Stránka 1 z 3

Počítač si dělá co chce( sám píše ), záseky

Napsal: 16 dub 2015 16:40
od Tulipan
Dobrý den,
poslední týden mám problém s počítačem. Sám mi začal psát věci, které rozhodně nechci aby psal. Například včera při debatě s jedním učitelem přes facebook sám napsal "BLOWJOB" do chatu a co je horší tak sám to i odeslal. Tohle se děje bez jakéhokoliv varování a uplně nezávysle na to co zrovna dělám. Nebo například hraji WoWko a zničeho nic se mi sám otevře chat napíše se "MUST BLOWJOB" a samo se to odešle. To samé na skypu, také když si sněkým píšu tak najednou sám začne psát "BEST PORN EU " atd. Vtipné na tomhle je to, že je to zrovna počítač na kterém se nikdy "Porno" nehledalo a slouží jen pro hraní ( K pornu mám starší notebook, kterej je už na odpis :D ).
Poté co jsem tyto problémy zaznamenal, jsem reinstalloval windowsi, kde proběhlo kompletní přehrání všeho a formátování HDD. Bohužel i přes to se dnes zase tento problém objevil a to když jsem si dohadoval s jednou dívčinou sraz a najednou se mi počítač sám rozhodl do chatu sní napsat "MUST BLOWJOB" a sám to potvrdil entrem a odeslal.

Děkuji za pomoc.

Logfile of random's system information tool 1.10 (written by random/random)
Run by HP at 2015-04-16 17:30:41
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 766 GB (91%) free of 841 GB
Total RAM: 4076 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:30:54, on 16.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\AVAST Software\Avast\avastUi.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Program Files\trend micro\HP.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
O4 - HKLM\..\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [20150107] C:\Program Files\AVAST Software\Avast\setup\emupdate\6504d047-73cd-4956-b6f3-ec6f06ff7eb8.exe /check
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (file missing)
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10652 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe"
WLIDSvcM.exe 2944
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 72843256-e42c-4285-bc60-7b4f679581ea 1
\??\C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f8f8c4dc-d9ce-4ead-a200-da82a5dd5fdb -SystemEventPortName:HostProcess-8f1b2fa8-4275-4220-90f9-b763eab8be9e -IoCancelEventPortName:HostProcess-55135c60-5ce5-4849-8812-e568c90f9845 -NonStateChangingEventPortName:HostProcess-20fca6b5-551d-453a-96b5-5669da86585a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2e13342c-5f6a-4ca5-8caa-d748659733ed
"C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
"taskhost.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe" /c /a /s UserSession
taskeng.exe {0E0E0197-EF94-4510-8A56-C0FF5A5434C4}
"C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe"
"C:\Program Files\IDT\WDM\beats64.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\AVAST Software\Avast\avastUi.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6572.1eac9450.15289636 "C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 6572 "\\.\pipe\gecko-crash-server-pipe.6572" plugin
"C:\Program Files (x86)\Origin\Origin.exe" "origin://LaunchGame/70619,71067,DGR01609244,DGR01609245?Title=Battlefield%u00203%u2122&ProductId=DR:225064100&CommandParams=-webMode%20MP%20-Origin_NoAppFocus%20-AuthCode%20QUORAPEDtmM-ERUUQCMZqKtePcL_4Z9nJrKI--Sv%20-requestState%20State_ClaimReservation%20-requestStateParams%20%22%3cdata%20logintoken%3d%5c%22lzP9aETcsieORoUBmL3CjNL5UKrOyEIcoLXv-FS0dT46f9EqRTXFDrHJYG4SRCcxyjpIxnZKOrXgUrthyEVyiUd8N2Kt8QEjE1Pmdh0OHgHGsWdBRliIssq_3rIzMDMhj3JLfBwGw5UwJCQfUtzdxXVcbBjuDA7SiYOMz8HVAA_uwg3VGEut4c0gh-Hzq91k%5c%22%20levelmode%3d%5c%22mp%5c%22%20personaref%3d%5c%22416085204%5c%22%20role%3d%5c%22soldier%5c%22%20gameid%3d%5c%227418515%5c%22%20putinsquad%3d%5c%22true%5c%22%3e%3c%2fdata%3e%22"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe36_ Global\UsGthrCtrlFltPipeMssGthrPipe36 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\HP\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8iznmrlj.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.6.2]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.6.2]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-16 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll [2011-04-29 436152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL [2011-03-31 210872]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-16 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll [2011-04-29 436152]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BeatsOSDApp"=C:\Program Files\IDT\WDM\beats64.exe [2010-10-21 37888]
"hpsysdrv"=c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [2008-11-20 62768]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-26 835072]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-03-28 2673296]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-03-28 1570672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-03-25 31682144]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BATINDICATOR"=C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe []
"LaunchHPOSIAPP"=C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe [2009-04-04 385024]
"Norton Online Backup"=C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2010-06-02 1155928]
"Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [2011-02-10 61112]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-04-16 5512912]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"20150107"=C:\Program Files\AVAST Software\Avast\setup\emupdate\6504d047-73cd-4956-b6f3-ec6f06ff7eb8.exe [2015-04-16 183232]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2011-08-16 52920]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-04-16 17:30:41 ----D---- C:\rsit
2015-04-16 17:30:41 ----D---- C:\Program Files\trend micro
2015-04-16 05:21:06 ----D---- C:\Users\HP\AppData\Roaming\AVAST Software
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswStm.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswSP.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2015-04-16 05:19:33 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2015-04-16 05:19:31 ----A---- C:\Windows\system32\aswBoot.exe
2015-04-16 05:19:29 ----A---- C:\Windows\avastSS.scr
2015-04-16 05:18:25 ----D---- C:\Program Files\AVAST Software
2015-04-16 05:14:32 ----D---- C:\ProgramData\AVAST Software
2015-04-16 00:59:31 ----D---- C:\Windows\SoftwareDistribution
2015-04-16 00:57:17 ----AH---- C:\Windows\SYSWOW64\ezsidmv.dat
2015-04-16 00:51:06 ----SHD---- C:\System Volume Information
2015-04-16 00:51:06 ----ASH---- C:\pagefile.sys
2015-04-16 00:51:06 ----ASH---- C:\hiberfil.sys
2015-04-16 00:06:49 ----D---- C:\Users\HP\AppData\Roaming\vlc
2015-04-16 00:01:22 ----D---- C:\Program Files (x86)\VideoLAN
2015-04-15 20:44:48 ----D---- C:\ProgramData\Recovery
2015-04-15 18:41:57 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-15 18:41:56 ----D---- C:\Windows\system32\Macromed
2015-04-15 18:08:16 ----D---- C:\Users\HP\AppData\Roaming\WinRAR
2015-04-15 18:05:04 ----D---- C:\Program Files (x86)\WinRAR
2015-04-15 17:49:01 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-04-15 17:46:32 ----A---- C:\Windows\system32\nvhdap64.dll
2015-04-15 17:46:32 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2015-04-15 17:46:32 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-04-15 17:46:31 ----A---- C:\Windows\system32\nvdispgenco6435012.dll
2015-04-15 17:46:31 ----A---- C:\Windows\system32\nvdispco6435012.dll
2015-04-15 17:46:30 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-04-15 17:46:29 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvopencl.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvoglv64.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvinitx.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\NvIFR64.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\NvFBC64.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvcuvid.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvcuda.dll
2015-04-15 17:46:29 ----A---- C:\Windows\system32\nvcompiler.dll
2015-04-15 17:37:12 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-04-15 17:37:12 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-04-15 17:37:12 ----A---- C:\Windows\system32\nvspcap64.dll
2015-04-15 17:37:12 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-04-15 17:36:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2015-04-15 17:36:53 ----A---- C:\Windows\system32\nvaudcap64v.dll
2015-04-15 17:36:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2015-04-15 17:30:59 ----D---- C:\ProgramData\EA Core
2015-04-15 17:30:40 ----D---- C:\ProgramData\EA Logs
2015-04-15 17:29:13 ----D---- C:\Users\HP\AppData\Roaming\Macromedia
2015-04-15 17:24:45 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2015-04-15 17:21:49 ----SHD---- C:\Config.Msi
2015-04-15 17:21:13 ----D---- C:\Users\HP\AppData\Roaming\hpqLog
2015-04-15 17:14:28 ----D---- C:\Users\HP\AppData\Roaming\Mozilla
2015-04-15 17:14:21 ----D---- C:\ProgramData\Mozilla
2015-04-15 17:14:21 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-15 17:14:20 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-15 17:00:09 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2015-04-15 17:00:08 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2015-04-15 17:00:06 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2015-04-15 17:00:06 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2015-04-15 17:00:06 ----A---- C:\Windows\system32\XAudio2_7.dll
2015-04-15 17:00:06 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2015-04-15 17:00:05 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2015-04-15 17:00:05 ----A---- C:\Windows\system32\xactengine3_7.dll
2015-04-15 17:00:04 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2015-04-15 17:00:04 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2015-04-15 17:00:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2015-04-15 17:00:04 ----A---- C:\Windows\system32\d3dx11_43.dll
2015-04-15 17:00:04 ----A---- C:\Windows\system32\d3dcsx_43.dll
2015-04-15 17:00:04 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2015-04-15 17:00:03 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2015-04-15 17:00:03 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2015-04-15 17:00:03 ----A---- C:\Windows\system32\D3DX9_43.dll
2015-04-15 17:00:03 ----A---- C:\Windows\system32\d3dx10_43.dll
2015-04-15 17:00:01 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2015-04-15 17:00:01 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2015-04-15 17:00:01 ----A---- C:\Windows\system32\XAudio2_6.dll
2015-04-15 17:00:01 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2015-04-15 17:00:00 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2015-04-15 17:00:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2015-04-15 17:00:00 ----A---- C:\Windows\system32\xactengine3_6.dll
2015-04-15 17:00:00 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2015-04-15 16:59:59 ----A---- C:\Windows\system32\XAudio2_5.dll
2015-04-15 16:59:58 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2015-04-15 16:59:58 ----A---- C:\Windows\system32\xactengine3_5.dll
2015-04-15 16:59:57 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2015-04-15 16:59:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2015-04-15 16:59:57 ----A---- C:\Windows\system32\d3dcsx_42.dll
2015-04-15 16:59:57 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2015-04-15 16:59:56 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2015-04-15 16:59:56 ----A---- C:\Windows\system32\d3dx11_42.dll
2015-04-15 16:59:55 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2015-04-15 16:59:55 ----A---- C:\Windows\system32\D3DX9_42.dll
2015-04-15 16:59:55 ----A---- C:\Windows\system32\d3dx10_41.dll
2015-04-15 16:59:55 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2015-04-15 16:59:54 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2015-04-15 16:59:54 ----A---- C:\Windows\system32\D3DX9_41.dll
2015-04-15 16:59:53 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2015-04-15 16:59:53 ----A---- C:\Windows\system32\XAudio2_4.dll
2015-04-15 16:59:53 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2015-04-15 16:59:52 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2015-04-15 16:59:52 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2015-04-15 16:59:52 ----A---- C:\Windows\system32\xactengine3_4.dll
2015-04-15 16:59:52 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2015-04-15 16:59:51 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2015-04-15 16:59:51 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2015-04-15 16:59:51 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2015-04-15 16:59:51 ----A---- C:\Windows\system32\D3DX9_40.dll
2015-04-15 16:59:51 ----A---- C:\Windows\system32\d3dx10_40.dll
2015-04-15 16:59:51 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2015-04-15 16:59:50 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2015-04-15 16:59:50 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2015-04-15 16:59:50 ----A---- C:\Windows\system32\XAudio2_3.dll
2015-04-15 16:59:50 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2015-04-15 16:59:49 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2015-04-15 16:59:49 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2015-04-15 16:59:49 ----A---- C:\Windows\system32\xactengine3_3.dll
2015-04-15 16:59:49 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2015-04-15 16:59:47 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2015-04-15 16:59:47 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2015-04-15 16:59:47 ----A---- C:\Windows\system32\XAudio2_2.dll
2015-04-15 16:59:47 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2015-04-15 16:59:46 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2015-04-15 16:59:46 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2015-04-15 16:59:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2015-04-15 16:59:46 ----A---- C:\Windows\system32\xactengine3_2.dll
2015-04-15 16:59:46 ----A---- C:\Windows\system32\d3dx10_39.dll
2015-04-15 16:59:46 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2015-04-15 16:59:45 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2015-04-15 16:59:45 ----A---- C:\Windows\system32\D3DX9_39.dll
2015-04-15 16:59:44 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2015-04-15 16:59:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2015-04-15 16:59:44 ----A---- C:\Windows\system32\XAudio2_1.dll
2015-04-15 16:59:44 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2015-04-15 16:59:43 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2015-04-15 16:59:43 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2015-04-15 16:59:43 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2015-04-15 16:59:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2015-04-15 16:59:43 ----A---- C:\Windows\system32\xactengine3_1.dll
2015-04-15 16:59:43 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2015-04-15 16:59:43 ----A---- C:\Windows\system32\d3dx10_38.dll
2015-04-15 16:59:43 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2015-04-15 16:59:42 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2015-04-15 16:59:42 ----A---- C:\Windows\system32\D3DX9_38.dll
2015-04-15 16:59:41 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2015-04-15 16:59:41 ----A---- C:\Windows\system32\XAudio2_0.dll
2015-04-15 16:59:40 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2015-04-15 16:59:40 ----A---- C:\Windows\system32\xactengine3_0.dll
2015-04-15 16:59:39 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2015-04-15 16:59:39 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2015-04-15 16:59:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2015-04-15 16:59:39 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2015-04-15 16:59:39 ----A---- C:\Windows\system32\d3dx10_37.dll
2015-04-15 16:59:39 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2015-04-15 16:59:38 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2015-04-15 16:59:38 ----A---- C:\Windows\system32\D3DX9_37.dll
2015-04-15 16:59:37 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2015-04-15 16:59:37 ----A---- C:\Windows\system32\xactengine2_10.dll
2015-04-15 16:59:36 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2015-04-15 16:59:36 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2015-04-15 16:59:36 ----A---- C:\Windows\system32\d3dx10_36.dll
2015-04-15 16:59:36 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2015-04-15 16:59:35 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2015-04-15 16:59:35 ----A---- C:\Windows\system32\d3dx9_36.dll
2015-04-15 16:59:34 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2015-04-15 16:59:34 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2015-04-15 16:59:34 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2015-04-15 16:59:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2015-04-15 16:59:34 ----A---- C:\Windows\system32\xactengine2_9.dll
2015-04-15 16:59:34 ----A---- C:\Windows\system32\d3dx9_35.dll
2015-04-15 16:59:34 ----A---- C:\Windows\system32\d3dx10_35.dll
2015-04-15 16:59:34 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2015-04-15 16:59:33 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2015-04-15 16:59:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2015-04-15 16:59:33 ----A---- C:\Windows\system32\xactengine2_8.dll
2015-04-15 16:59:33 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2015-04-15 16:59:32 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2015-04-15 16:59:32 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2015-04-15 16:59:32 ----A---- C:\Windows\system32\d3dx10_34.dll
2015-04-15 16:59:32 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2015-04-15 16:59:31 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2015-04-15 16:59:31 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2015-04-15 16:59:31 ----A---- C:\Windows\system32\xinput1_3.dll
2015-04-15 16:59:31 ----A---- C:\Windows\system32\d3dx9_34.dll
2015-04-15 16:59:30 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2015-04-15 16:59:30 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2015-04-15 16:59:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2015-04-15 16:59:30 ----A---- C:\Windows\system32\xactengine2_7.dll
2015-04-15 16:59:30 ----A---- C:\Windows\system32\d3dx10_33.dll
2015-04-15 16:59:30 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2015-04-15 16:59:29 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2015-04-15 16:59:29 ----A---- C:\Windows\system32\d3dx9_33.dll
2015-04-15 16:59:28 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2015-04-15 16:59:28 ----A---- C:\Windows\system32\xactengine2_6.dll
2015-04-15 16:59:27 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2015-04-15 16:59:27 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2015-04-15 16:59:27 ----A---- C:\Windows\system32\xactengine2_5.dll
2015-04-15 16:59:27 ----A---- C:\Windows\system32\d3dx10.dll
2015-04-15 16:59:25 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2015-04-15 16:59:25 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2015-04-15 16:59:25 ----A---- C:\Windows\system32\xactengine2_4.dll
2015-04-15 16:59:25 ----A---- C:\Windows\system32\x3daudio1_1.dll
2015-04-15 16:59:24 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2015-04-15 16:59:24 ----A---- C:\Windows\system32\d3dx9_31.dll
2015-04-15 16:59:23 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2015-04-15 16:59:23 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2015-04-15 16:59:23 ----A---- C:\Windows\system32\xinput1_2.dll
2015-04-15 16:59:23 ----A---- C:\Windows\system32\xactengine2_3.dll
2015-04-15 16:59:21 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2015-04-15 16:59:21 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2015-04-15 16:59:21 ----A---- C:\Windows\system32\xinput1_1.dll
2015-04-15 16:59:21 ----A---- C:\Windows\system32\xactengine2_2.dll
2015-04-15 16:59:20 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2015-04-15 16:59:20 ----A---- C:\Windows\system32\xactengine2_1.dll
2015-04-15 16:59:18 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2015-04-15 16:59:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2015-04-15 16:59:16 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2015-04-15 16:59:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2015-04-15 16:59:16 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2015-04-15 16:59:16 ----A---- C:\Windows\system32\xactengine2_0.dll
2015-04-15 16:59:16 ----A---- C:\Windows\system32\x3daudio1_0.dll
2015-04-15 16:59:16 ----A---- C:\Windows\system32\d3dx9_29.dll
2015-04-15 16:59:15 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2015-04-15 16:59:15 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2015-04-15 16:59:15 ----A---- C:\Windows\system32\d3dx9_28.dll
2015-04-15 16:59:15 ----A---- C:\Windows\system32\d3dx9_27.dll
2015-04-15 16:59:14 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2015-04-15 16:59:14 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2015-04-15 16:59:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2015-04-15 16:59:14 ----A---- C:\Windows\system32\d3dx9_25.dll
2015-04-15 16:59:13 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2015-04-15 16:59:13 ----A---- C:\Windows\system32\d3dx9_24.dll
2015-04-15 15:33:58 ----D---- C:\Program Files (x86)\Origin Games
2015-04-15 15:32:46 ----D---- C:\Users\HP\AppData\Roaming\Origin
2015-04-15 15:31:42 ----D---- C:\ProgramData\Origin
2015-04-15 15:31:41 ----D---- C:\ProgramData\Electronic Arts
2015-04-15 15:31:40 ----D---- C:\Program Files (x86)\Origin
2015-04-15 15:20:10 ----D---- C:\Users\HP\AppData\Roaming\Skype
2015-04-15 15:20:05 ----RD---- C:\Program Files (x86)\Skype
2015-04-15 15:20:00 ----D---- C:\ProgramData\Skype
2015-04-15 15:17:05 ----D---- C:\Users\HP\AppData\Roaming\TS3Client
2015-04-15 15:17:00 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2015-04-15 15:13:50 ----D---- C:\Program Files (x86)\Google
2015-04-15 15:12:24 ----D---- C:\Users\HP\AppData\Roaming\Adobe
2015-04-15 15:06:20 ----D---- C:\Users\HP\AppData\Roaming\Identities
2015-04-15 15:03:51 ----D---- C:\Users\HP\AppData\Roaming\Hewlett-Packard
2015-04-15 15:03:02 ----SD---- C:\Users\HP\AppData\Roaming\Microsoft
2015-04-15 15:03:02 ----D---- C:\Users\HP\AppData\Roaming\Media Center Programs

======List of files/folders modified in the last 1 month======

2015-04-16 17:30:54 ----D---- C:\Windows\Prefetch
2015-04-16 17:30:41 ----RD---- C:\Program Files
2015-04-16 17:21:52 ----D---- C:\Windows\System32
2015-04-16 17:21:52 ----D---- C:\Windows\inf
2015-04-16 17:21:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-16 16:56:01 ----AD---- C:\Windows\SysWOW64
2015-04-16 15:18:03 ----D---- C:\Windows\Temp
2015-04-16 07:01:21 ----D---- C:\Windows\winsxs
2015-04-16 07:00:58 ----D---- C:\Windows\system32\en-US
2015-04-16 07:00:57 ----D---- C:\Windows\system32\WCN
2015-04-16 07:00:56 ----D---- C:\Windows\Speech
2015-04-16 07:00:02 ----D---- C:\Windows\system32\config
2015-04-16 07:00:01 ----D---- C:\Windows\Logs
2015-04-16 05:19:47 ----D---- C:\Windows\system32\Tasks
2015-04-16 05:19:33 ----D---- C:\Windows\system32\drivers
2015-04-16 05:19:31 ----AD---- C:\Windows
2015-04-16 05:14:32 ----HD---- C:\ProgramData
2015-04-16 00:56:28 ----D---- C:\Windows\rescache
2015-04-16 00:54:20 ----D---- C:\ProgramData\Hewlett-Packard
2015-04-16 00:53:33 ----D---- C:\Windows\system32\sysprep
2015-04-16 00:01:22 ----RD---- C:\Program Files (x86)
2015-04-15 18:22:13 ----A---- C:\Windows\SYSWOW64\log.txt
2015-04-15 18:20:22 ----D---- C:\Windows\system32\drivers\NISx64
2015-04-15 18:20:14 ----D---- C:\ProgramData\PDFC
2015-04-15 18:19:44 ----D---- C:\ProgramData\NVIDIA
2015-04-15 17:49:55 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-04-15 17:49:54 ----SHD---- C:\Windows\Installer
2015-04-15 17:49:23 ----D---- C:\ProgramData\NVIDIA Corporation
2015-04-15 17:49:00 ----D---- C:\Windows\system32\DriverStore
2015-04-15 17:49:00 ----D---- C:\Windows\system32\catroot
2015-04-15 17:47:39 ----D---- C:\Program Files\NVIDIA Corporation
2015-04-15 17:28:31 ----D---- C:\Windows\system32\restore
2015-04-15 17:21:49 ----D---- C:\Program Files (x86)\Hp
2015-04-15 17:21:34 ----RSD---- C:\Windows\assembly
2015-04-15 17:21:05 ----D---- C:\Program Files (x86)\Bing Bar Installer
2015-04-15 17:19:58 ----D---- C:\Program Files (x86)\Microsoft
2015-04-15 17:19:46 ----SD---- C:\ProgramData\Microsoft
2015-04-15 17:01:53 ----D---- C:\Program Files\Symantec
2015-04-15 17:00:41 ----D---- C:\Program Files (x86)\Common Files
2015-04-15 17:00:08 ----D---- C:\Windows\system32\LogFiles
2015-04-15 16:59:19 ----D---- C:\Windows\Microsoft.NET
2015-04-15 15:13:51 ----D---- C:\Windows\Tasks
2015-04-15 15:11:55 ----RD---- C:\Program Files (x86)\Online Services
2015-04-15 15:06:17 ----SHD---- C:\$RECYCLE.BIN
2015-04-15 15:06:15 ----D---- C:\ProgramData\Norton
2015-04-15 15:06:13 ----D---- C:\swsetup
2015-04-15 15:06:09 ----RHD---- C:\SYSTEM.SAV
2015-04-15 15:03:47 ----RD---- C:\Program Files\Online Services
2015-04-15 15:03:41 ----D---- C:\Program Files\Windows Sidebar
2015-04-15 15:03:41 ----D---- C:\Program Files (x86)\Windows Sidebar
2015-04-15 15:03:20 ----D---- C:\Windows\SYSWOW64\drivers
2015-04-15 15:03:02 ----RD---- C:\Users
2015-04-15 15:03:00 ----D---- C:\Windows\Panther
2015-04-09 02:58:18 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-04-09 02:58:18 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-04-09 02:58:18 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-04-09 02:58:18 ----A---- C:\Windows\system32\nvapi64.dll
2015-04-08 23:30:18 ----A---- C:\Windows\system32\nvsvc64.dll
2015-04-08 23:30:18 ----A---- C:\Windows\system32\nvcpl.dll
2015-04-08 23:30:14 ----A---- C:\Windows\system32\nvvsvc.exe
2015-04-08 23:30:14 ----A---- C:\Windows\system32\nvsvcr.dll
2015-04-08 23:30:14 ----A---- C:\Windows\system32\nvshext.dll
2015-04-08 23:30:13 ----A---- C:\Windows\system32\nvmctray.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-04-16 271200]
R0 iaStor;Intel RAID Controller; C:\Windows\system32\drivers\iaStor.sys [2010-11-05 438808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [2011-01-27 450680]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [2011-03-15 912504]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-04-16 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-04-16 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-04-16 442264]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20150408.001\BHDrvx64.sys [2015-04-08 1639128]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2015-04-15 487216]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20150414.001\IDSvia64.sys [2015-04-14 671448]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NISx64\1206000.01D\SRTSPX64.SYS [2011-03-31 40568]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [2011-01-27 171128]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [2011-03-22 382584]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-04-16 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-04-16 88408]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-04-16 136752]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2015-04-15 142640]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\drivers\HECIx64.sys [2010-10-19 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20150414.041\ENG64.SYS [2015-04-15 129752]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20150414.041\EX64.SYS [2015-04-15 2137304]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-04-09 195728]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-03-28 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-12-28 412776]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NISx64\1206000.01D\SRTSP64.SYS [2011-03-31 744568]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10301; C:\Windows\system32\DRIVERS\stwrt64.sys [2011-01-26 520192]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2015-04-15 174200]
R3 tihub3;TI USB3 Hub Service; C:\Windows\system32\drivers\tihub3.sys [2011-01-18 125552]
R3 tixhci;TI XHCI Service; C:\Windows\system32\drivers\tixhci.sys [2011-02-22 382024]
S0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-04-16 65736]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-04-16 343336]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-03-28 1152144]
R2 HPAuto;HP Auto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168]
R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]
R2 NOBU;Norton Online Backup; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-06-02 2804568]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-03-28 1878672]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-03-28 22995600]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-04-08 936264]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2015-04-15 76152]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-26 296448]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-04-08 410952]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-19 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-15 107848]
S2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-15 107848]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe []
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-03 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2015-04-15 1931632]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

-----------------EOF-----------------

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 16 dub 2015 16:46
od Tulipan
Ještě bych rád dodal že mi zničeho nic přestalo jít na klávesnici tlačítko "DELETE". Ozkoušeno na 3 klávesnicích a na žádné to nejde. Přestalo to jít v době kdy mi začali s počítačem problémy popsané nahoře.

Počítač se také někdy sekne a začne bláznit. Bláznit ve stylu jako bych projel všechny tlačítka na klávesnici.

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 16 dub 2015 18:14
od Tulipan
Omlouvám se za double post, ale ještě bych se rád zeptal na jednu věc, než mi někdo bude radit aby to bylo v jednom postu.

Počítač poté co jsem ho reinstalloval, tak jsem neinstalloval žádné aktualizace. Pouze aktualizační program od Nvidie, kterej mi stáhl všechny drivery na mou grafickou kartu.
Ovšem windows aktualizace jsem zakázal a nic jsem neaktualizoval, zároveň jsem neaktualizoval žádné jiné věci v počítači. Chci se zeptat jestli mám windows aktualizace povolit a jestli to ovlivní výkon počítače ( nahorů x dolů ). Někde jsem četl že pro nejlepší výkonost počítače by se neměli stahovat aktualizace přes windows update, ale nevim je jich tam přes 594 a zároveň by mě zajímalo co vše je potřeba aktualizovat tak abych dal počítač do stavu tak aby měl co největší výkonost ?Děkuji za odpověď i na tuto otázku.

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 17 dub 2015 10:46
od altrok
Zdravim :bye:


:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 17 dub 2015 20:51
od Tulipan
Zdravim, vytvořilo mi to dva logy dám sem raději oba :D.

AdwCleaner[R0]:
# AdwCleaner v4.201 - Log vytvořen 17/04/2015 v 21:43:12
# Aktualizováno 08/04/2015 by Xplode
# Databáze : 2015-04-15.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : HP - HP-HP
# Spuštěno z : C:\Users\HP\Desktop\adwcleaner_4.201.exe
# Nastavení : Sken

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Soubor Nalezeno : C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8iznmrlj.default\user.js

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}

***** [ Prohlížeče ] *****

-\\ Internet Explorer v8.0.7601.17514


-\\ Mozilla Firefox v37.0.1 (x86 cs)


-\\ Google Chrome v42.0.2311.90


*************************

AdwCleaner[R0].txt - [1654 bytů] - [17/04/2015 21:43:12]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1712 bytů] ##########


AdwCleaner[S0]:

# AdwCleaner v4.201 - Log vytvořen 17/04/2015 v 21:44:29
# Aktualizováno 08/04/2015 by Xplode
# Databáze : 2015-04-15.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : HP - HP-HP
# Spuštěno z : C:\Users\HP\Desktop\adwcleaner_4.201.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Soubor Smazáno : C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8iznmrlj.default\user.js

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}

***** [ Prohlížeče ] *****

-\\ Internet Explorer v8.0.7601.17514


-\\ Mozilla Firefox v37.0.1 (x86 cs)


-\\ Google Chrome v42.0.2311.90


*************************

AdwCleaner[R0].txt - [1814 bytů] - [17/04/2015 21:43:12]
AdwCleaner[S0].txt - [1372 bytů] - [17/04/2015 21:44:29]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1430 bytů] ##########

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 17 dub 2015 21:13
od altrok
:arrow: Nez zacnem mazat, poprosim Vas jeste o nasledujici logy.

:arrow: Dejte log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101

:arrow: Ulozte na plochu MBRScan - http://eric71.geekstogo.com/tools/MbrScan.exe
  • Spustte jej, vpravo nahore kliknete na Options a vsechno dooznacte
  • kliknete na Report
  • obsah prave otevreneho textaku mi vlozte do pristi odpovedi


:arrow:
  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)

    Kód: Vybrat vše

    Start
    SaveMbr: drive=0
    End
  • nabootujte do nouzoveho rezimu
  • spustte FRST a kliknete na Fix
  • na plose se vytvori soubor MBRDUMP.txt, ktery zabalte do zipu/raru a prilozte k pristimu prispevku

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 08:59
od Tulipan
FRST:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-04-2015
Ran by HP (administrator) on HP-HP on 18-04-2015 09:42:43
Running from C:\Users\HP\Desktop
Loaded Profiles: HP (Available profiles: HP)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\ccsvchst.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\ccsvchst.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\beats64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [37888 2010-10-21] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-26] (IDT, Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe
HKLM-x32\...\Run: [LaunchHPOSIAPP] => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe [385024 2009-04-04] (Hewlett-Packard)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-02-10] (EasyBits Software AS)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [656920 2011-02-01] (PDF Complete Inc)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-16] (Avast Software s.r.o.)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\...\MountPoints2: {2db8c55e-e38b-11e4-8fbc-e06995d0fdb8} - L:\LaunchU3.exe -a
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\...\MountPoints2: {5df29909-e53a-11e4-a762-e06995d0fdb8} - L:\setup.exe
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\...\MountPoints2: {5df29910-e53a-11e4-a762-e06995d0fdb8} - M:\Setup.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDF
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDF
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDF
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDF
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDF
HKU\S-1-5-21-512532572-2427873822-1548518363-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDF
SearchScopes: HKLM -> {5F3F9639-E5E6-4C72-92D2-32A40E19016D} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKLM-x32 -> {5F3F9639-E5E6-4C72-92D2-32A40E19016D} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-512532572-2427873822-1548518363-1000 -> {5F3F9639-E5E6-4C72-92D2-32A40E19016D} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-16] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Symantec NCO BHO -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll [2011-12-09] (Symantec Corporation)
BHO-x32: Symantec Intrusion Prevention -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\IPS\IPSBHO.DLL [2011-03-31] (Symantec Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-16] (Avast Software s.r.o.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll [2011-12-09] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-512532572-2427873822-1548518363-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-08-16] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\8iznmrlj.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_5_1
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_5_1 [2015-04-17]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-16]

Chrome:
=======
CHR Profile: C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-15]
CHR Extension: (Google Docs) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-15]
CHR Extension: (Google Drive) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-15]
CHR Extension: (YouTube) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-15]
CHR Extension: (Google Search) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-15]
CHR Extension: (Google Sheets) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-15]
CHR Extension: (Bookmark Manager) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-15]
CHR Extension: (Google Wallet) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-15]
CHR Extension: (Gmail) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-15]
CHR Profile: C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google Slides) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-15]
CHR Extension: (Google Docs) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-15]
CHR Extension: (Google Drive) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-15]
CHR Extension: (YouTube) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-15]
CHR Extension: (Google Search) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-15]
CHR Extension: (Google Sheets) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-15]
CHR Extension: (Bookmark Manager) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-15]
CHR Extension: (Google Wallet) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-15]
CHR Extension: (Gmail) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-15]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-16] (Avast Software s.r.o.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation)
R2 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-17] (Hewlett-Packard)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-15] (Electronic Arts)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1127448 2011-02-01] (PDF Complete Inc)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-04-15] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 HP Health Check Service; "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe" [X]
S3 hpqwmiex; "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-04-16] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-16] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-16] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-16] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-04-16] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [271200 2015-04-16] ()
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20150408.001\BHDrvx64.sys [1639128 2015-04-08] (Symantec Corporation)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2015-04-17] (Disc Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2015-04-15] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2015-04-15] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20150417.001\IDSvia64.sys [671448 2015-04-14] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20150417.002\ENG64.SYS [129752 2015-04-15] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20150417.002\EX64.SYS [2137304 2015-04-15] (Symantec Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207000.00D\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207010.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1207010.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207010.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2015-04-15] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207010.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation)
R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1207000.00D\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-18 09:42 - 2015-04-18 09:43 - 00020386 _____ () C:\Users\HP\Desktop\FRST.txt
2015-04-18 09:41 - 2015-04-18 09:42 - 00000000 ____D () C:\FRST
2015-04-18 09:37 - 2015-04-18 09:37 - 02098176 _____ (Farbar) C:\Users\HP\Desktop\FRST64.exe
2015-04-17 22:48 - 2015-04-17 22:48 - 00001382 _____ () C:\Users\Public\Desktop\Watch_Dogs - Complete Edition.lnk
2015-04-17 22:41 - 2015-04-17 22:48 - 00000000 ____D () C:\Program Files (x86)\Watch_Dogs - Complete Edition
2015-04-17 22:12 - 2015-04-17 22:21 - 00030352 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-04-17 22:12 - 2015-04-17 22:21 - 00000000 ____D () C:\Users\HP\AppData\Roaming\DAEMON Tools Lite
2015-04-17 22:12 - 2015-04-17 22:13 - 00000000 ____D () C:\Program Files\DAEMON Tools Lite
2015-04-17 22:12 - 2015-04-17 22:12 - 00001745 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2015-04-17 22:12 - 2015-04-17 22:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2015-04-17 22:12 - 2015-04-17 22:12 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2015-04-17 22:11 - 2015-04-17 22:11 - 13146016 _____ (Disc Soft Ltd) C:\Users\HP\Downloads\DTLite501-0406.exe
2015-04-17 21:53 - 2015-04-17 21:53 - 00000000 ____D () C:\Windows\System32\Tasks\Symantec
2015-04-17 21:43 - 2015-04-17 21:44 - 00000000 ____D () C:\AdwCleaner
2015-04-17 20:52 - 2015-04-17 20:55 - 182577152 _____ () C:\Users\HP\Downloads\Dva-a-pul-chlapa-3x06.avi
2015-04-17 20:23 - 2015-04-17 20:23 - 02217984 _____ () C:\Users\HP\Desktop\adwcleaner_4.201.exe
2015-04-17 13:06 - 2015-04-17 13:19 - 3539151930 _____ () C:\Users\HP\Downloads\Pirati-z-Karibiku-2-Truhla-mrtveho-muze-2006.mkv
2015-04-17 07:53 - 2015-04-17 08:07 - 1244657712 _____ () C:\Users\HP\Downloads\Saga-prokleti-stinu-akcni-fantasy-2013-cz-SABRI.avi
2015-04-17 07:52 - 2015-04-17 08:14 - 2938026664 _____ () C:\Users\HP\Downloads\Mythica-A-Quest-for-Heroes-1080p-x264-DTS-Eng-Cz-tit-2015.mkv
2015-04-17 07:38 - 2015-04-17 08:19 - 2055987514 _____ () C:\Users\HP\Downloads\Need.for.Speed.2014.720p.BluRay.x264.DTS.CZ-4play.mkv
2015-04-17 07:36 - 2015-04-17 07:43 - 1009413816 _____ () C:\Users\HP\Downloads\Son-of-a-Gun-cz-tit.v-obraze.csfd-72-akcni-krimi-2014.avi
2015-04-17 07:25 - 2015-04-17 07:27 - 00000000 ____D () C:\hry
2015-04-16 21:23 - 2015-04-17 21:59 - 00000000 ____D () C:\Users\HP\AppData\Local\CrashDumps
2015-04-16 19:11 - 2015-04-16 19:11 - 00007642 _____ () C:\Users\HP\AppData\Local\Resmon.ResmonCfg
2015-04-16 17:30 - 2015-04-16 17:31 - 00000000 ____D () C:\rsit
2015-04-16 17:30 - 2015-04-16 17:30 - 00000000 ____D () C:\Program Files\trend micro
2015-04-16 17:29 - 2015-04-16 17:29 - 01222144 _____ () C:\Users\HP\Downloads\RSITx64.exe
2015-04-16 05:47 - 2015-04-16 05:48 - 182868016 _____ () C:\Users\HP\Downloads\Dva-a-pul-Chlapa-4x04.avi
2015-04-16 05:44 - 2015-04-16 05:45 - 182890395 _____ () C:\Users\HP\Downloads\Dva_a_pul_chlapa_4x03.avi
2015-04-16 05:21 - 2015-04-16 05:21 - 00000000 ____D () C:\Users\HP\AppData\Roaming\AVAST Software
2015-04-16 05:20 - 2015-04-16 05:20 - 00001924 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-04-16 05:20 - 2015-04-16 05:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-04-16 05:19 - 2015-04-16 05:21 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-04-16 05:19 - 2015-04-16 05:19 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-04-16 05:19 - 2015-04-16 05:19 - 00271200 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00136752 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00088408 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-04-16 05:19 - 2015-04-16 05:19 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-16 05:19 - 2015-04-16 05:19 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-04-16 05:18 - 2015-04-16 05:18 - 00000000 ____D () C:\Program Files\AVAST Software
2015-04-16 05:17 - 2015-04-16 05:19 - 182892544 _____ () C:\Users\HP\Downloads\Dva-a-pul-chlapa-4x01.avi
2015-04-16 05:17 - 2015-04-16 05:19 - 182870016 _____ () C:\Users\HP\Downloads\Dva-a-pul-chlapa-4x02.avi
2015-04-16 05:14 - 2015-04-16 05:14 - 05481352 _____ (Avast Software s.r.o.) C:\Users\HP\Downloads\avast_free_antivirus_setup_online.exe
2015-04-16 05:14 - 2015-04-16 05:14 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-04-16 00:59 - 2015-04-17 21:50 - 00016036 _____ () C:\Windows\WindowsUpdate.log
2015-04-16 00:57 - 2015-04-16 00:57 - 00000056 ____H () C:\Windows\SysWOW64\ezsidmv.dat
2015-04-16 00:06 - 2015-04-18 05:46 - 00000000 ____D () C:\Users\HP\AppData\Roaming\vlc
2015-04-16 00:01 - 2015-04-16 00:01 - 00001068 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-04-16 00:01 - 2015-04-16 00:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-04-16 00:01 - 2015-04-16 00:01 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2015-04-15 23:59 - 2015-04-16 00:10 - 2819718075 _____ () C:\Users\HP\Downloads\Sedmy-Syn-Seventh-Son-1080p-x264-AC3-Eng-Cz-tit-2014.mkv
2015-04-15 23:59 - 2015-04-16 00:00 - 28509232 _____ () C:\Users\HP\Downloads\vlc-2.2.0-win32.exe
2015-04-15 22:42 - 2015-04-15 22:43 - 01533584 _____ () C:\Users\HP\Downloads\battlelog-web-plugins_2.6.2_157 (1).exe
2015-04-15 21:16 - 2015-04-15 21:16 - 00000000 ____D () C:\Users\HP\hpremote
2015-04-15 20:44 - 2015-04-15 20:45 - 00000000 ____D () C:\ProgramData\Recovery
2015-04-15 18:42 - 2015-04-15 18:42 - 00000000 ____D () C:\Users\HP\AppData\Local\Macromedia
2015-04-15 18:41 - 2015-04-15 18:42 - 00000000 ____D () C:\Users\HP\AppData\Local\Adobe
2015-04-15 18:41 - 2015-04-15 18:41 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-15 18:41 - 2015-04-15 18:41 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-15 18:41 - 2015-04-15 18:41 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-15 18:20 - 2015-04-17 21:47 - 00002491 _____ () C:\Users\Public\Desktop\Norton Internet Security.lnk
2015-04-15 18:08 - 2015-04-15 18:08 - 00000000 ____D () C:\Users\HP\Downloads\Nová složka
2015-04-15 18:08 - 2015-04-15 18:08 - 00000000 ____D () C:\Users\HP\AppData\Roaming\WinRAR
2015-04-15 18:06 - 2015-04-15 18:06 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-15 18:06 - 2015-04-15 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-15 18:05 - 2015-04-15 18:06 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2015-04-15 18:04 - 2015-04-15 18:04 - 01945832 _____ () C:\Users\HP\Downloads\wrar521cz.exe
2015-04-15 17:49 - 2015-04-08 22:32 - 00560968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-04-15 17:48 - 2015-04-08 19:52 - 04336074 _____ () C:\Windows\system32\nvcoproc.bin
2015-04-15 17:46 - 2015-04-09 02:58 - 31570064 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 30397072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 25375048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 24053576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 15818528 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 15716232 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 14006752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 12852784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 11380728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 10423952 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-04-15 17:46 - 2015-04-09 02:58 - 02935416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 02896528 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 02573456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 01895568 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435012.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435012.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 01086424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 01047368 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 01037640 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00970568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00962192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00927440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-04-15 17:46 - 2015-04-09 02:58 - 00175880 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00150648 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-04-15 17:46 - 2015-04-09 02:58 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-04-15 17:39 - 2015-04-15 17:39 - 00001379 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2015-04-15 17:39 - 2015-04-15 17:39 - 00000000 ____D () C:\Users\HP\AppData\Local\NVIDIA Corporation
2015-04-15 17:39 - 2015-04-15 17:39 - 00000000 ____D () C:\Users\HP\AppData\Local\NVIDIA
2015-04-15 17:37 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-04-15 17:37 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-04-15 17:37 - 2015-03-28 05:43 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-04-15 17:37 - 2015-03-28 05:43 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-04-15 17:36 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-04-15 17:36 - 2014-11-22 12:46 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-04-15 17:36 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-04-15 17:35 - 2015-04-18 06:15 - 00348672 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-04-15 17:35 - 2015-04-15 17:35 - 00000000 ____D () C:\Users\HP\AppData\Local\PunkBuster
2015-04-15 17:34 - 2015-04-15 17:34 - 36450560 _____ (NVIDIA Corporation) C:\Users\HP\Downloads\GeForce_Experience_v2.4.1.21.exe
2015-04-15 17:30 - 2015-04-15 17:31 - 00000000 ____D () C:\Users\HP\Documents\Battlefield 3
2015-04-15 17:30 - 2015-04-15 17:30 - 00000000 ____D () C:\Users\HP\AppData\Local\ESN
2015-04-15 17:30 - 2015-04-15 17:30 - 00000000 ____D () C:\ProgramData\EA Core
2015-04-15 17:29 - 2015-04-15 17:29 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Macromedia
2015-04-15 17:24 - 2015-04-15 22:43 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2015-04-15 17:21 - 2015-04-15 17:21 - 00000000 ____D () C:\Users\HP\AppData\Roaming\hpqLog
2015-04-15 17:14 - 2015-04-15 17:14 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-15 17:14 - 2015-04-15 17:14 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-15 17:14 - 2015-04-15 17:14 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Mozilla
2015-04-15 17:14 - 2015-04-15 17:14 - 00000000 ____D () C:\Users\HP\AppData\Local\Mozilla
2015-04-15 17:14 - 2015-04-15 17:14 - 00000000 ____D () C:\ProgramData\Mozilla
2015-04-15 17:14 - 2015-04-15 17:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-15 17:14 - 2015-04-15 17:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-15 17:13 - 2015-04-15 17:13 - 00243504 _____ () C:\Users\HP\Downloads\Firefox Setup Stub 37.0.1.exe
2015-04-15 17:04 - 2015-04-15 17:08 - 01533584 _____ () C:\Users\HP\Downloads\battlelog-web-plugins_2.6.2_157.exe
2015-04-15 17:00 - 2015-04-18 06:15 - 00348672 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-04-15 17:00 - 2015-04-18 06:15 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-04-15 17:00 - 2015-04-15 18:26 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-04-15 17:00 - 2015-04-15 17:00 - 00001172 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2015-04-15 17:00 - 2015-04-15 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2015-04-15 17:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2015-04-15 17:00 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2015-04-15 17:00 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2015-04-15 17:00 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2015-04-15 17:00 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2015-04-15 17:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-04-15 17:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2015-04-15 17:00 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2015-04-15 16:59 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2015-04-15 16:59 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2015-04-15 16:59 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2015-04-15 16:59 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2015-04-15 16:59 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2015-04-15 16:59 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2015-04-15 16:59 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2015-04-15 16:59 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2015-04-15 16:59 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2015-04-15 16:59 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2015-04-15 16:59 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2015-04-15 16:59 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2015-04-15 16:59 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2015-04-15 16:59 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2015-04-15 16:59 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2015-04-15 16:59 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2015-04-15 16:59 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-04-15 16:59 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2015-04-15 16:59 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2015-04-15 16:59 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2015-04-15 16:59 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2015-04-15 16:59 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2015-04-15 16:59 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2015-04-15 16:59 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2015-04-15 16:59 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2015-04-15 16:59 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2015-04-15 16:59 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2015-04-15 16:59 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2015-04-15 16:59 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2015-04-15 16:59 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2015-04-15 16:59 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2015-04-15 16:59 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2015-04-15 16:59 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2015-04-15 16:59 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2015-04-15 16:59 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2015-04-15 16:59 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2015-04-15 16:59 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2015-04-15 16:59 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2015-04-15 16:59 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2015-04-15 16:59 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2015-04-15 16:59 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2015-04-15 16:59 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2015-04-15 16:59 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-04-15 16:59 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2015-04-15 16:59 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2015-04-15 16:59 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2015-04-15 16:59 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2015-04-15 16:59 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2015-04-15 16:59 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2015-04-15 16:59 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2015-04-15 16:59 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2015-04-15 16:59 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2015-04-15 16:59 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2015-04-15 16:59 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2015-04-15 16:59 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2015-04-15 16:59 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2015-04-15 16:59 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2015-04-15 16:59 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2015-04-15 16:59 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2015-04-15 16:59 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2015-04-15 16:59 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2015-04-15 16:59 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2015-04-15 16:59 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2015-04-15 16:59 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2015-04-15 16:59 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2015-04-15 16:59 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2015-04-15 16:59 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2015-04-15 16:59 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2015-04-15 16:59 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2015-04-15 16:59 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2015-04-15 16:59 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2015-04-15 16:59 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2015-04-15 16:59 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2015-04-15 16:59 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2015-04-15 16:59 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2015-04-15 16:59 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2015-04-15 16:59 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2015-04-15 16:59 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2015-04-15 16:59 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2015-04-15 16:59 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2015-04-15 16:59 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2015-04-15 16:59 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2015-04-15 16:59 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2015-04-15 16:59 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2015-04-15 16:59 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2015-04-15 16:59 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2015-04-15 16:59 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2015-04-15 16:59 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2015-04-15 16:59 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2015-04-15 16:59 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2015-04-15 16:59 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2015-04-15 16:59 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2015-04-15 16:59 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2015-04-15 16:59 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2015-04-15 16:59 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2015-04-15 16:59 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2015-04-15 16:59 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2015-04-15 16:59 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2015-04-15 16:59 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2015-04-15 16:59 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2015-04-15 16:59 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2015-04-15 16:59 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2015-04-15 16:59 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2015-04-15 16:59 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2015-04-15 16:59 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2015-04-15 16:59 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2015-04-15 16:59 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2015-04-15 16:59 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2015-04-15 16:59 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2015-04-15 16:59 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2015-04-15 16:59 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2015-04-15 16:59 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2015-04-15 16:59 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2015-04-15 16:59 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2015-04-15 16:59 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2015-04-15 16:59 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2015-04-15 16:59 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2015-04-15 16:59 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2015-04-15 16:59 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2015-04-15 16:59 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2015-04-15 16:59 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-04-15 16:59 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2015-04-15 16:59 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2015-04-15 16:59 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2015-04-15 16:59 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2015-04-15 16:59 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2015-04-15 16:59 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-04-15 16:59 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2015-04-15 16:59 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2015-04-15 16:59 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2015-04-15 16:59 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-04-15 16:59 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2015-04-15 16:59 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-04-15 16:59 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2015-04-15 16:59 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-04-15 16:59 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2015-04-15 15:39 - 2015-04-15 15:50 - 1646895104 _____ () C:\Users\HP\Downloads\Purpurove-reky_2000_Krimi_CZdabink_DVDRip-Lt.avi
2015-04-15 15:33 - 2015-04-15 15:41 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-04-15 15:32 - 2015-04-15 17:30 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Origin
2015-04-15 15:32 - 2015-04-15 17:30 - 00000000 ____D () C:\Users\HP\AppData\Local\Origin
2015-04-15 15:31 - 2015-04-17 22:01 - 00000000 ____D () C:\ProgramData\Origin
2015-04-15 15:31 - 2015-04-15 17:31 - 00000000 ____D () C:\ProgramData\Electronic Arts
2015-04-15 15:31 - 2015-04-15 15:32 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-04-15 15:31 - 2015-04-15 15:31 - 00000981 _____ () C:\Users\Public\Desktop\Origin.lnk
2015-04-15 15:31 - 2015-04-15 15:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-04-15 15:23 - 2015-04-15 15:23 - 17110336 _____ (Electronic Arts, Inc.) C:\Users\HP\Downloads\OriginThinSetup.exe
2015-04-15 15:20 - 2015-04-17 21:59 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Skype
2015-04-15 15:20 - 2015-04-15 15:20 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-15 15:20 - 2015-04-15 15:20 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-04-15 15:20 - 2015-04-15 15:20 - 00000000 ____D () C:\Users\HP\Tracing
2015-04-15 15:20 - 2015-04-15 15:20 - 00000000 ____D () C:\Users\HP\AppData\Local\Skype
2015-04-15 15:20 - 2015-04-15 15:20 - 00000000 ____D () C:\ProgramData\Skype
2015-04-15 15:20 - 2015-04-15 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-15 15:19 - 2015-04-15 15:19 - 01380960 _____ (Skype Technologies S.A.) C:\Users\HP\Downloads\SkypeSetup.exe
2015-04-15 15:17 - 2015-04-15 19:53 - 00000000 ____D () C:\Users\HP\AppData\Roaming\TS3Client
2015-04-15 15:17 - 2015-04-15 15:17 - 00001164 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-04-15 15:17 - 2015-04-15 15:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-04-15 15:17 - 2015-04-15 15:17 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2015-04-15 15:16 - 2015-04-15 15:16 - 28115400 _____ (TeamSpeak Systems GmbH) C:\Users\HP\Downloads\TeamSpeak3-Client-win32-3.0.16.exe
2015-04-15 15:14 - 2015-04-15 15:14 - 00002257 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-15 15:14 - 2015-04-15 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-04-15 15:13 - 2015-04-18 09:18 - 00000944 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-15 15:13 - 2015-04-17 21:48 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-15 15:13 - 2015-04-15 15:14 - 00000000 ____D () C:\Users\HP\AppData\Local\Google
2015-04-15 15:13 - 2015-04-15 15:14 - 00000000 ____D () C:\Program Files (x86)\Google
2015-04-15 15:13 - 2015-04-15 15:13 - 00003940 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-04-15 15:13 - 2015-04-15 15:13 - 00003688 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-04-15 15:13 - 2015-04-15 15:13 - 00000000 ____D () C:\Users\HP\AppData\Local\Deployment
2015-04-15 15:13 - 2015-04-15 15:13 - 00000000 ____D () C:\Users\HP\AppData\Local\Apps\2.0
2015-04-15 15:12 - 2015-04-15 15:12 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Adobe
2015-04-15 15:06 - 2015-04-15 17:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-04-15 15:06 - 2015-04-15 15:06 - 00003846 _____ () C:\Windows\System32\Tasks\SetupManager
2015-04-15 15:06 - 2015-04-15 15:06 - 00003504 _____ () C:\Windows\System32\Tasks\Registration
2015-04-15 15:06 - 2015-04-15 15:06 - 00001445 _____ () C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-15 15:06 - 2015-04-15 15:06 - 00001411 _____ () C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-04-15 15:06 - 2015-04-15 15:06 - 00000000 ____D () C:\Users\HP\AppData\Local\VirtualStore
2015-04-15 15:06 - 2015-04-15 15:06 - 00000000 ____D () C:\Users\HP\AppData\Local\RemEngine
2015-04-15 15:06 - 2015-04-15 15:06 - 00000000 ____D () C:\Users\HP\AppData\Local\PDFC
2015-04-15 15:05 - 2015-04-15 15:05 - 00057560 _____ () C:\Users\HP\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-15 15:03 - 2015-04-15 21:16 - 00000000 ____D () C:\Users\HP
2015-04-15 15:03 - 2015-04-15 21:15 - 00000000 ____D () C:\Users\HP\AppData\Roaming\Hewlett-Packard
2015-04-15 15:03 - 2015-04-15 15:06 - 00000000 ____D () C:\Users\HP\AppData\Local\Hewlett-Packard_Company
2015-04-15 15:03 - 2015-04-15 15:06 - 00000000 ____D () C:\Users\HP\AppData\Local\Hewlett-Packard
2015-04-15 15:03 - 2015-04-15 15:03 - 00001783 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Záruka.lnk
2015-04-15 15:03 - 2015-04-15 15:03 - 00000020 ___SH () C:\Users\HP\ntuser.ini
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Šablony
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Soubory cookie
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Poslední
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Okolní tiskárny
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Okolní síť
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Nabídka Start
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Dokumenty
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Documents\Obrázky
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Documents\Hudba
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Documents\Filmy
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\Data aplikací
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 _SHDL () C:\Users\HP\AppData\Local\Data aplikací
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 __RSH () C:\Windows\SysWOW64\Drivers\103C_HP_cPC_h8-1000cs_Y53316J_0U_QCZC133_E11EE2MRW605_4A_I2AB5_SPEGATRON CORPORATION_V1.01_B7.12_T111012_W73-1_L405_M4077_J1000_7Intel_86A7_93.30_#110902_N10EC8168_Z_G10DE1243_Ohp CDDVDW TS-H653T_DBNQ78BA.MRK
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 __RSH () C:\Windows\system32\Drivers\103C_HP_cPC_h8-1000cs_Y53316J_0U_QCZC133_E11EE2MRW605_4A_I2AB5_SPEGATRON CORPORATION_V1.01_B7.12_T111012_W73-1_L405_M4077_J1000_7Intel_86A7_93.30_#110902_N10EC8168_Z_G10DE1243_Ohp CDDVDW TS-H653T_DBNQ78BA.MRK
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 ____D () C:\Users\Public\Symantec
2015-04-15 15:03 - 2015-04-15 15:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Uživatelské Příručky
2015-04-15 15:03 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-15 15:03 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-15 15:02 - 2015-04-15 15:02 - 00003290 _____ () C:\Windows\System32\Tasks\RMCreator

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-17 22:54 - 2011-08-16 13:36 - 00000000 ____D () C:\Windows\system32\Drivers\NISx64
2015-04-17 21:55 - 2009-07-14 06:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-17 21:55 - 2009-07-14 06:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-17 21:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-04-17 21:47 - 2011-08-16 13:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2015-04-17 21:47 - 2011-08-16 13:32 - 00000000 ____D () C:\ProgramData\PDFC
2015-04-17 21:47 - 2011-08-16 13:15 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-17 21:47 - 2010-11-21 09:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-04-17 21:47 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2015-04-17 21:47 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2015-04-17 21:47 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2015-04-17 21:47 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-04-17 21:47 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-17 21:47 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-04-17 21:47 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-17 21:47 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2015-04-17 21:47 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-04-17 21:47 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-04-17 21:47 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-17 21:47 - 2009-07-14 06:51 - 00043907 _____ () C:\Windows\setupact.log
2015-04-17 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK
2015-04-17 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz
2015-04-17 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-04-17 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing
2015-04-17 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-17 21:46 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\winrm
2015-04-17 21:46 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\WCN
2015-04-17 21:46 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\slmgr
2015-04-17 21:46 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-04-17 21:46 - 2010-11-21 05:47 - 00038724 _____ () C:\Windows\PFRO.log
2015-04-17 21:46 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sk-SK
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\oobe
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\migwiz
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2015-04-17 21:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-16 17:21 - 2011-08-16 13:04 - 00665706 _____ () C:\Windows\system32\perfh005.dat
2015-04-16 17:21 - 2011-08-16 13:04 - 00139402 _____ () C:\Windows\system32\perfc005.dat
2015-04-16 17:21 - 2009-07-14 07:13 - 01575230 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-16 00:54 - 2011-08-16 13:19 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2015-04-16 00:53 - 2009-07-14 06:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-04-16 00:53 - 2009-07-14 06:46 - 00005075 _____ () C:\Windows\DtcInstall.log
2015-04-16 00:52 - 2011-02-11 19:04 - 00005949 _____ () C:\Windows\TSSysprep.log
2015-04-15 20:44 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-04-15 20:44 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2015-04-15 17:49 - 2011-08-16 13:15 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-04-15 17:49 - 2011-08-16 13:15 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-04-15 17:47 - 2011-08-16 13:15 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-15 17:28 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore
2015-04-15 17:21 - 2011-08-16 13:22 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-04-15 17:21 - 2011-08-16 13:21 - 00000000 ____D () C:\Program Files (x86)\Hp
2015-04-15 17:01 - 2011-08-16 13:36 - 00174200 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2015-04-15 17:01 - 2011-08-16 13:36 - 00007488 _____ () C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2015-04-15 17:01 - 2011-08-16 13:36 - 00000000 ____D () C:\Program Files\Symantec
2015-04-15 17:00 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-04-15 16:59 - 2011-08-16 13:33 - 00010245 _____ () C:\Windows\DirectX.log
2015-04-15 15:11 - 2011-08-16 13:26 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2015-04-15 15:06 - 2011-08-16 13:36 - 00000000 ____D () C:\ProgramData\Norton
2015-04-15 15:06 - 2011-02-11 18:32 - 00000000 __RHD () C:\SYSTEM.SAV
2015-04-15 15:06 - 2011-02-11 00:39 - 00000000 ____D () C:\swsetup
2015-04-15 15:03 - 2011-08-16 13:33 - 00000000 ___RD () C:\Program Files\Online Services
2015-04-15 15:03 - 2011-08-16 13:26 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2015-04-15 15:03 - 2011-02-11 19:00 - 00000000 ____D () C:\Windows\Panther
2015-04-15 15:02 - 2009-07-14 06:45 - 00276488 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-09 02:58 - 2011-08-16 13:11 - 17176128 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-04-09 02:58 - 2011-08-16 13:11 - 14617288 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-04-09 02:58 - 2011-08-16 13:11 - 12689592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-04-09 02:58 - 2011-08-16 13:11 - 03317344 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-04-09 02:58 - 2011-08-16 13:11 - 00029329 _____ () C:\Windows\system32\nvinfo.pb
2015-04-08 23:30 - 2011-03-30 10:45 - 06841488 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-04-08 23:30 - 2011-03-30 10:45 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-04-08 23:30 - 2011-03-30 10:45 - 00936264 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-04-08 23:30 - 2011-03-30 10:45 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-04-08 23:30 - 2011-03-30 10:45 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-04-08 23:30 - 2011-03-30 10:44 - 03478344 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll

==================== Files in the root of some directories =======

2015-04-16 19:11 - 2015-04-16 19:11 - 0007642 _____ () C:\Users\HP\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\HP\AppData\Local\Temp\MSN3DDE.exe
C:\Users\HP\AppData\Local\Temp\nvStInst.exe
C:\Users\HP\AppData\Local\Temp\Quarantine.exe
C:\Users\HP\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-16 06:53

==================== End Of Log ============================

___________________________________________________________________
ADDOTION:


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-04-2015
Ran by HP at 2015-04-18 09:43:24
Running from C:\Users\HP\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Internet Security (Disabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
Adobe Flash Player 10 ActiveX (HKLM-x32\...\{18BBF24A-6D04-4CA4-B6B4-1CF372162EEC}) (Version: 10.2.152.32 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
Aktualizace NVIDIA 2.4.1.21 (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2215 - AVAST Software)
Battlefield 3™ (HKLM-x32\...\{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden
Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd)
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE - The Traitor Soul (x32 Version: 2.2.0.95 - WildTangent) Hidden
Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.4 - WildTangent)
HP Keyboard (HKLM-x32\...\{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}) (Version: 1.5.0.4 - Hewlett-Packard)
HP LinkUp (HKLM-x32\...\{C1AD9241-3ADD-483F-914D-071F3E50855A}) (Version: 2.01.026 - Hewlett-Packard)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Setup (HKLM-x32\...\{210A03F5-B2ED-4947-B27E-516F50CBB292}) (Version: 8.6.4530.3651 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13253.3682 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.5.0.0 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6325.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3609 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.3609 - CyberLink Corp.) Hidden
Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS)
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 37.0.1 (x86 cs) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 cs)) (Version: 37.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.1 - Mozilla)
Mystery P.I. - Stolen in San Francisco (x32 Version: 2.2.0.95 - WildTangent) Hidden
Namco All-Stars PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
Norton Internet Security (HKLM-x32\...\NIS) (Version: 18.7.0.13 - Symantec Corporation)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 350.12 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 349.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 349.95 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0324 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0324 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.12.2862 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 350.12 (Version: 350.12 - NVIDIA Corporation) Hidden
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.35 - PDF Complete, Inc)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4817 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.4817 - CyberLink Corp.) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Recovery Manager (x32 Version: 5.5.3621 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\...\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Slingo Supreme (x32 Version: 2.2.0.95 - WildTangent) Hidden
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.0 - VideoLAN)
Watch_Dogs - Complete Edition verze 1.06.329 (HKLM-x32\...\{914F68F5-BE18-46C5-A7F7-EBC155F9F45A}_is1) (Version: 1.06.329 - )
WildTangent Games App (HP Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 5.21 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0D88C600-B96B-4231-9484-DC6B97A182E8} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-31] ()
Task: {221C2EC9-824F-471E-836D-900575ADAE4E} - System32\Tasks\Symantec\Norton Error Processor 18.7.0.13 => C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\SymErr.exe [2012-01-28] (Symantec Corporation)
Task: {27CDF0E3-1FA4-469B-AF0C-55D415299BE9} - System32\Tasks\SetupManager => C:\Program Files (x86)\Hewlett-Packard\Setup Manager\toaster.exe [2011-03-04] (Microsoft)
Task: {3CBD6B42-70DA-403C-8917-45073AA55CA6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-15] (Google Inc.)
Task: {5EDF571D-9280-4D4F-8446-252598AD292F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {AC97396B-0A0B-44E6-85F2-CF24B75C8547} - System32\Tasks\RMCreator => C:\Program Files (x86)\Hewlett-Packard\Recovery\Reminder.exe [2010-12-22] (CyberLink)
Task: {BDF74688-7EEB-4E01-9027-075A6B8C39B6} - System32\Tasks\Symantec\Norton Error Analyzer 18.7.0.13 => C:\Program Files (x86)\Norton Internet Security\Engine\18.7.0.13\SymErr.exe [2012-01-28] (Symantec Corporation)
Task: {CCB9F774-71E3-448C-9823-36BAD58B036E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {D680747D-A658-4942-9CE2-89A452D2BEFE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-16] (Avast Software s.r.o.)
Task: {DEC72B33-3CA8-4A77-B4D9-22DE1A4F5A94} - System32\Tasks\HPOSIAPP64 => C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe [2009-02-28] ()
Task: {FD62F768-D3A1-4529-9453-44E3F866AB9C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-15] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2015-04-15 17:00 - 2015-04-15 18:26 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-04-15 17:48 - 2015-04-08 23:30 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2011-08-16 13:26 - 2009-02-28 04:13 - 00053248 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
2015-04-16 05:19 - 2015-04-16 05:19 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-16 05:19 - 2015-04-16 05:19 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-04-17 13:51 - 2015-04-17 13:51 - 02926080 _____ () C:\Program Files\AVAST Software\Avast\defs\15041700\algo.dll
2015-04-15 17:37 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-04-16 05:19 - 2015-04-16 05:19 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2011-08-16 13:26 - 2009-02-20 02:22 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\WMINPUT.DLL
2015-04-15 15:32 - 2015-04-15 15:32 - 01007104 _____ () C:\Program Files (x86)\Origin\platforms\qwindows.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00023552 _____ () C:\Program Files (x86)\Origin\imageformats\qgif.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00024576 _____ () C:\Program Files (x86)\Origin\imageformats\qico.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00216576 _____ () C:\Program Files (x86)\Origin\imageformats\qjpeg.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00261120 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00019456 _____ () C:\Program Files (x86)\Origin\imageformats\qtga.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00337408 _____ () C:\Program Files (x86)\Origin\imageformats\qtiff.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00018944 _____ () C:\Program Files (x86)\Origin\imageformats\qwbmp.dll
2015-04-15 15:32 - 2015-04-15 15:32 - 00228352 _____ () C:\Program Files (x86)\Origin\mediaservice\wmfengine.dll
2015-04-15 18:41 - 2015-04-15 18:41 - 16863920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-512532572-2427873822-1548518363-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HP\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-512532572-2427873822-1548518363-500 - Administrator - Disabled)
Guest (S-1-5-21-512532572-2427873822-1548518363-501 - Limited - Disabled)
HP (S-1-5-21-512532572-2427873822-1548518363-1000 - Administrator - Enabled) => C:\Users\HP

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/17/2015 09:59:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Název chybujícího modulu: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Kód výjimky: 0xc0000005
Posun chyby: 0x00917049
ID chybujícího procesu: 0xbe0
Čas spuštění chybující aplikace: 0xbf3.exe0
Cesta k chybující aplikaci: bf3.exe1
Cesta k chybujícímu modulu: bf3.exe2
ID zprávy: bf3.exe3

Error: (04/17/2015 09:47:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/16/2015 10:21:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Název chybujícího modulu: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Kód výjimky: 0xc0000005
Posun chyby: 0x0133655d
ID chybujícího procesu: 0x2944
Čas spuštění chybující aplikace: 0xbf3.exe0
Cesta k chybující aplikaci: bf3.exe1
Cesta k chybujícímu modulu: bf3.exe2
ID zprávy: bf3.exe3

Error: (04/16/2015 09:22:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.17514, časové razítko: 0x4ce7ba58
Kód výjimky: 0xc0000005
Posun chyby: 0x00038da9
ID chybujícího procesu: 0xc5c
Čas spuštění chybující aplikace: 0xbf3.exe0
Cesta k chybující aplikaci: bf3.exe1
Cesta k chybujícímu modulu: bf3.exe2
ID zprávy: bf3.exe3

Error: (04/15/2015 06:21:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/15/2015 06:18:46 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0]

Error: (04/15/2015 05:19:42 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: HP-HP)
Description: Aplikaci nebo službu Panel nástrojů Bing nelze ukončit.

Error: (04/15/2015 03:04:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
.

Error: (04/15/2015 03:04:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/15/2015 03:03:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>. Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
.


System errors:
=============
Error: (04/18/2015 03:49:45 AM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (04/17/2015 09:49:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba HP Health Check Service neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (04/17/2015 09:45:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba zařazování tisku neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (04/17/2015 09:45:24 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba Spooler se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (04/17/2015 09:44:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Windows Presentation Foundation Font Cache 3.0.0.0 byla neočekávaně ukončena. Tento stav nastal již 2krát.

Error: (04/17/2015 09:44:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (04/17/2015 09:44:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (04/17/2015 09:44:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Presentation Foundation Font Cache 3.0.0.0 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.

Error: (04/17/2015 09:44:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba PnkBstrA byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/17/2015 09:44:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Management and Security Application User Notification Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


Microsoft Office Sessions:
=========================
Error: (04/17/2015 09:59:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bf3.exe1.6.0.0511c9356bf3.exe1.6.0.0511c9356c000000500917049be001d07948ed58d44dC:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exeC:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe31cac727-e53c-11e4-a762-e06995d0fdb8

Error: (04/17/2015 09:47:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/16/2015 10:21:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bf3.exe1.6.0.0511c9356bf3.exe1.6.0.0511c9356c00000050133655d294401d0787dba7b7b38C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exeC:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe1854d1fe-e476-11e4-8fbc-e06995d0fdb8

Error: (04/16/2015 09:22:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bf3.exe1.6.0.0511c9356ntdll.dll6.1.7601.175144ce7ba58c000000500038da9c5c01d0787a9ba08b81C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exeC:\Windows\SysWOW64\ntdll.dlle00b5250-e46d-11e4-8fbc-e06995d0fdb8

Error: (04/15/2015 06:21:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/15/2015 06:18:46 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcSSAU restarted too many times in a short period. Aborting. [0]

Error: (04/15/2015 05:19:42 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: HP-HP)
Description: 1C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\mswinext.exePanel nástrojů Bing0211754880

Error: (04/15/2015 03:04:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: http://www.download.windowsupdate.com/m ... stl.cabPři ověření se systémovými hodinami nebo časovým razítkem podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.

Error: (04/15/2015 03:04:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/15/2015 03:03:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: http://www.download.windowsupdate.com/m ... stl.cabPři ověření se systémovými hodinami nebo časovým razítkem podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2500 CPU @ 3.30GHz
Percentage of memory in use: 51%
Total physical RAM: 4076.32 MB
Available physical RAM: 1989.4 MB
Total Pagefile: 8150.85 MB
Available Pagefile: 5325.93 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:820.9 GB) (Free:699.36 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:12.85 GB) (Free:1.58 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive j: (Nový svazek) (Fixed) (Total:97.66 GB) (Free:97.56 GB) NTFS
Drive l: (Nové) (CDROM) (Total:2.04 GB) (Free:0 GB) UDF
Drive m: () (CDROM) (Total:17.27 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: D989473B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=820.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=97.7 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=12.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 09:00
od Tulipan
Mbrscan:

Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows 7 Service Pack 1 (64 bit)
PROCESSOR      : Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
BOOT           : Normal Boot
DATE           : 2015/04/18 (ISO 8601) at 09:53:39
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __Hitachi HDS721010CLA (JP4O)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : NO
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

Device\Harddisk0\DR0	931.5 Go  [Fixed] ==> HP Recovery Manager .

MBR_MD5   : DC644E62E3C3DAF964A2CE50B3C75559
MBR_SHA1  : BFFE0FC2545E822077BC60FC68A272C6C6B24919

Device\Harddisk0\Partition1	100.0 Mo  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	820.9 Go  	0x07 NTFS / HPFS
Device\Harddisk0\Partition3	12.85 Go  	0x07 NTFS / HPFS
Device\Harddisk0\Partition4	97.66 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\Windows\system32\hal.dll => Invisible on the disk
ADDRESS : 0x031FD000
SIZE    : 292.0 Ko

DRIVER  : C:\Windows\system32\kdcom.dll => Invisible on the disk
ADDRESS : 0x00BB2000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\mcupdate_GenuineIntel.dll => Invisible on the disk
ADDRESS : 0x00C63000
SIZE    : 316.0 Ko

DRIVER  : C:\Windows\system32\CLFS.SYS => Invisible on the disk
ADDRESS : 0x00CC6000
SIZE    : 376.0 Ko

DRIVER  : C:\Windows\system32\CI.dll => Invisible on the disk
ADDRESS : 0x00D24000
SIZE    : 768.0 Ko

DRIVER  : C:\Windows\system32\drivers\Wdf01000.sys => Invisible on the disk
ADDRESS : 0x00E7F000
SIZE    : 656.0 Ko

DRIVER  : C:\Windows\system32\drivers\WDFLDR.SYS => Invisible on the disk
ADDRESS : 0x00F23000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\drivers\ACPI.sys => Invisible on the disk
ADDRESS : 0x00F32000
SIZE    : 348.0 Ko

DRIVER  : C:\Windows\system32\drivers\WMILIB.SYS => Invisible on the disk
ADDRESS : 0x00F89000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\msisadrv.sys => Invisible on the disk
ADDRESS : 0x00F92000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\drivers\pci.sys => Invisible on the disk
ADDRESS : 0x00F9C000
SIZE    : 204.0 Ko

DRIVER  : C:\Windows\system32\drivers\vdrvroot.sys => Invisible on the disk
ADDRESS : 0x00FCF000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\System32\drivers\partmgr.sys => Invisible on the disk
ADDRESS : 0x00FDC000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\drivers\volmgr.sys => Invisible on the disk
ADDRESS : 0x00E00000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\System32\drivers\volmgrx.sys => Invisible on the disk
ADDRESS : 0x00E15000
SIZE    : 368.0 Ko

DRIVER  : C:\Windows\System32\drivers\mountmgr.sys => Invisible on the disk
ADDRESS : 0x00DE4000
SIZE    : 104.0 Ko

DRIVER  : C:\Windows\system32\drivers\iaStor.sys => Invisible on the disk
ADDRESS : 0x0104A000
SIZE    : 1.33 Mo

DRIVER  : C:\Windows\system32\drivers\amdxata.sys => Invisible on the disk
ADDRESS : 0x0119E000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\system32\drivers\fltmgr.sys => Invisible on the disk
ADDRESS : 0x011A9000
SIZE    : 304.0 Ko

DRIVER  : C:\Windows\system32\drivers\NISx64\1207000.00D\SYMDS64.SYS => Invisible on the disk
ADDRESS : 0x012FF000
SIZE    : 452.0 Ko

DRIVER  : C:\Windows\system32\drivers\fileinfo.sys => Invisible on the disk
ADDRESS : 0x01370000
SIZE    : 80.0 Ko

DRIVER  : C:\Windows\system32\drivers\NISx64\1207000.00D\SYMEFA64.SYS => Invisible on the disk
ADDRESS : 0x01200000
SIZE    : 912.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Ntfs.sys => Invisible on the disk
ADDRESS : 0x0141C000
SIZE    : 1.64 Mo

DRIVER  : C:\Windows\System32\Drivers\msrpc.sys => Invisible on the disk
ADDRESS : 0x01384000
SIZE    : 376.0 Ko

DRIVER  : C:\Windows\System32\Drivers\ksecdd.sys => Invisible on the disk
ADDRESS : 0x015BF000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\System32\Drivers\cng.sys => Invisible on the disk
ADDRESS : 0x0162B000
SIZE    : 456.0 Ko

DRIVER  : C:\Windows\System32\drivers\pcw.sys => Invisible on the disk
ADDRESS : 0x0169D000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Fs_Rec.sys => Invisible on the disk
ADDRESS : 0x016AE000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\drivers\ndis.sys => Invisible on the disk
ADDRESS : 0x016B8000
SIZE    : 972.0 Ko

DRIVER  : C:\Windows\system32\drivers\NETIO.SYS => Invisible on the disk
ADDRESS : 0x00C00000
SIZE    : 384.0 Ko

DRIVER  : C:\Windows\System32\Drivers\ksecpkg.sys => Invisible on the disk
ADDRESS : 0x017AB000
SIZE    : 172.0 Ko

DRIVER  : C:\Windows\System32\drivers\tcpip.sys => Invisible on the disk
ADDRESS : 0x018A0000
SIZE    : 2.02 Mo

DRIVER  : C:\Windows\System32\drivers\fwpkclnt.sys => Invisible on the disk
ADDRESS : 0x01AA4000
SIZE    : 296.0 Ko

DRIVER  : C:\Windows\system32\drivers\volsnap.sys => Invisible on the disk
ADDRESS : 0x01AEE000
SIZE    : 304.0 Ko

DRIVER  : C:\Windows\System32\Drivers\spldr.sys => Invisible on the disk
ADDRESS : 0x01B3A000
SIZE    : 32.0 Ko

DRIVER  : C:\Windows\System32\drivers\rdyboost.sys => Invisible on the disk
ADDRESS : 0x01B42000
SIZE    : 232.0 Ko

DRIVER  : C:\Windows\System32\Drivers\mup.sys => Invisible on the disk
ADDRESS : 0x01B7C000
SIZE    : 72.0 Ko

DRIVER  : C:\Windows\System32\drivers\hwpolicy.sys => Invisible on the disk
ADDRESS : 0x01B8E000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\fvevol.sys => Invisible on the disk
ADDRESS : 0x01B97000
SIZE    : 232.0 Ko

DRIVER  : C:\Windows\system32\drivers\disk.sys => Invisible on the disk
ADDRESS : 0x01BD1000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\drivers\CLASSPNP.SYS => Invisible on the disk
ADDRESS : 0x01800000
SIZE    : 192.0 Ko

DRIVER  : C:\Windows\System32\Drivers\aswVmm.sys => Invisible on the disk
ADDRESS : 0x01830000
SIZE    : 272.0 Ko

DRIVER  : C:\Windows\System32\Drivers\aswRvrt.sys => Invisible on the disk
ADDRESS : 0x01874000
SIZE    : 76.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\cdrom.sys => Invisible on the disk
ADDRESS : 0x043AC000
SIZE    : 168.0 Ko

DRIVER  : C:\Windows\system32\drivers\aswSnx.sys => Invisible on the disk
ADDRESS : 0x0444A000
SIZE    : 1.02 Mo

DRIVER  : C:\Windows\system32\drivers\aswSP.sys => Invisible on the disk
ADDRESS : 0x0454E000
SIZE    : 460.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Null.SYS => Invisible on the disk
ADDRESS : 0x045C1000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Beep.SYS => Invisible on the disk
ADDRESS : 0x045CA000
SIZE    : 28.0 Ko

DRIVER  : C:\Windows\System32\drivers\vga.sys => Invisible on the disk
ADDRESS : 0x045D1000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\System32\drivers\VIDEOPRT.SYS => Invisible on the disk
ADDRESS : 0x04400000
SIZE    : 148.0 Ko

DRIVER  : C:\Windows\System32\drivers\watchdog.sys => Invisible on the disk
ADDRESS : 0x04425000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\RDPCDD.sys => Invisible on the disk
ADDRESS : 0x04435000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\rdpencdd.sys => Invisible on the disk
ADDRESS : 0x0443E000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\drivers\rdprefmp.sys => Invisible on the disk
ADDRESS : 0x045DF000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Msfs.SYS => Invisible on the disk
ADDRESS : 0x045E8000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\System32\Drivers\Npfs.SYS => Invisible on the disk
ADDRESS : 0x043D6000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\tdx.sys => Invisible on the disk
ADDRESS : 0x04200000
SIZE    : 136.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\TDI.SYS => Invisible on the disk
ADDRESS : 0x045F3000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\system32\drivers\afd.sys => Invisible on the disk
ADDRESS : 0x04604000
SIZE    : 548.0 Ko

DRIVER  : C:\Windows\system32\drivers\aswRdr2.sys => Invisible on the disk
ADDRESS : 0x0468D000
SIZE    : 104.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\netbt.sys => Invisible on the disk
ADDRESS : 0x046A7000
SIZE    : 276.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\wfplwf.sys => Invisible on the disk
ADDRESS : 0x046EC000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\pacer.sys => Invisible on the disk
ADDRESS : 0x046F5000
SIZE    : 152.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\netbios.sys => Invisible on the disk
ADDRESS : 0x0471B000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\wanarp.sys => Invisible on the disk
ADDRESS : 0x0472A000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\system32\drivers\termdd.sys => Invisible on the disk
ADDRESS : 0x04745000
SIZE    : 80.0 Ko

DRIVER  : C:\Windows\system32\drivers\NISx64\1207000.00D\Ironx64.SYS => Invisible on the disk
ADDRESS : 0x04759000
SIZE    : 180.0 Ko

DRIVER  : C:\Windows\system32\drivers\NISx64\1207000.00D\SRTSPX64.SYS => Invisible on the disk
ADDRESS : 0x04786000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rdbss.sys => Invisible on the disk
ADDRESS : 0x0479C000
SIZE    : 324.0 Ko

DRIVER  : C:\Windows\system32\drivers\nsiproxy.sys => Invisible on the disk
ADDRESS : 0x047ED000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\drivers\mssmbios.sys => Invisible on the disk
ADDRESS : 0x04222000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\system32\Drivers\SYMEVENT64x86.SYS => Invisible on the disk
ADDRESS : 0x04AFB000
SIZE    : 216.0 Ko

DRIVER  : C:\Windows\System32\drivers\discache.sys => Invisible on the disk
ADDRESS : 0x04BD1000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dfsc.sys => Invisible on the disk
ADDRESS : 0x04BE0000
SIZE    : 120.0 Ko

DRIVER  : C:\Windows\system32\drivers\blbdrive.sys => Invisible on the disk
ADDRESS : 0x04A00000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\tunnel.sys => Invisible on the disk
ADDRESS : 0x04C00000
SIZE    : 152.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\nvlddmkm.sys => Invisible on the disk
ADDRESS : 0x058C5000
SIZE    : 10.22 Mo

DRIVER  : C:\Windows\System32\drivers\dxgkrnl.sys => Invisible on the disk
ADDRESS : 0x062FD000
SIZE    : 976.0 Ko

DRIVER  : C:\Windows\System32\drivers\dxgmms1.sys => Invisible on the disk
ADDRESS : 0x05800000
SIZE    : 280.0 Ko

DRIVER  : C:\Windows\system32\drivers\HDAudBus.sys => Invisible on the disk
ADDRESS : 0x05846000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\drivers\HECIx64.sys => Invisible on the disk
ADDRESS : 0x0586A000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\drivers\usbehci.sys => Invisible on the disk
ADDRESS : 0x0587B000
SIZE    : 68.0 Ko

DRIVER  : C:\Windows\system32\drivers\USBPORT.SYS => Invisible on the disk
ADDRESS : 0x04E43000
SIZE    : 344.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\Rt64win7.sys => Invisible on the disk
ADDRESS : 0x04E99000
SIZE    : 412.0 Ko

DRIVER  : C:\Windows\system32\drivers\tixhci.sys => Invisible on the disk
ADDRESS : 0x04F00000
SIZE    : 384.0 Ko

DRIVER  : C:\Windows\system32\drivers\intelppm.sys => Invisible on the disk
ADDRESS : 0x04F60000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\drivers\CompositeBus.sys => Invisible on the disk
ADDRESS : 0x04F76000
SIZE    : 64.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\AgileVpn.sys => Invisible on the disk
ADDRESS : 0x04F86000
SIZE    : 88.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rasl2tp.sys => Invisible on the disk
ADDRESS : 0x04F9C000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\ndistapi.sys => Invisible on the disk
ADDRESS : 0x04FC0000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\ndiswan.sys => Invisible on the disk
ADDRESS : 0x04FCC000
SIZE    : 188.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\raspppoe.sys => Invisible on the disk
ADDRESS : 0x04E00000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\raspptp.sys => Invisible on the disk
ADDRESS : 0x04E1B000
SIZE    : 132.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rassstp.sys => Invisible on the disk
ADDRESS : 0x0588C000
SIZE    : 104.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\kbdclass.sys => Invisible on the disk
ADDRESS : 0x058A6000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mouclass.sys => Invisible on the disk
ADDRESS : 0x058B5000
SIZE    : 60.0 Ko

DRIVER  : C:\Windows\system32\drivers\swenum.sys => Invisible on the disk
ADDRESS : 0x04E3C000
SIZE    : 8.0 Ko

DRIVER  : C:\Windows\system32\drivers\ks.sys => Invisible on the disk
ADDRESS : 0x01000000
SIZE    : 268.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\umbus.sys => Invisible on the disk
ADDRESS : 0x04C26000
SIZE    : 72.0 Ko

DRIVER  : C:\Windows\system32\drivers\nvvad64v.sys => Invisible on the disk
ADDRESS : 0x063F1000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\system32\drivers\portcls.sys => Invisible on the disk
ADDRESS : 0x04A11000
SIZE    : 244.0 Ko

DRIVER  : C:\Windows\system32\drivers\drmk.sys => Invisible on the disk
ADDRESS : 0x017D6000
SIZE    : 136.0 Ko

DRIVER  : C:\Windows\system32\drivers\ksthunk.sys => Invisible on the disk
ADDRESS : 0x04C38000
SIZE    : 24.0 Ko

DRIVER  : C:\Windows\system32\drivers\usbhub.sys => Invisible on the disk
ADDRESS : 0x0527D000
SIZE    : 360.0 Ko

DRIVER  : C:\Windows\System32\Drivers\NDProxy.SYS => Invisible on the disk
ADDRESS : 0x052D7000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\drivers\nvhda64v.sys => Invisible on the disk
ADDRESS : 0x052EC000
SIZE    : 208.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\stwrt64.sys => Invisible on the disk
ADDRESS : 0x05320000
SIZE    : 524.0 Ko

DRIVER  : C:\Windows\system32\drivers\tihub3.sys => Invisible on the disk
ADDRESS : 0x053A3000
SIZE    : 136.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\USBSTOR.SYS => Invisible on the disk
ADDRESS : 0x053C5000
SIZE    : 108.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\USBD.SYS => Invisible on the disk
ADDRESS : 0x053E0000
SIZE    : 8.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\usbccgp.sys => Invisible on the disk
ADDRESS : 0x053E2000
SIZE    : 116.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\hidusb.sys => Invisible on the disk
ADDRESS : 0x05200000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\HIDCLASS.SYS => Invisible on the disk
ADDRESS : 0x0520E000
SIZE    : 100.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\HIDPARSE.SYS => Invisible on the disk
ADDRESS : 0x05227000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\kbdhid.sys => Invisible on the disk
ADDRESS : 0x05230000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mouhid.sys => Invisible on the disk
ADDRESS : 0x0523E000
SIZE    : 52.0 Ko

DRIVER  : C:\Windows\System32\Drivers\crashdmp.sys => Invisible on the disk
ADDRESS : 0x0524B000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\System32\win32k.sys => Invisible on the disk
ADDRESS : 0x000B0000
SIZE    : 3.07 Mo

DRIVER  : C:\Windows\System32\drivers\Dxapi.sys => Invisible on the disk
ADDRESS : 0x0526C000
SIZE    : 48.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\monitor.sys => Invisible on the disk
ADDRESS : 0x04C3E000
SIZE    : 56.0 Ko

DRIVER  : C:\Windows\System32\TSDDD.dll => Invisible on the disk
ADDRESS : 0x004D0000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\System32\cdd.dll => Invisible on the disk
ADDRESS : 0x00720000
SIZE    : 156.0 Ko

DRIVER  : C:\Windows\system32\drivers\luafv.sys => Invisible on the disk
ADDRESS : 0x04381000
SIZE    : 140.0 Ko

DRIVER  : C:\Windows\system32\drivers\aswMonFlt.sys => Invisible on the disk
ADDRESS : 0x01600000
SIZE    : 140.0 Ko

DRIVER  : C:\Windows\system32\drivers\WudfPf.sys => Invisible on the disk
ADDRESS : 0x015DA000
SIZE    : 132.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\lltdio.sys => Invisible on the disk
ADDRESS : 0x03D00000
SIZE    : 84.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\rspndr.sys => Invisible on the disk
ADDRESS : 0x03D15000
SIZE    : 96.0 Ko

DRIVER  : C:\Windows\system32\drivers\HTTP.sys => Invisible on the disk
ADDRESS : 0x03D2D000
SIZE    : 804.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\bowser.sys => Invisible on the disk
ADDRESS : 0x03C00000
SIZE    : 120.0 Ko

DRIVER  : C:\Windows\System32\drivers\mpsdrv.sys => Invisible on the disk
ADDRESS : 0x03C1E000
SIZE    : 96.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb.sys => Invisible on the disk
ADDRESS : 0x03C36000
SIZE    : 180.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb10.sys => Invisible on the disk
ADDRESS : 0x03C63000
SIZE    : 308.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\mrxsmb20.sys => Invisible on the disk
ADDRESS : 0x03CB0000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\drivers\aswHwid.sys => Invisible on the disk
ADDRESS : 0x03DF6000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\system32\drivers\peauth.sys => Invisible on the disk
ADDRESS : 0x07C2D000
SIZE    : 664.0 Ko

DRIVER  : C:\Windows\System32\Drivers\secdrv.SYS => Invisible on the disk
ADDRESS : 0x07CD3000
SIZE    : 44.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\srvnet.sys => Invisible on the disk
ADDRESS : 0x07CDE000
SIZE    : 196.0 Ko

DRIVER  : C:\Windows\System32\drivers\tcpipreg.sys => Invisible on the disk
ADDRESS : 0x07D0F000
SIZE    : 72.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\srv2.sys => Invisible on the disk
ADDRESS : 0x07D21000
SIZE    : 428.0 Ko

DRIVER  : C:\Windows\System32\DRIVERS\srv.sys => Invisible on the disk
ADDRESS : 0x082FE000
SIZE    : 612.0 Ko

DRIVER  : C:\Windows\System32\Drivers\NISx64\1207000.00D\SYMNETS.SYS => Invisible on the disk
ADDRESS : 0x08397000
SIZE    : 412.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\WUDFRd.sys => Invisible on the disk
ADDRESS : 0x08200000
SIZE    : 196.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\dtlitescsibus.sys => Invisible on the disk
ADDRESS : 0x082AC000
SIZE    : 36.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\udfs.sys => Invisible on the disk
ADDRESS : 0x0823B000
SIZE    : 340.0 Ko

DRIVER  : C:\Windows\system32\DRIVERS\cdfs.sys => Invisible on the disk
ADDRESS : 0x082B5000
SIZE    : 116.0 Ko

DRIVER  : C:\Windows\System32\smss.exe => Invisible on the disk
ADDRESS : 0x475A0000
SIZE    : 128.0 Ko

Device\Harddisk0\DR0 => 7 MBR Code found in sector 2
SystemStartOptions :  NOEXECUTE=OPTIN

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D0 BC 00 7C FB 8E C0 8E D8 8B F4 BF 00   3À.м.|û.À.Ø.ô¿.
0x00000010   06 B9 00 02 FC F3 A4 EA 60 06 00 00 00 00 00 00   .¹..üó¤ê`.......
0x00000020   52 65 63 6F 76 65 72 79 4D 67 72 20 00 10 D5 72   RecoveryMgr ..Õr
0x00000030   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000040   00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D 0A   ................
0x00000050   00 00 00 00 57 00 00 00 FF FF FF FF FF FF FF FF   ....W...........
0x00000060   86 4C BD BE 30 06 AC B4 0E 33 DB CD 10 0A C0 75   .L½¾0.¬´.3ÛÍ..Àu
0x00000070   F5 E3 0B FE 06 13 06 53 53 E8 70 00 EB 39 B4 11   õã.þ...SSèp.ë9´.
0x00000080   CD 16 74 2D B4 10 CD 16 80 FC 85 75 F1 3C 00 75   Í.t-´.Í..ü.uñ<.u
0x00000090   ED EB 24 8B 16 6C 04 FA 66 A1 1C 06 BF 54 06 B1   íë$..l.úf¡..¿T.±
0x000000A0   03 F2 66 AF FB 3D 00 00 6C 04 2B C2 83 F8 24 76   .òf¯û=..l.+Â.ø$v
0x000000B0   E6 B0 01 84 C0 75 1C BB C6 7D 66 8B 37 66 8B 3E   æ°..Àu.»Æ}f.7f.>
0x000000C0   2C 06 66 3B F7 74 07 80 C3 10 73 EE EB 05 BB 28   ,.f;÷t..Ã.sîë.»(
0x000000D0   06 EB 10 BB C2 7D 80 7F FC 00 78 07 80 C3 10 73   .ë.»Â}..ü.x..Ã.s
0x000000E0   F5 EB FE 66 FF 77 04 E8 02 00 FF E4 C8 10 00 00   õëþf.w.è...äÈ...
0x000000F0   B4 08 B2 80 CD 13 8A C1 24 3F FE C6 8A D8 F6 E6   ´.².Í..Á$?þÆ.Øöæ
0x00000100   C0 E9 06 86 CD 41 91 F7 E1 39 56 06 8B 56 06 8B   Àé..ÍA.÷á9V..V..
0x00000110   46 04 73 1C F7 F1 91 92 F6 F3 86 CD C0 E1 06 02   F.s.÷ñ..öó.ÍÀá..
0x00000120   CC 41 8A F0 B8 01 02 BB 00 7C 86 26 13 06 EB 14   ÌA.ð¸..».|.&..ë.
0x00000130   83 C4 10 0E 0E 52 50 0E 68 00 7C 6A 01 6A 10 8B   .Ä...RP.h.|j.j..
0x00000140   F4 B8 00 42 B2 80 CD 13 C9 C2 04 00 1E 50 53 0E   ô¸.B².Í.ÉÂ...PS.
0x00000150   1F BB 1B 06 A0 17 04 24 0F 88 47 04 E4 60 3C E0   .».....$..G.ä`<à
0x00000160   74 1A 3C 1D 74 10 3C 2A 74 0C 3C 36 74 08 3C 38   t.<.t.<*t.<6t.<8
0x00000170   74 04 84 C0 79 06 66 83 27 00 EB 06 FE 07 02 1F   t..Ày.f.'.ë.þ...
0x00000180   88 07 5B 58 1F EA 00 00 00 00 00 00 00 00 00 00   ..[X.ê..........
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 00 00 00 3B 47 89 D9 00 00 80 20   ........;G.Ù... 
0x000001C0   21 00 07 DF 13 0C 00 08 00 00 00 20 03 00 00 DF   !..ß....... ...ß
0x000001D0   14 0C 07 FE FF FF 00 28 03 00 00 E8 9C 66 00 FE   ...þ...(...è.f.þ
0x000001E0   FF FF 0F FE FF FF 00 10 A0 66 00 00 35 0C 00 FE   ...þ.....f..5..þ
0x000001F0   FF FF 07 FE FF FF 00 10 D5 72 00 50 9B 01 55 AA   ...þ....Õr.P..Uª

__________________________16_BIT_ASM_CODE
   
0x0000    33c0            XOR AX, AX   
0x0002    8ed0            MOV SS, AX   
0x0004    bc 007c         MOV SP, 0x7c00   
0x0007    fb              STI   
0x0008    8ec0            MOV ES, AX   
0x000A    8ed8            MOV DS, AX   
0x000C    8bf4            MOV SI, SP   
0x000E    bf 0006         MOV DI, 0x600   
0x0011    b9 0002         MOV CX, 0x200   
0x0014    fc              CLD   
0x0015    f3 a4           REP MOVSB   
0x0017    ea 6006 0000    JMP FAR 0x0:0x660   
0x001C    0000            ADD [BX+SI], AL   
0x001E    0000            ADD [BX+SI], AL   
0x0020    52              PUSH DX   
0x0021    65 636f 76      ARPL GS:[BX+0x76], BP   
0x0025    65              DB 0x65   
0x0025    65 72 79        JB 0xa1   
0x0028    4d              DEC BP   
0x0029    67              DB 0x67   
0x0029    67 72 20        JB 0x4c   
0x002C    0010            ADD [BX+SI], DL   
0x002E    d5 72           AAD 0x72   
0x0030    0000            ADD [BX+SI], AL   
0x0032    0000            ADD [BX+SI], AL   
0x0034    0000            ADD [BX+SI], AL   
0x0036    0000            ADD [BX+SI], AL   
0x0038    0000            ADD [BX+SI], AL   
0x003A    0000            ADD [BX+SI], AL   
0x003C    0000            ADD [BX+SI], AL   
0x003E    0000            ADD [BX+SI], AL   
0x0040    0000            ADD [BX+SI], AL   
0x0042    0000            ADD [BX+SI], AL   
0x0044    0000            ADD [BX+SI], AL   
0x0046    0000            ADD [BX+SI], AL   
0x0048    0000            ADD [BX+SI], AL   
0x004A    0000            ADD [BX+SI], AL   
0x004C    0000            ADD [BX+SI], AL   
0x004E    0d 0a00         OR AX, 0xa   
0x0051    0000            ADD [BX+SI], AL   
0x0053    0057 00         ADD [BX+0x0], DL   
0x0056    0000            ADD [BX+SI], AL   
0x0058    ff              DB 0xff   
0x0059    ff              DB 0xff   
0x005A    ff              DB 0xff   
0x005B    ff              DB 0xff   
0x005C    ff              DB 0xff   
0x005D    ff              DB 0xff   
0x005E    ff              DB 0xff   
0x005F    ff86 4cbd       INC WORD [BP-0x42b4]   
0x0063    be 3006         MOV SI, 0x630   
0x0066    ac              LODSB   
0x0067    b4 0e           MOV AH, 0xe   
0x0069    33db            XOR BX, BX   
0x006B    cd 10           INT 0x10   
0x006D    0ac0            OR AL, AL   
0x006F    75 f5           JNZ 0x66   
0x0071    e3 0b           JCXZ 0x7e   
0x0073    fe06 1306       INC BYTE [0x613]   
0x0077    53              PUSH BX   
0x0078    53              PUSH BX   
0x0079    e8 7000         CALL 0xec   
0x007C    eb 39           JMP 0xb7   
0x007E    b4 11           MOV AH, 0x11   
0x0080    cd 16           INT 0x16   
0x0082    74 2d           JZ 0xb1   
0x0084    b4 10           MOV AH, 0x10   
0x0086    cd 16           INT 0x16   
0x0088    80fc 85         CMP AH, 0x85   
0x008B    75 f1           JNZ 0x7e   
0x008D    3c 00           CMP AL, 0x0   
0x008F    75 ed           JNZ 0x7e   
0x0091    eb 24           JMP 0xb7   
0x0093    8b16 6c04       MOV DX, [0x46c]   
0x0097    fa              CLI   
0x0098    66 a1 1c06      MOV EAX, [0x61c]   
0x009C    bf 5406         MOV DI, 0x654   
0x009F    b1 03           MOV CL, 0x3   
0x00A1    f2 66 af        REPNZ SCASD   
0x00A4    fb              STI   
0x00A5    3d 0000         CMP AX, 0x0   
0x00A8    6c              INSB   
0x00A9    04 2b           ADD AL, 0x2b   
0x00AB    c2 83f8         RET 0xf883   
0x00AE    24 76           AND AL, 0x76   
0x00B0    e6 b0           OUT 0xb0, AL   
0x00B2    0184 c075       ADD [SI+0x75c0], AX   
0x00B6    1c bb           SBB AL, 0xbb   
0x00B8    c6              DB 0xc6   
0x00B9    7d 66           JGE 0x121   
0x00BB    8b37            MOV SI, [BX]   
0x00BD    66 8b3e 2c06    MOV EDI, [0x62c]   
0x00C2    66 3bf7         CMP ESI, EDI   
0x00C5    74 07           JZ 0xce   
0x00C7    80c3 10         ADD BL, 0x10   
0x00CA    73 ee           JAE 0xba   
0x00CC    eb 05           JMP 0xd3   
0x00CE    bb 2806         MOV BX, 0x628   
0x00D1    eb 10           JMP 0xe3   
0x00D3    bb c27d         MOV BX, 0x7dc2   
0x00D6    807f fc 00      CMP BYTE [BX-0x4], 0x0   
0x00DA    78 07           JS 0xe3   
0x00DC    80c3 10         ADD BL, 0x10   
0x00DF    73 f5           JAE 0xd6   
0x00E1    eb fe           JMP 0xe1   
0x00E3    66 ff77 04      PUSH DWORD [BX+0x4]   
0x00E7    e8 0200         CALL 0xec   
0x00EA    ffe4            JMP SP   
0x00EC    c8 1000 00      ENTER 0x10, 0x0   
0x00F0    b4 08           MOV AH, 0x8   
0x00F2    b2 80           MOV DL, 0x80   
0x00F4    cd 13           INT 0x13   
0x00F6    8ac1            MOV AL, CL   
0x00F8    24 3f           AND AL, 0x3f   
0x00FA    fec6            INC DH   
0x00FC    8ad8            MOV BL, AL   
0x00FE    f6e6            MUL DH   
0x0100    c0e9 06         SHR CL, 0x6   
0x0103    86cd            XCHG CH, CL   
0x0105    41              INC CX   
0x0106    91              XCHG CX, AX   
0x0107    f7e1            MUL CX   
0x0109    3956 06         CMP [BP+0x6], DX   
0x010C    8b56 06         MOV DX, [BP+0x6]   
0x010F    8b46 04         MOV AX, [BP+0x4]   
0x0112    73 1c           JAE 0x130   
0x0114    f7f1            DIV CX   
0x0116    91              XCHG CX, AX   
0x0117    92              XCHG DX, AX   
0x0118    f6f3            DIV BL   
0x011A    86cd            XCHG CH, CL   
0x011C    c0e1 06         SHL CL, 0x6   
0x011F    02cc            ADD CL, AH   
0x0121    41              INC CX   
0x0122    8af0            MOV DH, AL   
0x0124    b8 0102         MOV AX, 0x201   
0x0127    bb 007c         MOV BX, 0x7c00   
0x012A    8626 1306       XCHG [0x613], AH   
0x012E    eb 14           JMP 0x144   
0x0130    83c4 10         ADD SP, 0x10   
0x0133    0e              PUSH CS   
0x0134    0e              PUSH CS   
0x0135    52              PUSH DX   
0x0136    50              PUSH AX   
0x0137    0e              PUSH CS   
0x0138    68 007c         PUSH 0x7c00   
0x013B    6a 01           PUSH 0x1   
0x013D    6a 10           PUSH 0x10   
0x013F    8bf4            MOV SI, SP   
0x0141    b8 0042         MOV AX, 0x4200   
0x0144    b2 80           MOV DL, 0x80   
0x0146    cd 13           INT 0x13   
0x0148    c9              LEAVE   
0x0149    c2 0400         RET 0x4   
0x014C    1e              PUSH DS   
0x014D    50              PUSH AX   
0x014E    53              PUSH BX   
0x014F    0e              PUSH CS   
0x0150    1f              POP DS   
0x0151    bb 1b06         MOV BX, 0x61b   
0x0154    a0 1704         MOV AL, [0x417]   
0x0157    24 0f           AND AL, 0xf   
0x0159    8847 04         MOV [BX+0x4], AL   
0x015C    e4 60           IN AL, 0x60   
0x015E    3c e0           CMP AL, 0xe0   
0x0160    74 1a           JZ 0x17c   
0x0162    3c 1d           CMP AL, 0x1d   
0x0164    74 10           JZ 0x176   
0x0166    3c 2a           CMP AL, 0x2a   
0x0168    74 0c           JZ 0x176   
0x016A    3c 36           CMP AL, 0x36   
0x016C    74 08           JZ 0x176   
0x016E    3c 38           CMP AL, 0x38   
0x0170    74 04           JZ 0x176   
0x0172    84c0            TEST AL, AL   
0x0174    79 06           JNS 0x17c   
0x0176    66 8327 00      AND DWORD [BX], 0x0   
0x017A    eb 06           JMP 0x182   
0x017C    fe07            INC BYTE [BX]   
0x017E    021f            ADD BL, [BX]   
0x0180    8807            MOV [BX], AL   
0x0182    5b              POP BX   
0x0183    58              POP AX   
0x0184    1f              POP DS   
0x0185    ea 0000 0000    JMP FAR 0x0:0x0   
0x018A    0000            ADD [BX+SI], AL   
0x018C    0000            ADD [BX+SI], AL   
0x018E    0000            ADD [BX+SI], AL   
0x0190    0000            ADD [BX+SI], AL   
0x0192    0000            ADD [BX+SI], AL   
0x0194    0000            ADD [BX+SI], AL   
0x0196    0000            ADD [BX+SI], AL   
0x0198    0000            ADD [BX+SI], AL   
0x019A    0000            ADD [BX+SI], AL   
0x019C    0000            ADD [BX+SI], AL   
0x019E    0000            ADD [BX+SI], AL   
0x01A0    0000            ADD [BX+SI], AL   
0x01A2    0000            ADD [BX+SI], AL   
0x01A4    0000            ADD [BX+SI], AL   
0x01A6    0000            ADD [BX+SI], AL   
0x01A8    0000            ADD [BX+SI], AL   
0x01AA    0000            ADD [BX+SI], AL   
0x01AC    0000            ADD [BX+SI], AL   
0x01AE    0000            ADD [BX+SI], AL   
0x01B0    0000            ADD [BX+SI], AL   
0x01B2    0000            ADD [BX+SI], AL   
0x01B4    0000            ADD [BX+SI], AL   
0x01B6    0000            ADD [BX+SI], AL   
0x01B8    3b47 89         CMP AX, [BX-0x77]   
0x01BB    d900            FLD DWORD [BX+SI]   
0x01BD    0080 2021       ADD [BX+SI+0x2120], AL   
0x01C1    0007            ADD [BX], AL   
0x01C3    df13            FIST WORD [BP+DI]   
0x01C5    0c 00           OR AL, 0x0   
0x01C7    0800            OR [BX+SI], AL   
0x01C9    0000            ADD [BX+SI], AL   
0x01CB    2003            AND [BP+DI], AL   
0x01CD    0000            ADD [BX+SI], AL   
0x01CF    df14            FIST WORD [SI]   
0x01D1    0c 07           OR AL, 0x7   
0x01D3    fe              DB 0xfe   
0x01D4    ff              DB 0xff   
0x01D5    ff00            INC WORD [BX+SI]   
0x01D7    2803            SUB [BP+DI], AL   
0x01D9    0000            ADD [BX+SI], AL   
0x01DB    e8 9c66         CALL 0x687a   
0x01DE    00fe            ADD DH, BH   
0x01E0    ff              DB 0xff   
0x01E1    ff0f            DEC WORD [BX]   
0x01E3    fe              DB 0xfe   
0x01E4    ff              DB 0xff   
0x01E5    ff00            INC WORD [BX+SI]   
0x01E7    10a0 6600       ADC [BX+SI+0x66], AH   
0x01EB    0035            ADD [DI], DH   
0x01ED    0c 00           OR AL, 0x0   
0x01EF    fe              DB 0xfe   
0x01F0    ff              DB 0xff   
0x01F1    ff07            INC WORD [BX]   
0x01F3    fe              DB 0xfe   
0x01F4    ff              DB 0xff   
0x01F5    ff00            INC WORD [BX+SI]   
0x01F7    10d5            ADC CH, DL   
0x01F9    72 00           JB 0x1fb   
0x01FB    50              PUSH AX   
0x01FC    9b              WAIT   
0x01FD    0155 aa         ADD [DI-0x56], DX   

Jdu do toho nouzáku takže MBRDUMP.txt dám do dalšího postu.

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 09:33
od Tulipan
MBRdump v příloze. Nedá mi to se nezeptat, díval jsem se do historie fora ( přes hledání :D ) a jsem první člověk, který MBRdump dělal. Jelikož jsem dost zvědavej tak jsem log otevřel ale tam byli jen kliky háky, nemusíte odpovídat pokud nechcete, jenom jsem trochu potřeboval ukojit zvědavost :).

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 11:11
od altrok
:arrow: Havet se neustale vyviji a proto hledame/ucime se nove a aktualni zpusoby detekce a likvidace haveti na nekolika svetovych bezpecnostnich forech, kde mame pristup do internich sekci. Kdyz otevrete Vami vytvoreny MBRDUMP.txt v kteremkoliv hexa editoru (napr. jej mysi pretahnete nad MbrScan.exe a pustite), mel by dat stejny vysledek jako report z MbrScanu. Tady se zase jednalo o moji zvedavost a kontrolu, zda se vysledky v pripade napadeni nulteho sektoru disku (tzv. Master Boot Record) bootkitem opravdu shoduji (druhy scan je z nouzoveho rezimu, kde absolutni vetsina haveti neni aktivni).


:arrow: Bezi Vam tam 2 antiviry (Norton a Avast), takze jeden z nich odinstalujte. Po odinstalovani pouzijte v nouzovem rezimu jeste oficialni odinstalator kvuli docisteni pripadnych zbytku - dle vyberu pouzijte jen jeden!
https://www.avast.com/cs-cz/uninstall-utility
https://support.norton.com/sp/cs/cz/hom ... file_en_us

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 11:35
od Tulipan
Hotovo, nechal jsem si tam Avast free. ( Norton licence mi za pár dní vyprší a já teď nemám na to si jej prodlužovat ).

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 11:37
od altrok
:arrow: Nevim jak dlouhu tu jeste dneska budu a kdy se pak vratim, takze mejte strpeni...

:arrow: Ulozte na plochu rkill.exe, ukoncete vsechny aplikace a spustte - kdyby ho havet blokovala, pouzijte alternativni odkaz POZOR - TATO UTILITA MA VELKOU SCHOPNOST MAZAT - NESPOUSTEJTE JI BEZ DOPORUCENI RADCE
:arrow: Ulozte na plochu ComboFix.exe - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete antiviry a vsechny real-time ochrany
  • spustte ComboFix jako spravce (lepe pod uctem s administratorskym opravnenim)
  • s licencnimi podminkami souhlaste - Ano
  • pokud je nabidnuta instalace konzoly pro zotaveni, souhlaste
  • v prubehu skenovani nechte PC v klidu - nic nespoustejte a do okna ComboFixu neklikejte
  • vysledek skenu naleznete v C:\ComboFix.txt, jehoz obsah mi zkopirujte do pristi odpovedi.

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 11:48
od Tulipan
Já teď také jdu pracovat, takže logy z Roguekillu a Combofixu dodám večer.

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 18 dub 2015 11:49
od altrok
OK, takze z me strany bude pokracovani pravdepodobne az zitra :) Preju Vam prijemne sobotni odpoledne :)

Re: Počítač si dělá co chce( sám píše ), záseky

Napsal: 19 dub 2015 02:25
od Tulipan
Dobré ráno, až teď jsem se vrátil z práce.

Trochu jsem počítač otestoval a nezdá se mi jedna věc, ve správci úloh mi ukazuje využití fyzické paměti neustále na 35% a neklesá to, není to nějak moc ? Všechno jsem vypnul a počítač je po restartu a stále je hodnota na 35%, se zapnutou hrou ( battlefield ) mi to dává 94%.

Další věc, nemůžu se nějak dostat do nouzového režimu, včera jsem stím už bojoval kvůli frst fixu, ovšem teď můžu mačkat klávesu F8 a stejně se mi furt načítají winy normálně a nemohu se nabootovat do nouzáku. Proto jsem ten odinstalátor nortonu prozatím pustil pouze v normálním režimu a až se mi podaří dostat se do nouzového tak odinstalátor spustím i tam.

Screeny procesů:
Obrázek
Obrázek

Nyní jdu na roguekill a combofix.