Zdvojené systémové soubory
Napsal: 23 úno 2015 15:13
Zdravím, získal jsme jeden starší NTB, který je rozdělen na C: a D:. Problém je v tom, že systémová složka Windows je zdvojená - je jak na D:, tak na C:. Navíc se jejich obsah trošičku liší. Můžete prosím poradit, co smazat? Děkuji.
Navíc je celý PC zpomalený. Posílám LOG (FRST).
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-02-2015
Ran by Jana (administrator) on JANA-PC on 23-02-2015 15:10:19
Running from C:\Users\Jana\Desktop
Loaded Profiles: Jana (Available profiles: Jana & JanaD & Guest)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(HiTRSUT) C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
() C:\Acer\Mobility Center\MobilityService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
() C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Realtek Semiconductor Corp.) C:\Users\Jana\AppData\Local\Temp\RtkBtMnt.exe
(CyberLink) C:\Acer\Empowering Technology\eAudio\eAudio.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-03-21] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4435968 2007-04-23] (Realtek Semiconductor)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [678672 2007-04-10] (Dritek System Inc.)
HKLM\...\Run: [Acer Tour] => [X]
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [159744 2006-11-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [WarReg_PopUp] => C:\Acer\WR_PopUp\WarReg_PopUp.exe [57344 2006-11-05] (Acer Inc.)
HKLM\...\Run: [eRecoveryService] => [X]
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [B2C_AGENT] => C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [317368 2010-05-20] (LG Electronics)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5074384 2012-11-26] (ESET)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1822720 2007-04-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [] => [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [213936 2006-03-20] (Macrovision Corporation)
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {3228e36f-8466-11e1-8ad9-c5abd5bca15e} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {4afa0c43-b401-11df-a7ca-e289ef7bb56f} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {89812af5-48ee-11e2-84e8-a0d64cc8dcbc} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {b7075b13-a3bb-11dc-b43e-daf119f20fd8} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe KOOTH.vbs
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {bab3b385-c856-11dc-8107-a3f0ff79d747} - G:\LaunchU3.exe
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {c4e5a7f1-9df7-11df-ac3c-9eedbc8221b6} - G:\USBAutoRun.exe
HKU\S-1-5-18\...\Run: [Acer Tour Reminder] => C:\Acer\AcerTour\Reminder.exe [151552 2007-02-15] (Acer Inc.)
AppInit_DLLs: eNetHook.dll => C:\Windows\system32\eNetHook.dll [90112 2007-04-17] (acer)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
ShortcutTarget: Empowering Technology Launcher.lnk -> C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cs.intl.acer.yahoo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cs.intl.acer.yahoo.com
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/en-us/?pc=UP97&ocid=UP97DHP
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.seznam.cz/
URLSearchHook: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.bing.com/search?FORM=UP97DF& ... -SearchBox
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.bing.com/search?FORM=UP97DF& ... -SearchBox
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {6F20D403-67F7-488E-AC59-1331D730377B} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {BD12A27D-16D2-464F-92E4-BAF984A3A57B} URL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {BE9654C9-9D79-42ec-B55A-3CAEB12DBF58} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {D4F2255C-C801-4EAE-AB8F-A96EBA71E81E} URL = http://www.slovnik-cizich-slov.cz/?q={s ... rms}&typ=0
BHO: IEHlprObj Class -> {CE7C3CF0-4B15-11D1-ABED-709549C10000} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll (HiTRUST)
Toolbar: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> Acer eDataSecurity Management - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll (HiTRUST)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-07]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-01-21]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-02]
CHR Extension: (Google Drive) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-02]
CHR Extension: (YouTube) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-02]
CHR Extension: (Google Search) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-02]
CHR Extension: (Spring Mood) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\facdidjmdhkmihcagdgmhffjnkklblge [2015-02-02]
CHR Extension: (Google Wallet) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-02]
CHR Extension: (Gmail) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-02]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [24576 2006-11-02] (Microsoft Corporation) [File not signed]
S3 ALG; C:\Windows\System32\alg.exe [59392 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Appinfo; C:\Windows\System32\appinfo.dll [33280 2014-06-02] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [315392 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Audiosrv; C:\Windows\System32\Audiosrv.dll [315392 2009-04-11] (Microsoft Corporation) [File not signed]
R2 BFE; C:\Windows\System32\bfe.dll [334848 2009-04-11] (Microsoft Corporation) [File not signed]
R2 BITS; C:\Windows\System32\qmgr.dll [758784 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Browser; C:\Windows\System32\browser.dll [81920 2008-01-19] (Microsoft Corporation) [File not signed]
S3 CertPropSvc; C:\Windows\System32\certprop.dll [40448 2009-04-11] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [133120 2013-07-08] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [550400 2009-04-11] (Microsoft Corporation) [File not signed]
S3 DFSR; C:\Windows\system32\DFSR.exe [2092544 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\System32\dhcpcsvc.dll [204288 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Dnscache; C:\Windows\System32\dnsrslvr.dll [86528 2011-03-02] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [175616 2009-04-11] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [134656 2008-01-19] (Microsoft Corporation) [File not signed]
R3 EapHost; C:\Windows\System32\eapsvc.dll [57344 2008-01-19] (Microsoft Corporation) [File not signed]
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe [457512 2007-04-12] (HiTRSUT)
S3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [292352 2008-01-19] (Microsoft Corporation) [File not signed]
S3 ehSched; C:\Windows\ehome\ehsched.exe [131072 2006-11-02] (Microsoft Corporation) [File not signed]
S2 ehstart; C:\Windows\ehome\ehstart.dll [13312 2006-11-02] (Microsoft Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1329304 2012-11-26] (ESET)
S4 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-03-14] (Acer Inc.) [File not signed]
R2 EMDMgmt; C:\Windows\system32\emdmgmt.dll [564224 2009-04-11] (Microsoft Corporation) [File not signed]
S4 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-04-17] (Acer Inc.) [File not signed]
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [53248 2007-02-13] (Acer Inc.) [File not signed]
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-05-10] () [File not signed]
R2 Eventlog; C:\Windows\System32\wevtsvc.dll [1017856 2009-04-11] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\system32\es.dll [268800 2009-04-11] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\Windows\system32\fdPHost.dll [13312 2008-01-19] (Microsoft Corporation) [File not signed]
R2 FDResPub; C:\Windows\system32\fdrespub.dll [27648 2006-11-02] (Microsoft Corporation) [File not signed]
R2 FontCache; C:\Windows\system32\FntCache.dll [798208 2013-08-27] (Microsoft Corporation) [File not signed]
R2 gpsvc; C:\Windows\System32\gpsvc.dll [576512 2009-04-11] (Microsoft Corporation) [File not signed]
R2 hidserv; C:\Windows\system32\hidserv.dll [26112 2009-04-11] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\Windows\system32\kmsvc.dll [68096 2008-01-19] (Microsoft Corporation) [File not signed]
R2 IKEEXT; C:\Windows\System32\ikeext.dll [444928 2013-10-11] (Microsoft Corporation) [File not signed]
R2 IPBusEnum; C:\Windows\system32\ipbusenum.dll [74240 2008-01-19] (Microsoft Corporation) [File not signed]
R2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [200704 2010-02-18] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
R2 KtmRm; C:\Windows\system32\msdtckrm.dll [344576 2008-01-19] (Microsoft Corporation) [File not signed]
R2 LanmanServer; C:\Windows\system32\srvsvc.dll [125952 2010-09-06] (Microsoft Corporation) [File not signed]
R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [160256 2009-06-10] (Microsoft Corporation) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [188928 2008-01-19] (Microsoft Corporation) [File not signed]
R2 lmhosts; C:\Windows\System32\lmhsvc.dll [18944 2006-11-02] (Microsoft Corporation) [File not signed]
R2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [303104 2007-10-15] (Motive Communications, Inc.) [File not signed]
S4 Mcx2Svc; C:\Windows\system32\Mcx2Svc.dll [53760 2008-01-19] (Microsoft Corporation) [File not signed]
R2 MMCSS; C:\Windows\system32\mmcss.dll [45056 2008-01-19] (Microsoft Corporation) [File not signed]
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [107008 2006-11-24] () [File not signed]
R2 MpsSvc; C:\Windows\system32\mpssvc.dll [407552 2009-04-11] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [105984 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSiSCSI; C:\Windows\system32\iscsiexe.dll [111616 2008-01-19] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\System32\msiexec.exe [73216 2009-04-11] (Microsoft Corporation) [File not signed]
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
S3 napagent; C:\Windows\system32\qagentRT.dll [302592 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
R3 Netman; C:\Windows\System32\netman.dll [274432 2008-01-19] (Microsoft Corporation) [File not signed]
R2 netprofm; C:\Windows\System32\netprofm.dll [237056 2008-01-19] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [168448 2008-01-19] (Microsoft Corporation) [File not signed]
R2 nsi; C:\Windows\system32\nsisvc.dll [18432 2008-01-19] (Microsoft Corporation) [File not signed]
S3 p2pimsvc; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
S3 p2psvc; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
R2 PcaSvc; C:\Windows\System32\pcasvc.dll [37888 2008-01-19] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1502208 2008-01-19] (Microsoft Corporation) [File not signed]
R2 PlugPlay; C:\Windows\system32\umpnpmgr.dll [222720 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S3 PNRPAutoReg; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
S3 PNRPsvc; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
R2 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [364032 2009-04-11] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [153088 2009-04-11] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\system32\qwave.dll [243712 2008-01-19] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [90624 2008-01-19] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\Windows\System32\rasmans.dll [262144 2009-04-11] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\System32\mprdim.dll [68608 2008-01-19] (Microsoft Corporation) [File not signed]
S3 RemoteRegistry; C:\Windows\system32\regsvc.dll [107008 2009-04-11] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\Windows\system32\locator.exe [7680 2006-11-02] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\Windows\system32\rpcss.dll [550400 2009-04-11] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\Windows\System32\SCardSvr.dll [95232 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\Windows\system32\schedsvc.dll [601600 2010-11-04] (Microsoft Corporation) [File not signed]
S3 SCPolicySvc; C:\Windows\System32\certprop.dll [40448 2009-04-11] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [104960 2008-01-19] (Microsoft Corporation) [File not signed]
R2 seclogon; C:\Windows\system32\seclogon.dll [19968 2008-01-19] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [47104 2008-01-19] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\system32\sessenv.dll [84992 2008-01-19] (Microsoft Corporation) [File not signed]
S3 SharedAccess; C:\Windows\System32\ipnathlp.dll [288256 2008-01-19] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation) [File not signed]
R2 slsvc; C:\Windows\system32\SLsvc.exe [3408896 2009-04-11] (Microsoft Corporation) [File not signed]
S3 SLUINotify; C:\Windows\system32\SLUINotify.dll [60928 2009-04-11] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2006-11-02] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\Windows\System32\spoolsv.exe [128000 2010-08-17] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [155648 2008-01-19] (Microsoft Corporation) [File not signed]
R3 SstpSvc; C:\Windows\system32\sstpsvc.dll [116736 2008-01-19] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\Windows\System32\wiaservc.dll [453120 2009-04-11] (Microsoft Corporation) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [311808 2009-04-11] (Microsoft Corporation) [File not signed]
R2 SysMain; C:\Windows\system32\sysmain.dll [558080 2009-04-11] (Microsoft Corporation) [File not signed]
R2 TabletInputService; C:\Windows\System32\TabSvc.dll [68096 2006-11-02] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\Windows\System32\tapisrv.dll [242688 2009-04-11] (Microsoft Corporation) [File not signed]
S2 TBS; C:\Windows\System32\tbssvc.dll [56320 2008-01-19] (Microsoft Corporation) [File not signed]
R2 TermService; C:\Windows\System32\termsrv.dll [449024 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation) [File not signed]
S3 THREADORDER; C:\Windows\system32\mmcss.dll [45056 2008-01-19] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\Windows\System32\trkwks.dll [75264 2008-01-19] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [39424 2009-04-11] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [35840 2008-01-19] (Microsoft Corporation) [File not signed]
R2 upnphost; C:\Windows\System32\upnphost.dll [259072 2008-01-19] (Microsoft Corporation) [File not signed]
R2 UxSms; C:\Windows\System32\uxsms.dll [29184 2009-04-11] (Microsoft Corporation) [File not signed]
S3 vds; C:\Windows\System32\vds.exe [385536 2009-04-11] (Microsoft Corporation) [File not signed]
S3 VSS; C:\Windows\system32\vssvc.exe [1055232 2009-04-11] (Microsoft Corporation) [File not signed]
R2 W32Time; C:\Windows\system32\w32time.dll [282624 2009-04-11] (Microsoft Corporation) [File not signed]
S3 wcncsvc; C:\Windows\System32\wcncsvc.dll [413696 2009-04-11] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [32256 2006-11-02] (Microsoft Corporation) [File not signed]
S3 WdiServiceHost; C:\Windows\system32\wdi.dll [73728 2008-01-19] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [73728 2008-01-19] (Microsoft Corporation) [File not signed]
R2 WebClient; C:\Windows\System32\webclnt.dll [199680 2009-04-11] (Microsoft Corporation) [File not signed]
S3 Wecsvc; C:\Windows\system32\wecsvc.dll [146944 2009-10-09] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\Windows\System32\wercplsupport.dll [62976 2008-01-19] (Microsoft Corporation) [File not signed]
R2 WerSvc; C:\Windows\System32\WerSvc.dll [126976 2009-04-11] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S3 WinHttpAutoProxySvc; C:\Windows\system32\winhttp.dll [377344 2011-11-16] (Microsoft Corporation) [File not signed]
R2 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [162304 2009-04-11] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\system32\WsmSvc.dll [1181696 2009-10-09] (Microsoft Corporation) [File not signed]
R2 Wlansvc; C:\Windows\System32\wlansvc.dll [513536 2009-07-11] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [137728 2009-04-11] (Microsoft Corporation) [File not signed]
S4 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [163840 2007-04-24] (acer) [File not signed]
R3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [896512 2008-01-19] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [140288 2009-04-11] (Microsoft Corporation) [File not signed]
R2 WPDBusEnum; C:\Windows\system32\wpdbusenum.dll [81920 2009-10-01] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\Windows\System32\wscsvc.dll [61440 2009-04-11] (Microsoft Corporation) [File not signed]
S2 WSearch; C:\Windows\system32\SearchIndexer.exe [441344 2009-04-11] (Microsoft Corporation) [File not signed]
R2 wudfsvc; C:\Windows\System32\WUDFSvc.dll [73216 2012-07-26] (Microsoft Corporation) [File not signed]
R2 XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [386560 2007-01-30] (Conexant Systems, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 AFD; C:\Windows\system32\drivers\afd.sys [273408 2014-05-30] (Microsoft Corporation) [File not signed]
S4 AmdK7; C:\Windows\system32\drivers\amdk7.sys [38912 2006-11-02] (Microsoft Corporation) [File not signed]
S4 AmdK8; C:\Windows\system32\drivers\amdk8.sys [40960 2006-11-02] (Microsoft Corporation) [File not signed]
R3 ApfiltrService; C:\Windows\System32\DRIVERS\Apfiltr.sys [140800 2006-12-05] (Alps Electric Co., Ltd.) [File not signed]
R3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [17408 2008-01-19] (Microsoft Corporation) [File not signed]
S3 b57nd60x; C:\Windows\System32\DRIVERS\b57nd60x.sys [179712 2007-02-08] (Broadcom Corporation) [File not signed]
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl6.sys [538112 2007-01-10] (Broadcom Corporation) [File not signed]
R1 Beep; C:\Windows\system32\Drivers\Beep.sys [6144 2008-01-19] (Microsoft Corporation) [File not signed]
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [69632 2011-02-22] (Microsoft Corporation) [File not signed]
S3 BrFiltLo; C:\Windows\system32\drivers\brfiltlo.sys [13568 2006-11-02] (Brother Industries, Ltd.) [File not signed]
S3 BrFiltUp; C:\Windows\system32\drivers\brfiltup.sys [5248 2006-11-02] (Brother Industries, Ltd.) [File not signed]
S4 Brserid; C:\Windows\system32\drivers\brserid.sys [71808 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BrSerWdm; C:\Windows\system32\drivers\brserwdm.sys [62336 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BrUsbMdm; C:\Windows\system32\drivers\brusbmdm.sys [12160 2006-11-02] (Brother Industries Ltd.) [File not signed]
S3 BrUsbSer; C:\Windows\system32\drivers\brusbser.sys [11904 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BTHMODEM; C:\Windows\system32\drivers\bthmodem.sys [39936 2006-11-02] (Microsoft Corporation) [File not signed]
R4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [70144 2008-01-19] (Microsoft Corporation) [File not signed]
R1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [67072 2009-04-11] (Microsoft Corporation) [File not signed]
S4 circlass; C:\Windows\system32\drivers\circlass.sys [35328 2006-11-02] (Microsoft Corporation) [File not signed]
R3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [14208 2008-01-19] (Microsoft Corporation) [File not signed]
S4 Crusoe; C:\Windows\system32\drivers\crusoe.sys [38912 2006-11-02] (Microsoft Corporation) [File not signed]
R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [75264 2011-04-14] (Microsoft Corporation) [File not signed]
S3 Dot4; C:\Windows\System32\DRIVERS\Dot4.sys [131584 2008-01-19] (Microsoft Corporation) [File not signed]
S3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [16384 2008-01-19] (Microsoft Corporation) [File not signed]
S3 dot4usb; C:\Windows\System32\DRIVERS\dot4usb.sys [36864 2008-01-19] (Microsoft Corporation) [File not signed]
R1 DritekPortIO; C:\Program Files\Launch Manager\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
S3 drmkaud; C:\Windows\System32\drivers\drmkaud.sys [5632 2008-01-19] (Microsoft Corporation) [File not signed]
S3 E1G60; C:\Windows\System32\DRIVERS\E1G60I32.sys [117760 2006-11-02] (Intel Corporation) [File not signed]
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170656 2012-10-08] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [121216 2012-10-08] (ESET)
R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [67584 2007-04-11] (ENE Technology Inc.) [File not signed]
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [104712 2012-10-08] (ESET)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [46592 2007-04-11] (ENE Technology Inc.) [File not signed]
R3 ESMCR; C:\Windows\System32\DRIVERS\ESM7SK.sys [63488 2007-04-11] (ENE Technology Inc.) [File not signed]
R2 Ethpdrv; C:\Windows\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.) [File not signed]
S3 exfat; C:\Windows\system32\Drivers\exfat.sys [136704 2009-04-11] (Microsoft Corporation) [File not signed]
S3 fastfat; C:\Windows\system32\Drivers\fastfat.sys [143360 2014-09-05] (Microsoft Corporation) [File not signed]
S4 fdc; C:\Windows\System32\DRIVERS\fdc.sys [25088 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [27648 2008-01-19] (Microsoft Corporation) [File not signed]
S4 flpydisk; C:\Windows\System32\DRIVERS\flpydisk.sys [20480 2006-11-02] (Microsoft Corporation) [File not signed]
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
U1 Fs_Rec; C:\Windows\system32\Drivers\Fs_Rec.sys [12800 2012-02-29] (Microsoft Corporation) [File not signed]
S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [235520 2006-11-02] (Microsoft Corporation) [File not signed]
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [561152 2009-04-11] (Microsoft Corporation) [File not signed]
S4 HidBth; C:\Windows\system32\drivers\hidbth.sys [29184 2006-11-02] (Microsoft Corporation) [File not signed]
S4 HidIr; C:\Windows\system32\drivers\hidir.sys [21504 2006-11-02] (Microsoft Corporation) [File not signed]
R3 HidUsb; C:\Windows\System32\DRIVERS\hidusb.sys [12800 2009-04-11] (Microsoft Corporation) [File not signed]
S3 HSFHWAZL; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [200704 2006-11-02] (Conexant Systems, Inc.) [File not signed]
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [984064 2007-03-01] (Conexant Systems, Inc.) [File not signed]
R3 HSXHWAZL; C:\Windows\System32\DRIVERS\HSXHWAZL.sys [208384 2007-03-01] (Conexant Systems, Inc.) [File not signed]
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [411648 2010-02-20] (Microsoft Corporation) [File not signed]
R1 i8042prt; C:\Windows\System32\DRIVERS\i8042prt.sys [54784 2008-01-19] (Microsoft Corporation) [File not signed]
S3 ialm; C:\Windows\System32\DRIVERS\igdkmd32.sys [1771008 2007-05-22] (Intel Corporation) [File not signed]
R3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [1771008 2007-05-22] (Intel Corporation) [File not signed]
R2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [76584 2006-12-07] ()
R3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [41472 2008-01-19] (Microsoft Corporation) [File not signed]
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [47616 2008-01-19] (Microsoft Corporation) [File not signed]
S4 IPMIDRV; C:\Windows\system32\drivers\ipmidrv.sys [65536 2006-11-02] (Microsoft Corporation) [File not signed]
S3 IPNAT; C:\Windows\System32\DRIVERS\ipnat.sys [100864 2008-01-19] (Microsoft Corporation) [File not signed]
S3 IpwP; C:\Windows\System32\DRIVERS\ipw3gnet.sys [51040 2007-06-12] (IPWireless Inc.) [File not signed]
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [13312 2008-01-19] (Microsoft Corporation) [File not signed]
S3 k510bus; C:\Windows\System32\DRIVERS\k510bus.sys [58288 2006-02-17] (MCCI) [File not signed]
S1 kbdhid; C:\Windows\System32\DRIVERS\kbdhid.sys [17408 2009-04-11] (Microsoft Corporation) [File not signed]
R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [47104 2008-01-19] (Microsoft Corporation) [File not signed]
R2 luafv; C:\Windows\system32\drivers\luafv.sys [84480 2008-01-19] (Microsoft Corporation) [File not signed]
R2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2006-06-19] (Conexant) [File not signed]
R3 Modem; C:\Windows\System32\drivers\modem.sys [31744 2008-01-19] (Microsoft Corporation) [File not signed]
R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [41984 2008-01-19] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [15872 2008-01-19] (Microsoft Corporation) [File not signed]
R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [64000 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [114688 2009-04-11] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [106496 2011-04-29] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [214016 2011-07-06] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [79872 2011-04-29] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [8192 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [5888 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [5504 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [6016 2008-01-19] (Microsoft Corporation) [File not signed]
R3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [148480 2009-04-11] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [20992 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [16896 2008-01-19] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [121344 2009-04-11] (Microsoft Corporation) [File not signed]
R3 NDProxy; C:\Windows\system32\Drivers\NDProxy.sys [49664 2008-01-19] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [35840 2008-01-19] (Microsoft Corporation) [File not signed]
R1 netbt; C:\Windows\System32\DRIVERS\netbt.sys [185856 2009-04-11] (Microsoft Corporation) [File not signed]
S3 NETw4v32; C:\Windows\System32\DRIVERS\NETw4v32.sys [2216448 2007-02-25] (Intel Corporation) [File not signed]
S3 nmwcd; C:\Windows\System32\drivers\ccdcmb.sys [17664 2009-02-09] (Nokia) [File not signed]
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbo.sys [22016 2009-02-09] (Nokia) [File not signed]
S3 nmwcdnsu; C:\Windows\System32\drivers\nmwcdnsu.sys [136704 2009-03-19] (Nokia) [File not signed]
S3 nmwcdnsuc; C:\Windows\System32\drivers\nmwcdnsuc.sys [8320 2009-03-19] (Nokia) [File not signed]
R1 Npfs; C:\Windows\system32\Drivers\Npfs.sys [35328 2009-04-11] (Microsoft Corporation) [File not signed]
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [16384 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 NTIDrvr; C:\Windows\System32\DRIVERS\NTIDrvr.sys [6144 2007-06-20] (NewTech Infosystems, Inc.) [File not signed]
S4 ntrigdigi; C:\Windows\system32\drivers\ntrigdigi.sys [20608 2006-11-02] (N-trig Innovative Technologies) [File not signed]
R1 Null; C:\Windows\system32\Drivers\Null.sys [4608 2008-01-19] (Microsoft Corporation) [File not signed]
S4 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [62080 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Parport; C:\Windows\system32\drivers\parport.sys [79360 2006-11-02] (Microsoft Corporation) [File not signed]
S2 Parvdm; C:\Windows\system32\drivers\parvdm.sys [8704 2006-11-02] (Microsoft Corporation) [File not signed]
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [878080 2006-11-02] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [62976 2008-01-19] (Microsoft Corporation) [File not signed]
S4 Processor; C:\Windows\system32\drivers\processr.sys [38400 2006-11-02] (Microsoft Corporation) [File not signed]
R1 PSched; C:\Windows\System32\DRIVERS\pacer.sys [72192 2009-04-11] (Microsoft Corporation) [File not signed]
R0 PSDFilter; C:\Windows\System32\DRIVERS\psdfilter.sys [20264 2007-04-12] (HiTRUST)
R0 PSDNServ; C:\Windows\System32\drivers\PSDNServ.sys [16680 2007-04-12] (HiTRUST)
R0 psdvdisk; C:\Windows\System32\drivers\psdvdisk.sys [60712 2007-04-12] (HiTRUST)
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [31232 2008-01-19] (Microsoft Corporation) [File not signed]
R1 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [11776 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [76288 2008-01-19] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [41472 2009-04-11] (Microsoft Corporation) [File not signed]
R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [69120 2009-04-11] (Microsoft Corporation) [File not signed]
R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [225280 2009-04-11] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [6144 2008-01-19] (Microsoft Corporation) [File not signed]
S4 rdpdr; C:\Windows\system32\drivers\rdpdr.sys [242688 2006-11-02] (Microsoft Corporation) [File not signed]
R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [6144 2008-01-19] (Microsoft Corporation) [File not signed]
R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [60416 2008-01-19] (Microsoft Corporation) [File not signed]
R3 sdbus; C:\Windows\System32\DRIVERS\sdbus.sys [89088 2009-04-11] (Microsoft Corporation) [File not signed]
R2 secdrv; C:\Windows\system32\Drivers\secdrv.sys [20480 2006-11-02] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 Serenum; C:\Windows\system32\drivers\serenum.sys [17920 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Serial; C:\Windows\system32\drivers\serial.sys [83456 2006-11-02] (Microsoft Corporation) [File not signed]
S4 sermouse; C:\Windows\system32\drivers\sermouse.sys [19968 2008-01-19] (Microsoft Corporation) [File not signed]
S3 sffdisk; C:\Windows\System32\DRIVERS\sffdisk.sys [13312 2008-01-19] (Microsoft Corporation) [File not signed]
S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [12800 2006-11-02] (Microsoft Corporation) [File not signed]
S3 sffp_sd; C:\Windows\System32\DRIVERS\sffp_sd.sys [11776 2009-04-11] (Microsoft Corporation) [File not signed]
S4 sfloppy; C:\Windows\system32\drivers\sfloppy.sys [13312 2006-11-02] (Microsoft Corporation) [File not signed]
R1 Smb; C:\Windows\System32\DRIVERS\smb.sys [66560 2009-04-11] (Microsoft Corporation) [File not signed]
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [305152 2011-02-18] (Microsoft Corporation) [File not signed]
R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [146432 2011-04-29] (Microsoft Corporation) [File not signed]
R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [102400 2011-04-29] (Microsoft Corporation) [File not signed]
R3 StillCam; C:\Windows\System32\DRIVERS\serscan.sys [9216 2008-01-19] (Microsoft Corporation) [File not signed]
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [30720 2009-12-08] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [17920 2008-01-19] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [29184 2008-01-19] (Microsoft Corporation) [File not signed]
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [72192 2009-04-11] (Microsoft Corporation) [File not signed]
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [24064 2013-06-15] (Microsoft Corporation) [File not signed]
R3 tunmp; C:\Windows\System32\DRIVERS\tunmp.sys [15360 2008-01-19] (Microsoft Corporation) [File not signed]
R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [25088 2010-02-18] (Microsoft Corporation) [File not signed]
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [226816 2009-04-11] (Microsoft Corporation) [File not signed]
R3 umbus; C:\Windows\System32\DRIVERS\umbus.sys [34816 2008-01-19] (Microsoft Corporation) [File not signed]
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerflt.sys [7808 2009-02-09] (Nokia) [File not signed]
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.) [File not signed]
S3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [73216 2013-06-29] (Microsoft Corporation) [File not signed]
S4 usbcir; C:\Windows\system32\drivers\usbcir.sys [68608 2006-11-02] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [39936 2011-05-05] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [197632 2013-06-29] (Microsoft Corporation) [File not signed]
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.) [File not signed]
S4 usbohci; C:\Windows\system32\drivers\usbohci.sys [19456 2006-11-02] (Microsoft Corporation) [File not signed]
S3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [18944 2008-01-19] (Microsoft Corporation) [File not signed]
S3 usbscan; C:\Windows\System32\DRIVERS\usbscan.sys [35328 2013-07-03] (Microsoft Corporation) [File not signed]
S3 usbser; C:\Windows\System32\drivers\usbser.sys [27648 2013-08-29] (Microsoft Corporation) [File not signed]
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltj.sys [7808 2009-02-09] (Nokia) [File not signed]
S3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [65536 2009-04-11] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [23552 2011-05-05] (Microsoft Corporation) [File not signed]
S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [26112 2006-11-02] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\Windows\System32\drivers\vga.sys [25088 2008-01-19] (Microsoft Corporation) [File not signed]
S4 ViaC7; C:\Windows\system32\drivers\viac7.sys [39424 2006-11-02] (Microsoft Corporation) [File not signed]
S4 WacomPen; C:\Windows\system32\drivers\wacompen.sys [20608 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Wanarp; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-19] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-19] (Microsoft Corporation) [File not signed]
R3 winachsf; C:\Windows\System32\DRIVERS\HSX_CNXT.sys [660480 2007-03-01] (Conexant Systems, Inc.) [File not signed]
R3 WmiAcpi; C:\Windows\System32\DRIVERS\wmiacpi.sys [11264 2008-01-19] (Microsoft Corporation) [File not signed]
S3 WpdUsb; C:\Windows\System32\DRIVERS\wpdusb.sys [40448 2009-10-01] (Microsoft Corporation) [File not signed]
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [15872 2008-01-19] (Microsoft Corporation) [File not signed]
R3 WSDPrintDevice; C:\Windows\System32\DRIVERS\WSDPrint.sys [16896 2008-01-19] (Microsoft Corporation) [File not signed]
R3 WSDScan; C:\Windows\System32\DRIVERS\WSDScan.sys [19968 2009-04-11] (Microsoft Corporation) [File not signed]
R3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [66560 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation) [File not signed]
R2 XAudio; C:\Windows\System32\DRIVERS\xaudio.sys [8704 2007-01-30] (Conexant Systems, Inc.) [File not signed]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [13560 2006-11-02] (Cyberlink Corp.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 ipw_bus; system32\DRIVERS\ipw_bus.sys [X]
S3 ipw_mdfl; system32\DRIVERS\ipw_mdfl.sys [X]
S3 ipw_mdm; system32\DRIVERS\ipw_mdm.sys [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 15:09 - 2015-02-23 15:12 - 00047453 _____ () C:\Users\Jana\Desktop\FRST.txt
2015-02-23 15:07 - 2015-02-23 15:10 - 00000000 ____D () C:\FRST
2015-02-23 15:03 - 2015-02-23 15:03 - 01126912 _____ (Farbar) C:\Users\Jana\Desktop\FRST.exe
2015-02-23 14:10 - 2015-02-23 14:10 - 00105048 _____ () C:\Users\JanaD\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-23 14:09 - 2015-02-23 14:09 - 00000953 _____ () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-23 14:09 - 2015-02-23 14:09 - 00000948 _____ () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-02-23 14:09 - 2015-02-23 14:09 - 00000000 ____D () C:\Users\JanaD\AppData\Local\Google
2015-02-23 14:06 - 2015-02-23 14:11 - 00000000 ____D () C:\Users\JanaD\AppData\Local\VirtualStore
2015-02-23 14:06 - 2015-02-23 14:09 - 00000000 ____D () C:\Users\JanaD
2015-02-23 14:06 - 2015-02-23 14:06 - 00000919 _____ () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-02-23 14:06 - 2015-02-23 14:06 - 00000020 ___SH () C:\Users\JanaD\ntuser.ini
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Šablony
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Soubory cookie
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Okolní tiskárny
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Okolní síť
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Nabídka Start
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Dokumenty
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Documents\Obrázky
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Documents\Hudba
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Documents\Filmy
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Data aplikací
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\AppData\Local\Historie
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\AppData\Local\Data aplikací
2015-02-23 14:06 - 2009-03-03 03:44 - 00000000 ___RD () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-02-23 14:06 - 2009-03-03 03:44 - 00000000 ___RD () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-23 14:06 - 2007-09-16 08:44 - 00000000 ____D () C:\Users\JanaD\AppData\Local\Microsoft Help
2015-02-23 13:29 - 2015-02-23 13:29 - 00000007 _____ () C:\ISACER.id
2015-02-19 09:24 - 2015-02-19 09:24 - 00000371 _____ () C:\Users\Jana\Obrázky – zástupce.lnk
2015-02-11 16:10 - 2015-02-11 16:10 - 00001114 _____ () C:\Users\Jana\Desktop\Ashampoo Burning Studio 6 FREE.lnk
2015-02-11 16:10 - 2015-02-11 16:10 - 00000214 _____ () C:\Users\Public\Desktop\Your Software Deals.url
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Users\Jana\AppData\Local\ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\ProgramData\Ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Program Files\Ashampoo
2015-02-11 08:13 - 2015-02-11 08:13 - 00000536 _____ () C:\Windows\PFRO.log
2015-02-09 14:29 - 2015-02-09 14:29 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chatango
2015-02-09 14:29 - 2015-02-09 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chatango
2015-02-09 14:29 - 2015-02-09 14:29 - 00000000 ____D () C:\Program Files\Chatango
2015-02-09 12:20 - 2015-02-09 12:20 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Software602
2015-02-09 12:13 - 2015-02-09 12:13 - 00000000 ____D () C:\Program Files\Software602
2015-02-05 11:33 - 2015-02-05 11:33 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\PeerNetworking
2015-02-05 09:09 - 2015-02-05 09:09 - 00000916 _____ () C:\Users\Jana\Desktop\ProFact 4.0 Manuál.lnk
2015-02-05 09:09 - 2015-02-05 09:09 - 00000841 _____ () C:\Users\Jana\Desktop\Vzdálená podpora ProFact.lnk
2015-02-05 09:09 - 2015-02-05 09:09 - 00000824 _____ () C:\Users\Jana\Desktop\ProFact 4.0.lnk
2015-02-05 09:09 - 2015-02-05 09:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProFact 4.0
2015-02-05 09:08 - 2015-02-05 09:09 - 00000000 ____D () C:\Program Files\ProFact 4.0
2015-02-05 09:08 - 2015-02-05 09:08 - 00000000 ____D () C:\ProgramData\eXmind
2015-02-03 13:20 - 2015-02-03 13:21 - 00000174 _____ () C:\PowerDV.log
2015-02-03 13:19 - 2015-02-03 13:20 - 00000091 _____ () C:\MDR.log
2015-02-03 13:18 - 2015-02-03 13:19 - 00000091 _____ () C:\MDisc.log
2015-02-03 12:08 - 2015-02-03 12:09 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-03 12:02 - 2015-02-03 12:03 - 11743631 _____ () C:\Users\Guest\Downloads\cc-setup (1).exe
2015-02-03 11:59 - 2015-02-03 11:59 - 03334144 _____ () C:\Users\Guest\Downloads\cc-setup.exe
2015-02-02 14:18 - 2015-02-02 14:18 - 00000000 ____D () C:\Windows\Hewlett-Packard
2015-02-02 14:06 - 2015-02-02 14:06 - 00001792 _____ () C:\Users\Public\Desktop\HP Photo Creations.lnk
2015-02-02 14:06 - 2015-02-02 14:06 - 00000000 ____D () C:\ProgramData\Visan
2015-02-02 14:06 - 2015-02-02 14:06 - 00000000 ____D () C:\ProgramData\HP Photo Creations
2015-02-02 14:06 - 2015-02-02 14:06 - 00000000 ____D () C:\Program Files\HP Photo Creations
2015-02-02 14:04 - 2015-02-09 08:30 - 00002119 _____ () C:\Users\Public\Desktop\HP Deskjet 5520 series.lnk
2015-02-02 14:04 - 2015-02-02 14:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-02-02 14:04 - 2015-02-02 14:04 - 00001066 _____ () C:\Users\Public\Desktop\Zakoupit spotřební materiál - HP Deskjet 5520 series.lnk
2015-02-02 14:04 - 2012-10-17 04:04 - 00580712 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPMB611.dll
2015-02-02 14:01 - 2015-02-02 14:01 - 00000057 _____ () C:\ProgramData\Ament.ini
2015-02-02 14:00 - 2015-02-02 16:29 - 00000000 ____D () C:\Users\Jana\AppData\Local\HP
2015-02-02 11:52 - 2015-02-23 21:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-02 11:52 - 2015-02-06 09:19 - 00001975 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-02 11:48 - 2015-02-02 11:53 - 00000000 ____D () C:\Program Files\Google
2015-02-02 11:46 - 2015-02-11 16:35 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-02-02 11:46 - 2015-02-02 11:46 - 00001896 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2015-02-02 11:45 - 2015-02-02 11:46 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-02-02 09:11 - 2015-02-02 09:11 - 00000000 ____D () C:\Users\Jana\AppData\Local\Skype
2015-02-02 09:10 - 2015-02-02 09:10 - 00000000 ___RD () C:\Program Files\Skype
2015-02-02 09:10 - 2015-02-02 09:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-02-02 09:10 - 2015-02-02 09:10 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-01-31 19:07 - 2015-01-31 19:07 - 00000000 ____D () C:\Windows\WindowsMobile
2015-01-31 18:58 - 2015-01-31 18:58 - 00000000 ____D () C:\Windows\PLA
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 21:41 - 2009-07-20 15:34 - 00000000 ____D () C:\Users\Guest
2015-02-23 21:41 - 2008-07-30 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OLYMPUS Master 2
2015-02-23 21:41 - 2007-09-15 15:22 - 00000000 ____D () C:\Users\Jana
2015-02-23 21:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool
2015-02-23 21:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-02-23 21:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration
2015-02-23 21:41 - 2006-11-02 11:22 - 51593216 _____ () C:\Windows\system32\config\software_previous
2015-02-23 21:41 - 2006-11-02 11:22 - 253493248 _____ () C:\Windows\system32\config\system_previous
2015-02-23 21:37 - 2006-11-02 11:22 - 42991616 _____ () C:\Windows\system32\config\components_previous
2015-02-23 21:37 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2015-02-23 15:11 - 2010-09-29 16:15 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-23 15:03 - 2006-11-02 13:47 - 00003168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-23 15:03 - 2006-11-02 13:47 - 00003168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-23 14:46 - 2007-09-15 21:04 - 01710842 _____ () C:\Windows\WindowsUpdate.log
2015-02-23 14:45 - 2010-09-29 16:15 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-23 14:39 - 2012-04-10 10:50 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-23 14:00 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-23 13:58 - 2006-11-02 14:01 - 00032610 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-23 12:50 - 2009-10-29 08:16 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\HpUpdate
2015-02-23 12:33 - 2006-11-02 11:22 - 01118208 _____ () C:\Windows\system32\config\default_previous
2015-02-23 12:32 - 2008-11-19 12:20 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Skype
2015-02-22 08:39 - 2006-11-02 11:22 - 00028672 _____ () C:\Windows\system32\config\security_previous
2015-02-16 13:51 - 2009-03-05 09:33 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2015-02-11 08:17 - 2007-09-15 15:25 - 00105048 _____ () C:\Users\Jana\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-11 08:13 - 2006-11-02 13:47 - 00388936 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-09 13:27 - 2008-11-05 10:14 - 00000000 ____D () C:\Program Files\Common Files\soft602
2015-02-09 13:11 - 2007-06-20 11:05 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-02-09 13:11 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-02-09 12:27 - 2011-03-14 11:42 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\602XML
2015-02-09 12:26 - 2007-06-20 10:08 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-05 13:00 - 2012-04-10 10:50 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-05 13:00 - 2012-04-10 10:50 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-05 09:08 - 2010-02-18 10:05 - 00000000 ____D () C:\Users\Jana\AppData\Local\eXmind
2015-02-04 16:59 - 2007-09-15 17:42 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Adobe
2015-02-04 13:38 - 2007-06-20 18:52 - 00000000 ___DC () C:\Acer
2015-02-04 13:34 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public
2015-02-03 13:48 - 2008-07-30 11:27 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-02-03 13:22 - 2007-06-20 09:54 - 00000000 ____D () C:\Program Files\Acer Arcade Deluxe
2015-02-03 13:13 - 2007-06-20 09:54 - 00000000 ____D () C:\Program Files\Acer Inc
2015-02-03 13:13 - 2007-06-20 09:49 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-02-03 11:54 - 2010-07-02 14:21 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2015-02-02 14:05 - 2007-09-17 08:44 - 00000000 ____D () C:\Program Files\HP
2015-02-02 14:01 - 2007-09-17 08:40 - 00000000 ____D () C:\ProgramData\HP
2015-02-02 14:01 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32
2015-02-02 13:36 - 2007-09-17 08:41 - 00050361 _____ () C:\ProgramData\hpzinstall.log
2015-02-02 11:57 - 2007-09-15 17:42 - 00000000 ____D () C:\Users\Jana\AppData\Local\Adobe
2015-02-02 11:53 - 2007-09-21 07:00 - 00000000 ____D () C:\Users\Jana\AppData\Local\Google
2015-02-02 11:45 - 2007-06-20 10:06 - 00000000 ____D () C:\Program Files\Adobe
2015-02-02 09:11 - 2008-11-19 12:19 - 00000000 ____D () C:\ProgramData\Skype
2015-01-31 19:04 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Movie Maker
2015-01-31 18:58 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\DigitalLocker
==================== Files in the root of some directories =======
2010-11-08 15:17 - 2010-11-08 15:17 - 0000600 _____ () C:\Users\Jana\AppData\Roaming\winscp.rnd
2008-07-22 05:44 - 2011-10-17 11:10 - 0005000 _____ () C:\Users\Jana\AppData\Local\d3d9caps.dat
2007-09-15 18:30 - 2012-12-18 10:19 - 0117248 _____ () C:\Users\Jana\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-03-12 13:12 - 2009-03-12 13:12 - 0000092 _____ () C:\Users\Jana\AppData\Local\fusioncache.dat
2012-12-27 17:17 - 2013-01-20 10:05 - 1434678 ____T () C:\ProgramData\0tbpw.pad
2015-02-02 14:01 - 2015-02-02 14:01 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-11-27 16:23 - 2012-11-27 16:24 - 0811895 ____T () C:\ProgramData\dsgsdgdsgdsgw.pad
2010-12-26 08:31 - 2010-12-26 08:31 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-09-17 08:41 - 2015-02-02 13:36 - 0050361 _____ () C:\ProgramData\hpzinstall.log
2012-11-27 16:23 - 2012-11-27 16:23 - 0044544 _____ (Microsoft Corporation) C:\ProgramData\lsass.exe
2007-09-25 10:07 - 2007-09-25 10:07 - 0000013 ____H () C:\ProgramData\ÄĐ3113.sys
Files to move or delete:
====================
C:\ProgramData\0tbpw.pad
C:\ProgramData\dsgsdgdsgdsgw.pad
C:\ProgramData\lsass.exe
Some content of TEMP:
====================
C:\Users\Guest\AppData\Local\Temp\jre-1.6.0_20-windows-i586-iftw.exe_90744722.exe
C:\Users\Guest\AppData\Local\Temp\jre-6u20-windows-i586-jinstall_uac.exe
C:\Users\Guest\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\Guest\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Jana\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\JanaD\AppData\Local\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-23 14:07
==================== End Of Log ============================
Navíc je celý PC zpomalený. Posílám LOG (FRST).
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-02-2015
Ran by Jana (administrator) on JANA-PC on 23-02-2015 15:10:19
Running from C:\Users\Jana\Desktop
Loaded Profiles: Jana (Available profiles: Jana & JanaD & Guest)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(HiTRSUT) C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
() C:\Acer\Mobility Center\MobilityService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
() C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Realtek Semiconductor Corp.) C:\Users\Jana\AppData\Local\Temp\RtkBtMnt.exe
(CyberLink) C:\Acer\Empowering Technology\eAudio\eAudio.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-03-21] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4435968 2007-04-23] (Realtek Semiconductor)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [678672 2007-04-10] (Dritek System Inc.)
HKLM\...\Run: [Acer Tour] => [X]
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [159744 2006-11-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [WarReg_PopUp] => C:\Acer\WR_PopUp\WarReg_PopUp.exe [57344 2006-11-05] (Acer Inc.)
HKLM\...\Run: [eRecoveryService] => [X]
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [B2C_AGENT] => C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [317368 2010-05-20] (LG Electronics)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5074384 2012-11-26] (ESET)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1822720 2007-04-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [] => [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [213936 2006-03-20] (Macrovision Corporation)
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {3228e36f-8466-11e1-8ad9-c5abd5bca15e} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {4afa0c43-b401-11df-a7ca-e289ef7bb56f} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {89812af5-48ee-11e2-84e8-a0d64cc8dcbc} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {b7075b13-a3bb-11dc-b43e-daf119f20fd8} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe KOOTH.vbs
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {bab3b385-c856-11dc-8107-a3f0ff79d747} - G:\LaunchU3.exe
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\...\MountPoints2: {c4e5a7f1-9df7-11df-ac3c-9eedbc8221b6} - G:\USBAutoRun.exe
HKU\S-1-5-18\...\Run: [Acer Tour Reminder] => C:\Acer\AcerTour\Reminder.exe [151552 2007-02-15] (Acer Inc.)
AppInit_DLLs: eNetHook.dll => C:\Windows\system32\eNetHook.dll [90112 2007-04-17] (acer)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
ShortcutTarget: Empowering Technology Launcher.lnk -> C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cs.intl.acer.yahoo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cs.intl.acer.yahoo.com
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/en-us/?pc=UP97&ocid=UP97DHP
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKU\S-1-5-21-1730743208-2182468026-483216861-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.seznam.cz/
URLSearchHook: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.bing.com/search?FORM=UP97DF& ... -SearchBox
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.bing.com/search?FORM=UP97DF& ... -SearchBox
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {6F20D403-67F7-488E-AC59-1331D730377B} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {BD12A27D-16D2-464F-92E4-BAF984A3A57B} URL = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {BE9654C9-9D79-42ec-B55A-3CAEB12DBF58} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> {D4F2255C-C801-4EAE-AB8F-A96EBA71E81E} URL = http://www.slovnik-cizich-slov.cz/?q={s ... rms}&typ=0
BHO: IEHlprObj Class -> {CE7C3CF0-4B15-11D1-ABED-709549C10000} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll (HiTRUST)
Toolbar: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKU\S-1-5-21-1730743208-2182468026-483216861-1000 -> Acer eDataSecurity Management - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll (HiTRUST)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-07]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-01-21]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-02]
CHR Extension: (Google Drive) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-02]
CHR Extension: (YouTube) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-02]
CHR Extension: (Google Search) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-02]
CHR Extension: (Spring Mood) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\facdidjmdhkmihcagdgmhffjnkklblge [2015-02-02]
CHR Extension: (Google Wallet) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-02]
CHR Extension: (Gmail) - C:\Users\Jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-02]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [24576 2006-11-02] (Microsoft Corporation) [File not signed]
S3 ALG; C:\Windows\System32\alg.exe [59392 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Appinfo; C:\Windows\System32\appinfo.dll [33280 2014-06-02] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [315392 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Audiosrv; C:\Windows\System32\Audiosrv.dll [315392 2009-04-11] (Microsoft Corporation) [File not signed]
R2 BFE; C:\Windows\System32\bfe.dll [334848 2009-04-11] (Microsoft Corporation) [File not signed]
R2 BITS; C:\Windows\System32\qmgr.dll [758784 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Browser; C:\Windows\System32\browser.dll [81920 2008-01-19] (Microsoft Corporation) [File not signed]
S3 CertPropSvc; C:\Windows\System32\certprop.dll [40448 2009-04-11] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [133120 2013-07-08] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [550400 2009-04-11] (Microsoft Corporation) [File not signed]
S3 DFSR; C:\Windows\system32\DFSR.exe [2092544 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\System32\dhcpcsvc.dll [204288 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Dnscache; C:\Windows\System32\dnsrslvr.dll [86528 2011-03-02] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [175616 2009-04-11] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [134656 2008-01-19] (Microsoft Corporation) [File not signed]
R3 EapHost; C:\Windows\System32\eapsvc.dll [57344 2008-01-19] (Microsoft Corporation) [File not signed]
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe [457512 2007-04-12] (HiTRSUT)
S3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [292352 2008-01-19] (Microsoft Corporation) [File not signed]
S3 ehSched; C:\Windows\ehome\ehsched.exe [131072 2006-11-02] (Microsoft Corporation) [File not signed]
S2 ehstart; C:\Windows\ehome\ehstart.dll [13312 2006-11-02] (Microsoft Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1329304 2012-11-26] (ESET)
S4 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-03-14] (Acer Inc.) [File not signed]
R2 EMDMgmt; C:\Windows\system32\emdmgmt.dll [564224 2009-04-11] (Microsoft Corporation) [File not signed]
S4 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-04-17] (Acer Inc.) [File not signed]
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [53248 2007-02-13] (Acer Inc.) [File not signed]
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-05-10] () [File not signed]
R2 Eventlog; C:\Windows\System32\wevtsvc.dll [1017856 2009-04-11] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\system32\es.dll [268800 2009-04-11] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\Windows\system32\fdPHost.dll [13312 2008-01-19] (Microsoft Corporation) [File not signed]
R2 FDResPub; C:\Windows\system32\fdrespub.dll [27648 2006-11-02] (Microsoft Corporation) [File not signed]
R2 FontCache; C:\Windows\system32\FntCache.dll [798208 2013-08-27] (Microsoft Corporation) [File not signed]
R2 gpsvc; C:\Windows\System32\gpsvc.dll [576512 2009-04-11] (Microsoft Corporation) [File not signed]
R2 hidserv; C:\Windows\system32\hidserv.dll [26112 2009-04-11] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\Windows\system32\kmsvc.dll [68096 2008-01-19] (Microsoft Corporation) [File not signed]
R2 IKEEXT; C:\Windows\System32\ikeext.dll [444928 2013-10-11] (Microsoft Corporation) [File not signed]
R2 IPBusEnum; C:\Windows\system32\ipbusenum.dll [74240 2008-01-19] (Microsoft Corporation) [File not signed]
R2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [200704 2010-02-18] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
R2 KtmRm; C:\Windows\system32\msdtckrm.dll [344576 2008-01-19] (Microsoft Corporation) [File not signed]
R2 LanmanServer; C:\Windows\system32\srvsvc.dll [125952 2010-09-06] (Microsoft Corporation) [File not signed]
R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [160256 2009-06-10] (Microsoft Corporation) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [188928 2008-01-19] (Microsoft Corporation) [File not signed]
R2 lmhosts; C:\Windows\System32\lmhsvc.dll [18944 2006-11-02] (Microsoft Corporation) [File not signed]
R2 McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [303104 2007-10-15] (Motive Communications, Inc.) [File not signed]
S4 Mcx2Svc; C:\Windows\system32\Mcx2Svc.dll [53760 2008-01-19] (Microsoft Corporation) [File not signed]
R2 MMCSS; C:\Windows\system32\mmcss.dll [45056 2008-01-19] (Microsoft Corporation) [File not signed]
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [107008 2006-11-24] () [File not signed]
R2 MpsSvc; C:\Windows\system32\mpssvc.dll [407552 2009-04-11] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [105984 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSiSCSI; C:\Windows\system32\iscsiexe.dll [111616 2008-01-19] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\System32\msiexec.exe [73216 2009-04-11] (Microsoft Corporation) [File not signed]
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
S3 napagent; C:\Windows\system32\qagentRT.dll [302592 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
R3 Netman; C:\Windows\System32\netman.dll [274432 2008-01-19] (Microsoft Corporation) [File not signed]
R2 netprofm; C:\Windows\System32\netprofm.dll [237056 2008-01-19] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [168448 2008-01-19] (Microsoft Corporation) [File not signed]
R2 nsi; C:\Windows\system32\nsisvc.dll [18432 2008-01-19] (Microsoft Corporation) [File not signed]
S3 p2pimsvc; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
S3 p2psvc; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
R2 PcaSvc; C:\Windows\System32\pcasvc.dll [37888 2008-01-19] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1502208 2008-01-19] (Microsoft Corporation) [File not signed]
R2 PlugPlay; C:\Windows\system32\umpnpmgr.dll [222720 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S3 PNRPAutoReg; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
S3 PNRPsvc; C:\Windows\system32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation) [File not signed]
R2 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [364032 2009-04-11] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [153088 2009-04-11] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\system32\qwave.dll [243712 2008-01-19] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [90624 2008-01-19] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\Windows\System32\rasmans.dll [262144 2009-04-11] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\System32\mprdim.dll [68608 2008-01-19] (Microsoft Corporation) [File not signed]
S3 RemoteRegistry; C:\Windows\system32\regsvc.dll [107008 2009-04-11] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\Windows\system32\locator.exe [7680 2006-11-02] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\Windows\system32\rpcss.dll [550400 2009-04-11] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [9728 2011-11-16] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\Windows\System32\SCardSvr.dll [95232 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\Windows\system32\schedsvc.dll [601600 2010-11-04] (Microsoft Corporation) [File not signed]
S3 SCPolicySvc; C:\Windows\System32\certprop.dll [40448 2009-04-11] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [104960 2008-01-19] (Microsoft Corporation) [File not signed]
R2 seclogon; C:\Windows\system32\seclogon.dll [19968 2008-01-19] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [47104 2008-01-19] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\system32\sessenv.dll [84992 2008-01-19] (Microsoft Corporation) [File not signed]
S3 SharedAccess; C:\Windows\System32\ipnathlp.dll [288256 2008-01-19] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation) [File not signed]
R2 slsvc; C:\Windows\system32\SLsvc.exe [3408896 2009-04-11] (Microsoft Corporation) [File not signed]
S3 SLUINotify; C:\Windows\system32\SLUINotify.dll [60928 2009-04-11] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2006-11-02] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\Windows\System32\spoolsv.exe [128000 2010-08-17] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [155648 2008-01-19] (Microsoft Corporation) [File not signed]
R3 SstpSvc; C:\Windows\system32\sstpsvc.dll [116736 2008-01-19] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\Windows\System32\wiaservc.dll [453120 2009-04-11] (Microsoft Corporation) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [311808 2009-04-11] (Microsoft Corporation) [File not signed]
R2 SysMain; C:\Windows\system32\sysmain.dll [558080 2009-04-11] (Microsoft Corporation) [File not signed]
R2 TabletInputService; C:\Windows\System32\TabSvc.dll [68096 2006-11-02] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\Windows\System32\tapisrv.dll [242688 2009-04-11] (Microsoft Corporation) [File not signed]
S2 TBS; C:\Windows\System32\tbssvc.dll [56320 2008-01-19] (Microsoft Corporation) [File not signed]
R2 TermService; C:\Windows\System32\termsrv.dll [449024 2009-04-11] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation) [File not signed]
S3 THREADORDER; C:\Windows\system32\mmcss.dll [45056 2008-01-19] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\Windows\System32\trkwks.dll [75264 2008-01-19] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [39424 2009-04-11] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [35840 2008-01-19] (Microsoft Corporation) [File not signed]
R2 upnphost; C:\Windows\System32\upnphost.dll [259072 2008-01-19] (Microsoft Corporation) [File not signed]
R2 UxSms; C:\Windows\System32\uxsms.dll [29184 2009-04-11] (Microsoft Corporation) [File not signed]
S3 vds; C:\Windows\System32\vds.exe [385536 2009-04-11] (Microsoft Corporation) [File not signed]
S3 VSS; C:\Windows\system32\vssvc.exe [1055232 2009-04-11] (Microsoft Corporation) [File not signed]
R2 W32Time; C:\Windows\system32\w32time.dll [282624 2009-04-11] (Microsoft Corporation) [File not signed]
S3 wcncsvc; C:\Windows\System32\wcncsvc.dll [413696 2009-04-11] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [32256 2006-11-02] (Microsoft Corporation) [File not signed]
S3 WdiServiceHost; C:\Windows\system32\wdi.dll [73728 2008-01-19] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [73728 2008-01-19] (Microsoft Corporation) [File not signed]
R2 WebClient; C:\Windows\System32\webclnt.dll [199680 2009-04-11] (Microsoft Corporation) [File not signed]
S3 Wecsvc; C:\Windows\system32\wecsvc.dll [146944 2009-10-09] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\Windows\System32\wercplsupport.dll [62976 2008-01-19] (Microsoft Corporation) [File not signed]
R2 WerSvc; C:\Windows\System32\WerSvc.dll [126976 2009-04-11] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S3 WinHttpAutoProxySvc; C:\Windows\system32\winhttp.dll [377344 2011-11-16] (Microsoft Corporation) [File not signed]
R2 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [162304 2009-04-11] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\system32\WsmSvc.dll [1181696 2009-10-09] (Microsoft Corporation) [File not signed]
R2 Wlansvc; C:\Windows\System32\wlansvc.dll [513536 2009-07-11] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [137728 2009-04-11] (Microsoft Corporation) [File not signed]
S4 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [163840 2007-04-24] (acer) [File not signed]
R3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [896512 2008-01-19] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [140288 2009-04-11] (Microsoft Corporation) [File not signed]
R2 WPDBusEnum; C:\Windows\system32\wpdbusenum.dll [81920 2009-10-01] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\Windows\System32\wscsvc.dll [61440 2009-04-11] (Microsoft Corporation) [File not signed]
S2 WSearch; C:\Windows\system32\SearchIndexer.exe [441344 2009-04-11] (Microsoft Corporation) [File not signed]
R2 wudfsvc; C:\Windows\System32\WUDFSvc.dll [73216 2012-07-26] (Microsoft Corporation) [File not signed]
R2 XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [386560 2007-01-30] (Conexant Systems, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 AFD; C:\Windows\system32\drivers\afd.sys [273408 2014-05-30] (Microsoft Corporation) [File not signed]
S4 AmdK7; C:\Windows\system32\drivers\amdk7.sys [38912 2006-11-02] (Microsoft Corporation) [File not signed]
S4 AmdK8; C:\Windows\system32\drivers\amdk8.sys [40960 2006-11-02] (Microsoft Corporation) [File not signed]
R3 ApfiltrService; C:\Windows\System32\DRIVERS\Apfiltr.sys [140800 2006-12-05] (Alps Electric Co., Ltd.) [File not signed]
R3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [17408 2008-01-19] (Microsoft Corporation) [File not signed]
S3 b57nd60x; C:\Windows\System32\DRIVERS\b57nd60x.sys [179712 2007-02-08] (Broadcom Corporation) [File not signed]
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl6.sys [538112 2007-01-10] (Broadcom Corporation) [File not signed]
R1 Beep; C:\Windows\system32\Drivers\Beep.sys [6144 2008-01-19] (Microsoft Corporation) [File not signed]
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [69632 2011-02-22] (Microsoft Corporation) [File not signed]
S3 BrFiltLo; C:\Windows\system32\drivers\brfiltlo.sys [13568 2006-11-02] (Brother Industries, Ltd.) [File not signed]
S3 BrFiltUp; C:\Windows\system32\drivers\brfiltup.sys [5248 2006-11-02] (Brother Industries, Ltd.) [File not signed]
S4 Brserid; C:\Windows\system32\drivers\brserid.sys [71808 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BrSerWdm; C:\Windows\system32\drivers\brserwdm.sys [62336 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BrUsbMdm; C:\Windows\system32\drivers\brusbmdm.sys [12160 2006-11-02] (Brother Industries Ltd.) [File not signed]
S3 BrUsbSer; C:\Windows\system32\drivers\brusbser.sys [11904 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BTHMODEM; C:\Windows\system32\drivers\bthmodem.sys [39936 2006-11-02] (Microsoft Corporation) [File not signed]
R4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [70144 2008-01-19] (Microsoft Corporation) [File not signed]
R1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [67072 2009-04-11] (Microsoft Corporation) [File not signed]
S4 circlass; C:\Windows\system32\drivers\circlass.sys [35328 2006-11-02] (Microsoft Corporation) [File not signed]
R3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [14208 2008-01-19] (Microsoft Corporation) [File not signed]
S4 Crusoe; C:\Windows\system32\drivers\crusoe.sys [38912 2006-11-02] (Microsoft Corporation) [File not signed]
R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [75264 2011-04-14] (Microsoft Corporation) [File not signed]
S3 Dot4; C:\Windows\System32\DRIVERS\Dot4.sys [131584 2008-01-19] (Microsoft Corporation) [File not signed]
S3 Dot4Print; C:\Windows\System32\DRIVERS\Dot4Prt.sys [16384 2008-01-19] (Microsoft Corporation) [File not signed]
S3 dot4usb; C:\Windows\System32\DRIVERS\dot4usb.sys [36864 2008-01-19] (Microsoft Corporation) [File not signed]
R1 DritekPortIO; C:\Program Files\Launch Manager\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
S3 drmkaud; C:\Windows\System32\drivers\drmkaud.sys [5632 2008-01-19] (Microsoft Corporation) [File not signed]
S3 E1G60; C:\Windows\System32\DRIVERS\E1G60I32.sys [117760 2006-11-02] (Intel Corporation) [File not signed]
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170656 2012-10-08] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [121216 2012-10-08] (ESET)
R3 EMSCR; C:\Windows\System32\DRIVERS\EMS7SK.sys [67584 2007-04-11] (ENE Technology Inc.) [File not signed]
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [104712 2012-10-08] (ESET)
R3 ESDCR; C:\Windows\System32\DRIVERS\ESD7SK.sys [46592 2007-04-11] (ENE Technology Inc.) [File not signed]
R3 ESMCR; C:\Windows\System32\DRIVERS\ESM7SK.sys [63488 2007-04-11] (ENE Technology Inc.) [File not signed]
R2 Ethpdrv; C:\Windows\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.) [File not signed]
S3 exfat; C:\Windows\system32\Drivers\exfat.sys [136704 2009-04-11] (Microsoft Corporation) [File not signed]
S3 fastfat; C:\Windows\system32\Drivers\fastfat.sys [143360 2014-09-05] (Microsoft Corporation) [File not signed]
S4 fdc; C:\Windows\System32\DRIVERS\fdc.sys [25088 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [27648 2008-01-19] (Microsoft Corporation) [File not signed]
S4 flpydisk; C:\Windows\System32\DRIVERS\flpydisk.sys [20480 2006-11-02] (Microsoft Corporation) [File not signed]
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
U1 Fs_Rec; C:\Windows\system32\Drivers\Fs_Rec.sys [12800 2012-02-29] (Microsoft Corporation) [File not signed]
S3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [235520 2006-11-02] (Microsoft Corporation) [File not signed]
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [561152 2009-04-11] (Microsoft Corporation) [File not signed]
S4 HidBth; C:\Windows\system32\drivers\hidbth.sys [29184 2006-11-02] (Microsoft Corporation) [File not signed]
S4 HidIr; C:\Windows\system32\drivers\hidir.sys [21504 2006-11-02] (Microsoft Corporation) [File not signed]
R3 HidUsb; C:\Windows\System32\DRIVERS\hidusb.sys [12800 2009-04-11] (Microsoft Corporation) [File not signed]
S3 HSFHWAZL; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [200704 2006-11-02] (Conexant Systems, Inc.) [File not signed]
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [984064 2007-03-01] (Conexant Systems, Inc.) [File not signed]
R3 HSXHWAZL; C:\Windows\System32\DRIVERS\HSXHWAZL.sys [208384 2007-03-01] (Conexant Systems, Inc.) [File not signed]
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [411648 2010-02-20] (Microsoft Corporation) [File not signed]
R1 i8042prt; C:\Windows\System32\DRIVERS\i8042prt.sys [54784 2008-01-19] (Microsoft Corporation) [File not signed]
S3 ialm; C:\Windows\System32\DRIVERS\igdkmd32.sys [1771008 2007-05-22] (Intel Corporation) [File not signed]
R3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [1771008 2007-05-22] (Intel Corporation) [File not signed]
R2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [76584 2006-12-07] ()
R3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [41472 2008-01-19] (Microsoft Corporation) [File not signed]
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [47616 2008-01-19] (Microsoft Corporation) [File not signed]
S4 IPMIDRV; C:\Windows\system32\drivers\ipmidrv.sys [65536 2006-11-02] (Microsoft Corporation) [File not signed]
S3 IPNAT; C:\Windows\System32\DRIVERS\ipnat.sys [100864 2008-01-19] (Microsoft Corporation) [File not signed]
S3 IpwP; C:\Windows\System32\DRIVERS\ipw3gnet.sys [51040 2007-06-12] (IPWireless Inc.) [File not signed]
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [13312 2008-01-19] (Microsoft Corporation) [File not signed]
S3 k510bus; C:\Windows\System32\DRIVERS\k510bus.sys [58288 2006-02-17] (MCCI) [File not signed]
S1 kbdhid; C:\Windows\System32\DRIVERS\kbdhid.sys [17408 2009-04-11] (Microsoft Corporation) [File not signed]
R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [47104 2008-01-19] (Microsoft Corporation) [File not signed]
R2 luafv; C:\Windows\system32\drivers\luafv.sys [84480 2008-01-19] (Microsoft Corporation) [File not signed]
R2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2006-06-19] (Conexant) [File not signed]
R3 Modem; C:\Windows\System32\drivers\modem.sys [31744 2008-01-19] (Microsoft Corporation) [File not signed]
R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [41984 2008-01-19] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [15872 2008-01-19] (Microsoft Corporation) [File not signed]
R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [64000 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [114688 2009-04-11] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [106496 2011-04-29] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [214016 2011-07-06] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [79872 2011-04-29] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [8192 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [5888 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [5504 2008-01-19] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [6016 2008-01-19] (Microsoft Corporation) [File not signed]
R3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [148480 2009-04-11] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [20992 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [16896 2008-01-19] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [121344 2009-04-11] (Microsoft Corporation) [File not signed]
R3 NDProxy; C:\Windows\system32\Drivers\NDProxy.sys [49664 2008-01-19] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [35840 2008-01-19] (Microsoft Corporation) [File not signed]
R1 netbt; C:\Windows\System32\DRIVERS\netbt.sys [185856 2009-04-11] (Microsoft Corporation) [File not signed]
S3 NETw4v32; C:\Windows\System32\DRIVERS\NETw4v32.sys [2216448 2007-02-25] (Intel Corporation) [File not signed]
S3 nmwcd; C:\Windows\System32\drivers\ccdcmb.sys [17664 2009-02-09] (Nokia) [File not signed]
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbo.sys [22016 2009-02-09] (Nokia) [File not signed]
S3 nmwcdnsu; C:\Windows\System32\drivers\nmwcdnsu.sys [136704 2009-03-19] (Nokia) [File not signed]
S3 nmwcdnsuc; C:\Windows\System32\drivers\nmwcdnsuc.sys [8320 2009-03-19] (Nokia) [File not signed]
R1 Npfs; C:\Windows\system32\Drivers\Npfs.sys [35328 2009-04-11] (Microsoft Corporation) [File not signed]
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [16384 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 NTIDrvr; C:\Windows\System32\DRIVERS\NTIDrvr.sys [6144 2007-06-20] (NewTech Infosystems, Inc.) [File not signed]
S4 ntrigdigi; C:\Windows\system32\drivers\ntrigdigi.sys [20608 2006-11-02] (N-trig Innovative Technologies) [File not signed]
R1 Null; C:\Windows\system32\Drivers\Null.sys [4608 2008-01-19] (Microsoft Corporation) [File not signed]
S4 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [62080 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Parport; C:\Windows\system32\drivers\parport.sys [79360 2006-11-02] (Microsoft Corporation) [File not signed]
S2 Parvdm; C:\Windows\system32\drivers\parvdm.sys [8704 2006-11-02] (Microsoft Corporation) [File not signed]
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [878080 2006-11-02] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [62976 2008-01-19] (Microsoft Corporation) [File not signed]
S4 Processor; C:\Windows\system32\drivers\processr.sys [38400 2006-11-02] (Microsoft Corporation) [File not signed]
R1 PSched; C:\Windows\System32\DRIVERS\pacer.sys [72192 2009-04-11] (Microsoft Corporation) [File not signed]
R0 PSDFilter; C:\Windows\System32\DRIVERS\psdfilter.sys [20264 2007-04-12] (HiTRUST)
R0 PSDNServ; C:\Windows\System32\drivers\PSDNServ.sys [16680 2007-04-12] (HiTRUST)
R0 psdvdisk; C:\Windows\System32\drivers\psdvdisk.sys [60712 2007-04-12] (HiTRUST)
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [31232 2008-01-19] (Microsoft Corporation) [File not signed]
R1 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [11776 2008-01-19] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [76288 2008-01-19] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [41472 2009-04-11] (Microsoft Corporation) [File not signed]
R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [69120 2009-04-11] (Microsoft Corporation) [File not signed]
R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [225280 2009-04-11] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [6144 2008-01-19] (Microsoft Corporation) [File not signed]
S4 rdpdr; C:\Windows\system32\drivers\rdpdr.sys [242688 2006-11-02] (Microsoft Corporation) [File not signed]
R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [6144 2008-01-19] (Microsoft Corporation) [File not signed]
R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [60416 2008-01-19] (Microsoft Corporation) [File not signed]
R3 sdbus; C:\Windows\System32\DRIVERS\sdbus.sys [89088 2009-04-11] (Microsoft Corporation) [File not signed]
R2 secdrv; C:\Windows\system32\Drivers\secdrv.sys [20480 2006-11-02] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 Serenum; C:\Windows\system32\drivers\serenum.sys [17920 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Serial; C:\Windows\system32\drivers\serial.sys [83456 2006-11-02] (Microsoft Corporation) [File not signed]
S4 sermouse; C:\Windows\system32\drivers\sermouse.sys [19968 2008-01-19] (Microsoft Corporation) [File not signed]
S3 sffdisk; C:\Windows\System32\DRIVERS\sffdisk.sys [13312 2008-01-19] (Microsoft Corporation) [File not signed]
S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [12800 2006-11-02] (Microsoft Corporation) [File not signed]
S3 sffp_sd; C:\Windows\System32\DRIVERS\sffp_sd.sys [11776 2009-04-11] (Microsoft Corporation) [File not signed]
S4 sfloppy; C:\Windows\system32\drivers\sfloppy.sys [13312 2006-11-02] (Microsoft Corporation) [File not signed]
R1 Smb; C:\Windows\System32\DRIVERS\smb.sys [66560 2009-04-11] (Microsoft Corporation) [File not signed]
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [305152 2011-02-18] (Microsoft Corporation) [File not signed]
R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [146432 2011-04-29] (Microsoft Corporation) [File not signed]
R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [102400 2011-04-29] (Microsoft Corporation) [File not signed]
R3 StillCam; C:\Windows\System32\DRIVERS\serscan.sys [9216 2008-01-19] (Microsoft Corporation) [File not signed]
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [30720 2009-12-08] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [17920 2008-01-19] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [29184 2008-01-19] (Microsoft Corporation) [File not signed]
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [72192 2009-04-11] (Microsoft Corporation) [File not signed]
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [24064 2013-06-15] (Microsoft Corporation) [File not signed]
R3 tunmp; C:\Windows\System32\DRIVERS\tunmp.sys [15360 2008-01-19] (Microsoft Corporation) [File not signed]
R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [25088 2010-02-18] (Microsoft Corporation) [File not signed]
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [226816 2009-04-11] (Microsoft Corporation) [File not signed]
R3 umbus; C:\Windows\System32\DRIVERS\umbus.sys [34816 2008-01-19] (Microsoft Corporation) [File not signed]
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerflt.sys [7808 2009-02-09] (Nokia) [File not signed]
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.) [File not signed]
S3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [73216 2013-06-29] (Microsoft Corporation) [File not signed]
S4 usbcir; C:\Windows\system32\drivers\usbcir.sys [68608 2006-11-02] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [39936 2011-05-05] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [197632 2013-06-29] (Microsoft Corporation) [File not signed]
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.) [File not signed]
S4 usbohci; C:\Windows\system32\drivers\usbohci.sys [19456 2006-11-02] (Microsoft Corporation) [File not signed]
S3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [18944 2008-01-19] (Microsoft Corporation) [File not signed]
S3 usbscan; C:\Windows\System32\DRIVERS\usbscan.sys [35328 2013-07-03] (Microsoft Corporation) [File not signed]
S3 usbser; C:\Windows\System32\drivers\usbser.sys [27648 2013-08-29] (Microsoft Corporation) [File not signed]
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltj.sys [7808 2009-02-09] (Nokia) [File not signed]
S3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [65536 2009-04-11] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [23552 2011-05-05] (Microsoft Corporation) [File not signed]
S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [26112 2006-11-02] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\Windows\System32\drivers\vga.sys [25088 2008-01-19] (Microsoft Corporation) [File not signed]
S4 ViaC7; C:\Windows\system32\drivers\viac7.sys [39424 2006-11-02] (Microsoft Corporation) [File not signed]
S4 WacomPen; C:\Windows\system32\drivers\wacompen.sys [20608 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Wanarp; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-19] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-19] (Microsoft Corporation) [File not signed]
R3 winachsf; C:\Windows\System32\DRIVERS\HSX_CNXT.sys [660480 2007-03-01] (Conexant Systems, Inc.) [File not signed]
R3 WmiAcpi; C:\Windows\System32\DRIVERS\wmiacpi.sys [11264 2008-01-19] (Microsoft Corporation) [File not signed]
S3 WpdUsb; C:\Windows\System32\DRIVERS\wpdusb.sys [40448 2009-10-01] (Microsoft Corporation) [File not signed]
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [15872 2008-01-19] (Microsoft Corporation) [File not signed]
R3 WSDPrintDevice; C:\Windows\System32\DRIVERS\WSDPrint.sys [16896 2008-01-19] (Microsoft Corporation) [File not signed]
R3 WSDScan; C:\Windows\System32\DRIVERS\WSDScan.sys [19968 2009-04-11] (Microsoft Corporation) [File not signed]
R3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [66560 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation) [File not signed]
R2 XAudio; C:\Windows\System32\DRIVERS\xaudio.sys [8704 2007-01-30] (Conexant Systems, Inc.) [File not signed]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [13560 2006-11-02] (Cyberlink Corp.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 ipw_bus; system32\DRIVERS\ipw_bus.sys [X]
S3 ipw_mdfl; system32\DRIVERS\ipw_mdfl.sys [X]
S3 ipw_mdm; system32\DRIVERS\ipw_mdm.sys [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 15:09 - 2015-02-23 15:12 - 00047453 _____ () C:\Users\Jana\Desktop\FRST.txt
2015-02-23 15:07 - 2015-02-23 15:10 - 00000000 ____D () C:\FRST
2015-02-23 15:03 - 2015-02-23 15:03 - 01126912 _____ (Farbar) C:\Users\Jana\Desktop\FRST.exe
2015-02-23 14:10 - 2015-02-23 14:10 - 00105048 _____ () C:\Users\JanaD\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-23 14:09 - 2015-02-23 14:09 - 00000953 _____ () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-23 14:09 - 2015-02-23 14:09 - 00000948 _____ () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-02-23 14:09 - 2015-02-23 14:09 - 00000000 ____D () C:\Users\JanaD\AppData\Local\Google
2015-02-23 14:06 - 2015-02-23 14:11 - 00000000 ____D () C:\Users\JanaD\AppData\Local\VirtualStore
2015-02-23 14:06 - 2015-02-23 14:09 - 00000000 ____D () C:\Users\JanaD
2015-02-23 14:06 - 2015-02-23 14:06 - 00000919 _____ () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-02-23 14:06 - 2015-02-23 14:06 - 00000020 ___SH () C:\Users\JanaD\ntuser.ini
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Šablony
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Soubory cookie
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Okolní tiskárny
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Okolní síť
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Nabídka Start
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Dokumenty
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Documents\Obrázky
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Documents\Hudba
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Documents\Filmy
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\Data aplikací
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\AppData\Local\Historie
2015-02-23 14:06 - 2015-02-23 14:06 - 00000000 _SHDL () C:\Users\JanaD\AppData\Local\Data aplikací
2015-02-23 14:06 - 2009-03-03 03:44 - 00000000 ___RD () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-02-23 14:06 - 2009-03-03 03:44 - 00000000 ___RD () C:\Users\JanaD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-23 14:06 - 2007-09-16 08:44 - 00000000 ____D () C:\Users\JanaD\AppData\Local\Microsoft Help
2015-02-23 13:29 - 2015-02-23 13:29 - 00000007 _____ () C:\ISACER.id
2015-02-19 09:24 - 2015-02-19 09:24 - 00000371 _____ () C:\Users\Jana\Obrázky – zástupce.lnk
2015-02-11 16:10 - 2015-02-11 16:10 - 00001114 _____ () C:\Users\Jana\Desktop\Ashampoo Burning Studio 6 FREE.lnk
2015-02-11 16:10 - 2015-02-11 16:10 - 00000214 _____ () C:\Users\Public\Desktop\Your Software Deals.url
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Users\Jana\AppData\Local\ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\ProgramData\Ashampoo
2015-02-11 16:10 - 2015-02-11 16:10 - 00000000 ____D () C:\Program Files\Ashampoo
2015-02-11 08:13 - 2015-02-11 08:13 - 00000536 _____ () C:\Windows\PFRO.log
2015-02-09 14:29 - 2015-02-09 14:29 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chatango
2015-02-09 14:29 - 2015-02-09 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chatango
2015-02-09 14:29 - 2015-02-09 14:29 - 00000000 ____D () C:\Program Files\Chatango
2015-02-09 12:20 - 2015-02-09 12:20 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Software602
2015-02-09 12:13 - 2015-02-09 12:13 - 00000000 ____D () C:\Program Files\Software602
2015-02-05 11:33 - 2015-02-05 11:33 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\PeerNetworking
2015-02-05 09:09 - 2015-02-05 09:09 - 00000916 _____ () C:\Users\Jana\Desktop\ProFact 4.0 Manuál.lnk
2015-02-05 09:09 - 2015-02-05 09:09 - 00000841 _____ () C:\Users\Jana\Desktop\Vzdálená podpora ProFact.lnk
2015-02-05 09:09 - 2015-02-05 09:09 - 00000824 _____ () C:\Users\Jana\Desktop\ProFact 4.0.lnk
2015-02-05 09:09 - 2015-02-05 09:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProFact 4.0
2015-02-05 09:08 - 2015-02-05 09:09 - 00000000 ____D () C:\Program Files\ProFact 4.0
2015-02-05 09:08 - 2015-02-05 09:08 - 00000000 ____D () C:\ProgramData\eXmind
2015-02-03 13:20 - 2015-02-03 13:21 - 00000174 _____ () C:\PowerDV.log
2015-02-03 13:19 - 2015-02-03 13:20 - 00000091 _____ () C:\MDR.log
2015-02-03 13:18 - 2015-02-03 13:19 - 00000091 _____ () C:\MDisc.log
2015-02-03 12:08 - 2015-02-03 12:09 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-03 12:02 - 2015-02-03 12:03 - 11743631 _____ () C:\Users\Guest\Downloads\cc-setup (1).exe
2015-02-03 11:59 - 2015-02-03 11:59 - 03334144 _____ () C:\Users\Guest\Downloads\cc-setup.exe
2015-02-02 14:18 - 2015-02-02 14:18 - 00000000 ____D () C:\Windows\Hewlett-Packard
2015-02-02 14:06 - 2015-02-02 14:06 - 00001792 _____ () C:\Users\Public\Desktop\HP Photo Creations.lnk
2015-02-02 14:06 - 2015-02-02 14:06 - 00000000 ____D () C:\ProgramData\Visan
2015-02-02 14:06 - 2015-02-02 14:06 - 00000000 ____D () C:\ProgramData\HP Photo Creations
2015-02-02 14:06 - 2015-02-02 14:06 - 00000000 ____D () C:\Program Files\HP Photo Creations
2015-02-02 14:04 - 2015-02-09 08:30 - 00002119 _____ () C:\Users\Public\Desktop\HP Deskjet 5520 series.lnk
2015-02-02 14:04 - 2015-02-02 14:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-02-02 14:04 - 2015-02-02 14:04 - 00001066 _____ () C:\Users\Public\Desktop\Zakoupit spotřební materiál - HP Deskjet 5520 series.lnk
2015-02-02 14:04 - 2012-10-17 04:04 - 00580712 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPMB611.dll
2015-02-02 14:01 - 2015-02-02 14:01 - 00000057 _____ () C:\ProgramData\Ament.ini
2015-02-02 14:00 - 2015-02-02 16:29 - 00000000 ____D () C:\Users\Jana\AppData\Local\HP
2015-02-02 11:52 - 2015-02-23 21:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-02 11:52 - 2015-02-06 09:19 - 00001975 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-02 11:48 - 2015-02-02 11:53 - 00000000 ____D () C:\Program Files\Google
2015-02-02 11:46 - 2015-02-11 16:35 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-02-02 11:46 - 2015-02-02 11:46 - 00001896 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2015-02-02 11:45 - 2015-02-02 11:46 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-02-02 09:11 - 2015-02-02 09:11 - 00000000 ____D () C:\Users\Jana\AppData\Local\Skype
2015-02-02 09:10 - 2015-02-02 09:10 - 00000000 ___RD () C:\Program Files\Skype
2015-02-02 09:10 - 2015-02-02 09:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-02-02 09:10 - 2015-02-02 09:10 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-01-31 19:07 - 2015-01-31 19:07 - 00000000 ____D () C:\Windows\WindowsMobile
2015-01-31 18:58 - 2015-01-31 18:58 - 00000000 ____D () C:\Windows\PLA
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-23 21:41 - 2009-07-20 15:34 - 00000000 ____D () C:\Users\Guest
2015-02-23 21:41 - 2008-07-30 11:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OLYMPUS Master 2
2015-02-23 21:41 - 2007-09-15 15:22 - 00000000 ____D () C:\Users\Jana
2015-02-23 21:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool
2015-02-23 21:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-02-23 21:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration
2015-02-23 21:41 - 2006-11-02 11:22 - 51593216 _____ () C:\Windows\system32\config\software_previous
2015-02-23 21:41 - 2006-11-02 11:22 - 253493248 _____ () C:\Windows\system32\config\system_previous
2015-02-23 21:37 - 2006-11-02 11:22 - 42991616 _____ () C:\Windows\system32\config\components_previous
2015-02-23 21:37 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2015-02-23 15:11 - 2010-09-29 16:15 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-23 15:03 - 2006-11-02 13:47 - 00003168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-23 15:03 - 2006-11-02 13:47 - 00003168 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-23 14:46 - 2007-09-15 21:04 - 01710842 _____ () C:\Windows\WindowsUpdate.log
2015-02-23 14:45 - 2010-09-29 16:15 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-23 14:39 - 2012-04-10 10:50 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-23 14:00 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-23 13:58 - 2006-11-02 14:01 - 00032610 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-23 12:50 - 2009-10-29 08:16 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\HpUpdate
2015-02-23 12:33 - 2006-11-02 11:22 - 01118208 _____ () C:\Windows\system32\config\default_previous
2015-02-23 12:32 - 2008-11-19 12:20 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Skype
2015-02-22 08:39 - 2006-11-02 11:22 - 00028672 _____ () C:\Windows\system32\config\security_previous
2015-02-16 13:51 - 2009-03-05 09:33 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2015-02-11 08:17 - 2007-09-15 15:25 - 00105048 _____ () C:\Users\Jana\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-11 08:13 - 2006-11-02 13:47 - 00388936 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-09 13:27 - 2008-11-05 10:14 - 00000000 ____D () C:\Program Files\Common Files\soft602
2015-02-09 13:11 - 2007-06-20 11:05 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-02-09 13:11 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-02-09 12:27 - 2011-03-14 11:42 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\602XML
2015-02-09 12:26 - 2007-06-20 10:08 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-05 13:00 - 2012-04-10 10:50 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-05 13:00 - 2012-04-10 10:50 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-05 09:08 - 2010-02-18 10:05 - 00000000 ____D () C:\Users\Jana\AppData\Local\eXmind
2015-02-04 16:59 - 2007-09-15 17:42 - 00000000 ____D () C:\Users\Jana\AppData\Roaming\Adobe
2015-02-04 13:38 - 2007-06-20 18:52 - 00000000 ___DC () C:\Acer
2015-02-04 13:34 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public
2015-02-03 13:48 - 2008-07-30 11:27 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-02-03 13:22 - 2007-06-20 09:54 - 00000000 ____D () C:\Program Files\Acer Arcade Deluxe
2015-02-03 13:13 - 2007-06-20 09:54 - 00000000 ____D () C:\Program Files\Acer Inc
2015-02-03 13:13 - 2007-06-20 09:49 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-02-03 11:54 - 2010-07-02 14:21 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2015-02-02 14:05 - 2007-09-17 08:44 - 00000000 ____D () C:\Program Files\HP
2015-02-02 14:01 - 2007-09-17 08:40 - 00000000 ____D () C:\ProgramData\HP
2015-02-02 14:01 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32
2015-02-02 13:36 - 2007-09-17 08:41 - 00050361 _____ () C:\ProgramData\hpzinstall.log
2015-02-02 11:57 - 2007-09-15 17:42 - 00000000 ____D () C:\Users\Jana\AppData\Local\Adobe
2015-02-02 11:53 - 2007-09-21 07:00 - 00000000 ____D () C:\Users\Jana\AppData\Local\Google
2015-02-02 11:45 - 2007-06-20 10:06 - 00000000 ____D () C:\Program Files\Adobe
2015-02-02 09:11 - 2008-11-19 12:19 - 00000000 ____D () C:\ProgramData\Skype
2015-01-31 19:04 - 2006-11-02 13:37 - 00000000 ____D () C:\Program Files\Movie Maker
2015-01-31 18:58 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\DigitalLocker
==================== Files in the root of some directories =======
2010-11-08 15:17 - 2010-11-08 15:17 - 0000600 _____ () C:\Users\Jana\AppData\Roaming\winscp.rnd
2008-07-22 05:44 - 2011-10-17 11:10 - 0005000 _____ () C:\Users\Jana\AppData\Local\d3d9caps.dat
2007-09-15 18:30 - 2012-12-18 10:19 - 0117248 _____ () C:\Users\Jana\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-03-12 13:12 - 2009-03-12 13:12 - 0000092 _____ () C:\Users\Jana\AppData\Local\fusioncache.dat
2012-12-27 17:17 - 2013-01-20 10:05 - 1434678 ____T () C:\ProgramData\0tbpw.pad
2015-02-02 14:01 - 2015-02-02 14:01 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-11-27 16:23 - 2012-11-27 16:24 - 0811895 ____T () C:\ProgramData\dsgsdgdsgdsgw.pad
2010-12-26 08:31 - 2010-12-26 08:31 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-09-17 08:41 - 2015-02-02 13:36 - 0050361 _____ () C:\ProgramData\hpzinstall.log
2012-11-27 16:23 - 2012-11-27 16:23 - 0044544 _____ (Microsoft Corporation) C:\ProgramData\lsass.exe
2007-09-25 10:07 - 2007-09-25 10:07 - 0000013 ____H () C:\ProgramData\ÄĐ3113.sys
Files to move or delete:
====================
C:\ProgramData\0tbpw.pad
C:\ProgramData\dsgsdgdsgdsgw.pad
C:\ProgramData\lsass.exe
Some content of TEMP:
====================
C:\Users\Guest\AppData\Local\Temp\jre-1.6.0_20-windows-i586-iftw.exe_90744722.exe
C:\Users\Guest\AppData\Local\Temp\jre-6u20-windows-i586-jinstall_uac.exe
C:\Users\Guest\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\Guest\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Jana\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\JanaD\AppData\Local\Temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-23 14:07
==================== End Of Log ============================