vfw.dll
    "msacm.ac3acm"=ac3acm.acm
    "msacm.l3codecp"=l3codecp.acm
    "wave2"=wdmaud.drv
    "midi2"=wdmaud.drv
    "mixer2"=wdmaud.drv
    "wave3"=wdmaud.drv
    "midi3"=wdmaud.drv
    "mixer3"=wdmaud.drv

    ======File associations======

    .ini - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
    .js - edit - C:\Windows\System32\Notepad.exe %1
    .js - open - C:\Windows\System32\WScript.exe "%1" %*
    .scr - open - C:\Windows\system32\notepad.exe "%1"
    .scr - install -
    .scr - config -
    .txt - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"

    ======List of files/folders created in the last 1 month======

    2015-02-09 21:31:29 ----D---- C:\Users\Jirka\AppData\Roaming\Comodo
    2015-02-04 18:30:14 ----D---- C:\Program Files\Freeware PDF Unlocker
    2015-02-02 14:50:37 ----D---- C:\ProgramData\Sony Corporation
    2015-02-02 14:50:37 ----D---- C:\Program Files\Common Files\Sony Shared
    2015-02-02 14:49:26 ----A---- C:\Windows\system32\D3DX9_43.dll
    2015-02-02 14:45:15 ----D---- C:\Users\Jirka\AppData\Roaming\Sony
    2015-02-02 14:45:15 ----D---- C:\Program Files\Sony Media Go Install
    2015-02-02 14:22:24 ----D---- C:\ProgramData\Sony
    2015-02-02 14:22:24 ----D---- C:\Program Files\Sony
    2015-01-31 18:28:55 ----D---- C:\Program Files\GLC_Player
    2015-01-31 18:24:40 ----D---- C:\Users\Jirka\AppData\Roaming\SketchUp
    2015-01-31 18:24:40 ----D---- C:\ProgramData\SketchUp
    2015-01-31 18:23:34 ----D---- C:\Program Files\SketchUp
    2015-01-31 18:17:17 ----D---- C:\Program Files\COLLADA VIEWER
    2015-01-30 16:59:16 ----D---- C:\Users\Jirka\AppData\Roaming\Process Hacker 2
    2015-01-30 16:54:21 ----D---- C:\Program Files\Process Hacker 2
    2015-01-28 19:57:10 ----D---- C:\Program Files\ImageMagick-6.8.9-Q16
    2015-01-28 19:06:25 ----D---- C:\Program Files\GnuWin32
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1150.dll
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1140.dll
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1100.dll
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1021.dll
    2015-01-28 16:01:12 ----D---- C:\Program Files\Visual Micro
    2015-01-28 15:50:20 ----D---- C:\Users\Jirka\AppData\Roaming\VisualAssistAtmel
    2015-01-28 15:29:51 ----D---- C:\Users\Jirka\AppData\Roaming\Atmel
    2015-01-28 15:24:10 ----D---- C:\Program Files\Seggger
    2015-01-28 15:22:29 ----D---- C:\Windows\ServicePackFiles
    2015-01-28 15:22:27 ----A---- C:\Windows\system32\wdapi1130.dll
    2015-01-28 14:53:52 ----D---- C:\Avrdude
    2015-01-26 13:51:36 ----D---- C:\Program Files\teraterm
    2015-01-26 12:57:12 ----D---- C:\Program Files\STMicroelectronics
    2015-01-26 12:55:58 ----D---- C:\Windows\Downloaded Installations
    2015-01-26 12:55:55 ----D---- C:\Program Files\Common Files\InstallShield
    2015-01-26 11:45:53 ----D---- C:\Program Files\Microsoft .NET Micro Framework
    2015-01-26 11:42:47 ----D---- C:\Users\Jirka\AppData\Roaming\Microsoft Corporation
    2015-01-26 11:24:26 ----D---- C:\Program Files\Seeed
    2015-01-26 11:20:51 ----D---- C:\Program Files\Microsoft .NET Gadgeteer
    2015-01-26 11:18:38 ----D---- C:\Program Files\GHI Electronics
    2015-01-24 17:27:17 ----A---- C:\Windows\system32\ntkrnlpa.exe
    2015-01-24 17:27:16 ----A---- C:\Windows\system32\ntoskrnl.exe
    2015-01-24 17:27:10 ----A---- C:\Windows\system32\profsvc.dll
    2015-01-24 17:27:09 ----A---- C:\Windows\system32\TSWbPrxy.exe
    2015-01-24 17:26:35 ----A---- C:\Windows\system32\nlasvc.dll
    2015-01-24 17:26:24 ----A---- C:\Windows\system32\drivers\mrxdav.sys
    2015-01-24 09:34:52 ----D---- C:\Program Files\Common Files\Java
    2015-01-18 19:28:40 ----D---- C:\Program Files\GanttProject-2.6
    2015-01-18 19:23:33 ----D---- C:\SmartDraw CI
    2015-01-16 19:44:31 ----RASH---- C:\MSDOS.SYS
    2015-01-16 19:44:31 ----RASH---- C:\IO.SYS
    2015-01-16 19:33:23 ----A---- C:\Windows\system32\drivers\mchpusb.sys
    2015-01-14 19:46:22 ----D---- C:\Program Files\Mozilla Thunderbird

    ======List of files/folders modified in the last 1 month======

    2015-02-09 22:39:32 ----D---- C:\Program Files\trend micro
    2015-02-09 22:39:24 ----D---- C:\Windows\Temp
    2015-02-09 22:23:11 ----D---- C:\Windows\Tasks
    2015-02-09 22:21:04 ----D---- C:\Users\Jirka\AppData\Roaming\Dropbox
    2015-02-09 22:21:01 ----D---- C:\Windows
    2015-02-09 22:21:01 ----A---- C:\Windows\KMSEmulator.exe
    2015-02-09 22:20:47 ----D---- C:\Windows\Microsoft.NET
    2015-02-09 22:20:35 ----D---- C:\Windows\inf
    2015-02-09 21:31:34 ----D---- C:\ProgramData\Comodo
    2015-02-09 19:37:26 ----D---- C:\Users\Jirka\AppData\Roaming\SPB_Data
    2015-02-09 14:20:23 ----D---- C:\Windows\Minidump
    2015-02-09 14:03:26 ----D---- C:\Windows\SoftwareDistribution
    2015-02-06 22:51:40 ----D---- C:\Windows\system32\config
    2015-02-05 23:45:52 ----D---- C:\Users\Jirka\AppData\Roaming\uTorrent
    2015-02-05 16:21:18 ----SHD---- C:\System Volume Information
    2015-02-05 09:44:08 ----SHD---- C:\Windows\Installer
    2015-02-05 09:40:03 ----RD---- C:\Program Files
    2015-02-04 10:40:08 ----D---- C:\Windows\System32
    2015-02-03 19:59:38 ----D---- C:\Windows\system32\Tasks
    2015-02-03 16:55:41 ----D---- C:\Windows\Logs
    2015-02-03 09:00:14 ----D---- C:\Windows\system32\catroot2
    2015-02-02 14:50:37 ----HD---- C:\ProgramData
    2015-02-02 14:50:37 ----D---- C:\Program Files\Common Files
    2015-02-02 14:48:02 ----D---- C:\ProgramData\Package Cache
    2015-02-02 14:47:14 ----D---- C:\Windows\winsxs
    2015-02-02 14:26:27 ----D---- C:\Windows\system32\DriverStore
    2015-02-02 14:26:27 ----D---- C:\Windows\system32\catroot
    2015-02-02 14:22:24 ----HD---- C:\Program Files\InstallShield Installation Information
    2015-02-01 10:32:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2015-01-30 13:27:46 ----A---- C:\Windows\system32\cmdcsr.dll
    2015-01-30 13:27:45 ----A---- C:\Windows\system32\guard32.dll
    2015-01-30 13:27:35 ----A---- C:\Windows\system32\cmdvrt32.dll
    2015-01-30 13:27:34 ----A---- C:\Windows\system32\cmdkbd32.dll
    2015-01-29 09:12:20 ----RSD---- C:\Windows\assembly
    2015-01-28 17:27:20 ----D---- C:\Program Files\Atmel
    2015-01-28 17:04:31 ----D---- C:\Windows\system32\drivers
    2015-01-28 15:42:03 ----SD---- C:\ProgramData\Microsoft
    2015-01-28 15:29:42 ----SD---- C:\Users\Jirka\AppData\Roaming\Microsoft
    2015-01-28 15:24:11 ----D---- C:\Program Files\DIFX
    2015-01-28 15:22:28 ----A---- C:\Windows\system32\wdapi921.dll
    2015-01-28 15:22:28 ----A---- C:\Windows\system32\wdapi1002.dll
    2015-01-28 15:22:28 ----A---- C:\Windows\system32\wdapi1001.dll
    2015-01-28 15:22:27 ----A---- C:\Windows\system32\wdapi811.dll
    2015-01-28 15:10:31 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
    2015-01-28 12:37:59 ----D---- C:\Users\Jirka\AppData\Roaming\Notepad++
    2015-01-28 08:54:03 ----D---- C:\Windows\Prefetch
    2015-01-26 22:48:20 ----D---- C:\Windows\debug
    2015-01-26 22:47:32 ----D---- C:\Windows\pss
    2015-01-26 13:51:36 ----RD---- C:\Windows\Fonts
    2015-01-26 11:27:09 ----A---- C:\Windows\system32\WinUsbCoInstaller2.dll
    2015-01-26 11:27:09 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
    2015-01-24 17:58:26 ----D---- C:\Windows\system32\MRT
    2015-01-24 17:42:15 ----A---- C:\Windows\system32\MRT.exe
    2015-01-24 14:27:29 ----D---- C:\Program Files\COMODO
    2015-01-24 09:33:55 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
    2015-01-24 09:33:04 ----D---- C:\Program Files\Java
    2015-01-20 12:05:41 ----D---- C:\Windows\system32\drivers\etc
    2015-01-16 19:31:36 ----A---- C:\Windows\system32\WP_usbci.dll
    2015-01-15 15:53:56 ----D---- C:\Program Files\Mozilla Maintenance Service
    2015-01-12 15:59:27 ----D---- C:\Users\Jirka\AppData\Roaming\Foxit Software

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-28 49944]
    R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-28 206248]
    R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 25656]
    R0 NIPALK;NIPALK; C:\Windows\System32\drivers\nipalk.sys [2014-06-05 604504]
    R0 nipbcfk;National Instruments Class Upper Filter Driver; C:\Windows\System32\drivers\nipbcfk.sys [2014-02-28 17752]
    R0 nipxibaf;National Instruments PXI Bridge Access Driver; C:\Windows\System32\drivers\nipxibaf.sys [2014-06-12 64904]
    R0 nipxibrc;National Instruments PXI Bridge Configuration Driver; C:\Windows\System32\drivers\nipxibrc.sys [2014-05-16 51904]
    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
    R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-28 81768]
    R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-28 787800]
    R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-28 423784]
    R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2015-01-30 17088]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2015-01-30 618072]
    R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2015-01-30 41248]
    R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
    R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2015-01-30 91200]
    R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2014-10-08 113904]
    R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-28 24184]
    R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-28 70384]
    R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-28 91496]
    R2 cvintdrv;cvintdrv; C:\Windows\system32\drivers\cvintdrv.sys [2014-01-15 21792]
    R2 GIVEIO;GIVEIO BDM Access Driver; C:\Windows\system32\drivers\GIVEIO.sys [2009-10-16 10032]
    R2 niarbk;niarbk; C:\Windows\system32\drivers\niarbk.dll [2007-04-16 37376]
    R2 nibffrk;nibffrk; C:\Windows\system32\drivers\nibffrk.dll [2007-04-16 21504]
    R2 Nidaq32k;Nidaq32k; C:\Windows\system32\drivers\Nidaq32k.sys [2007-04-16 674304]
    R2 nidmmk;NI DMM and Data Logger Kernel Driver; C:\Windows\system32\drivers\nidmmk.dll [2007-04-16 50688]
    R2 nimdsk;nimdsk; C:\Windows\system32\drivers\nimdsk.dll [2007-04-16 30208]
    R2 nipxirmk;nipxirmk; \??\C:\Windows\system32\drivers\nipxirmkl.sys [2014-01-09 14160]
    R2 nistck;nistck; C:\Windows\system32\drivers\nistck.dll [2007-04-16 111616]
    R2 nistreamk;nistreamk; C:\Windows\system32\drivers\nistreamkl.sys [2014-06-04 23376]
    R2 NiViPxiK;NI-VISA PXI Driver; C:\Windows\System32\drivers\NiViPxiKl.sys [2014-06-13 14176]
    R2 PEDRV;P&E Microcomputer System PCI Driver.; C:\Windows\system32\drivers\PEDRV.sys [2009-10-16 28080]
    R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 35896]
    R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-05-18 381440]
    R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2010-01-26 1163328]
    R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-08 2506232]
    R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
    R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
    R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
    R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-12-25 86056]
    R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2014-12-25 108072]
    R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2014-12-25 29472]
    R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2014-12-25 18344]
    R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-25 15872]
    R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2012-11-13 9037312]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
    R3 nidimk;nidimk; \??\C:\Windows\system32\drivers\nidimkl.sys [2014-03-13 14176]
    R3 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver; C:\Windows\system32\DRIVERS\niede.sys [2012-01-12 32432]
    R3 nimdbgk;nimdbgk; \??\C:\Windows\system32\drivers\nimdbgkl.sys [2014-03-12 14176]
    R3 nimru2k;nimru2k; \??\C:\Windows\system32\drivers\nimru2kl.sys [2014-03-13 14176]
    R3 nimxdfk;nimxdfk; \??\C:\Windows\system32\drivers\nimxdfkl.sys [2014-03-13 14160]
    R3 niorbk;niorbk; \??\C:\Windows\system32\drivers\niorbkl.sys [2014-03-12 14160]
    R3 NiViPciK;NI-VISA PCI Driver; C:\Windows\System32\drivers\NiViPciKl.sys [2014-06-13 14176]
    R3 portio;WinPic800 IO Drivers; C:\Windows\system32\DRIVERS\WP800IO.sys [2015-01-16 5248]
    R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
    R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-10-17 418032]
    S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
    S3 acsock;acsock; C:\Windows\system32\DRIVERS\acsock.sys [2014-08-15 92528]
    S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
    S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
    S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
    S3 cpudrv;cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys [2011-06-02 11336]
    S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2014-12-27 80752]
    S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2014-12-27 74096]
    S3 GHI_SpotUsb;GHI_SpotUsb; C:\Windows\system32\DRIVERS\GHI_NETMF_Interface.sys [2015-01-26 28888]
    S3 libusb0;libusb-win32 - Kernel Driver 10/02/2010 1.2.2.0; C:\Windows\system32\DRIVERS\libusb0.sys [2014-02-06 42592]
    S3 lvalarmk;lvalarmk; \??\C:\Windows\system32\drivers\lvalarmk.sys [2014-06-13 23432]
    S3 ni1045k;NI PXI-1045 Chassis Pilot; \??\C:\Windows\system32\drivers\ni1045kl.sys [2014-05-16 11960]
    S3 ni1065k;NI PXIe-1065 Chassis Pilot; \??\C:\Windows\system32\drivers\ni1065k.sys [2014-05-16 25936]
    S3 nicdcck;nicdcck; \??\C:\Windows\system32\drivers\nicdcckl.sys [2014-04-29 14168]
    S3 nicdrk;nicdrk; \??\C:\Windows\system32\drivers\nicdrkl.sys [2014-04-29 14168]
    S3 nicmrk;nicmrk; \??\C:\Windows\system32\drivers\nicmrkl.sys [2014-06-10 14184]
    S3 nicondrk;nicondrk; \??\C:\Windows\system32\drivers\nicondrkl.sys [2014-05-06 14152]
    S3 nicsrk;nicsrk; \??\C:\Windows\system32\drivers\nicsrkl.sys [2014-06-24 14152]
    S3 nidmxfk;nidmxfk; \??\C:\Windows\system32\drivers\nidmxfkl.sys [2014-06-25 14152]
    S3 nidsark;nidsark; \??\C:\Windows\system32\drivers\nidsarkl.sys [2014-04-29 14160]
    S3 nidwgk;nidwgk; \??\C:\Windows\system32\drivers\nidwgkl.sys [2014-06-27 13664]
    S3 niemrk;niemrk; \??\C:\Windows\system32\drivers\niemrkl.sys [2014-05-02 14152]
    S3 niesrk;niesrk; \??\C:\Windows\system32\drivers\niesrkl.sys [2014-05-02 14152]
    S3 nifslk;nifslk; \??\C:\Windows\system32\drivers\nifslkl.sys [2014-03-14 14168]
    S3 nihorbrk;nihorbrk; \??\C:\Windows\system32\drivers\nihorbrkl.sys [2014-05-02 14152]
    S3 nihsdrk;nihsdrk; \??\C:\Windows\system32\drivers\nihsdrkl.sys [2014-06-27 13656]
    S3 nimsdrk;nimsdrk; \??\C:\Windows\system32\drivers\nimsdrkl.sys [2014-06-13 14208]
    S3 nimslk;nimslk; \??\C:\Windows\system32\drivers\nimslk.dll []
    S3 nimsrlk;nimsrlk; \??\C:\Windows\system32\drivers\nimsrlk.dll []
    S3 nimstsk;nimstsk; \??\C:\Windows\system32\drivers\nimstskl.sys [2014-06-12 14176]
    S3 nimxpk;nimxpk; \??\C:\Windows\system32\drivers\nimxpkl.sys [2014-06-12 14184]
    S3 ninshsdk;ninshsdk; \??\C:\Windows\system32\drivers\ninshsdkl.sys [2014-04-01 14176]
    S3 nipalfwedl;nipalfwedl; C:\Windows\System32\drivers\nipalfwedl.sys [2014-06-05 13696]
    S3 nipalusbedl;nipalusbedl; C:\Windows\System32\drivers\nipalusbedl.sys [2014-06-05 13688]
    S3 nipsdk;nipsdk; \??\C:\Windows\system32\drivers\nipsdkl.sys [2014-06-28 14208]
    S3 nipxifpk;NI PXI Forwarding Chassis Pilot; \??\C:\Windows\system32\drivers\nipxifpk.sys [2013-09-10 33176]
    S3 nipxigpk;NI PXI Generic Chassis Pilot; \??\C:\Windows\system32\drivers\nipxigpk.sys [2011-08-09 21144]
    S3 niraptrk;niraptrk; \??\C:\Windows\system32\drivers\niraptrkl.sys [2014-05-06 14152]
    S3 niscdk;niscdk; \??\C:\Windows\system32\drivers\niscdkl.sys [2014-04-29 14192]
    S3 nisdigk;nisdigk; \??\C:\Windows\system32\drivers\nisdigkl.sys [2014-05-02 14168]
    S3 nisftk;nisftk; \??\C:\Windows\system32\drivers\nisftkl.sys [2014-04-01 14160]
    S3 nisldk;nisldk; \??\C:\Windows\system32\drivers\nisldkl.sys [2014-06-28 11448]
    S3 nispdk;nispdk; \??\C:\Windows\system32\drivers\nispdkl.sys [2014-04-29 14192]
    S3 nisrcdk;nisrcdk; \??\C:\Windows\system32\drivers\nisrcdkl.sys [2014-06-26 13656]
    S3 nissrk;nissrk; \??\C:\Windows\system32\drivers\nissrkl.sys [2014-05-02 14152]
    S3 nistc2k;nistc2k; \??\C:\Windows\system32\drivers\nistc2kl.sys [2014-04-29 14128]
    S3 nistc3rk;nistc3rk; \??\C:\Windows\system32\drivers\nistc3rkl.sys [2014-04-29 14144]
    S3 nistcrk;nistcrk; \??\C:\Windows\system32\drivers\nistcrkl.sys [2014-04-29 14176]
    S3 niswdk;niswdk; \??\C:\Windows\system32\drivers\niswdkl.sys [2014-06-23 14152]
    S3 nitfurk;nitfurk; \??\C:\Windows\system32\drivers\nitfurkl.sys [2014-05-02 14192]
    S3 nitiork;nitiork; \??\C:\Windows\system32\drivers\nitiorkl.sys [2014-04-29 14176]
    S3 niufurk;niufurk; \??\C:\Windows\system32\drivers\niufurkl.sys [2014-06-24 14368]
    S3 niwfrk;niwfrk; \??\C:\Windows\system32\drivers\niwfrkl.sys [2014-05-02 14152]
    S3 nixfmrrk;nixfmrrk; \??\C:\Windows\system32\drivers\nixfmrrkl.sys [2014-05-06 14160]
    S3 nixsrk;nixsrk; \??\C:\Windows\system32\drivers\nixsrkl.sys [2014-05-02 14152]
    S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
    S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
    S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
    S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
    S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
    S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
    S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2008-07-15 90112]
    R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-12-03 26112]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-28 50344]
    R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2014-12-25 582944]
    R2 Cadence License Manager;Cadence License Manager; C:\Cadence\LicenseManager\lmgrd.exe [2013-03-06 1379664]
    R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2015-02-03 5868440]
    R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
    R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 26168]
    R2 LkCitadelServer;NI Citadel 4 Service; C:\Windows\system32\lkcitdl.exe [2014-01-14 695136]
    R2 lkClassAds;NI PSP Service Locator; C:\Windows\system32\lkads.exe [2014-06-09 53032]
    R2 lkTimeSync;NI Time Synchronization; C:\Windows\system32\lktsrv.exe [2014-06-09 63280]
    R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
    R2 mxssvr;NI Configuration Manager; C:\Program Files\National Instruments\MAX\nimxs.exe [2014-06-07 84280]
    R2 ni488enumsvc;NI GPIB Enumeration Service; C:\Windows\system32\nipalsm.exe [2014-06-05 19280]
    R2 NIApplicationWebServer;NI Application Web Server; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2014-06-10 57184]
    R2 niauth;NI Authentication Service; C:\Program Files\National Instruments\Shared\niauth\niauth_daemon.exe [2014-06-20 569152]
    R2 nidevldu;NI Device Loader; C:\Windows\system32\nidevldu.exe [2014-06-13 103800]
    R2 NIDomainService;NI Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2014-06-09 394544]
    R2 niLXIDiscovery;NI LXI Discovery Service; C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe [2014-06-13 383352]
    R2 nimDNSResponder;NI mDNS Responder Service; C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2014-06-06 320368]
    R2 NINetworkDiscovery;NI Network Discovery; C:\Program Files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [2014-06-19 177536]
    R2 nipxirmu;NI PXI Resource Manager; C:\Windows\system32\nipxism.exe [2014-01-09 20816]
    R2 NiSvcLoc;NI Service Locator; C:\Program Files\National Instruments\Shared\niSvcLoc\nisvcloc.exe [2014-06-06 89928]
    R2 NISystemWebServer;NI System Web Server; C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe [2014-06-10 57168]
    R2 NITaggerService;NI Variable Engine; C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2014-06-10 692040]
    R2 PSI_SVC_2;Corel License Validation Service V2, Powered by arvato; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2013-09-13 277360]
    R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
    R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
    R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
    R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-01-24 103608]
    S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-30 116648]
    S2 KMService;KMService; C:\Windows\system32\srvany.exe [2010-06-16 8192]
    S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
    S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-12-11 315496]
    S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
    S3 BoxSyncUpdateService;Box Sync Update Service; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [2014-11-13 28184]
    S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2015-02-03 1664216]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2014-11-01 1045256]
    S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-30 116648]
    S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-12-12 102912]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\MS Office\Office14\GROOVE.EXE [2010-03-25 30969208]
    S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-14 119408]
    S3 NiRioRpc;NI-RIO Server; C:\Windows\system32\NiRioRpc.exe [2014-06-18 39232]
    S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
    S3 OpcEnum;OpcEnum; C:\Windows\system32\Opcenum.exe [2013-05-21 172832]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
    S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
    S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2015-02-02 155824]
    S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-01-24 45744]
    S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
    S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
    S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-01-24 139944]
    S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-01-24 139944]
    S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-01-24 139944]
    S4 NILM License Manager;NI License Server; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2010-08-02 1427688]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
    S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

    -----------------EOF-----------------

Re: Podezření na vir

Napsal: 09 úno 2015 22:46
od Roli
Zdravím, nejprve musíme pořešit co s tím nelegálním produktem od Microsoftu ?

Re: Podezření na vir

Napsal: 09 úno 2015 22:53
od jirkaj44
W7 legál, mám krabici doma. Office 2003 taktéž.

Takže asi to budou ty Office 2010. No já jsem se synáčka ptal a prý joooo. No měl jsem podezření, nic jdu rozdát pár facek.

Takže co mám odstranit??

Re: Podezření na vir

Napsal: 09 úno 2015 22:58
od Roli
Odinstalovat ty cracklé Office a pak mi sem dej aktuální log z Rsit, ale mrknu na to až zítra :)

Re: Podezření na vir

Napsal: 09 úno 2015 23:32
od jirkaj44
Tak já se už uklidnil, synáček má štěstí, že už spí a já office už odinstaloval. Takže zde je nový log. :)
  • Logfile of random's system information tool 1.10 (written by random/random)
    Run by Jirka at 2015-02-09 23:29:57
    Microsoft Windows 7 Ultimate Service Pack 1
    System drive C: has 41 GB (41%) free of 100 GB
    Total RAM: 3000 MB (30% free)

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 23:30:08, on 9.2.2015
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v11.0 (11.00.9600.17496)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
    C:\Program Files\AVAST Software\Avast\avastui.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Google\Drive\googledrivesync.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
    C:\Program Files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe
    C:\Program Files\CCleaner\CCleaner.exe
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files\Stardock\ObjectDock Plus\ObjectDock.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Stardock\ObjectDock Plus\ObjectDockTray.exe
    C:\Program Files\Google\Drive\googledrivesync.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\COMODO\COMODO Internet Security\cis.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Program Files\Google\Chrome\Application\chrome.exe
    C:\Users\Jirka\Desktop\RSIT.exe
    C:\Program Files\trend micro\Jirka.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
    O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
    O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
    O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
    O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [ACPW08EN] "C:\Program Files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
    O4 - HKCU\..\Run: [ACDSeeCommanderPro8] C:\Program Files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe
    O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - Startup: Dropbox.lnk = C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
    O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock Plus\ObjectDock.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MSOFFI~1\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MSOFFI~1\Office14\ONBttnIE.dll/105
    O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0F5D245C-A2D6-415D-9437-C5A4CB9A001A}: NameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}: NameServer = 156.154.70.25,156.154.71.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0F5D245C-A2D6-415D-9437-C5A4CB9A001A}: NameServer = 192.168.1.1
    O17 - HKLM\System\CS2\Services\Tcpip\..\{0F5D245C-A2D6-415D-9437-C5A4CB9A001A}: NameServer = 192.168.1.1
    O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    O23 - Service: Box Sync Update Service (BoxSyncUpdateService) - Box, Inc. - C:\Program Files\Box\Box Sync\SyncUpdaterService.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    O23 - Service: Cadence License Manager - Flexera Software, Inc. - C:\Cadence\LicenseManager\lmgrd.exe
    O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
    O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
    O23 - Service: NI Citadel 4 Service (LkCitadelServer) - National Instruments, Inc. - C:\Windows\system32\lkcitdl.exe
    O23 - Service: NI PSP Service Locator (lkClassAds) - National Instruments Corporation - C:\Windows\system32\lkads.exe
    O23 - Service: NI Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\Windows\system32\lktsrv.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
    O23 - Service: NI GPIB Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\Windows\system32\nipalsm.exe
    O23 - Service: NI Application Web Server (NIApplicationWebServer) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
    O23 - Service: NI Authentication Service (niauth) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\niauth\niauth_daemon.exe
    O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\Windows\system32\nidevldu.exe
    O23 - Service: NI Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
    O23 - Service: NI LXI Discovery Service (niLXIDiscovery) - National Instruments Corporation - C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
    O23 - Service: NI mDNS Responder Service (nimDNSResponder) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
    O23 - Service: NI Network Discovery (NINetworkDiscovery) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe
    O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\Windows\system32\nipxism.exe
    O23 - Service: NI-RIO Server (NiRioRpc) - National Instruments Corporation - C:\Windows\system32\NiRioRpc.exe
    O23 - Service: NI Service Locator (NiSvcLoc) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\niSvcLoc\nisvcloc.exe
    O23 - Service: NI System Web Server (NISystemWebServer) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe
    O23 - Service: NI Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: OpcEnum - OPC Foundation - C:\Windows\system32\Opcenum.exe
    O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
    O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
    O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe

    --
    End of file - 12255 bytes

    ======Scheduled tasks folder======

    C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS.exe
    C:\Windows\tasks\AutoKMSDaily.job - C:\Windows\AutoKMS.exe
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-24 460712]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
    avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-28 586968]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-24 172968]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
    Microsoft Web Test Recorder 10.0 Helper - C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-26 5227112]
    "COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-02-03 1243864]
    "SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
    "ACPW08EN"=C:\Program Files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe [2014-09-17 1470224]
    "IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-11-13 138784]
    "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-11-13 172064]
    "Persistence"=C:\Windows\system32\igfxpers.exe [2012-11-13 173600]
    "QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2010-02-25 287800]
    "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-17 2439920]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "GoogleDriveSync"=C:\Program Files\Google\Drive\googledrivesync.exe [2015-01-27 23308256]
    "ACDSeeCommanderPro8"=C:\Program Files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe [2014-09-30 2029576]
    "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-09-26 4811032]
    "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BoxSync]
    C:\Program Files\Box\Box Sync\BoxSync.exe [2014-11-13 5669176]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
    C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [2014-12-14 707496]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
    C:\Program Files\FileZilla Server\FileZilla Server Interface.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI Background Service]
    C:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\niDevMon]
    C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe [2014-02-12 119120]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NIRegistrationWizard]
    C:\Program Files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [2013-04-19 847000]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-01-24 508800]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tvncontrol]
    C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe -controlservice -slave []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NI Error Reporting.lnk]
    C:\PROGRA~1\NATION~1\Shared\NIERRO~1\NIERSE~1.EXE [2014-05-20 665944]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk]
    C:\PROGRA~1\COMODO\GEEKBU~1\launcher.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Collector.lnk]
    C:\PROGRA~1\teraterm\COLLEC~1\COLLEC~1.EXE [2015-01-26 139264]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk]
    C:\Windows\system32\RunDll32.exe [2009-07-14 44544]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TeraTerm Menu.lnk]
    C:\PROGRA~1\teraterm\ttpmenu.exe [2015-01-26 94208]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    Dropbox.lnk - C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
    Mozilla Thunderbird.lnk - C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock Plus\ObjectDock.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\Windows\system32\igfxdev.dll [2012-11-13 228864]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "ConsentPromptBehaviorAdmin"=0
    "ConsentPromptBehaviorUser"=3
    "EnableLUA"=0
    "EnableUIADesktopToggle"=0
    "PromptOnSecureDesktop"=0
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "SoftwareSASGeneration"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
    "Debugger="C:\Program Files\COMODO\COMODO Internet Security\killswitch.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
    "vidc.mrle"=msrle32.dll
    "vidc.msvc"=msvidc32.dll
    "msacm.imaadpcm"=imaadp32.acm
    "msacm.msg711"=msg711.acm
    "msacm.msgsm610"=msgsm32.acm
    "msacm.msadpcm"=msadp32.acm
    "midimapper"=midimap.dll
    "wavemapper"=msacm32.drv
    "VIDC.UYVY"=msyuv.dll
    "VIDC.YUY2"=msyuv.dll
    "VIDC.YVYU"=msyuv.dll
    "VIDC.IYUV"=iyuv_32.dll
    "vidc.i420"=iyuv_32.dll
    "VIDC.YVU9"=tsbyuv.dll
    "msacm.l3acm"=l3codeca.acm
    "vidc.cvid"=iccvid.dll
    "MSVideo8"=VfWWDM32.dll
    "wave"=wdmaud.drv
    "midi"=wdmaud.drv
    "mixer"=wdmaud.drv
    "aux"=wdmaud.drv
    "wave1"=wdmaud.drv
    "midi1"=wdmaud.drv
    "mixer1"=wdmaud.drv
    "aux1"=wdmaud.drv
    "VIDC.LAGS"=lagarith.dll
    "VIDC.X264"=x264vfw.dll
    "VIDC.XVID"=xvidvfw.dll
    "VIDC.FFDS"=ff_vfw.dll
    "msacm.ac3acm"=ac3acm.acm
    "msacm.l3codecp"=l3codecp.acm
    "wave2"=wdmaud.drv
    "midi2"=wdmaud.drv
    "mixer2"=wdmaud.drv
    "wave3"=wdmaud.drv
    "midi3"=wdmaud.drv
    "mixer3"=wdmaud.drv

    ======File associations======

    .ini - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
    .js - edit - C:\Windows\System32\Notepad.exe %1
    .js - open - C:\Windows\System32\WScript.exe "%1" %*
    .scr - open - C:\Windows\system32\notepad.exe "%1"
    .scr - install -
    .scr - config -
    .txt - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"

    ======List of files/folders created in the last 1 month======

    2015-02-09 23:20:40 ----A---- C:\Windows\ntbtlog.txt
    2015-02-09 23:02:28 ----SHD---- C:\Config.Msi
    2015-02-09 21:31:29 ----D---- C:\Users\Jirka\AppData\Roaming\Comodo
    2015-02-04 18:30:14 ----D---- C:\Program Files\Freeware PDF Unlocker
    2015-02-02 14:50:37 ----D---- C:\ProgramData\Sony Corporation
    2015-02-02 14:50:37 ----D---- C:\Program Files\Common Files\Sony Shared
    2015-02-02 14:49:26 ----A---- C:\Windows\system32\D3DX9_43.dll
    2015-02-02 14:45:15 ----D---- C:\Users\Jirka\AppData\Roaming\Sony
    2015-02-02 14:45:15 ----D---- C:\Program Files\Sony Media Go Install
    2015-02-02 14:22:24 ----D---- C:\ProgramData\Sony
    2015-02-02 14:22:24 ----D---- C:\Program Files\Sony
    2015-01-31 18:28:55 ----D---- C:\Program Files\GLC_Player
    2015-01-31 18:24:40 ----D---- C:\Users\Jirka\AppData\Roaming\SketchUp
    2015-01-31 18:24:40 ----D---- C:\ProgramData\SketchUp
    2015-01-31 18:23:34 ----D---- C:\Program Files\SketchUp
    2015-01-31 18:17:17 ----D---- C:\Program Files\COLLADA VIEWER
    2015-01-30 16:59:16 ----D---- C:\Users\Jirka\AppData\Roaming\Process Hacker 2
    2015-01-30 16:54:21 ----D---- C:\Program Files\Process Hacker 2
    2015-01-28 19:57:10 ----D---- C:\Program Files\ImageMagick-6.8.9-Q16
    2015-01-28 19:06:25 ----D---- C:\Program Files\GnuWin32
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1150.dll
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1140.dll
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1100.dll
    2015-01-28 17:03:46 ----A---- C:\Windows\system32\wdapi1021.dll
    2015-01-28 16:01:12 ----D---- C:\Program Files\Visual Micro
    2015-01-28 15:50:20 ----D---- C:\Users\Jirka\AppData\Roaming\VisualAssistAtmel
    2015-01-28 15:29:51 ----D---- C:\Users\Jirka\AppData\Roaming\Atmel
    2015-01-28 15:24:10 ----D---- C:\Program Files\Seggger
    2015-01-28 15:22:29 ----D---- C:\Windows\ServicePackFiles
    2015-01-28 15:22:27 ----A---- C:\Windows\system32\wdapi1130.dll
    2015-01-28 14:53:52 ----D---- C:\Avrdude
    2015-01-26 13:51:36 ----D---- C:\Program Files\teraterm
    2015-01-26 12:57:12 ----D---- C:\Program Files\STMicroelectronics
    2015-01-26 12:55:58 ----D---- C:\Windows\Downloaded Installations
    2015-01-26 12:55:55 ----D---- C:\Program Files\Common Files\InstallShield
    2015-01-26 11:45:53 ----D---- C:\Program Files\Microsoft .NET Micro Framework
    2015-01-26 11:42:47 ----D---- C:\Users\Jirka\AppData\Roaming\Microsoft Corporation
    2015-01-26 11:24:26 ----D---- C:\Program Files\Seeed
    2015-01-26 11:20:51 ----D---- C:\Program Files\Microsoft .NET Gadgeteer
    2015-01-26 11:18:38 ----D---- C:\Program Files\GHI Electronics
    2015-01-24 17:27:17 ----A---- C:\Windows\system32\ntkrnlpa.exe
    2015-01-24 17:27:16 ----A---- C:\Windows\system32\ntoskrnl.exe
    2015-01-24 17:27:10 ----A---- C:\Windows\system32\profsvc.dll
    2015-01-24 17:27:09 ----A---- C:\Windows\system32\TSWbPrxy.exe
    2015-01-24 17:26:35 ----A---- C:\Windows\system32\nlasvc.dll
    2015-01-24 17:26:24 ----A---- C:\Windows\system32\drivers\mrxdav.sys
    2015-01-24 09:34:52 ----D---- C:\Program Files\Common Files\Java
    2015-01-18 19:28:40 ----D---- C:\Program Files\GanttProject-2.6
    2015-01-18 19:23:33 ----D---- C:\SmartDraw CI
    2015-01-16 19:44:31 ----RASH---- C:\MSDOS.SYS
    2015-01-16 19:44:31 ----RASH---- C:\IO.SYS
    2015-01-16 19:33:23 ----A---- C:\Windows\system32\drivers\mchpusb.sys
    2015-01-14 19:46:22 ----D---- C:\Program Files\Mozilla Thunderbird

    ======List of files/folders modified in the last 1 month======

    2015-02-09 23:29:59 ----D---- C:\Program Files\trend micro
    2015-02-09 23:29:58 ----D---- C:\Windows\Temp
    2015-02-09 23:26:09 ----D---- C:\Users\Jirka\AppData\Roaming\Dropbox
    2015-02-09 23:26:05 ----D---- C:\Windows\inf
    2015-02-09 23:25:40 ----D---- C:\Windows\Microsoft.NET
    2015-02-09 23:23:23 ----D---- C:\Windows
    2015-02-09 23:17:06 ----SHD---- C:\Windows\Installer
    2015-02-09 23:16:47 ----D---- C:\ProgramData\Microsoft Help
    2015-02-09 23:16:43 ----RSD---- C:\Windows\assembly
    2015-02-09 23:14:57 ----SD---- C:\ProgramData\Microsoft
    2015-02-09 23:14:57 ----D---- C:\Program Files\MS Office
    2015-02-09 23:14:56 ----SD---- C:\Users\Jirka\AppData\Roaming\Microsoft
    2015-02-09 23:14:56 ----RD---- C:\Program Files
    2015-02-09 23:14:55 ----D---- C:\Program Files\Common Files\microsoft shared
    2015-02-09 23:14:27 ----RD---- C:\Windows\Fonts
    2015-02-09 23:13:55 ----D---- C:\Windows\System32
    2015-02-09 23:11:50 ----D---- C:\Windows\ShellNew
    2015-02-09 23:11:27 ----D---- C:\Program Files\Common Files\System
    2015-02-09 23:11:26 ----A---- C:\Windows\win.ini
    2015-02-09 23:09:15 ----SHD---- C:\System Volume Information
    2015-02-09 23:03:17 ----D---- C:\Windows\Help
    2015-02-09 22:23:11 ----D---- C:\Windows\Tasks
    2015-02-09 22:21:01 ----A---- C:\Windows\KMSEmulator.exe
    2015-02-09 21:31:34 ----D---- C:\ProgramData\Comodo
    2015-02-09 19:37:26 ----D---- C:\Users\Jirka\AppData\Roaming\SPB_Data
    2015-02-09 14:20:23 ----D---- C:\Windows\Minidump
    2015-02-09 14:03:26 ----D---- C:\Windows\SoftwareDistribution
    2015-02-06 22:51:40 ----D---- C:\Windows\system32\config
    2015-02-05 23:45:52 ----D---- C:\Users\Jirka\AppData\Roaming\uTorrent
    2015-02-03 19:59:38 ----D---- C:\Windows\system32\Tasks
    2015-02-03 16:55:41 ----D---- C:\Windows\Logs
    2015-02-03 09:00:14 ----D---- C:\Windows\system32\catroot2
    2015-02-02 14:50:37 ----HD---- C:\ProgramData
    2015-02-02 14:50:37 ----D---- C:\Program Files\Common Files
    2015-02-02 14:48:02 ----D---- C:\ProgramData\Package Cache
    2015-02-02 14:47:14 ----D---- C:\Windows\winsxs
    2015-02-02 14:26:27 ----D---- C:\Windows\system32\DriverStore
    2015-02-02 14:26:27 ----D---- C:\Windows\system32\catroot
    2015-02-02 14:22:24 ----HD---- C:\Program Files\InstallShield Installation Information
    2015-02-01 10:32:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2015-01-30 13:27:46 ----A---- C:\Windows\system32\cmdcsr.dll
    2015-01-30 13:27:45 ----A---- C:\Windows\system32\guard32.dll
    2015-01-30 13:27:35 ----A---- C:\Windows\system32\cmdvrt32.dll
    2015-01-30 13:27:34 ----A---- C:\Windows\system32\cmdkbd32.dll
    2015-01-28 17:27:20 ----D---- C:\Program Files\Atmel
    2015-01-28 17:04:31 ----D---- C:\Windows\system32\drivers
    2015-01-28 15:24:11 ----D---- C:\Program Files\DIFX
    2015-01-28 15:22:28 ----A---- C:\Windows\system32\wdapi921.dll
    2015-01-28 15:22:28 ----A---- C:\Windows\system32\wdapi1002.dll
    2015-01-28 15:22:28 ----A---- C:\Windows\system32\wdapi1001.dll
    2015-01-28 15:22:27 ----A---- C:\Windows\system32\wdapi811.dll
    2015-01-28 15:10:31 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
    2015-01-28 12:37:59 ----D---- C:\Users\Jirka\AppData\Roaming\Notepad++
    2015-01-28 08:54:03 ----D---- C:\Windows\Prefetch
    2015-01-26 22:48:20 ----D---- C:\Windows\debug
    2015-01-26 22:47:32 ----D---- C:\Windows\pss
    2015-01-26 11:27:09 ----A---- C:\Windows\system32\WinUsbCoInstaller2.dll
    2015-01-26 11:27:09 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
    2015-01-24 17:58:26 ----D---- C:\Windows\system32\MRT
    2015-01-24 17:42:15 ----A---- C:\Windows\system32\MRT.exe
    2015-01-24 14:27:29 ----D---- C:\Program Files\COMODO
    2015-01-24 09:33:55 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
    2015-01-24 09:33:04 ----D---- C:\Program Files\Java
    2015-01-20 12:05:41 ----D---- C:\Windows\system32\drivers\etc
    2015-01-16 19:31:36 ----A---- C:\Windows\system32\WP_usbci.dll
    2015-01-15 15:53:56 ----D---- C:\Program Files\Mozilla Maintenance Service
    2015-01-12 15:59:27 ----D---- C:\Users\Jirka\AppData\Roaming\Foxit Software

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-28 49944]
    R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-28 206248]
    R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 25656]
    R0 NIPALK;NIPALK; C:\Windows\System32\drivers\nipalk.sys [2014-06-05 604504]
    R0 nipbcfk;National Instruments Class Upper Filter Driver; C:\Windows\System32\drivers\nipbcfk.sys [2014-02-28 17752]
    R0 nipxibaf;National Instruments PXI Bridge Access Driver; C:\Windows\System32\drivers\nipxibaf.sys [2014-06-12 64904]
    R0 nipxibrc;National Instruments PXI Bridge Configuration Driver; C:\Windows\System32\drivers\nipxibrc.sys [2014-05-16 51904]
    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
    R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-28 81768]
    R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-28 787800]
    R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-28 423784]
    R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2015-01-30 17088]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2015-01-30 618072]
    R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2015-01-30 41248]
    R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
    R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2015-01-30 91200]
    R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2014-10-08 113904]
    R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-28 24184]
    R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-28 70384]
    R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-28 91496]
    R2 cvintdrv;cvintdrv; C:\Windows\system32\drivers\cvintdrv.sys [2014-01-15 21792]
    R2 GIVEIO;GIVEIO BDM Access Driver; C:\Windows\system32\drivers\GIVEIO.sys [2009-10-16 10032]
    R2 niarbk;niarbk; C:\Windows\system32\drivers\niarbk.dll [2007-04-16 37376]
    R2 nibffrk;nibffrk; C:\Windows\system32\drivers\nibffrk.dll [2007-04-16 21504]
    R2 Nidaq32k;Nidaq32k; C:\Windows\system32\drivers\Nidaq32k.sys [2007-04-16 674304]
    R2 nidmmk;NI DMM and Data Logger Kernel Driver; C:\Windows\system32\drivers\nidmmk.dll [2007-04-16 50688]
    R2 nimdsk;nimdsk; C:\Windows\system32\drivers\nimdsk.dll [2007-04-16 30208]
    R2 nipxirmk;nipxirmk; \??\C:\Windows\system32\drivers\nipxirmkl.sys [2014-01-09 14160]
    R2 nistck;nistck; C:\Windows\system32\drivers\nistck.dll [2007-04-16 111616]
    R2 nistreamk;nistreamk; C:\Windows\system32\drivers\nistreamkl.sys [2014-06-04 23376]
    R2 NiViPxiK;NI-VISA PXI Driver; C:\Windows\System32\drivers\NiViPxiKl.sys [2014-06-13 14176]
    R2 PEDRV;P&E Microcomputer System PCI Driver.; C:\Windows\system32\drivers\PEDRV.sys [2009-10-16 28080]
    R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 35896]
    R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-05-18 381440]
    R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2010-01-26 1163328]
    R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-08 2506232]
    R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
    R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
    R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
    R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-12-25 86056]
    R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2014-12-25 108072]
    R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2014-12-25 29472]
    R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2014-12-25 18344]
    R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-25 15872]
    R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2012-11-13 9037312]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
    R3 nidimk;nidimk; \??\C:\Windows\system32\drivers\nidimkl.sys [2014-03-13 14176]
    R3 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver; C:\Windows\system32\DRIVERS\niede.sys [2012-01-12 32432]
    R3 nimdbgk;nimdbgk; \??\C:\Windows\system32\drivers\nimdbgkl.sys [2014-03-12 14176]
    R3 nimru2k;nimru2k; \??\C:\Windows\system32\drivers\nimru2kl.sys [2014-03-13 14176]
    R3 nimxdfk;nimxdfk; \??\C:\Windows\system32\drivers\nimxdfkl.sys [2014-03-13 14160]
    R3 niorbk;niorbk; \??\C:\Windows\system32\drivers\niorbkl.sys [2014-03-12 14160]
    R3 NiViPciK;NI-VISA PCI Driver; C:\Windows\System32\drivers\NiViPciKl.sys [2014-06-13 14176]
    R3 portio;WinPic800 IO Drivers; C:\Windows\system32\DRIVERS\WP800IO.sys [2015-01-16 5248]
    R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
    R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-10-17 418032]
    S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
    S3 acsock;acsock; C:\Windows\system32\DRIVERS\acsock.sys [2014-08-15 92528]
    S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
    S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
    S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
    S3 cpudrv;cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys [2011-06-02 11336]
    S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2014-12-27 80752]
    S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2014-12-27 74096]
    S3 GHI_SpotUsb;GHI_SpotUsb; C:\Windows\system32\DRIVERS\GHI_NETMF_Interface.sys [2015-01-26 28888]
    S3 libusb0;libusb-win32 - Kernel Driver 10/02/2010 1.2.2.0; C:\Windows\system32\DRIVERS\libusb0.sys [2014-02-06 42592]
    S3 lvalarmk;lvalarmk; \??\C:\Windows\system32\drivers\lvalarmk.sys [2014-06-13 23432]
    S3 ni1045k;NI PXI-1045 Chassis Pilot; \??\C:\Windows\system32\drivers\ni1045kl.sys [2014-05-16 11960]
    S3 ni1065k;NI PXIe-1065 Chassis Pilot; \??\C:\Windows\system32\drivers\ni1065k.sys [2014-05-16 25936]
    S3 nicdcck;nicdcck; \??\C:\Windows\system32\drivers\nicdcckl.sys [2014-04-29 14168]
    S3 nicdrk;nicdrk; \??\C:\Windows\system32\drivers\nicdrkl.sys [2014-04-29 14168]
    S3 nicmrk;nicmrk; \??\C:\Windows\system32\drivers\nicmrkl.sys [2014-06-10 14184]
    S3 nicondrk;nicondrk; \??\C:\Windows\system32\drivers\nicondrkl.sys [2014-05-06 14152]
    S3 nicsrk;nicsrk; \??\C:\Windows\system32\drivers\nicsrkl.sys [2014-06-24 14152]
    S3 nidmxfk;nidmxfk; \??\C:\Windows\system32\drivers\nidmxfkl.sys [2014-06-25 14152]
    S3 nidsark;nidsark; \??\C:\Windows\system32\drivers\nidsarkl.sys [2014-04-29 14160]
    S3 nidwgk;nidwgk; \??\C:\Windows\system32\drivers\nidwgkl.sys [2014-06-27 13664]
    S3 niemrk;niemrk; \??\C:\Windows\system32\drivers\niemrkl.sys [2014-05-02 14152]
    S3 niesrk;niesrk; \??\C:\Windows\system32\drivers\niesrkl.sys [2014-05-02 14152]
    S3 nifslk;nifslk; \??\C:\Windows\system32\drivers\nifslkl.sys [2014-03-14 14168]
    S3 nihorbrk;nihorbrk; \??\C:\Windows\system32\drivers\nihorbrkl.sys [2014-05-02 14152]
    S3 nihsdrk;nihsdrk; \??\C:\Windows\system32\drivers\nihsdrkl.sys [2014-06-27 13656]
    S3 nimsdrk;nimsdrk; \??\C:\Windows\system32\drivers\nimsdrkl.sys [2014-06-13 14208]
    S3 nimslk;nimslk; \??\C:\Windows\system32\drivers\nimslk.dll []
    S3 nimsrlk;nimsrlk; \??\C:\Windows\system32\drivers\nimsrlk.dll []
    S3 nimstsk;nimstsk; \??\C:\Windows\system32\drivers\nimstskl.sys [2014-06-12 14176]
    S3 nimxpk;nimxpk; \??\C:\Windows\system32\drivers\nimxpkl.sys [2014-06-12 14184]
    S3 ninshsdk;ninshsdk; \??\C:\Windows\system32\drivers\ninshsdkl.sys [2014-04-01 14176]
    S3 nipalfwedl;nipalfwedl; C:\Windows\System32\drivers\nipalfwedl.sys [2014-06-05 13696]
    S3 nipalusbedl;nipalusbedl; C:\Windows\System32\drivers\nipalusbedl.sys [2014-06-05 13688]
    S3 nipsdk;nipsdk; \??\C:\Windows\system32\drivers\nipsdkl.sys [2014-06-28 14208]
    S3 nipxifpk;NI PXI Forwarding Chassis Pilot; \??\C:\Windows\system32\drivers\nipxifpk.sys [2013-09-10 33176]
    S3 nipxigpk;NI PXI Generic Chassis Pilot; \??\C:\Windows\system32\drivers\nipxigpk.sys [2011-08-09 21144]
    S3 niraptrk;niraptrk; \??\C:\Windows\system32\drivers\niraptrkl.sys [2014-05-06 14152]
    S3 niscdk;niscdk; \??\C:\Windows\system32\drivers\niscdkl.sys [2014-04-29 14192]
    S3 nisdigk;nisdigk; \??\C:\Windows\system32\drivers\nisdigkl.sys [2014-05-02 14168]
    S3 nisftk;nisftk; \??\C:\Windows\system32\drivers\nisftkl.sys [2014-04-01 14160]
    S3 nisldk;nisldk; \??\C:\Windows\system32\drivers\nisldkl.sys [2014-06-28 11448]
    S3 nispdk;nispdk; \??\C:\Windows\system32\drivers\nispdkl.sys [2014-04-29 14192]
    S3 nisrcdk;nisrcdk; \??\C:\Windows\system32\drivers\nisrcdkl.sys [2014-06-26 13656]
    S3 nissrk;nissrk; \??\C:\Windows\system32\drivers\nissrkl.sys [2014-05-02 14152]
    S3 nistc2k;nistc2k; \??\C:\Windows\system32\drivers\nistc2kl.sys [2014-04-29 14128]
    S3 nistc3rk;nistc3rk; \??\C:\Windows\system32\drivers\nistc3rkl.sys [2014-04-29 14144]
    S3 nistcrk;nistcrk; \??\C:\Windows\system32\drivers\nistcrkl.sys [2014-04-29 14176]
    S3 niswdk;niswdk; \??\C:\Windows\system32\drivers\niswdkl.sys [2014-06-23 14152]
    S3 nitfurk;nitfurk; \??\C:\Windows\system32\drivers\nitfurkl.sys [2014-05-02 14192]
    S3 nitiork;nitiork; \??\C:\Windows\system32\drivers\nitiorkl.sys [2014-04-29 14176]
    S3 niufurk;niufurk; \??\C:\Windows\system32\drivers\niufurkl.sys [2014-06-24 14368]
    S3 niwfrk;niwfrk; \??\C:\Windows\system32\drivers\niwfrkl.sys [2014-05-02 14152]
    S3 nixfmrrk;nixfmrrk; \??\C:\Windows\system32\drivers\nixfmrrkl.sys [2014-05-06 14160]
    S3 nixsrk;nixsrk; \??\C:\Windows\system32\drivers\nixsrkl.sys [2014-05-02 14152]
    S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
    S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
    S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
    S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
    S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
    S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
    S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2008-07-15 90112]
    R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-12-03 26112]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-28 50344]
    R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2014-12-25 582944]
    R2 Cadence License Manager;Cadence License Manager; C:\Cadence\LicenseManager\lmgrd.exe [2013-03-06 1379664]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-01-24 103608]
    R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2015-02-03 5868440]
    R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
    R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 26168]
    R2 LkCitadelServer;NI Citadel 4 Service; C:\Windows\system32\lkcitdl.exe [2014-01-14 695136]
    R2 lkClassAds;NI PSP Service Locator; C:\Windows\system32\lkads.exe [2014-06-09 53032]
    R2 lkTimeSync;NI Time Synchronization; C:\Windows\system32\lktsrv.exe [2014-06-09 63280]
    R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
    R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
    R2 mxssvr;NI Configuration Manager; C:\Program Files\National Instruments\MAX\nimxs.exe [2014-06-07 84280]
    R2 ni488enumsvc;NI GPIB Enumeration Service; C:\Windows\system32\nipalsm.exe [2014-06-05 19280]
    R2 NIApplicationWebServer;NI Application Web Server; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2014-06-10 57184]
    R2 niauth;NI Authentication Service; C:\Program Files\National Instruments\Shared\niauth\niauth_daemon.exe [2014-06-20 569152]
    R2 NIDomainService;NI Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2014-06-09 394544]
    R2 niLXIDiscovery;NI LXI Discovery Service; C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe [2014-06-13 383352]
    R2 nimDNSResponder;NI mDNS Responder Service; C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2014-06-06 320368]
    R2 NINetworkDiscovery;NI Network Discovery; C:\Program Files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [2014-06-19 177536]
    R2 nipxirmu;NI PXI Resource Manager; C:\Windows\system32\nipxism.exe [2014-01-09 20816]
    R2 NiSvcLoc;NI Service Locator; C:\Program Files\National Instruments\Shared\niSvcLoc\nisvcloc.exe [2014-06-06 89928]
    R2 NISystemWebServer;NI System Web Server; C:\Program Files\National Instruments\Shared\NI WebServer\SystemWebServer.exe [2014-06-10 57168]
    R2 NITaggerService;NI Variable Engine; C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2014-06-10 692040]
    R2 PSI_SVC_2;Corel License Validation Service V2, Powered by arvato; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2013-09-13 277360]
    R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
    R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
    R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
    S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-30 116648]
    S2 KMService;KMService; C:\Windows\system32\srvany.exe [2010-06-16 8192]
    S2 nidevldu;NI Device Loader; C:\Windows\system32\nidevldu.exe [2014-06-13 103800]
    S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-12-11 315496]
    S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
    S3 BoxSyncUpdateService;Box Sync Update Service; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [2014-11-13 28184]
    S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2015-02-03 1664216]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2014-11-01 1045256]
    S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-30 116648]
    S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-12-12 102912]
    S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-14 119408]
    S3 NiRioRpc;NI-RIO Server; C:\Windows\system32\NiRioRpc.exe [2014-06-18 39232]
    S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
    S3 OpcEnum;OpcEnum; C:\Windows\system32\Opcenum.exe [2013-05-21 172832]
    S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
    S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2015-02-02 155824]
    S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-01-24 45744]
    S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
    S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
    S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-01-24 139944]
    S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-01-24 139944]
    S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-01-24 139944]
    S4 NILM License Manager;NI License Server; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2010-08-02 1427688]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
    S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

    -----------------EOF-----------------

Re: Podezření na vir

Napsal: 10 úno 2015 17:55
od Roli
Doufám, že u COMODO Internet Security je zapnutý jen firewall ?


Tohle :

C:\Windows\system32\srvany.exe

otestuj na VIRUSTOTAL

(po načtení stránky klikni na tlačítko Procházet - Choose File, najdi cestu k výše zmíněnému souboru

nebo tam výše zmíněný text nakopíruj a klikni na tlačítko Odeslat soubor - Scan It!

trvá to okolo deseti minut pak mi sem zkopíruj link, to je ten řádek nahoře v prohlížeči)

Pokud ti to napíše že soubor již byl testován nech Otestovat znovu - Reanalyse.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Služba Google Update (gupdate)
Služba Google Update (gupdatem)
NMIndexingService


dvojklikem se otevře karta kde nejprve službu zastav tlačítkem Zastavit u položky Typ spouštění vyber Zakázáno a klik na OK.


Stáhni a spusť OTMoveIt

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files
C:\Windows\tasks\AutoKMS.job
C:\Windows\AutoKMS.exe
C:\Windows\tasks\AutoKMSDaily.job
C:\Windows\AutoKMS.exe 
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\KMSEmulator.exe

:services
KMService

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci zkopírovat obsah logu uloženého na C:\_OTMoveIt\MovedFiles\


Stáhni a ulož na plochu AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.


Nakonec použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !

Re: Podezření na vir

Napsal: 11 úno 2015 12:26
od jirkaj44
Tak zde je odkaz na ten soubor "C:\Windows\system32\srvany.exe":
https://www.virustotal.com/cs/file/abd4 ... 423653234/

Výpis z OTMoveIt
  • All processes killed
    ========== PROCESSES ==========
    No active process named explorer.exe was found!
    ========== FILES ==========
    C:\Windows\tasks\AutoKMS.job moved successfully.
    C:\Windows\AutoKMS.exe moved successfully.
    C:\Windows\tasks\AutoKMSDaily.job moved successfully.
    File/Folder C:\Windows\AutoKMS.exe not found.
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
    C:\Windows\KMSEmulator.exe moved successfully.
    ========== SERVICES/DRIVERS ==========
    Service KMService stopped successfully!
    Service KMService deleted successfully!
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Jirka
    ->Temp folder emptied: 46373427 bytes
    ->Temporary Internet Files folder emptied: 13531 bytes
    ->Java cache emptied: 1093062 bytes
    ->Google Chrome cache emptied: 7888809 bytes
    ->Flash cache emptied: 638 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 34724 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 28481744 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 80,00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 02112015_121705

    Files moved on Reboot...
    File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
    C:\Windows\temp\lvtl819145212.rsc moved successfully.
    C:\Windows\temp\NIWebServiceContainer_32_14.0_SYSTEM_cur.txt moved successfully.
    C:\Windows\temp\{529AA9A9-8853-44F1-81B4-491C308F9FAC} moved successfully.

    Registry entries deleted on Reboot...
Výstup z AdwCleaner
  • # AdwCleaner v4.110 - Logfile created 11/02/2015 at 12:33:24
    # Updated 05/02/2015 by Xplode
    # Database : 2015-02-05.2 [Local]
    # Operating system : Windows 7 Ultimate Service Pack 1 (x86)
    # Username : Jirka - JIRKA-PC
    # Running from : C:\Users\Jirka\Desktop\adwcleaner_4.110.exe
    # Option : Cleaning

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\Users\Jirka\AppData\Roaming\pdfforge

    ***** [ Scheduled tasks ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DE1D6B0C-D8F3-4FC0-9B9F-E5EB1529BF94}

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v11.0.9600.17496


    -\\ Google Chrome v40.0.2214.111


    *************************

    AdwCleaner[R0].txt - [995 bytes] - [11/02/2015 12:29:34]
    AdwCleaner[S0].txt - [929 bytes] - [11/02/2015 12:33:24]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [987 bytes] ##########
MBAM výsledek: Prohledávání bylo úspěšně dokončeno. Nebyly detekovány žádné hrozby.

Re: Podezření na vir

Napsal: 11 úno 2015 18:11
od Roli
Znovu spusť OTMoveIt a nahoře v aplikaci klini na CleanUP!

tímto po sobě uklidí.


Mbam klidně odinstaluj.


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.

Re: Podezření na vir

Napsal: 11 úno 2015 20:12
od jirkaj44
Výpis z ComboBoxu
  • ComboFix 15-02-09.01 - Jirka 11.02.2015 19:28:43.1.2 - x86
    Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3000.1787 [GMT 1:00]
    Spuštěný z: c:\users\Jirka\Downloads\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
    SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Jirka\AppData\Local\assembly\tmp
    c:\users\Jirka\AppData\Roaming\.#
    .
    .
    ((((((((((((((((((((((((( Soubory vytvořené od 2015-01-11 do 2015-02-11 )))))))))))))))))))))))))))))))
    .
    .
    2015-02-11 18:45 . 2015-02-11 18:45 -------- d-----w- c:\users\Default\AppData\Local\temp
    2015-02-11 13:20 . 2015-02-11 13:19 26136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
    2015-02-11 13:19 . 2014-11-28 21:35 291352 ----a-w- c:\windows\system32\aswBoot.exe
    2015-02-11 13:19 . 2015-02-11 13:19 271288 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
    2015-02-11 11:47 . 2015-02-11 16:28 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2015-02-11 11:46 . 2015-02-11 11:46 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
    2015-02-11 11:46 . 2015-02-11 11:46 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2015-02-11 11:46 . 2015-02-11 11:46 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
    2015-02-11 11:46 . 2015-02-11 11:46 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
    2015-02-11 11:28 . 2015-02-11 11:33 -------- d-----w- C:\AdwCleaner
    2015-02-09 20:31 . 2015-02-09 20:33 -------- d-----w- c:\users\Jirka\AppData\Roaming\Comodo
    2015-02-04 17:30 . 2015-02-04 17:38 -------- d-----w- c:\program files\Freeware PDF Unlocker
    2015-02-02 13:50 . 2015-02-02 13:51 -------- d-----w- c:\program files\Common Files\Sony Shared
    2015-02-02 13:50 . 2015-02-02 13:50 -------- d-----w- c:\programdata\Sony Corporation
    2015-02-02 13:49 . 2015-02-02 13:49 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
    2015-02-02 13:45 . 2015-02-02 13:52 -------- d-----w- c:\users\Jirka\AppData\Roaming\Sony
    2015-02-02 13:45 . 2015-02-02 13:49 -------- d-----w- c:\program files\Sony Media Go Install
    2015-02-02 13:41 . 2015-02-02 13:55 -------- d-----w- c:\users\Jirka\AppData\Local\Sony
    2015-02-02 13:22 . 2015-02-02 13:51 -------- d-----w- c:\program files\Sony
    2015-02-02 13:22 . 2015-02-02 13:22 -------- d-----w- c:\programdata\Sony
    2015-01-31 17:32 . 2015-01-31 17:32 -------- d-----w- c:\users\Jirka\Ahoj
    2015-01-31 17:29 . 2015-01-31 17:29 -------- d-----w- c:\users\Jirka\GLC_Player_Cache
    2015-01-31 17:28 . 2015-01-31 17:28 -------- d-----w- c:\program files\GLC_Player
    2015-01-31 17:24 . 2015-01-31 17:24 -------- d-----w- c:\users\Jirka\AppData\Roaming\SketchUp
    2015-01-31 17:24 . 2015-01-31 17:24 -------- d-----w- c:\programdata\SketchUp
    2015-01-31 17:23 . 2015-01-31 17:23 -------- d-----w- c:\program files\SketchUp
    2015-01-31 17:17 . 2015-01-31 17:17 -------- d-----w- c:\program files\COLLADA VIEWER
    2015-01-30 15:59 . 2015-01-30 15:59 -------- d-----w- c:\users\Jirka\AppData\Roaming\Process Hacker 2
    2015-01-30 15:54 . 2015-01-30 15:54 -------- d-----w- c:\program files\Process Hacker 2
    2015-01-30 09:00 . 2015-01-30 09:00 -------- d-----w- c:\users\Jirka\AppData\Local\LIBFREDO6_DATA_Dir
    2015-01-28 18:57 . 2015-01-28 18:57 -------- d-----w- c:\program files\ImageMagick-6.8.9-Q16
    2015-01-28 18:06 . 2015-01-28 18:06 -------- d-----w- c:\program files\GnuWin32
    2015-01-28 16:03 . 2014-01-28 07:59 151552 ----a-w- c:\windows\system32\wdapi1150.dll
    2015-01-28 16:03 . 2013-11-11 08:42 151552 ----a-w- c:\windows\system32\wdapi1140.dll
    2015-01-28 16:03 . 2013-11-11 08:42 151552 ----a-w- c:\windows\system32\wdapi1100.dll
    2015-01-28 16:03 . 2013-11-11 08:42 147456 ----a-w- c:\windows\system32\wdapi1021.dll
    2015-01-28 15:01 . 2015-01-28 15:01 -------- d-----w- c:\program files\Visual Micro
    2015-01-28 14:50 . 2015-01-28 14:50 -------- d-----w- c:\users\Jirka\AppData\Local\IsolatedStorage
    2015-01-28 14:50 . 2015-01-28 17:04 -------- d-----w- c:\users\Jirka\AppData\Roaming\VisualAssistAtmel
    2015-01-28 14:50 . 2015-01-28 17:04 -------- d-----w- c:\users\Jirka\AppData\Local\VisualAssistAtmel
    2015-01-28 14:29 . 2015-01-28 14:29 -------- d-----w- c:\users\Jirka\AppData\Roaming\Atmel
    2015-01-28 14:29 . 2015-01-28 14:29 -------- d-----w- c:\users\Jirka\AppData\Local\Atmel
    2015-01-28 14:24 . 2015-01-28 14:24 -------- d-----w- c:\program files\Seggger
    2015-01-28 14:22 . 2015-01-28 14:22 -------- d-----w- c:\windows\ServicePackFiles
    2015-01-28 14:22 . 2015-01-28 14:22 151552 ----a-w- c:\windows\system32\wdapi1130.dll
    2015-01-28 13:53 . 2015-01-28 13:53 -------- d-----w- C:\Avrdude
    2015-01-26 12:51 . 2015-01-26 12:51 -------- d-----w- c:\program files\teraterm
    2015-01-26 11:57 . 2015-01-26 11:57 -------- d-----w- c:\program files\STMicroelectronics
    2015-01-26 11:55 . 2015-01-26 11:55 -------- d-----w- c:\windows\Downloaded Installations
    2015-01-26 11:55 . 2015-01-26 11:55 -------- d-----w- c:\program files\Common Files\InstallShield
    2015-01-26 10:45 . 2015-01-26 12:44 -------- d-----w- c:\program files\Microsoft .NET Micro Framework
    2015-01-26 10:42 . 2015-01-26 10:42 -------- d-----w- c:\users\Jirka\AppData\Roaming\Microsoft Corporation
    2015-01-26 10:24 . 2015-01-26 10:24 -------- d-----w- c:\program files\Seeed
    2015-01-26 10:20 . 2015-01-26 10:20 -------- d-----w- c:\program files\Microsoft .NET Gadgeteer
    2015-01-26 10:18 . 2015-01-26 11:59 -------- d-----w- c:\program files\GHI Electronics
    2015-01-24 16:27 . 2015-01-24 16:27 3971512 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2015-01-24 16:27 . 2015-01-24 16:27 3916728 ----a-w- c:\windows\system32\ntoskrnl.exe
    2015-01-24 16:27 . 2015-01-24 16:27 164864 ----a-w- c:\windows\system32\profsvc.dll
    2015-01-24 16:27 . 2015-01-24 16:27 74240 ----a-w- c:\windows\system32\TSWbPrxy.exe
    2015-01-24 16:26 . 2015-01-24 16:26 242688 ----a-w- c:\windows\system32\nlasvc.dll
    2015-01-24 16:26 . 2015-01-24 16:26 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
    2015-01-24 08:34 . 2015-01-24 08:34 -------- d-----w- c:\program files\Common Files\Java
    2015-01-20 11:11 . 2015-01-20 11:11 -------- d-----w- c:\users\Jirka\AppData\Local\GHISLER
    2015-01-18 18:28 . 2015-01-18 18:28 -------- d-----w- c:\program files\GanttProject-2.6
    2015-01-18 18:23 . 2015-01-18 18:24 -------- d-----w- C:\SmartDraw CI
    2015-01-16 18:33 . 2007-12-19 10:40 53760 ----a-w- c:\windows\system32\drivers\mchpusb.sys
    2015-01-14 18:46 . 2015-01-15 09:42 -------- d-----w- c:\program files\Mozilla Thunderbird
    2015-01-14 09:40 . 2015-01-14 09:40 -------- d-----w- c:\users\Default\AppData\Local\Google
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2015-01-28 16:03 . 2014-01-28 07:59 204320 ----a-w- c:\windows\system32\drivers\windrvr6.sys
    2015-01-28 14:22 . 2014-10-30 22:12 143360 ----a-w- c:\windows\system32\wdapi921.dll
    2015-01-28 14:22 . 2014-10-30 22:12 143360 ----a-w- c:\windows\system32\wdapi1002.dll
    2015-01-28 14:22 . 2014-10-30 22:12 143360 ----a-w- c:\windows\system32\wdapi1001.dll
    2015-01-28 14:22 . 2014-10-30 22:12 102400 ----a-w- c:\windows\system32\wdapi811.dll
    2015-01-28 14:19 . 2014-11-14 13:05 2478304 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
    2015-01-26 17:04 . 2012-02-16 11:04 28888 ----a-w- c:\windows\system32\drivers\GHI_NETMF_Interface.sys
    2015-01-26 11:01 . 2014-10-30 23:41 28160 ----a-w- c:\windows\system32\drivers\usbser.sys
    2015-01-26 10:27 . 2013-09-10 09:41 851176 ----a-w- c:\windows\system32\WinUsbCoInstaller2.dll
    2015-01-26 10:27 . 2013-09-09 15:09 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
    2015-01-24 08:33 . 2014-10-30 19:39 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2015-01-16 18:31 . 2007-08-26 08:51 5248 ----a-w- c:\windows\system32\drivers\WP800IO.sys
    2015-01-16 18:31 . 2007-06-21 07:19 9728 ----a-w- c:\windows\system32\WP_usbci.dll
    2015-01-04 21:26 . 2014-05-16 14:24 126752 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
    2015-01-04 21:25 . 2014-05-16 14:24 116512 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
    2015-01-04 21:25 . 2015-01-04 21:25 204064 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
    2015-01-04 21:25 . 2015-01-04 21:25 104736 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
    2014-12-27 16:10 . 2014-12-27 16:10 54640 ----a-w- c:\windows\system32\ftserui2.dll
    2014-12-27 16:10 . 2014-12-27 16:10 74096 ----a-w- c:\windows\system32\drivers\ftser2k.sys
    2014-12-27 16:10 . 2014-12-27 16:10 63488 ----a-w- c:\windows\system32\ftcserco.dll
    2014-12-27 16:10 . 2014-12-27 16:10 80752 ----a-w- c:\windows\system32\drivers\ftdibus.sys
    2014-12-27 16:10 . 2014-12-27 16:10 265040 ----a-w- c:\windows\system32\ftd2xx.dll
    2014-12-27 16:10 . 2014-12-27 16:10 246608 ----a-w- c:\windows\system32\FTLang.dll
    2014-12-27 16:10 . 2014-12-27 16:10 147280 ----a-w- c:\windows\system32\ftbusui.dll
    2014-12-25 15:55 . 2014-12-25 15:55 29472 ----a-w- c:\windows\system32\drivers\btwl2cap.sys
    2014-12-25 15:55 . 2014-12-25 15:55 18344 ----a-w- c:\windows\system32\drivers\btwrchid.sys
    2014-12-25 15:55 . 2014-12-25 15:55 86056 ----a-w- c:\windows\system32\drivers\btwaudio.sys
    2014-12-25 15:55 . 2014-12-25 15:55 108072 ----a-w- c:\windows\system32\drivers\btwavdt.sys
    2014-12-14 10:32 . 2014-08-15 18:07 43888 ----a-w- c:\windows\system32\drivers\vpnva-6.sys
    2014-12-13 03:33 . 2014-12-24 13:38 115712 ----a-w- c:\windows\system32\ieUnatt.exe
    2014-12-12 13:11 . 2014-12-12 13:11 2048 ----a-w- c:\windows\system32\mferror.dll
    2014-12-12 13:11 . 2014-12-12 13:11 23040 ----a-w- c:\windows\system32\mfpmp.exe
    2014-12-12 13:11 . 2014-12-12 13:11 103424 ----a-w- c:\windows\system32\mfps.dll
    2014-12-12 13:11 . 2014-12-12 13:11 3209728 ----a-w- c:\windows\system32\mf.dll
    2014-12-12 13:11 . 2014-12-12 13:11 50176 ----a-w- c:\windows\system32\rrinstaller.exe
    2014-12-12 13:00 . 2014-12-12 13:00 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
    2014-12-12 13:00 . 2014-12-12 13:00 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
    2014-12-12 13:00 . 2014-12-12 13:00 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
    2014-12-12 13:00 . 2014-12-12 13:00 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
    2014-12-12 13:00 . 2014-12-12 13:00 620032 ----a-w- c:\windows\system32\jscript9diag.dll
    2014-12-12 13:00 . 2014-12-12 13:00 501248 ----a-w- c:\windows\system32\vbscript.dll
    2014-12-12 13:00 . 2014-12-12 13:00 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
    2014-12-12 13:00 . 2014-12-12 13:00 1888256 ----a-w- c:\windows\system32\wininet.dll
    2014-12-12 13:00 . 2014-12-12 13:00 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
    2014-12-12 13:00 . 2014-12-12 13:00 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
    2014-12-12 13:00 . 2014-12-12 13:00 2052096 ----a-w- c:\windows\system32\inetcpl.cpl
    2014-12-12 13:00 . 2014-12-12 13:00 62464 ----a-w- c:\windows\system32\iesetup.dll
    2014-12-12 13:00 . 2014-12-12 13:00 1160872 ----a-w- c:\windows\system32\aitstatic.exe
    2014-12-12 13:00 . 2014-12-12 13:00 873984 ----a-w- c:\windows\system32\aeinv.dll
    2014-12-12 13:00 . 2014-12-12 13:00 728576 ----a-w- c:\windows\system32\appraiser.dll
    2014-12-12 13:00 . 2014-12-12 13:00 159744 ----a-w- c:\windows\system32\aepic.dll
    2014-12-12 13:00 . 2014-12-12 13:00 610304 ----a-w- c:\windows\system32\invagent.dll
    2014-12-12 13:00 . 2014-12-12 13:00 337920 ----a-w- c:\windows\system32\generaltel.dll
    2014-12-12 13:00 . 2014-12-12 13:00 315392 ----a-w- c:\windows\system32\devinv.dll
    2014-12-12 13:00 . 2014-12-12 13:00 202752 ----a-w- c:\windows\system32\aepdu.dll
    2014-12-12 13:00 . 2014-12-12 13:00 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
    2014-12-12 13:00 . 2014-12-12 13:00 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2014-12-12 12:59 . 2014-12-12 12:59 2048 ----a-w- c:\windows\system32\tzres.dll
    2014-12-12 12:59 . 2014-12-12 12:59 155136 ----a-w- c:\windows\system32\charmap.exe
    2014-12-12 12:58 . 2014-12-12 12:58 1177088 ----a-w- c:\windows\system32\WsmSvc.dll
    2014-12-12 12:58 . 2014-12-12 12:58 248832 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
    2014-12-12 12:58 . 2014-12-12 12:58 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
    2014-12-12 12:58 . 2014-12-12 12:58 198656 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
    2014-12-12 12:58 . 2014-12-12 12:58 145920 ----a-w- c:\windows\system32\WsmAuto.dll
    2014-12-07 18:19 . 2014-12-07 18:17 15823872 ----a-w- c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
    2014-12-07 18:19 . 2014-12-07 18:17 107008 ----a-w- c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
    2014-12-07 18:19 . 2014-12-07 18:17 786492 ----a-w- c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
    2014-11-29 16:40 . 2014-11-29 16:40 97 ----a-w- c:\users\Jirka\IP_Log_Data.js
    2014-11-28 21:35 . 2014-10-30 18:23 787800 ----a-w- c:\windows\system32\drivers\aswsnx.sys
    2014-11-28 21:35 . 2014-10-30 18:23 423784 ----a-w- c:\windows\system32\drivers\aswsp.sys
    2014-11-28 21:35 . 2014-10-30 18:23 91496 ----a-w- c:\windows\system32\drivers\aswStm.sys
    2014-11-28 21:35 . 2014-10-30 18:23 206248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2014-11-28 21:35 . 2014-10-30 18:23 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
    2014-11-28 21:35 . 2014-10-30 18:23 70384 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
    2014-11-28 21:35 . 2014-10-30 18:23 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
    2014-11-28 21:35 . 2014-10-30 18:23 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
    2014-11-28 21:35 . 2014-11-28 21:35 43152 ----a-w- c:\windows\avastSS.scr
    2014-11-27 15:11 . 2014-11-29 15:29 97464 ----a-w- c:\windows\system32\pdfcmon.dll
    2014-11-22 02:20 . 2014-12-12 13:00 2724864 ----a-w- c:\windows\system32\mshtml.tlb
    2014-11-22 01:29 . 2014-12-12 13:00 4299264 ----a-w- c:\windows\system32\jscript9.dll
    2011-08-29 14:50 . 2011-08-29 14:50 158720 ----a-w- c:\program files\internet explorer\plugins\LV2010ActiveXControl.dll
    2013-07-12 10:03 . 2013-07-12 10:03 158720 ----a-w- c:\program files\internet explorer\plugins\LV2011ActiveXControl.dll
    2014-05-13 18:03 . 2014-05-13 18:03 158720 ----a-w- c:\program files\internet explorer\plugins\LV2012ActiveXControl.dll
    2014-05-12 16:59 . 2014-05-12 16:59 158720 ----a-w- c:\program files\internet explorer\plugins\LV2013ActiveXControl.dll
    2014-06-25 04:37 . 2014-06-25 04:37 158720 ----a-w- c:\program files\internet explorer\plugins\LV2014ActiveXControl.dll
    2008-12-10 13:50 . 2008-12-10 13:50 118784 ----a-w- c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
    2009-10-07 15:11 . 2009-10-07 15:11 158720 ----a-w- c:\program files\internet explorer\plugins\LV90ActiveXControl.dll
    .
    .
    (((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncFileLocked]
    @="{9a216f5d-3530-3b1a-8006-9a1233402fba}"
    [HKEY_CLASSES_ROOT\CLSID\{9a216f5d-3530-3b1a-8006-9a1233402fba}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncNotSynced]
    @="{4c3d7a5e-7476-3c21-9717-0614ce209c44}"
    [HKEY_CLASSES_ROOT\CLSID\{4c3d7a5e-7476-3c21-9717-0614ce209c44}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncProblem]
    @="{aa0bacc8-a5df-34b0-acd8-e6739d92010e}"
    [HKEY_CLASSES_ROOT\CLSID\{aa0bacc8-a5df-34b0-acd8-e6739d92010e}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncSynced]
    @="{0f20db5b-365d-3cc6-82eb-41207f77bb71}"
    [HKEY_CLASSES_ROOT\CLSID\{0f20db5b-365d-3cc6-82eb-41207f77bb71}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
    @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
    @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
    @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
    @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2014-11-28 21:34 723976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2015-01-27 23308256]
    "ACDSeeCommanderPro8"="c:\program files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe" [2014-09-30 2029576]
    "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2014-09-26 4811032]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-26 5227112]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
    "ACPW08EN"="c:\program files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe" [2014-09-17 1470224]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-13 138784]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-13 172064]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2012-11-13 173600]
    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 287800]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2013-10-17 2439920]
    .
    c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2015-1-4 39206760]
    Mozilla Thunderbird.lnk - c:\program files\Mozilla Thunderbird\thunderbird.exe [2015-1-14 389744]
    Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock Plus\ObjectDock.exe [2011-11-12 4152536]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-30 795936]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "SoftwareSASGeneration"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NI Error Reporting.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk
    backup=c:\windows\pss\NI Error Reporting.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
    backup=c:\windows\pss\Start GeekBuddy.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Collector.lnk]
    path=c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Collector.lnk
    backup=c:\windows\pss\Collector.lnk.Startup
    backupExtension=.Startup
    .
    [HKLM\~\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk]
    path=c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk
    backup=c:\windows\pss\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk.Startup
    backupExtension=.Startup
    .
    [HKLM\~\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TeraTerm Menu.lnk]
    path=c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TeraTerm Menu.lnk
    backup=c:\windows\pss\TeraTerm Menu.lnk.Startup
    backupExtension=.Startup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2007-09-20 14:35 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BoxSync]
    2014-11-13 11:42 5669176 ----a-w- c:\program files\Box\Box Sync\BoxSync.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
    2014-12-14 10:32 707496 ----a-w- c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
    2007-09-20 08:51 1836328 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\niDevMon]
    2014-02-12 17:59 119120 ----a-w- c:\program files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NIRegistrationWizard]
    2013-04-19 13:27 847000 ----a-w- c:\program files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2015-01-24 08:34 508800 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
    .
    R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-11-28 91496]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-02-11 969016]
    R2 nidevldu;NI Device Loader;c:\windows\system32\nidevldu.exe [2014-06-13 103800]
    R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-12-11 315496]
    R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock.sys [2014-08-15 92528]
    R3 BoxSyncUpdateService;Box Sync Update Service;c:\program files\Box\Box Sync\SyncUpdaterService.exe [2014-11-13 28184]
    R3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2011-06-02 11336]
    R3 GHI_SpotUsb;GHI_SpotUsb;c:\windows\system32\DRIVERS\GHI_NETMF_Interface.sys [2015-01-26 28888]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-12-12 102912]
    R3 libusb0;libusb-win32 - Kernel Driver 10/02/2010 1.2.2.0;c:\windows\system32\DRIVERS\libusb0.sys [2014-02-06 42592]
    R3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys [2014-06-13 23432]
    R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2015-02-11 114904]
    R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-02-11 51928]
    R3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys [2014-05-16 11960]
    R3 ni1065k;NI PXIe-1065 Chassis Pilot;c:\windows\system32\drivers\ni1065k.sys [2014-05-16 25936]
    R3 nicdcck;nicdcck;c:\windows\system32\drivers\nicdcckl.sys [2014-04-29 14168]
    R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys [2014-04-29 14168]
    R3 nicmrk;nicmrk;c:\windows\system32\drivers\nicmrkl.sys [2014-06-10 14184]
    R3 nicondrk;nicondrk;c:\windows\system32\drivers\nicondrkl.sys [2014-05-06 14152]
    R3 nicsrk;nicsrk;c:\windows\system32\drivers\nicsrkl.sys [2014-06-24 14152]
    R3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys [2014-06-25 14152]
    R3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys [2014-04-29 14160]
    R3 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgkl.sys [2014-06-27 13664]
    R3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys [2014-05-02 14152]
    R3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys [2014-05-02 14152]
    R3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys [2014-03-14 14168]
    R3 nihorbrk;nihorbrk;c:\windows\system32\drivers\nihorbrkl.sys [2014-05-02 14152]
    R3 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrkl.sys [2014-06-26 13656]
    R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys [2014-06-13 14208]
    R3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [x]
    R3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [x]
    R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys [2014-06-12 14176]
    R3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys [2014-06-12 14184]
    R3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys [2014-04-01 14176]
    R3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2014-06-05 13696]
    R3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2014-06-05 13688]
    R3 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdkl.sys [2014-06-28 14208]
    R3 nipxifpk;NI PXI Forwarding Chassis Pilot;c:\windows\system32\drivers\nipxifpk.sys [2013-09-10 33176]
    R3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys [2011-08-09 21144]
    R3 niraptrk;niraptrk;c:\windows\system32\drivers\niraptrkl.sys [2014-05-06 14152]
    R3 NiRioRpc;NI-RIO Server;c:\windows\system32\NiRioRpc.exe [2014-06-18 39232]
    R3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys [2014-04-29 14192]
    R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys [2014-05-02 14168]
    R3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys [2014-04-01 14160]
    R3 nisldk;nisldk;c:\windows\system32\drivers\nisldkl.sys [2014-06-28 11448]
    R3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys [2014-04-29 14192]
    R3 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdkl.sys [2014-06-26 13656]
    R3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys [2014-05-02 14152]
    R3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys [2014-04-29 14128]
    R3 nistc3rk;nistc3rk;c:\windows\system32\drivers\nistc3rkl.sys [2014-04-29 14144]
    R3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys [2014-04-29 14176]
    R3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys [2014-06-23 14152]
    R3 nitfurk;nitfurk;c:\windows\system32\drivers\nitfurkl.sys [2014-05-02 14192]
    R3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys [2014-04-29 14176]
    R3 niufurk;niufurk;c:\windows\system32\drivers\niufurkl.sys [2014-06-24 14368]
    R3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys [2014-05-02 14152]
    R3 nixfmrrk;nixfmrrk;c:\windows\system32\drivers\nixfmrrkl.sys [2014-05-06 14160]
    R3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys [2014-05-02 14152]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
    R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2015-02-02 155824]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxkl.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
    R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
    R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
    R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
    S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys [2015-02-11 271288]
    S0 aswRvrt;avast! Revert; [x]
    S0 aswVmm;avast! VM Monitor; [x]
    S0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\System32\drivers\nipbcfk.sys [2014-02-28 17752]
    S0 nipxibaf;National Instruments PXI Bridge Access Driver;c:\windows\System32\drivers\nipxibaf.sys [2014-06-12 64904]
    S0 nipxibrc;National Instruments PXI Bridge Configuration Driver;c:\windows\System32\drivers\nipxibrc.sys [2014-05-16 51904]
    S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2015-02-11 26136]
    S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-11-28 787800]
    S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-11-28 423784]
    S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2015-01-04 204064]
    S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2015-01-04 104736]
    S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-11-28 24184]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-11-28 70384]
    S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2015-02-11 104416]
    S2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2013-03-06 1379664]
    S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168]
    S2 ni488enumsvc;NI GPIB Enumeration Service;c:\windows\system32\nipalsm.exe [2014-06-05 19280]
    S2 NIApplicationWebServer;NI Application Web Server;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2014-06-10 57184]
    S2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2007-04-16 37376]
    S2 niauth;NI Authentication Service;c:\program files\National Instruments\Shared\niauth\niauth_daemon.exe [2014-06-20 569152]
    S2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2007-04-16 21504]
    S2 Nidaq32k;Nidaq32k; [x]
    S2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2007-04-16 50688]
    S2 niLXIDiscovery;NI LXI Discovery Service;c:\program files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe [2014-06-13 383352]
    S2 nimDNSResponder;NI mDNS Responder Service;c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2014-06-06 320368]
    S2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2007-04-16 30208]
    S2 NINetworkDiscovery;NI Network Discovery;c:\program files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [2014-06-19 177536]
    S2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys [2014-01-09 14160]
    S2 nistck;nistck;c:\windows\system32\drivers\nistck.dll [2007-04-16 111616]
    S2 nistreamk;nistreamk;c:\windows\system32\drivers\nistreamkl.sys [2014-06-04 23376]
    S2 NISystemWebServer;NI System Web Server;c:\program files\National Instruments\Shared\NI WebServer\SystemWebServer.exe [2014-06-10 57168]
    S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2014-06-13 14176]
    S2 PEDRV;P&E Microcomputer System PCI Driver.; [x]
    S2 VICHW11;P&E BDM Cable Driver II; [x]
    S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2014-12-14 563112]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2014-12-25 29472]
    S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-02-11 23256]
    S3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys [2014-03-12 14176]
    S3 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver;c:\windows\system32\DRIVERS\niede.sys [2012-01-12 32432]
    S3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys [2014-03-13 14176]
    S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2014-06-13 14176]
    S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2015-01-04 116512]
    S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2015-01-04 126752]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\SPB_16.6]
    2011-07-05 00:47 930 ----a-w- c:\cadence\SPB_16.6\tools\ConfigUtility\CreateShortcut.vbs
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2015-02-06 12:45 1086280 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.111\Installer\chrmstp.exe
    .
    .
    ------- Doplňkový sken -------
    .
    IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MSOFFI~1\Office14\EXCEL.EXE/3000
    IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Od&eslat do aplikace OneNote - c:\progra~1\MSOFFI~1\Office14\ONBttnIE.dll/105
    IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    TCP: DhcpNameServer = 213.46.172.37 213.46.172.36
    TCP: Interfaces\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}\4556E64616F5137324142403: NameServer = 156.154.70.25,156.154.71.25
    TCP: Interfaces\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}\A49627B616F575946494: NameServer = 156.154.70.25,156.154.71.25
    TCP: Interfaces\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}\A557A7B616F586F6573756: NameServer = 156.154.70.25,156.154.71.25
    .
    .
    ------- Asociace souborů -------
    .
    .scr=AutoCADScriptFile
    .txt=Notepad++_file
    .
    - - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
    .
    MSConfigStartUp-FileZilla Server Interface - c:\program files\FileZilla Server\FileZilla Server Interface.exe
    MSConfigStartUp-NI Background Service - c:\program files\National Instruments\Shared\Update Service\BackgroundService.exe
    MSConfigStartUp-tvncontrol - c:\program files\Common Files\COMODO\GeekBuddyRSP.exe
    AddRemove-LSI Soft Modem - c:\windows\agrsmdel
    .
    .
    .
    --------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.032"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.abr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acdc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.acdc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.ani"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.apd"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.arw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.bay"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.bmp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.cr2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.crw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.cs1"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.cur"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dcr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dcx"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dib"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.djv"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
    @Denied: (2) (S-1-5-21-3613966304-22207449-3729038092-1001)
    @Denied: (2) (LocalSystem)
    "Progid"="Applications\\djvuviewer.exe"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dng"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.emf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.eps"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.erf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.fff"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.gif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.hdr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.icl"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.icn"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.iw4"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.j2c"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.j2k"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jbr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jfif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jp2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpe"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpeg"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpg"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpk"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpx"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.kdc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.mef"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.mos"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.mrw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.nef"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.nrw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.orf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pbr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pct"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pcx"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pef"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pic"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pict"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.png"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.psd"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.psp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pspbrush"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pspimage"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.raf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.raw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.rle"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.rw2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.rwl"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.sr2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.srf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.srw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.tga"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.thm"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.tif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.tiff"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.ttc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.ttf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v80po\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.v80po"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v80pp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.v80pp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v80ppf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.v80ppf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.wbm"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.wbmp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.webp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.wmf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.xif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.xmp"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    --------------------- Knihovny navázané na běžící procesy ---------------------
    .
    - - - - - - - > 'Explorer.exe'(1148)
    c:\program files\Stardock\ObjectDock Plus\DockShellHook.dll
    c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
    .
    Celkový čas: 2015-02-11 19:50:00
    ComboFix-quarantined-files.txt 2015-02-11 18:49
    .
    Před spuštěním: Volných bajtů: 44 302 512 128
    Po spuštění: Volných bajtů: 43 737 165 824
    .
    - - End Of File - - A683E5003D2BEC7878EB36B0CE27DAE8
    A36C5E4F47E84449FF07ED3517B43A31

Re: Podezření na vir

Napsal: 12 úno 2015 13:27
od Roli
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

File::  
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci

Re: Podezření na vir

Napsal: 12 úno 2015 14:26
od jirkaj44
Tak hotovo. Zde je znovu ten výpis z Comba
  • ComboFix 15-02-09.01 - Jirka 12.02.2015 13:56:00.2.2 - x86
    Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3000.1303 [GMT 1:00]
    Spuštěný z: c:\users\Jirka\Downloads\ComboFix.exe
    Použité ovládací přepínače :: c:\users\Jirka\Desktop\CFScript.txt
    AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
    SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    FILE ::
    "c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe"
    "c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe"
    "c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe"
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Jirka\AppData\Local\assembly\tmp
    c:\windows\system32\is-OICDJ.tmp
    .
    .
    ((((((((((((((((((((((((( Soubory vytvořené od 2015-01-12 do 2015-02-12 )))))))))))))))))))))))))))))))
    .
    .
    2015-02-12 13:12 . 2015-02-12 13:12 -------- d-----w- c:\users\Jirka\AppData\Local\temp
    2015-02-12 13:12 . 2015-02-12 13:12 -------- d-----w- c:\users\Default\AppData\Local\temp
    2015-02-12 12:21 . 2015-02-12 12:21 -------- d-----w- c:\users\Jirka\AppData\Roaming\pdfforge
    2015-02-12 12:20 . 2015-02-12 12:21 -------- d-----w- c:\program files\PDFCreator
    2015-02-11 22:56 . 2015-01-14 05:44 3972544 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2015-02-11 22:55 . 2014-12-12 05:07 1174528 ----a-w- c:\windows\system32\crypt32.dll
    2015-02-11 22:55 . 2014-07-07 01:40 179200 ----a-w- c:\windows\system32\wintrust.dll
    2015-02-11 22:55 . 2014-07-07 01:40 143872 ----a-w- c:\windows\system32\cryptsvc.dll
    2015-02-11 22:55 . 2014-12-08 02:46 308224 ----a-w- c:\windows\system32\scesrv.dll
    2015-02-11 22:52 . 2015-01-13 02:49 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2015-02-11 21:22 . 2015-02-11 21:23 -------- d-----w- C:\rsit
    2015-02-11 20:27 . 2015-02-11 20:27 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
    2015-02-11 20:17 . 2015-02-11 20:17 -------- d-----w- c:\program files\Microsoft Analysis Services
    2015-02-11 20:13 . 2015-02-11 20:13 -------- d-----r- C:\MSOCache
    2015-02-11 13:20 . 2015-02-11 13:19 26136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
    2015-02-11 13:19 . 2014-11-28 21:35 291352 ----a-w- c:\windows\system32\aswBoot.exe
    2015-02-11 13:19 . 2015-02-11 13:19 271288 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
    2015-02-11 11:47 . 2015-02-12 11:18 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2015-02-11 11:46 . 2015-02-11 11:46 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
    2015-02-11 11:46 . 2015-02-11 11:46 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2015-02-11 11:46 . 2015-02-11 11:46 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
    2015-02-11 11:46 . 2015-02-11 11:46 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
    2015-02-11 11:28 . 2015-02-11 11:33 -------- d-----w- C:\AdwCleaner
    2015-02-09 20:31 . 2015-02-09 20:33 -------- d-----w- c:\users\Jirka\AppData\Roaming\Comodo
    2015-02-04 17:30 . 2015-02-04 17:38 -------- d-----w- c:\program files\Freeware PDF Unlocker
    2015-02-02 13:50 . 2015-02-02 13:51 -------- d-----w- c:\program files\Common Files\Sony Shared
    2015-02-02 13:50 . 2015-02-02 13:50 -------- d-----w- c:\programdata\Sony Corporation
    2015-02-02 13:49 . 2015-02-02 13:49 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
    2015-02-02 13:45 . 2015-02-02 13:52 -------- d-----w- c:\users\Jirka\AppData\Roaming\Sony
    2015-02-02 13:45 . 2015-02-02 13:49 -------- d-----w- c:\program files\Sony Media Go Install
    2015-02-02 13:41 . 2015-02-02 13:55 -------- d-----w- c:\users\Jirka\AppData\Local\Sony
    2015-02-02 13:22 . 2015-02-02 13:51 -------- d-----w- c:\program files\Sony
    2015-02-02 13:22 . 2015-02-02 13:22 -------- d-----w- c:\programdata\Sony
    2015-01-31 17:32 . 2015-01-31 17:32 -------- d-----w- c:\users\Jirka\Ahoj
    2015-01-31 17:29 . 2015-01-31 17:29 -------- d-----w- c:\users\Jirka\GLC_Player_Cache
    2015-01-31 17:28 . 2015-01-31 17:28 -------- d-----w- c:\program files\GLC_Player
    2015-01-31 17:24 . 2015-01-31 17:24 -------- d-----w- c:\users\Jirka\AppData\Roaming\SketchUp
    2015-01-31 17:24 . 2015-01-31 17:24 -------- d-----w- c:\programdata\SketchUp
    2015-01-31 17:23 . 2015-01-31 17:23 -------- d-----w- c:\program files\SketchUp
    2015-01-31 17:17 . 2015-01-31 17:17 -------- d-----w- c:\program files\COLLADA VIEWER
    2015-01-30 15:59 . 2015-01-30 15:59 -------- d-----w- c:\users\Jirka\AppData\Roaming\Process Hacker 2
    2015-01-30 15:54 . 2015-01-30 15:54 -------- d-----w- c:\program files\Process Hacker 2
    2015-01-30 09:00 . 2015-01-30 09:00 -------- d-----w- c:\users\Jirka\AppData\Local\LIBFREDO6_DATA_Dir
    2015-01-28 18:57 . 2015-01-28 18:57 -------- d-----w- c:\program files\ImageMagick-6.8.9-Q16
    2015-01-28 18:06 . 2015-01-28 18:06 -------- d-----w- c:\program files\GnuWin32
    2015-01-28 16:03 . 2014-01-28 07:59 151552 ----a-w- c:\windows\system32\wdapi1150.dll
    2015-01-28 16:03 . 2013-11-11 08:42 151552 ----a-w- c:\windows\system32\wdapi1140.dll
    2015-01-28 16:03 . 2013-11-11 08:42 151552 ----a-w- c:\windows\system32\wdapi1100.dll
    2015-01-28 16:03 . 2013-11-11 08:42 147456 ----a-w- c:\windows\system32\wdapi1021.dll
    2015-01-28 15:01 . 2015-01-28 15:01 -------- d-----w- c:\program files\Visual Micro
    2015-01-28 14:50 . 2015-01-28 14:50 -------- d-----w- c:\users\Jirka\AppData\Local\IsolatedStorage
    2015-01-28 14:50 . 2015-01-28 17:04 -------- d-----w- c:\users\Jirka\AppData\Roaming\VisualAssistAtmel
    2015-01-28 14:50 . 2015-01-28 17:04 -------- d-----w- c:\users\Jirka\AppData\Local\VisualAssistAtmel
    2015-01-28 14:29 . 2015-01-28 14:29 -------- d-----w- c:\users\Jirka\AppData\Roaming\Atmel
    2015-01-28 14:29 . 2015-01-28 14:29 -------- d-----w- c:\users\Jirka\AppData\Local\Atmel
    2015-01-28 14:24 . 2015-01-28 14:24 -------- d-----w- c:\program files\Seggger
    2015-01-28 14:22 . 2015-01-28 14:22 -------- d-----w- c:\windows\ServicePackFiles
    2015-01-28 14:22 . 2015-01-28 14:22 151552 ----a-w- c:\windows\system32\wdapi1130.dll
    2015-01-28 13:53 . 2015-01-28 13:53 -------- d-----w- C:\Avrdude
    2015-01-26 12:51 . 2015-01-26 12:51 -------- d-----w- c:\program files\teraterm
    2015-01-26 11:57 . 2015-01-26 11:57 -------- d-----w- c:\program files\STMicroelectronics
    2015-01-26 11:55 . 2015-01-26 11:55 -------- d-----w- c:\windows\Downloaded Installations
    2015-01-26 11:55 . 2015-01-26 11:55 -------- d-----w- c:\program files\Common Files\InstallShield
    2015-01-26 10:45 . 2015-01-26 12:44 -------- d-----w- c:\program files\Microsoft .NET Micro Framework
    2015-01-26 10:42 . 2015-01-26 10:42 -------- d-----w- c:\users\Jirka\AppData\Roaming\Microsoft Corporation
    2015-01-26 10:24 . 2015-01-26 10:24 -------- d-----w- c:\program files\Seeed
    2015-01-26 10:20 . 2015-01-26 10:20 -------- d-----w- c:\program files\Microsoft .NET Gadgeteer
    2015-01-26 10:18 . 2015-01-26 11:59 -------- d-----w- c:\program files\GHI Electronics
    2015-01-24 16:27 . 2015-01-24 16:27 164864 ----a-w- c:\windows\system32\profsvc.dll
    2015-01-24 16:27 . 2015-01-24 16:27 74240 ----a-w- c:\windows\system32\TSWbPrxy.exe
    2015-01-24 16:26 . 2015-01-24 16:26 242688 ----a-w- c:\windows\system32\nlasvc.dll
    2015-01-24 16:26 . 2015-01-24 16:26 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
    2015-01-24 08:34 . 2015-01-24 08:34 -------- d-----w- c:\program files\Common Files\Java
    2015-01-20 11:11 . 2015-01-20 11:11 -------- d-----w- c:\users\Jirka\AppData\Local\GHISLER
    2015-01-18 18:28 . 2015-01-18 18:28 -------- d-----w- c:\program files\GanttProject-2.6
    2015-01-18 18:23 . 2015-01-18 18:24 -------- d-----w- C:\SmartDraw CI
    2015-01-16 18:33 . 2007-12-19 10:40 53760 ----a-w- c:\windows\system32\drivers\mchpusb.sys
    2015-01-14 18:46 . 2015-01-15 09:42 -------- d-----w- c:\program files\Mozilla Thunderbird
    2015-01-14 09:40 . 2015-01-14 09:40 -------- d-----w- c:\users\Default\AppData\Local\Google
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2015-01-28 16:03 . 2014-01-28 07:59 204320 ----a-w- c:\windows\system32\drivers\windrvr6.sys
    2015-01-28 14:22 . 2014-10-30 22:12 143360 ----a-w- c:\windows\system32\wdapi921.dll
    2015-01-28 14:22 . 2014-10-30 22:12 143360 ----a-w- c:\windows\system32\wdapi1002.dll
    2015-01-28 14:22 . 2014-10-30 22:12 143360 ----a-w- c:\windows\system32\wdapi1001.dll
    2015-01-28 14:22 . 2014-10-30 22:12 102400 ----a-w- c:\windows\system32\wdapi811.dll
    2015-01-28 14:19 . 2014-11-14 13:05 2478304 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
    2015-01-26 17:04 . 2012-02-16 11:04 28888 ----a-w- c:\windows\system32\drivers\GHI_NETMF_Interface.sys
    2015-01-26 11:01 . 2014-10-30 23:41 28160 ----a-w- c:\windows\system32\drivers\usbser.sys
    2015-01-26 10:27 . 2013-09-10 09:41 851176 ----a-w- c:\windows\system32\WinUsbCoInstaller2.dll
    2015-01-26 10:27 . 2013-09-09 15:09 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
    2015-01-24 08:33 . 2014-10-30 19:39 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2015-01-16 18:31 . 2007-08-26 08:51 5248 ----a-w- c:\windows\system32\drivers\WP800IO.sys
    2015-01-16 18:31 . 2007-06-21 07:19 9728 ----a-w- c:\windows\system32\WP_usbci.dll
    2015-01-04 21:26 . 2014-05-16 14:24 126752 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
    2015-01-04 21:25 . 2014-05-16 14:24 116512 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
    2015-01-04 21:25 . 2015-01-04 21:25 204064 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
    2015-01-04 21:25 . 2015-01-04 21:25 104736 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
    2014-12-27 16:10 . 2014-12-27 16:10 54640 ----a-w- c:\windows\system32\ftserui2.dll
    2014-12-27 16:10 . 2014-12-27 16:10 74096 ----a-w- c:\windows\system32\drivers\ftser2k.sys
    2014-12-27 16:10 . 2014-12-27 16:10 63488 ----a-w- c:\windows\system32\ftcserco.dll
    2014-12-27 16:10 . 2014-12-27 16:10 80752 ----a-w- c:\windows\system32\drivers\ftdibus.sys
    2014-12-27 16:10 . 2014-12-27 16:10 265040 ----a-w- c:\windows\system32\ftd2xx.dll
    2014-12-27 16:10 . 2014-12-27 16:10 246608 ----a-w- c:\windows\system32\FTLang.dll
    2014-12-27 16:10 . 2014-12-27 16:10 147280 ----a-w- c:\windows\system32\ftbusui.dll
    2014-12-25 15:55 . 2014-12-25 15:55 29472 ----a-w- c:\windows\system32\drivers\btwl2cap.sys
    2014-12-25 15:55 . 2014-12-25 15:55 18344 ----a-w- c:\windows\system32\drivers\btwrchid.sys
    2014-12-25 15:55 . 2014-12-25 15:55 86056 ----a-w- c:\windows\system32\drivers\btwaudio.sys
    2014-12-25 15:55 . 2014-12-25 15:55 108072 ----a-w- c:\windows\system32\drivers\btwavdt.sys
    2014-12-14 10:32 . 2014-08-15 18:07 43888 ----a-w- c:\windows\system32\drivers\vpnva-6.sys
    2014-12-12 13:11 . 2014-12-12 13:11 2048 ----a-w- c:\windows\system32\mferror.dll
    2014-12-12 13:11 . 2014-12-12 13:11 23040 ----a-w- c:\windows\system32\mfpmp.exe
    2014-12-12 13:11 . 2014-12-12 13:11 103424 ----a-w- c:\windows\system32\mfps.dll
    2014-12-12 13:11 . 2014-12-12 13:11 3209728 ----a-w- c:\windows\system32\mf.dll
    2014-12-12 13:11 . 2014-12-12 13:11 50176 ----a-w- c:\windows\system32\rrinstaller.exe
    2014-12-12 13:00 . 2014-12-12 13:00 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
    2014-12-12 12:59 . 2014-12-12 12:59 2048 ----a-w- c:\windows\system32\tzres.dll
    2014-12-12 12:59 . 2014-12-12 12:59 155136 ----a-w- c:\windows\system32\charmap.exe
    2014-12-12 12:58 . 2014-12-12 12:58 1177088 ----a-w- c:\windows\system32\WsmSvc.dll
    2014-12-12 12:58 . 2014-12-12 12:58 248832 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
    2014-12-12 12:58 . 2014-12-12 12:58 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
    2014-12-12 12:58 . 2014-12-12 12:58 198656 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
    2014-12-12 12:58 . 2014-12-12 12:58 145920 ----a-w- c:\windows\system32\WsmAuto.dll
    2014-12-07 18:19 . 2014-12-07 18:17 15823872 ----a-w- c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
    2014-12-07 18:19 . 2014-12-07 18:17 107008 ----a-w- c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
    2014-12-07 18:19 . 2014-12-07 18:17 786492 ----a-w- c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe
    2014-11-29 16:40 . 2014-11-29 16:40 97 ----a-w- c:\users\Jirka\IP_Log_Data.js
    2014-11-28 21:35 . 2014-10-30 18:23 787800 ----a-w- c:\windows\system32\drivers\aswsnx.sys
    2014-11-28 21:35 . 2014-10-30 18:23 423784 ----a-w- c:\windows\system32\drivers\aswsp.sys
    2014-11-28 21:35 . 2014-10-30 18:23 91496 ----a-w- c:\windows\system32\drivers\aswStm.sys
    2014-11-28 21:35 . 2014-10-30 18:23 206248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2014-11-28 21:35 . 2014-10-30 18:23 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
    2014-11-28 21:35 . 2014-10-30 18:23 70384 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
    2014-11-28 21:35 . 2014-10-30 18:23 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
    2014-11-28 21:35 . 2014-10-30 18:23 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
    2014-11-28 21:35 . 2014-11-28 21:35 43152 ----a-w- c:\windows\avastSS.scr
    2014-11-27 15:11 . 2014-11-29 15:29 97464 ----a-w- c:\windows\system32\pdfcmon.dll
    2011-08-29 14:50 . 2011-08-29 14:50 158720 ----a-w- c:\program files\internet explorer\plugins\LV2010ActiveXControl.dll
    2013-07-12 10:03 . 2013-07-12 10:03 158720 ----a-w- c:\program files\internet explorer\plugins\LV2011ActiveXControl.dll
    2014-05-13 18:03 . 2014-05-13 18:03 158720 ----a-w- c:\program files\internet explorer\plugins\LV2012ActiveXControl.dll
    2014-05-12 16:59 . 2014-05-12 16:59 158720 ----a-w- c:\program files\internet explorer\plugins\LV2013ActiveXControl.dll
    2014-06-25 04:37 . 2014-06-25 04:37 158720 ----a-w- c:\program files\internet explorer\plugins\LV2014ActiveXControl.dll
    2008-12-10 13:50 . 2008-12-10 13:50 118784 ----a-w- c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
    2009-10-07 15:11 . 2009-10-07 15:11 158720 ----a-w- c:\program files\internet explorer\plugins\LV90ActiveXControl.dll
    .
    .
    (((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncFileLocked]
    @="{9a216f5d-3530-3b1a-8006-9a1233402fba}"
    [HKEY_CLASSES_ROOT\CLSID\{9a216f5d-3530-3b1a-8006-9a1233402fba}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncNotSynced]
    @="{4c3d7a5e-7476-3c21-9717-0614ce209c44}"
    [HKEY_CLASSES_ROOT\CLSID\{4c3d7a5e-7476-3c21-9717-0614ce209c44}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncProblem]
    @="{aa0bacc8-a5df-34b0-acd8-e6739d92010e}"
    [HKEY_CLASSES_ROOT\CLSID\{aa0bacc8-a5df-34b0-acd8-e6739d92010e}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ BoxSyncSynced]
    @="{0f20db5b-365d-3cc6-82eb-41207f77bb71}"
    [HKEY_CLASSES_ROOT\CLSID\{0f20db5b-365d-3cc6-82eb-41207f77bb71}]
    2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
    @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
    [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
    2012-10-01 19:33 1720976 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
    @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
    [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
    2012-10-01 19:33 1720976 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
    @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
    [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
    2012-10-01 19:33 1720976 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
    @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
    @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
    @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
    @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
    2014-08-17 04:09 131480 ----a-w- c:\users\Jirka\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2014-11-28 21:34 723976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
    @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
    [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
    2015-01-15 15:59 577864 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2015-01-27 23308256]
    "ACDSeeCommanderPro8"="c:\program files\ACD Systems\ACDSee Pro\8.0\ACDSeeCommanderPro8.exe" [2014-09-30 2029576]
    "CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2014-09-26 4811032]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-26 5227112]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
    "ACPW08EN"="c:\program files\ACD Systems\ACDSee Pro\8.0\acdIDInTouch2.exe" [2014-09-17 1470224]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-11-13 138784]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-11-13 172064]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2012-11-13 173600]
    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 287800]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2013-10-17 2439920]
    .
    c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2015-1-4 39206760]
    Mozilla Thunderbird.lnk - c:\program files\Mozilla Thunderbird\thunderbird.exe [2015-1-14 389744]
    Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock Plus\ObjectDock.exe [2011-11-12 4152536]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-30 795936]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "SoftwareSASGeneration"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NI Error Reporting.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk
    backup=c:\windows\pss\NI Error Reporting.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
    backup=c:\windows\pss\Start GeekBuddy.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Collector.lnk]
    path=c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Collector.lnk
    backup=c:\windows\pss\Collector.lnk.Startup
    backupExtension=.Startup
    .
    [HKLM\~\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk]
    path=c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk
    backup=c:\windows\pss\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk.Startup
    backupExtension=.Startup
    .
    [HKLM\~\startupfolder\C:^Users^Jirka^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TeraTerm Menu.lnk]
    path=c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TeraTerm Menu.lnk
    backup=c:\windows\pss\TeraTerm Menu.lnk.Startup
    backupExtension=.Startup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2007-09-20 14:35 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BoxSync]
    2014-11-13 11:42 5669176 ----a-w- c:\program files\Box\Box Sync\BoxSync.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
    2014-12-14 10:32 707496 ----a-w- c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
    2007-09-20 08:51 1836328 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\niDevMon]
    2014-02-12 17:59 119120 ----a-w- c:\program files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NIRegistrationWizard]
    2013-04-19 13:27 847000 ----a-w- c:\program files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2015-01-24 08:34 508800 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
    .
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-02-11 969016]
    R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-12-11 315496]
    R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock.sys [2014-08-15 92528]
    R3 BoxSyncUpdateService;Box Sync Update Service;c:\program files\Box\Box Sync\SyncUpdaterService.exe [2014-11-13 28184]
    R3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2011-06-02 11336]
    R3 GHI_SpotUsb;GHI_SpotUsb;c:\windows\system32\DRIVERS\GHI_NETMF_Interface.sys [2015-01-26 28888]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-01-12 102912]
    R3 libusb0;libusb-win32 - Kernel Driver 10/02/2010 1.2.2.0;c:\windows\system32\DRIVERS\libusb0.sys [2014-02-06 42592]
    R3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys [2014-06-13 23432]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-02-11 23256]
    R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-02-11 51928]
    R3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys [2014-05-16 11960]
    R3 ni1065k;NI PXIe-1065 Chassis Pilot;c:\windows\system32\drivers\ni1065k.sys [2014-05-16 25936]
    R3 nicdcck;nicdcck;c:\windows\system32\drivers\nicdcckl.sys [2014-04-29 14168]
    R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys [2014-04-29 14168]
    R3 nicmrk;nicmrk;c:\windows\system32\drivers\nicmrkl.sys [2014-06-10 14184]
    R3 nicondrk;nicondrk;c:\windows\system32\drivers\nicondrkl.sys [2014-05-06 14152]
    R3 nicsrk;nicsrk;c:\windows\system32\drivers\nicsrkl.sys [2014-06-24 14152]
    R3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys [2014-06-25 14152]
    R3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys [2014-04-29 14160]
    R3 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgkl.sys [2014-06-27 13664]
    R3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys [2014-05-02 14152]
    R3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys [2014-05-02 14152]
    R3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys [2014-03-14 14168]
    R3 nihorbrk;nihorbrk;c:\windows\system32\drivers\nihorbrkl.sys [2014-05-02 14152]
    R3 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrkl.sys [2014-06-26 13656]
    R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys [2014-06-13 14208]
    R3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [x]
    R3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [x]
    R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys [2014-06-12 14176]
    R3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys [2014-06-12 14184]
    R3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys [2014-04-01 14176]
    R3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2014-06-05 13696]
    R3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2014-06-05 13688]
    R3 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdkl.sys [2014-06-28 14208]
    R3 nipxifpk;NI PXI Forwarding Chassis Pilot;c:\windows\system32\drivers\nipxifpk.sys [2013-09-10 33176]
    R3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys [2011-08-09 21144]
    R3 niraptrk;niraptrk;c:\windows\system32\drivers\niraptrkl.sys [2014-05-06 14152]
    R3 NiRioRpc;NI-RIO Server;c:\windows\system32\NiRioRpc.exe [2014-06-18 39232]
    R3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys [2014-04-29 14192]
    R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys [2014-05-02 14168]
    R3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys [2014-04-01 14160]
    R3 nisldk;nisldk;c:\windows\system32\drivers\nisldkl.sys [2014-06-28 11448]
    R3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys [2014-04-29 14192]
    R3 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdkl.sys [2014-06-26 13656]
    R3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys [2014-05-02 14152]
    R3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys [2014-04-29 14128]
    R3 nistc3rk;nistc3rk;c:\windows\system32\drivers\nistc3rkl.sys [2014-04-29 14144]
    R3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys [2014-04-29 14176]
    R3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys [2014-06-23 14152]
    R3 nitfurk;nitfurk;c:\windows\system32\drivers\nitfurkl.sys [2014-05-02 14192]
    R3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys [2014-04-29 14176]
    R3 niufurk;niufurk;c:\windows\system32\drivers\niufurkl.sys [2014-06-24 14368]
    R3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys [2014-05-02 14152]
    R3 nixfmrrk;nixfmrrk;c:\windows\system32\drivers\nixfmrrkl.sys [2014-05-06 14160]
    R3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys [2014-05-02 14152]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
    R3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2015-02-02 155824]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxkl.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
    R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
    R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
    R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
    S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys [2015-02-11 271288]
    S0 aswRvrt;avast! Revert; [x]
    S0 aswVmm;avast! VM Monitor; [x]
    S0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\System32\drivers\nipbcfk.sys [2014-02-28 17752]
    S0 nipxibaf;National Instruments PXI Bridge Access Driver;c:\windows\System32\drivers\nipxibaf.sys [2014-06-12 64904]
    S0 nipxibrc;National Instruments PXI Bridge Configuration Driver;c:\windows\System32\drivers\nipxibrc.sys [2014-05-16 51904]
    S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2015-02-11 26136]
    S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-11-28 787800]
    S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-11-28 423784]
    S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2015-01-04 204064]
    S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2015-01-04 104736]
    S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-11-28 24184]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-11-28 70384]
    S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-11-28 91496]
    S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2015-02-11 104416]
    S2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2013-03-06 1379664]
    S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 26168]
    S2 ni488enumsvc;NI GPIB Enumeration Service;c:\windows\system32\nipalsm.exe [2014-06-05 19280]
    S2 NIApplicationWebServer;NI Application Web Server;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2014-06-10 57184]
    S2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2007-04-16 37376]
    S2 niauth;NI Authentication Service;c:\program files\National Instruments\Shared\niauth\niauth_daemon.exe [2014-06-20 569152]
    S2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2007-04-16 21504]
    S2 Nidaq32k;Nidaq32k; [x]
    S2 nidevldu;NI Device Loader;c:\windows\system32\nidevldu.exe [2014-06-13 103800]
    S2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2007-04-16 50688]
    S2 niLXIDiscovery;NI LXI Discovery Service;c:\program files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe [2014-06-13 383352]
    S2 nimDNSResponder;NI mDNS Responder Service;c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2014-06-06 320368]
    S2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2007-04-16 30208]
    S2 NINetworkDiscovery;NI Network Discovery;c:\program files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [2014-06-19 177536]
    S2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys [2014-01-09 14160]
    S2 nistck;nistck;c:\windows\system32\drivers\nistck.dll [2007-04-16 111616]
    S2 nistreamk;nistreamk;c:\windows\system32\drivers\nistreamkl.sys [2014-06-04 23376]
    S2 NISystemWebServer;NI System Web Server;c:\program files\National Instruments\Shared\NI WebServer\SystemWebServer.exe [2014-06-10 57168]
    S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2014-06-13 14176]
    S2 PEDRV;P&E Microcomputer System PCI Driver.; [x]
    S2 VICHW11;P&E BDM Cable Driver II; [x]
    S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2014-12-14 563112]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2014-12-25 29472]
    S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
    S3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys [2014-03-12 14176]
    S3 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver;c:\windows\system32\DRIVERS\niede.sys [2012-01-12 32432]
    S3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys [2014-03-13 14176]
    S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2014-06-13 14176]
    S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2015-01-04 116512]
    S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2015-01-04 126752]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\SPB_16.6]
    2011-07-05 00:47 930 ----a-w- c:\cadence\SPB_16.6\tools\ConfigUtility\CreateShortcut.vbs
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2015-02-06 12:45 1086280 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.111\Installer\chrmstp.exe
    .
    .
    ------- Doplňkový sken -------
    .
    IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MSOFFI~1\Office14\EXCEL.EXE/3000
    IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: E&xportovat do Microsoft Excelu - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
    IE: Od&eslat do aplikace OneNote - c:\progra~1\MSOFFI~1\Office14\ONBttnIE.dll/105
    IE: Od&eslat do OneNotu - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
    IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    TCP: DhcpNameServer = 213.46.172.37 213.46.172.36
    TCP: Interfaces\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}\4556E64616F5137324142403: NameServer = 156.154.70.25,156.154.71.25
    TCP: Interfaces\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}\A49627B616F575946494: NameServer = 156.154.70.25,156.154.71.25
    TCP: Interfaces\{1A4D9801-E828-45F1-A6B6-BDE949EB112E}\A557A7B616F586F6573756: NameServer = 156.154.70.25,156.154.71.25
    Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
    .
    .
    --------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.032"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.abr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acdc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.acdc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.ani"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.apd"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.arw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.bay"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.bmp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.cr2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.crw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.cs1"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.cur"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dcr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dcx"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dib"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.djv"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
    @Denied: (2) (S-1-5-21-3613966304-22207449-3729038092-1001)
    @Denied: (2) (LocalSystem)
    "Progid"="Applications\\djvuviewer.exe"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.dng"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.emf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.eps"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.erf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.fff"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.gif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.hdr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.icl"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.icn"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.iw4"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.j2c"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.j2k"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jbr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jfif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jp2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpe"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpeg"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpg"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpk"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.jpx"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.kdc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.mef"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.mos"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.mrw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.nef"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.nrw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.orf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pbr"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pct"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pcx"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pef"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pic"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pict"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.png"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.psd"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.psp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pspbrush"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.pspimage"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.raf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.raw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.rle"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.rw2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.rwl"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.sr2"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.srf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.srw"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.tga"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.thm"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.tif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.tiff"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.ttc"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.ttf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v80po\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.v80po"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v80pp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.v80pp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v80ppf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.v80ppf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.wbm"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.wbmp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.webp"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.wmf"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.xif"
    .
    [HKEY_USERS\S-1-5-21-3613966304-22207449-3729038092-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee Pro 8.xmp"
    .
    Celkový čas: 2015-02-12 14:16:08
    ComboFix-quarantined-files.txt 2015-02-12 13:16
    ComboFix2.txt 2015-02-11 18:50
    .
    Před spuštěním: Volných bajtů: 38 394 966 016
    Po spuštění: Volných bajtů: 38 199 689 216
    .
    - - End Of File - - AC9BEC3BB8A988C73E245DDC04B78577
    A36C5E4F47E84449FF07ED3517B43A31

Re: Podezření na vir

Napsal: 12 úno 2015 17:08
od Roli
Aha, tak musíme na ty potvory jinak.


Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Znovu stáhni a spusť OTMoveIt

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe
c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci zkopírovat obsah logu uloženého na C:\_OTMoveIt\MovedFiles\

Re: Podezření na vir

Napsal: 12 úno 2015 18:30
od jirkaj44
Kroky z minula úspěšně dokončeny. Zde je ten log z OTM.
  • All processes killed
    ========== PROCESSES ==========
    No active process named explorer.exe was found!
    ========== FILES ==========
    c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Office 2010 Toolkit.exe moved successfully.
    c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\Torrant.exe moved successfully.
    c:\users\Jirka\AppData\Roaming\Microsoft\Windows\Templates\cryptedcybertoirrent.exe moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Jirka
    ->Temp folder emptied: 1200745 bytes
    ->Temporary Internet Files folder emptied: 36999 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 19064670 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 17362 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 19,00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 02122015_181832

    Files moved on Reboot...
    File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
    C:\Windows\temp\lvtl819144080.rsc moved successfully.
    C:\Windows\temp\NIWebServiceContainer_32_14.0_SYSTEM_cur.txt moved successfully.
    C:\Windows\temp\{C20D900A-2AB9-43E3-A527-C3F64B225C80} moved successfully.

    Registry entries deleted on Reboot...

Re: Podezření na vir

Napsal: 13 úno 2015 20:03
od Roli
A pak že nepůjdou ven :)


Znovu spusť OTMoveIt a nahoře v aplikaci klini na CleanUP!

tímto po sobě uklidí.


Tím by bylo uklizeno a jak se PC chová ?

Re: Podezření na vir

Napsal: 14 úno 2015 09:38
od jirkaj44
PC se chová naštěstí pořád stejně. Je pomalý, ale za to může HW. :D :)

Ale jsem rád, že už je čistý.

Roli děkují ti za pomoc.