Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

zpomalený notebook

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

zpomalený notebook

#1 Příspěvek od canonnn_nn »

dobrý den, rád bych vás požádal o kontrolu logu z notebooku HP ProBook 4530s.
systém Win 7 Home premium
antivir Avira Free + mbam
po instalaci update microsoft se notebook značně spomalil a mbam stále detekuje jeden soubor jako hrozbu
proto přikládám i log z mbam
předem děkuji za pomoc

oLogfile of random's system information tool 1.10 (written by random/random)
Run by nada at 2015-08-16 12:14:45
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 128 GB (22%) free of 588 GB
Total RAM: 4030 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:14:55, on 16.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\instalace\TheAeroClock.exe
C:\Program Files (x86)\AIMP3\AIMP3.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\nada.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [TheAeroClock] "C:\instalace\TheAeroClock.exe" -bg
O4 - HKCU\..\Run: [AIMP3] C:\PROGRA~2\AIMP3\AIMP3.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe

--
End of file - 15673 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
winlogon.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\windows\System32\svchost.exe -k utcsvc
"c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3000
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000004e0
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\windows\system32\Dwm.exe"
"explorer.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\instalace\TheAeroClock.exe" -bg
"C:\Program Files (x86)\AIMP3\AIMP3.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
taskeng.exe {84A9875B-FBFE-467C-A85A-FCE7FE572075}

"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
"C:\Program Files\Windows Sidebar\sidebar.exe" /showGadgets
C:\windows\system32\igfxsrvc.exe -Embedding
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\totalcmd\TOTALCMD.EXE"
"C:\Users\nada\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@idsoftware.com/QuakeLive]
"Description"=
"Path"=C:\ProgramData\id Software\QuakeLive\npquakezero.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\extensions\
abs@avira.com
bingsearch.full@microsoft.com
fastdial@telega.phpnet.us

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-07 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-07 615584]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-07 379040]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-01-27 167960]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-01-27 391704]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-01-27 418328]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]
"AutoKMS"=C:\windows\AutoKMS.exe [2012-07-25 615936]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
"TheAeroClock"=C:\instalace\TheAeroClock.exe [2012-09-05 1500160]
"AIMP3"=C:\PROGRA~2\AIMP3\AIMP3.exe [2015-07-28 1441864]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-07-28 53655680]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACPW07EN]
C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [2013-09-25 1739080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon]
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc]
C:\Users\nada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-04-07 144008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun]
c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager]
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy]
c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-02-11 76344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2015-08-13 170256]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MfeEpePcMonitor]
C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [2011-02-09 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QLBController]
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-28 336384]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2015-06-19 730416]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896]
"Avira Systray"=C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [2015-07-02 134368]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-01-27 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=EpePcNp64
DPPassFilter
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.l3codecp"=l3codecp.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-16 11:29:52 ----A---- C:\windows\system32\drivers\06015E49.sys
2015-08-16 08:11:27 ----D---- C:\Program Files\trend micro
2015-08-16 08:11:26 ----D---- C:\rsit
2015-08-15 09:20:41 ----D---- C:\Program Files\iPod
2015-08-15 09:20:41 ----D---- C:\Program Files (x86)\iTunes
2015-08-15 09:20:40 ----D---- C:\Program Files\iTunes
2015-08-15 08:49:09 ----D---- C:\windows\Minidump
2015-08-13 09:45:51 ----A---- C:\windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:45:51 ----A---- C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msimsg.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msihnd.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msiexec.exe
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msi.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\authui.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\msimsg.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\msihnd.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\msiexec.exe
2015-08-13 09:20:18 ----A---- C:\windows\system32\msi.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\consent.exe
2015-08-13 09:20:18 ----A---- C:\windows\system32\authui.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\appinfo.dll
2015-08-13 09:19:59 ----A---- C:\windows\SYSWOW64\ole32.dll
2015-08-13 09:19:59 ----A---- C:\windows\system32\ole32.dll
2015-08-13 09:19:56 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 09:19:56 ----A---- C:\windows\system32\iertutil.dll
2015-08-13 09:19:55 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-08-13 09:19:55 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-08-13 09:19:55 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-08-13 09:19:55 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-08-13 09:19:55 ----A---- C:\windows\system32\ieetwcollector.exe
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-08-13 09:19:54 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 09:19:54 ----A---- C:\windows\system32\iernonce.dll
2015-08-13 09:19:54 ----A---- C:\windows\system32\ie4uinit.exe
2015-08-13 09:19:53 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\urlmon.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 09:19:52 ----A---- C:\windows\system32\msfeeds.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\iedkcs32.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\dxtrans.dll
2015-08-13 09:19:51 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-08-13 09:19:51 ----A---- C:\windows\system32\iesetup.dll
2015-08-13 09:19:51 ----A---- C:\windows\system32\ieapfltr.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-08-13 09:19:50 ----A---- C:\windows\system32\vbscript.dll
2015-08-13 09:19:50 ----A---- C:\windows\system32\jsproxy.dll
2015-08-13 09:19:50 ----A---- C:\windows\system32\ieUnatt.exe
2015-08-13 09:19:49 ----A---- C:\windows\system32\mshtmled.dll
2015-08-13 09:19:49 ----A---- C:\windows\system32\ieui.dll
2015-08-13 09:19:49 ----A---- C:\windows\system32\ieframe.dll
2015-08-13 09:19:49 ----A---- C:\windows\system32\dxtmsft.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\wininet.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\jscript9diag.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\jscript9.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\jscript.dll
2015-08-13 09:19:47 ----A---- C:\windows\system32\msrating.dll
2015-08-13 09:19:47 ----A---- C:\windows\system32\MshtmlDac.dll
2015-08-13 09:19:46 ----A---- C:\windows\system32\mshtml.dll
2015-08-13 09:19:40 ----A---- C:\windows\system32\shell32.dll
2015-08-13 09:19:39 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-08-13 09:19:36 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2015-08-13 09:19:36 ----A---- C:\windows\system32\cryptsvc.dll
2015-08-13 09:19:35 ----A---- C:\windows\SYSWOW64\wintrust.dll
2015-08-13 09:19:35 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2015-08-13 09:19:35 ----A---- C:\windows\SYSWOW64\crypt32.dll
2015-08-13 09:19:35 ----A---- C:\windows\system32\wintrust.dll
2015-08-13 09:19:35 ----A---- C:\windows\system32\cryptnet.dll
2015-08-13 09:19:35 ----A---- C:\windows\system32\crypt32.dll
2015-08-13 09:19:17 ----A---- C:\windows\SYSWOW64\gdi32.dll
2015-08-13 09:19:17 ----A---- C:\windows\system32\gdi32.dll
2015-08-13 09:18:57 ----A---- C:\windows\system32\basesrv.dll
2015-08-13 09:18:41 ----A---- C:\windows\system32\rpcrt4.dll
2015-08-13 09:18:41 ----A---- C:\windows\system32\lsasrv.dll
2015-08-13 09:18:40 ----A---- C:\windows\system32\kerberos.dll
2015-08-13 09:18:39 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-08-13 09:18:39 ----A---- C:\windows\system32\schannel.dll
2015-08-13 09:18:39 ----A---- C:\windows\system32\ntoskrnl.exe
2015-08-13 09:18:38 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-08-13 09:18:38 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-08-13 09:18:38 ----A---- C:\windows\system32\ntdll.dll
2015-08-13 09:18:38 ----A---- C:\windows\system32\msv1_0.dll
2015-08-13 09:18:37 ----A---- C:\windows\system32\kernel32.dll
2015-08-13 09:18:37 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-08-13 09:18:37 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-08-13 09:18:36 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-08-13 09:18:36 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-08-13 09:18:35 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-08-13 09:18:35 ----A---- C:\windows\system32\sysmain.dll
2015-08-13 09:18:35 ----A---- C:\windows\system32\adtschema.dll
2015-08-13 09:18:34 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-08-13 09:18:32 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 09:18:31 ----A---- C:\windows\system32\ncrypt.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\wow64.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\winsrv.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\wdigest.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\TSpkg.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\sspicli.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\srcore.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\smss.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\rstrui.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\lsass.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\KernelBase.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\mountmgr.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\csrsrv.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\cryptbase.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\conhost.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\auditpol.exe
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\wow64win.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\wow64cpu.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\sspisrv.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\srclient.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\secur32.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\ntvdm64.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\msobjs.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\msmmsp.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\msaudite.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\credssp.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 09:18:27 ----A---- C:\windows\SYSWOW64\user.exe
2015-08-13 09:18:27 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-08-13 09:18:27 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-08-13 09:18:27 ----A---- C:\windows\system32\apisetschema.dll
2015-08-13 09:17:57 ----A---- C:\windows\SYSWOW64\DWrite.dll
2015-08-13 09:17:57 ----A---- C:\windows\system32\FntCache.dll
2015-08-13 09:17:57 ----A---- C:\windows\system32\DWrite.dll
2015-08-13 09:17:57 ----A---- C:\windows\system32\atmfd.dll
2015-08-13 09:17:56 ----A---- C:\windows\SYSWOW64\atmfd.dll
2015-08-13 09:17:56 ----A---- C:\windows\system32\win32k.sys
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\lpk.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\fontsub.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\dciman32.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\atmlib.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\lpk.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\fontsub.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\dciman32.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\d3d10warp.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\atmlib.dll
2015-08-13 09:17:53 ----A---- C:\windows\SYSWOW64\WebClnt.dll
2015-08-13 09:17:53 ----A---- C:\windows\SYSWOW64\davclnt.dll
2015-08-13 09:17:53 ----A---- C:\windows\system32\WebClnt.dll
2015-08-13 09:17:53 ----A---- C:\windows\system32\davclnt.dll
2015-08-13 09:17:52 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2015-08-13 09:17:52 ----A---- C:\windows\system32\rdpcorets.dll
2015-08-13 09:17:51 ----A---- C:\windows\SYSWOW64\notepad.exe
2015-08-13 09:17:51 ----A---- C:\windows\system32\notepad.exe
2015-08-13 09:17:51 ----A---- C:\windows\notepad.exe
2015-08-13 09:17:17 ----A---- C:\windows\SYSWOW64\cewmdm.dll
2015-08-13 09:17:17 ----A---- C:\windows\system32\cewmdm.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\invagent.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\generaltel.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\devinv.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\appraiser.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\aeinv.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\acmigration.dll
2015-08-13 09:17:13 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-08-13 09:17:13 ----A---- C:\windows\system32\aepdu.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wups.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuwebv.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wups2.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wups.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wudriver.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wucltux.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuaueng.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuauclt.exe
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuapp.exe
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuapi.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\WinSetupUI.dll
2015-08-13 09:17:05 ----A---- C:\windows\system32\wksprt.exe
2015-08-13 09:17:05 ----A---- C:\windows\system32\mstscax.dll
2015-08-13 09:17:04 ----A---- C:\windows\SYSWOW64\mstscax.dll
2015-08-13 09:17:04 ----A---- C:\windows\system32\rdvidcrl.dll
2015-08-13 09:17:03 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2015-08-13 09:17:03 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2015-08-13 09:17:03 ----A---- C:\windows\system32\tsgqec.dll
2015-08-13 09:17:03 ----A---- C:\windows\system32\msxml6.dll
2015-08-13 09:17:03 ----A---- C:\windows\system32\msxml3.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml6r.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml6.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml3.dll
2015-08-13 09:17:02 ----A---- C:\windows\system32\msxml6r.dll
2015-08-13 09:17:02 ----A---- C:\windows\system32\msxml3r.dll
2015-08-13 09:06:49 ----A---- C:\windows\system32\mcupdate_GenuineIntel.dll
2015-08-13 08:31:07 ----A---- C:\windows\SYSWOW64\FlashPlayerInstaller.exe

======List of files/folders modified in the last 1 month======

2015-08-16 12:14:55 ----D---- C:\windows\Prefetch
2015-08-16 12:14:49 ----D---- C:\windows\Temp
2015-08-16 12:10:10 ----D---- C:\Users\nada\AppData\Roaming\Skype
2015-08-16 12:09:36 ----D---- C:\Windows
2015-08-16 12:01:07 ----A---- C:\windows\SYSWOW64\log.txt
2015-08-16 11:59:18 ----D---- C:\ProgramData\PDFC
2015-08-16 11:59:15 ----D---- C:\windows\system32\config
2015-08-16 11:59:07 ----D---- C:\ProgramData\HPQLOG
2015-08-16 11:56:01 ----D---- C:\Users\nada\AppData\Roaming\AIMP3
2015-08-16 11:52:13 ----D---- C:\windows\inf
2015-08-16 11:29:52 ----D---- C:\windows\system32\drivers
2015-08-16 08:43:18 ----D---- C:\Program Files (x86)
2015-08-16 08:11:27 ----RD---- C:\Program Files
2015-08-16 01:31:34 ----D---- C:\instalace
2015-08-15 22:07:42 ----D---- C:\windows\winsxs
2015-08-15 21:13:29 ----SHD---- C:\System Volume Information
2015-08-15 19:02:14 ----SHD---- C:\Config.Msi
2015-08-15 15:02:36 ----D---- C:\windows\system32\catroot
2015-08-15 09:23:01 ----SHD---- C:\windows\Installer
2015-08-15 09:20:40 ----D---- C:\Program Files\Common Files\Apple
2015-08-15 09:20:26 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-08-15 09:16:14 ----D---- C:\windows\system32\DriverStore
2015-08-13 23:51:51 ----D---- C:\Program Files (x86)\SpeedFan
2015-08-13 19:16:56 ----D---- C:\windows\rescache
2015-08-13 17:42:48 ----D---- C:\windows\Microsoft.NET
2015-08-13 17:41:16 ----RSD---- C:\windows\assembly
2015-08-13 17:25:52 ----D---- C:\ProgramData\Skype
2015-08-13 17:25:39 ----RD---- C:\Program Files (x86)\Skype
2015-08-13 17:14:51 ----D---- C:\windows\System32
2015-08-13 11:56:15 ----D---- C:\windows\debug
2015-08-13 11:54:17 ----D---- C:\windows\SysWOW64
2015-08-13 11:48:47 ----SD---- C:\windows\system32\GWX
2015-08-13 11:47:00 ----SD---- C:\windows\SYSWOW64\GWX
2015-08-13 10:30:17 ----D---- C:\windows\SoftwareDistribution
2015-08-13 10:13:18 ----D---- C:\ProgramData\Package Cache
2015-08-13 10:04:27 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-13 10:04:26 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 09:58:45 ----SD---- C:\windows\system32\CompatTel
2015-08-13 09:58:43 ----D---- C:\windows\system32\appraiser
2015-08-13 09:58:42 ----D---- C:\windows\system32\wbem
2015-08-13 09:58:38 ----D---- C:\windows\AppPatch
2015-08-13 09:58:09 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-08-13 09:57:59 ----D---- C:\windows\system32\drivers\cs-CZ
2015-08-13 09:57:59 ----D---- C:\windows\system32\cs-CZ
2015-08-13 09:57:16 ----D---- C:\Program Files\Internet Explorer
2015-08-13 09:57:13 ----D---- C:\windows\SYSWOW64\en-US
2015-08-13 09:57:08 ----D---- C:\windows\system32\en-US
2015-08-13 09:57:00 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-13 09:47:22 ----D---- C:\ProgramData\Microsoft Help
2015-08-13 09:47:21 ----A---- C:\windows\win.ini
2015-08-13 09:32:39 ----D---- C:\windows\system32\MRT
2015-08-13 09:31:20 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 09:22:10 ----D---- C:\windows\system32\catroot2
2015-07-28 10:59:08 ----A---- C:\windows\system32\MRT.exe
2015-07-28 00:58:30 ----D---- C:\Program Files (x86)\AIMP3
2015-07-28 00:27:24 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-28 00:25:44 ----HD---- C:\ProgramData
2015-07-28 00:25:34 ----D---- C:\ProgramData\APN

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2011-02-09 168008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\windows\SysWOW64\speedfan.sys [2011-03-18 29592]
R1 avipbb;avipbb; C:\windows\system32\DRIVERS\avipbb.sys [2015-06-19 132656]
R1 avkmgr;avkmgr; C:\windows\system32\DRIVERS\avkmgr.sys [2013-11-26 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-26 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\windows\system32\DRIVERS\avgntflt.sys [2015-06-19 153256]
R2 avnetflt;avnetflt; C:\windows\system32\DRIVERS\avnetflt.sys [2015-03-10 44088]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-28 9319424]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-28 303616]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2012-02-03 42816]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2011-01-07 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2011-01-07 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2011-01-07 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-07 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-07 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-07 154272]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2011-01-07 279200]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-12-03 25912]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2015-08-16 113880]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2015-07-16 2621128]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10301; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-10-30 549104]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2011-02-07 63336]
S3 FTDIBUS;USB Serial Converter Driver; C:\windows\system32\drivers\ftdibus.sys [2011-03-18 74376]
S3 FTSER2K;USB Serial Port Driver; C:\windows\system32\drivers\ftser2k.sys [2011-03-18 85384]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\windows\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\windows\system32\DRIVERS\ewusbdev.sys []
S3 KMWDFILTER;HIDServiceDesc; C:\windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBAAPL64;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-28 203264]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2015-06-19 450808]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2015-06-19 450808]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-05-29 77128]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 53920]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2015-07-02 218816]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-02-12 481104]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 210896]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-06-18 1871160]
R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2015-04-09 5261584]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2012-04-05 498352]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-22 3154224]
R3 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2011-01-12 36864]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-03-29 799800]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [2015-06-19 827184]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2015-06-19 1188360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-02-04 464480]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-08-13 644880]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-07-07 148136]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-08-22 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

mbam log

<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2015/08/16 11:37:38 +0200</date>
<logfile>mbam-log-2015-08-16 (11-37-35).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.1.8.1057</version>
<malware-database>v2015.08.15.06</malware-database>
<rootkit-database>v2015.08.06.01</rootkit-database>
<license>premium</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>nada</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>hyper</type>
<result>completed</result>
<objects>290023</objects>
<time>909</time>
<processes>0</processes>
<modules>0</modules>
<keys>0</keys>
<values>0</values>
<datas>0</datas>
<folders>0</folders>
<files>33</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>disabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.admin", false);</baddata><gooddata></gooddata><hash>25fd52b73e4d79bd34e8ccc03bca748c</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ferences

/* Do not edit this file.
*
</baddata><gooddata></gooddata><hash>051d9178a8e376c051cbf498dd288e72</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>references

/* Do not edit this file.
*
* If </baddata><gooddata></gooddata><hash>a37f5dac14773402a676315ba65f3ec2</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ces

/* Do not edit this file.
*
* If y</baddata><gooddata></gooddata><hash>92901eebabe00f2747d5a4e855b0e917</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>eferences

/* Do not edit this file.
*
* I</baddata><gooddata></gooddata><hash>d052f31622694aec21fbf399fa0b45bb</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>rences

/* Do not edit this file.
*
* If you make changes to th</baddata><gooddata></gooddata><hash>26fcfc0d484363d346d6662657ae47b9</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>dit this file.
*
* If you make changes to this </baddata><gooddata></gooddata><hash>d54d0bfeb6d5f1453ce0a8e4e223669a</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ces

/* Do not edit this file.
*
* If you </baddata><gooddata></gooddata><hash>6cb61aefc4c7d06676a6b3d9bc49a35d</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>rences

/* Do not edit this file.
*
* If you make changes to this file while the application is runn</baddata><gooddata></gooddata><hash>f72b9475f992f54139e33359768fd32d</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>anges to this file while the application is running,
* the changes will be overwritten when the applic</baddata><gooddata></gooddata><hash>bd65b059c2c92610e13b513bba4b3bc5</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>changes to this file while the application is running,
* the c</baddata><gooddata></gooddata><hash>8a987d8c75160c2a6ab29cf0b352d030</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>not edit this file.
*
* If you make changes to this file while the a</baddata><gooddata></gooddata><hash>fb2748c1c2c9f54179a36923d530d927</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata> this file.
*
* If you make changes to this fil</baddata><gooddata></gooddata><hash>ad7583865e2dac8a04187e0ebf46748c</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ces

/* Do not edit this file.
*
* If you make c</baddata><gooddata></gooddata><hash>4dd51aef9deed5610d0f6c205aabf40c</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>

/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* th</baddata><gooddata></gooddata><hash>ad75e4252962eb4b021aaddf10f50ef2</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata> to this file while the application is running,
* the changes will be overwritten when the application exi</baddata><gooddata></gooddata><hash>2101e5244348c175f329e1abc83d629e</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ges to this file while the application is running,
</baddata><gooddata></gooddata><hash>25fd66a3ddae94a2e636c6c69a6b916f</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ces

/* Do not edit this file.
*
* If you make </baddata><gooddata></gooddata><hash>8b9723e64f3c290d35e7197354b14cb4</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>s

/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when </baddata><gooddata></gooddata><hash>bd652bde5536f640ab7190fcd82dcd33</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>is running,
* the changes will be overwritten when the application exi</baddata><gooddata></gooddata><hash>d9496a9f8308211548d4127a56af7d83</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata> this file.
*
* If you make changes to this </baddata><gooddata></gooddata><hash>bf630504b3d891a5f22aa6e612f3b947</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>rences

/* Do not edit this file.
*
* If you make changes to this file while the application is running,
</baddata><gooddata></gooddata><hash>0022c5448ffcf54119031f6ddb2a8878</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>to this file while the application is running,
*</baddata><gooddata></gooddata><hash>5ec4cf3ae2a9082e49d35537bc4929d7</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>nces

/* Do not edit this file.
*
* If you ma</baddata><gooddata></gooddata><hash>9989d1384744e2543fdd9cf0a95c11ef</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>rences

/* Do not edit this file.
*
* If</baddata><gooddata></gooddata><hash>c959b85158337bbb7d9f4b41aa5b847c</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ferences

/* Do not edit this file.
*
* If</baddata><gooddata></gooddata><hash>df4329e0fb902610e834fd8f050056aa</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>rences

/* Do not edit this file.
*
* If you </baddata><gooddata></gooddata><hash>49d961a8ddae1a1c75a7abe1d233bd43</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>ces

/* Do not edit this file.
*
* If you make changes t</baddata><gooddata></gooddata><hash>d34ff514701bce688399622a41c401ff</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.hmpgUrl", "http://search.softonic.com/MON00005/tb_ ... rce=13&cc=");</baddata><gooddata></gooddata><hash>b76ba7621774c472071dee9e7590ea16</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>edit this file.
*
* If you make changes to this file while the application is running,
* the chang</baddata><gooddata></gooddata><hash>c75bf910197269cd69bbdcb08d787b85</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>r_pref("app.update.lastUpdateTime.addon-background-update-timer", 1439705781);
user_pref("app.update.lastUpdat</baddata><gooddata></gooddata><hash>f32fee1bbfcc58de50d4721a47beba46</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>it this file.
*
* If you make changes to this file while the application is running,
* the changes wil</baddata><gooddata></gooddata><hash>da4822e78308bb7b0a1acac253b22bd5</hash></file>
<file><path>C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>te-timer", 1439705541);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1439705901);
</baddata><gooddata></gooddata><hash>33ef74959bf0bb7b50d4a7e5cb3a51af</hash></file>
</items>
</mbam-log>

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#2 Příspěvek od canonnn_nn »

ještě jednou dobrý den, nevím zda jsem něco udělal špatně, že se nikdo neozval na mou prosbu o pomoc,pokud ano bylo by fér napsát, že to nebo ono se tady na foru tak nedělá. je mi šedesát let a myslím, že moje prosba byla podána slušně.
děkuji za odpověd
canonnn_nn

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: zpomalený notebook

#3 Příspěvek od Márty84 »

Zdravim :)

Nic jste neudelal spatne. Tedy v tom uvodnim prispevku. Tim druhym jste si spis uskodil, protoze hledame prednostne temata bez odpovedi. Chce to trosku trpelivosti. Je to "jen" nas konicek. Jsme tu ve svem volnem case a zdarma. Je vikend, navic prazdniny. Taky mame sve rodiny, jine zajmy a povinnosti. Takze si musite pockat, jako vsichni ostatni. Pokud pospichate, budete se muset obratit na nekterou placenou sluzbu, napriklad http://neslape.cz/?utm_campaign=neslape ... edium=link



:arrow: Stahnete crystal disk info http://sourceforge.jp/projects/crystald ... 5_0_0.zip/
Spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)


:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Cleaning
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner[C?].txt ). Ten mi sem zkopirujte.


:arrow: Udelejte novou kontrolu s MBAM. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#4 Příspěvek od canonnn_nn »

OK, omlouvám se nikam nespěchám jen se mi zdálo, že dlouho, že se nikdo neozval, vím, že to děláte jako koníček a pomáháte druhým. takže velký dík za to.

tady je crystaldiskinfo

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.0 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium Edition SP1 [6.1 Build 7601] (x64)
Date : 2015/08/16 16:41:51

-- Controller Map ----------------------------------------------------------
+ Intel(R) Mobile Express Chipset SATA AHCI Controller [ATA]
- Hitachi HTS547564A9E384
- hp DVD A DS8A5LH

-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS547564A9E384 : 640,1 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(1) Hitachi HTS547564A9E384
----------------------------------------------------------------------------
Model : Hitachi HTS547564A9E384
Firmware : JEDOA50A
Serial Number : J2180053C8JY0D
Disk Size : 640,1 GB (8,4/137,4/640,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1250263728
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : SATA/300
Power On Hours : 6268 hod.
Power On Count : 1615 krát
Temparature : 38 C (100 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 _99 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 173 100 _33 001100000001 Čas na roztočení ploten
04 _99 _99 __0 00000000064F Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _86 _86 __0 00000000187C Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _99 _99 __0 00000000064F Počet cyklů zapnutí zařízení
B7 100 100 __0 000000000000 Neznámý
B8 100 100 _97 000000000000 Ukončovacích chyb
BB 100 100 __0 0098001A0000 Ohlášeno neopravitelných chyb
BC 100 100 __0 00000011004B Časový limit příkazu
BE _62 _53 _45 0000212C0026 Teplota toku vzduchu
BF _95 _95 __0 000000000553 Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 0000000C000C Počet vypnutí disku
C1 100 100 __0 0000000015A4 Počet cyklů načítání/vymazání
C4 100 100 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 100 100 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 003F 003F 0000 0000 0000
010: 2020 2020 2020 4A32 3138 3533 3533 4338 4A59 3044
020: 0003 4000 0004 4A45 444F 3041 3041 4869 7461 6368
030: 6920 4854 5335 3437 3536 3945 3945 3338 3420 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0007 3FFF 003F 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 0D06 0D06 0000 004C 004C
080: 01FC 0028 706B 7C09 6123 BC09 BC09 6123 203F 0051
090: 0052 4080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 82B0 4A85 0000 0000 0000 6003 6003 826C 5000 CCA6
110: 3EC3 E28B 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 000B
130: 0000 0000 2182 1CF1 3A10 4000 4000 0400 0108 0000
140: 0000 0A05 0905 0905 0807 0000 0000 0000 0000 0000
150: 0000 0000 4448 4435 0000 0000 0000 5DAD 2518 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 003D 003D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 101F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 DCA5

jenom dodatek dělal jsem chkdsk s parametrem "r" a žádná chyba

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: zpomalený notebook

#5 Příspěvek od Márty84 »

No psal jste uz po trech hodinach, to se mi nezda nejak moc dlouho :D

Program bohuzel chyby disku hlasi. I to muze byt pricina problemu. Uvidime po docisteni.
canonnn_nn píše:BB 100 100 __0 0098001A0000 Ohlášeno neopravitelných chyb
BF _95 _95 __0 000000000553 Počet udalostí zaznamenaných otřesovým senzorem
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#6 Příspěvek od canonnn_nn »

adwcleaner log

# AdwCleaner v5.000 - Logfile created 16/08/2015 at 16:46:50
# Updated 14/08/2015 by Xplode
# Database : 2015-08-16.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : nada - HOME
# Running from : C:\Users\nada\Desktop\adwcleaner_5.000.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\Users\nada\AppData\Local\PackageAware
[-] Folder Deleted : C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\ICQToolbarData
[#] Folder Deleted : C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[#] Folder Deleted : C:\Users\nada\Documents\hosts

***** [ Files ] *****

[-] File Deleted : C:\user.js
[-] File Deleted : C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\invalidprefs.js
[-] File Deleted : C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\user.js

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
[!] Key Not Deleted : [x64] HKCU\Software\Conduit
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[!] Data Not Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
[!] Data Not Restored : HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main [ICQ Search]
[!] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}

***** [ Web browsers ] *****

[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.admin", false);
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.aflt", "SD");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.autoRvrt", "false");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.dfltLng", "");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.dfltSrch", true);
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.dspOld", "Ask.com");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.excTlbr", false);
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.hpOld", "hxxp://www.seznam.cz/");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.id", "42ac87110000000000000aa3c4cc625a");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.instlDay", "15493");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.instlRef", "MON00005");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=2&cc=&q=");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=15&cc=");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.prdct", "Softonic");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.prtnrId", "softonic");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search settings, Click No to restore original settings");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.tlbrId", "base");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=1&cc=&q=");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.vrsn", "1.5.24.3");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic.vrsni", "1.5.24.3");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic_i.dnsErr", true);
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic_i.hmpg", true);
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic_i.newTab", true);
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic_i.smplGrp", "none");
[-] [C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\prefs.js] [Preference] Deleted : user_pref("extensions.Softonic_i.vrsnTs", "1.5.24.311:01:12");

*************************

:: Proxy settings cleared
:: Winsock settings cleared

*************************

C:\AdwCleaner[C1].txt - [8817 octets] - [16/08/2015 16:46:50]
C:\AdwCleaner[S1].txt - [8717 octets] - [16/08/2015 16:45:01]

########## EOF - C:\AdwCleaner[C1].txt - [8943 octets] ##########

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#7 Příspěvek od canonnn_nn »

jen se zeptám mbam vytváří dva logy
mbam log
a
protection log
který vám mám poslat ?

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: zpomalený notebook

#8 Příspěvek od Márty84 »

Fajn, tak jeste ten MBAM a podle vysledku se zaridime dale.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#9 Příspěvek od canonnn_nn »

<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2015/08/16 17:13:36 +0200</date>
<logfile>mbam-log-2015-08-16 (17-13-32).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.1.8.1057</version>
<malware-database>v2015.08.16.01</malware-database>
<rootkit-database>v2015.08.06.01</rootkit-database>
<license>premium</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>nada</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>custom</type>
<result>completed</result>
<objects>668100</objects>
<time>15108</time>
<processes>0</processes>
<modules>0</modules>
<keys>0</keys>
<values>0</values>
<datas>0</datas>
<folders>0</folders>
<files>1</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<file><path>C:\instalace\DTLite4461-0327.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>none</action><hash>ceb3b6533754c373882b20573fc68977</hash></file>
</items>
</mbam-log>

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: zpomalený notebook

#10 Příspěvek od Márty84 »

:???: Proc davate log z MBAM v tomhle formatu? Kdo to ma lustit? :) Log ma vypadat nejak takhle http://forum.viry.cz/viewtopic.php?f=30 ... 6#p1411205

:arrow: Pokud to dobre vidim, je tam jeden nalez a to je instalacka DTLite. Nalez smazte.

:???: Vy mate zakoupenou plnou verzi MBAM?



:arrow: Dejte novy log z RSIT
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#11 Příspěvek od canonnn_nn »

mbam to uloží jako xml, tak jsem to vykopíroval, sorry
ne
Logfile of random's system information tool 1.10 (written by random/random)
Run by nada at 2015-08-16 22:57:53
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 131 GB (22%) free of 588 GB
Total RAM: 4030 MB (32% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:58:09, on 16.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\instalace\TheAeroClock.exe
C:\Program Files (x86)\AIMP3\AIMP3.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\nada.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [TheAeroClock] "C:\instalace\TheAeroClock.exe" -bg
O4 - HKCU\..\Run: [AIMP3] C:\PROGRA~2\AIMP3\AIMP3.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe

--
End of file - 15725 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
winlogon.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"

C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\System32\spoolsv.exe
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\windows\System32\svchost.exe -k utcsvc
"c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3028
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000780
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\windows\system32\Dwm.exe"
"explorer.exe"
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\instalace\TheAeroClock.exe" -bg
"C:\Program Files (x86)\AIMP3\AIMP3.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\totalcmd\TOTALCMD.EXE"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\nada\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@idsoftware.com/QuakeLive]
"Description"=
"Path"=C:\ProgramData\id Software\QuakeLive\npquakezero.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\extensions\
abs@avira.com
bingsearch.full@microsoft.com
fastdial@telega.phpnet.us

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-07 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-07 615584]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-07 379040]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-01-27 167960]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-01-27 391704]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-01-27 418328]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]
"AutoKMS"=C:\windows\AutoKMS.exe [2012-07-25 615936]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
"TheAeroClock"=C:\instalace\TheAeroClock.exe [2012-09-05 1500160]
"AIMP3"=C:\PROGRA~2\AIMP3\AIMP3.exe [2015-07-28 1441864]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-07-28 53655680]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACPW07EN]
C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [2013-09-25 1739080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon]
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc]
C:\Users\nada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-04-07 144008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun]
c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager]
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy]
c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-02-11 76344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2015-08-13 170256]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MfeEpePcMonitor]
C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [2011-02-09 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QLBController]
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-28 336384]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2015-06-19 730416]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896]
"Avira Systray"=C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [2015-07-02 134368]

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-01-27 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=EpePcNp64
DPPassFilter
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.l3codecp"=l3codecp.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-16 16:46:50 ----A---- C:\AdwCleaner[C1].txt
2015-08-16 16:45:01 ----A---- C:\AdwCleaner[S1].txt
2015-08-16 16:44:58 ----D---- C:\AdwCleaner
2015-08-16 11:29:52 ----A---- C:\windows\system32\drivers\06015E49.sys
2015-08-16 08:11:27 ----D---- C:\Program Files\trend micro
2015-08-16 08:11:26 ----D---- C:\rsit
2015-08-15 09:20:41 ----D---- C:\Program Files\iPod
2015-08-15 09:20:41 ----D---- C:\Program Files (x86)\iTunes
2015-08-15 09:20:40 ----D---- C:\Program Files\iTunes
2015-08-15 08:49:09 ----D---- C:\windows\Minidump
2015-08-13 09:45:51 ----A---- C:\windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:45:51 ----A---- C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msimsg.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msihnd.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msiexec.exe
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\msi.dll
2015-08-13 09:20:18 ----A---- C:\windows\SYSWOW64\authui.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\msimsg.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\msihnd.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\msiexec.exe
2015-08-13 09:20:18 ----A---- C:\windows\system32\msi.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\consent.exe
2015-08-13 09:20:18 ----A---- C:\windows\system32\authui.dll
2015-08-13 09:20:18 ----A---- C:\windows\system32\appinfo.dll
2015-08-13 09:19:59 ----A---- C:\windows\SYSWOW64\ole32.dll
2015-08-13 09:19:59 ----A---- C:\windows\system32\ole32.dll
2015-08-13 09:19:56 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 09:19:56 ----A---- C:\windows\system32\iertutil.dll
2015-08-13 09:19:55 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-08-13 09:19:55 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-08-13 09:19:55 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-08-13 09:19:55 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-08-13 09:19:55 ----A---- C:\windows\system32\ieetwcollector.exe
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-08-13 09:19:54 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-08-13 09:19:54 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 09:19:54 ----A---- C:\windows\system32\iernonce.dll
2015-08-13 09:19:54 ----A---- C:\windows\system32\ie4uinit.exe
2015-08-13 09:19:53 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-08-13 09:19:52 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\urlmon.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 09:19:52 ----A---- C:\windows\system32\msfeeds.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\iedkcs32.dll
2015-08-13 09:19:52 ----A---- C:\windows\system32\dxtrans.dll
2015-08-13 09:19:51 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-08-13 09:19:51 ----A---- C:\windows\system32\iesetup.dll
2015-08-13 09:19:51 ----A---- C:\windows\system32\ieapfltr.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-08-13 09:19:50 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-08-13 09:19:50 ----A---- C:\windows\system32\vbscript.dll
2015-08-13 09:19:50 ----A---- C:\windows\system32\jsproxy.dll
2015-08-13 09:19:50 ----A---- C:\windows\system32\ieUnatt.exe
2015-08-13 09:19:49 ----A---- C:\windows\system32\mshtmled.dll
2015-08-13 09:19:49 ----A---- C:\windows\system32\ieui.dll
2015-08-13 09:19:49 ----A---- C:\windows\system32\ieframe.dll
2015-08-13 09:19:49 ----A---- C:\windows\system32\dxtmsft.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\wininet.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\jscript9diag.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\jscript9.dll
2015-08-13 09:19:48 ----A---- C:\windows\system32\jscript.dll
2015-08-13 09:19:47 ----A---- C:\windows\system32\msrating.dll
2015-08-13 09:19:47 ----A---- C:\windows\system32\MshtmlDac.dll
2015-08-13 09:19:46 ----A---- C:\windows\system32\mshtml.dll
2015-08-13 09:19:40 ----A---- C:\windows\system32\shell32.dll
2015-08-13 09:19:39 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-08-13 09:19:36 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2015-08-13 09:19:36 ----A---- C:\windows\system32\cryptsvc.dll
2015-08-13 09:19:35 ----A---- C:\windows\SYSWOW64\wintrust.dll
2015-08-13 09:19:35 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2015-08-13 09:19:35 ----A---- C:\windows\SYSWOW64\crypt32.dll
2015-08-13 09:19:35 ----A---- C:\windows\system32\wintrust.dll
2015-08-13 09:19:35 ----A---- C:\windows\system32\cryptnet.dll
2015-08-13 09:19:35 ----A---- C:\windows\system32\crypt32.dll
2015-08-13 09:19:17 ----A---- C:\windows\SYSWOW64\gdi32.dll
2015-08-13 09:19:17 ----A---- C:\windows\system32\gdi32.dll
2015-08-13 09:18:57 ----A---- C:\windows\system32\basesrv.dll
2015-08-13 09:18:41 ----A---- C:\windows\system32\rpcrt4.dll
2015-08-13 09:18:41 ----A---- C:\windows\system32\lsasrv.dll
2015-08-13 09:18:40 ----A---- C:\windows\system32\kerberos.dll
2015-08-13 09:18:39 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-08-13 09:18:39 ----A---- C:\windows\system32\schannel.dll
2015-08-13 09:18:39 ----A---- C:\windows\system32\ntoskrnl.exe
2015-08-13 09:18:38 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-08-13 09:18:38 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-08-13 09:18:38 ----A---- C:\windows\system32\ntdll.dll
2015-08-13 09:18:38 ----A---- C:\windows\system32\msv1_0.dll
2015-08-13 09:18:37 ----A---- C:\windows\system32\kernel32.dll
2015-08-13 09:18:37 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-08-13 09:18:37 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-08-13 09:18:36 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-08-13 09:18:36 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-08-13 09:18:35 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-08-13 09:18:35 ----A---- C:\windows\system32\sysmain.dll
2015-08-13 09:18:35 ----A---- C:\windows\system32\adtschema.dll
2015-08-13 09:18:34 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-08-13 09:18:32 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 09:18:31 ----A---- C:\windows\system32\ncrypt.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-08-13 09:18:30 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\wow64.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\winsrv.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\wdigest.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\TSpkg.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\sspicli.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\srcore.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\smss.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\rstrui.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\lsass.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\KernelBase.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\mountmgr.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-08-13 09:18:30 ----A---- C:\windows\system32\csrsrv.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\cryptbase.dll
2015-08-13 09:18:30 ----A---- C:\windows\system32\conhost.exe
2015-08-13 09:18:30 ----A---- C:\windows\system32\auditpol.exe
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 09:18:29 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-08-13 09:18:29 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\wow64win.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\wow64cpu.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\sspisrv.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\srclient.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\secur32.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\ntvdm64.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\msobjs.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\msmmsp.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\msaudite.dll
2015-08-13 09:18:29 ----A---- C:\windows\system32\credssp.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 09:18:28 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 09:18:27 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 09:18:27 ----A---- C:\windows\SYSWOW64\user.exe
2015-08-13 09:18:27 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-08-13 09:18:27 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-08-13 09:18:27 ----A---- C:\windows\system32\apisetschema.dll
2015-08-13 09:17:57 ----A---- C:\windows\SYSWOW64\DWrite.dll
2015-08-13 09:17:57 ----A---- C:\windows\system32\FntCache.dll
2015-08-13 09:17:57 ----A---- C:\windows\system32\DWrite.dll
2015-08-13 09:17:57 ----A---- C:\windows\system32\atmfd.dll
2015-08-13 09:17:56 ----A---- C:\windows\SYSWOW64\atmfd.dll
2015-08-13 09:17:56 ----A---- C:\windows\system32\win32k.sys
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\lpk.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\fontsub.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\dciman32.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2015-08-13 09:17:54 ----A---- C:\windows\SYSWOW64\atmlib.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\lpk.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\fontsub.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\dciman32.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\d3d10warp.dll
2015-08-13 09:17:54 ----A---- C:\windows\system32\atmlib.dll
2015-08-13 09:17:53 ----A---- C:\windows\SYSWOW64\WebClnt.dll
2015-08-13 09:17:53 ----A---- C:\windows\SYSWOW64\davclnt.dll
2015-08-13 09:17:53 ----A---- C:\windows\system32\WebClnt.dll
2015-08-13 09:17:53 ----A---- C:\windows\system32\davclnt.dll
2015-08-13 09:17:52 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2015-08-13 09:17:52 ----A---- C:\windows\system32\rdpcorets.dll
2015-08-13 09:17:51 ----A---- C:\windows\SYSWOW64\notepad.exe
2015-08-13 09:17:51 ----A---- C:\windows\system32\notepad.exe
2015-08-13 09:17:51 ----A---- C:\windows\notepad.exe
2015-08-13 09:17:17 ----A---- C:\windows\SYSWOW64\cewmdm.dll
2015-08-13 09:17:17 ----A---- C:\windows\system32\cewmdm.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\invagent.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\generaltel.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\devinv.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\appraiser.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\aeinv.dll
2015-08-13 09:17:14 ----A---- C:\windows\system32\acmigration.dll
2015-08-13 09:17:13 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-08-13 09:17:13 ----A---- C:\windows\system32\aepdu.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wups.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-08-13 09:17:10 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuwebv.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wups2.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wups.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wudriver.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wucltux.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuaueng.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuauclt.exe
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuapp.exe
2015-08-13 09:17:10 ----A---- C:\windows\system32\wuapi.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 09:17:10 ----A---- C:\windows\system32\WinSetupUI.dll
2015-08-13 09:17:05 ----A---- C:\windows\system32\wksprt.exe
2015-08-13 09:17:05 ----A---- C:\windows\system32\mstscax.dll
2015-08-13 09:17:04 ----A---- C:\windows\SYSWOW64\mstscax.dll
2015-08-13 09:17:04 ----A---- C:\windows\system32\rdvidcrl.dll
2015-08-13 09:17:03 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2015-08-13 09:17:03 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2015-08-13 09:17:03 ----A---- C:\windows\system32\tsgqec.dll
2015-08-13 09:17:03 ----A---- C:\windows\system32\msxml6.dll
2015-08-13 09:17:03 ----A---- C:\windows\system32\msxml3.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml6r.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml6.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2015-08-13 09:17:02 ----A---- C:\windows\SYSWOW64\msxml3.dll
2015-08-13 09:17:02 ----A---- C:\windows\system32\msxml6r.dll
2015-08-13 09:17:02 ----A---- C:\windows\system32\msxml3r.dll
2015-08-13 09:06:49 ----A---- C:\windows\system32\mcupdate_GenuineIntel.dll
2015-08-13 08:31:07 ----A---- C:\windows\SYSWOW64\FlashPlayerInstaller.exe

======List of files/folders modified in the last 1 month======

2015-08-16 22:57:57 ----D---- C:\windows\Temp
2015-08-16 22:52:21 ----D---- C:\Users\nada\AppData\Roaming\Skype
2015-08-16 22:38:57 ----SHD---- C:\System Volume Information
2015-08-16 17:10:21 ----D---- C:\instalace
2015-08-16 17:01:13 ----D---- C:\Users\nada\AppData\Roaming\AIMP3
2015-08-16 16:52:34 ----A---- C:\windows\SYSWOW64\log.txt
2015-08-16 16:52:07 ----D---- C:\Windows
2015-08-16 16:51:06 ----D---- C:\windows\Prefetch
2015-08-16 16:50:25 ----D---- C:\ProgramData\PDFC
2015-08-16 16:50:20 ----D---- C:\ProgramData\HPQLOG
2015-08-16 16:50:14 ----D---- C:\windows\system32\config
2015-08-16 16:50:08 ----D---- C:\windows\inf
2015-08-16 16:46:50 ----HD---- C:\ProgramData
2015-08-16 11:29:52 ----D---- C:\windows\system32\drivers
2015-08-16 08:43:18 ----D---- C:\Program Files (x86)
2015-08-16 08:11:27 ----RD---- C:\Program Files
2015-08-15 22:07:42 ----D---- C:\windows\winsxs
2015-08-15 19:02:14 ----SHD---- C:\Config.Msi
2015-08-15 15:02:36 ----D---- C:\windows\system32\catroot
2015-08-15 09:23:01 ----SHD---- C:\windows\Installer
2015-08-15 09:20:40 ----D---- C:\Program Files\Common Files\Apple
2015-08-15 09:20:26 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-08-15 09:16:14 ----D---- C:\windows\system32\DriverStore
2015-08-13 23:51:51 ----D---- C:\Program Files (x86)\SpeedFan
2015-08-13 19:16:56 ----D---- C:\windows\rescache
2015-08-13 17:42:48 ----D---- C:\windows\Microsoft.NET
2015-08-13 17:41:16 ----RSD---- C:\windows\assembly
2015-08-13 17:25:52 ----D---- C:\ProgramData\Skype
2015-08-13 17:25:39 ----RD---- C:\Program Files (x86)\Skype
2015-08-13 17:14:51 ----D---- C:\windows\System32
2015-08-13 11:56:15 ----D---- C:\windows\debug
2015-08-13 11:54:17 ----D---- C:\windows\SysWOW64
2015-08-13 11:48:47 ----SD---- C:\windows\system32\GWX
2015-08-13 11:47:00 ----SD---- C:\windows\SYSWOW64\GWX
2015-08-13 10:30:17 ----D---- C:\windows\SoftwareDistribution
2015-08-13 10:13:18 ----D---- C:\ProgramData\Package Cache
2015-08-13 10:04:27 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-13 10:04:26 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 09:58:45 ----SD---- C:\windows\system32\CompatTel
2015-08-13 09:58:43 ----D---- C:\windows\system32\appraiser
2015-08-13 09:58:42 ----D---- C:\windows\system32\wbem
2015-08-13 09:58:38 ----D---- C:\windows\AppPatch
2015-08-13 09:58:09 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-08-13 09:57:59 ----D---- C:\windows\system32\drivers\cs-CZ
2015-08-13 09:57:59 ----D---- C:\windows\system32\cs-CZ
2015-08-13 09:57:16 ----D---- C:\Program Files\Internet Explorer
2015-08-13 09:57:13 ----D---- C:\windows\SYSWOW64\en-US
2015-08-13 09:57:08 ----D---- C:\windows\system32\en-US
2015-08-13 09:57:00 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-13 09:47:22 ----D---- C:\ProgramData\Microsoft Help
2015-08-13 09:47:21 ----A---- C:\windows\win.ini
2015-08-13 09:32:39 ----D---- C:\windows\system32\MRT
2015-08-13 09:31:20 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 09:22:10 ----D---- C:\windows\system32\catroot2
2015-07-28 10:59:08 ----A---- C:\windows\system32\MRT.exe
2015-07-28 00:58:30 ----D---- C:\Program Files (x86)\AIMP3
2015-07-28 00:27:24 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2011-02-09 168008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 speedfan;speedfan; C:\windows\SysWOW64\speedfan.sys [2011-03-18 29592]
R1 avipbb;avipbb; C:\windows\system32\DRIVERS\avipbb.sys [2015-06-19 132656]
R1 avkmgr;avkmgr; C:\windows\system32\DRIVERS\avkmgr.sys [2013-11-26 28600]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-26 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\windows\system32\DRIVERS\avgntflt.sys [2015-06-19 153256]
R2 avnetflt;avnetflt; C:\windows\system32\DRIVERS\avnetflt.sys [2015-03-10 44088]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-28 9319424]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-28 303616]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2012-02-03 42816]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2011-01-07 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2011-01-07 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2011-01-07 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-07 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-07 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-07 154272]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2011-01-07 279200]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-12-03 25912]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2015-08-16 113880]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2015-07-16 2621128]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10301; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-10-30 549104]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2011-02-07 63336]
S3 FTDIBUS;USB Serial Converter Driver; C:\windows\system32\drivers\ftdibus.sys [2011-03-18 74376]
S3 FTSER2K;USB Serial Port Driver; C:\windows\system32\drivers\ftser2k.sys [2011-03-18 85384]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\windows\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\windows\system32\DRIVERS\ewusbdev.sys []
S3 KMWDFILTER;HIDServiceDesc; C:\windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBAAPL64;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-28 203264]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2015-06-19 450808]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2015-06-19 450808]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-05-29 77128]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 53920]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2015-07-02 218816]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-02-12 481104]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 210896]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-06-18 1871160]
R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2015-04-09 5261584]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2012-04-05 498352]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-22 3154224]
R3 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2011-01-12 36864]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-03-29 799800]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [2015-06-19 827184]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2015-06-19 1188360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-02-04 464480]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-08-13 644880]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-07-07 148136]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-08-22 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: zpomalený notebook

#12 Příspěvek od Márty84 »

:arrow: Podle toho logu tam mate verzi Premium, coz je plna verze i se stity. Pokud vam bezi stity MBAM i Aviry, perou se mezi sebou a nedela to dobrotu.

:arrow: Dejte logy podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach :)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#13 Příspěvek od canonnn_nn »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:16-08-2015
Ran by nada (administrator) on HOME (17-08-2015 09:00:44)
Running from C:\Users\nada\Desktop
Loaded Profiles: nada (Available Profiles: nada)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(ArcSoft, Inc.) C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Nenad Hrg (SoftwareOK.com)) C:\instalace\TheAeroClock.exe
(AIMP DevTeam) C:\Program Files (x86)\AIMP3\AIMP3.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Hewlett-Packard Development Company, L.P) C:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(forum.viry.cz) C:\Users\nada\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [615584 2011-01-07] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379040 2011-01-07] (Atheros Commnucations)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM\...\Run: [AutoKMS] => C:\windows\AutoKMS.exe [615936 2012-07-25] ()
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [730416 2015-06-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [134368 2015-07-02] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [TheAeroClock] => C:\instalace\TheAeroClock.exe [1500160 2012-09-05] (Nenad Hrg (SoftwareOK.com))
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [AIMP3] => C:\Program Files (x86)\AIMP3\AIMP3.exe [1441864 2015-07-28] (AIMP DevTeam)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=CMNTDF
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> DefaultScope {0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97 ... -SearchBox
SearchScopes: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> {0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97 ... -SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: No Name -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-07] (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000}
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{333F1D5D-E9A3-46C3-BDDD-42907D27686B}: [DhcpNameServer] 178.22.112.22 178.22.118.10
Tcpip\..\Interfaces\{6D69829C-161A-4BEF-BB7E-AD1EEF27C6B6}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default
FF Homepage: https://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @idsoftware.com/QuakeLive -> C:\ProgramData\id Software\QuakeLive\npquakezero.dll [2011-10-20] (id Software Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll [No File]
FF Plugin HKU\S-1-5-21-1287106222-1829384790-4251411741-1001: @Google.com/GoogleEarthPlugin -> C:\Users\nada\AppData\Local\Google\Google Earth\plugin\npgeplugin.dll [2012-04-14] (Google)
FF Extension: Avira Browser Safety - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\abs@avira.com [2015-08-13]
FF Extension: Bing Search - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\bingsearch.full@microsoft.com [2015-07-05]
FF Extension: Fast Dial - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\fastdial@telega.phpnet.us [2015-05-31]
FF Extension: TinEye Reverse Image Search - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\tineye@ideeinc.com.xpi [2011-10-14]
FF Extension: Flagfox - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-08]
FF Extension: ImTranslator - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2012-03-11]
FF Extension: Adblock Plus - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-09-29]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-07]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-05-10]

Chrome:
=======
CHR Profile: C:\Users\nada\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\nada\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda [2012-11-04]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827184 2015-06-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [450808 2015-06-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [450808 2015-06-19] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1188360 2015-06-19] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-07] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [53920 2011-01-07] (Atheros Commnucations) [File not signed]
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [218816 2015-07-02] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [481104 2011-02-12] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464480 2011-02-04] (Hewlett-Packard Company)
R3 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2011-01-12] (Hewlett-Packard Development Company, L.P) [File not signed]
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-29] (Hewlett-Packard Company)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1318912 2011-02-09] () [File not signed]
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1127448 2011-02-01] (PDF Complete Inc)
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [498352 2012-04-05] (ArcSoft, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [42816 2012-02-03] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [153256 2015-06-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132656 2015-06-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-10] (Avira Operations GmbH & Co. KG)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [63336 2011-02-07] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-26] (DT Soft Ltd)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [168008 2011-02-09] (McAfee, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [2621128 2015-07-16] (Sonix Tech. Co., Ltd.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-08-15] (Apple, Inc.) [File not signed]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-17 09:00 - 2015-08-17 09:01 - 00021022 _____ C:\Users\nada\Desktop\FRST.txt
2015-08-17 08:59 - 2015-08-17 09:00 - 00000000 ____D C:\FRST
2015-08-17 08:58 - 2015-08-17 08:58 - 02173440 _____ (Farbar) C:\Users\nada\Desktop\FRST64.exe
2015-08-17 08:55 - 2015-08-17 08:55 - 00000000 ____D C:\Users\nada\AppData\Local\PackageAware
2015-08-17 08:41 - 2015-08-17 08:33 - 00112640 _____ (forum.viry.cz) C:\Users\nada\Desktop\FRSTLauncher.exe
2015-08-17 00:04 - 2015-08-17 00:04 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\3A0C2031.sys
2015-08-16 16:46 - 2015-08-16 16:47 - 00009056 _____ C:\AdwCleaner[C1].txt
2015-08-16 16:45 - 2015-08-16 16:45 - 00008717 _____ C:\AdwCleaner[S1].txt
2015-08-16 16:44 - 2015-08-16 16:46 - 00000000 ____D C:\AdwCleaner
2015-08-16 16:37 - 2015-08-16 16:37 - 01563648 _____ C:\Users\nada\Desktop\adwcleaner_5.000.exe
2015-08-16 16:36 - 2015-08-16 16:41 - 00000262 _____ C:\Users\nada\Downloads\DiskInfo.ini
2015-08-16 16:36 - 2015-08-16 16:36 - 00000000 ____D C:\Users\nada\Downloads\Smart
2015-08-16 16:36 - 2012-06-15 14:08 - 01149912 _____ (Crystal Dew World) C:\Users\nada\Downloads\DiskInfo.exe
2015-08-16 16:36 - 2012-05-27 20:28 - 00000000 ____D C:\Users\nada\Downloads\CdiResource
2015-08-16 16:36 - 2012-01-05 14:02 - 00001268 _____ C:\Users\nada\Downloads\COPYRIGHT.txt
2015-08-16 16:36 - 2012-01-05 14:02 - 00001122 _____ C:\Users\nada\Downloads\COPYRIGHT-ja.txt
2015-08-16 16:35 - 2015-08-16 16:35 - 01496172 _____ C:\Users\nada\Downloads\CrystalDiskInfo5_0_0.zip
2015-08-16 11:57 - 2015-08-17 08:14 - 00000280 _____ C:\windows\setupact.log
2015-08-16 11:57 - 2015-08-16 11:57 - 00000000 _____ C:\windows\setuperr.log
2015-08-16 11:56 - 2015-08-17 00:01 - 00001012 _____ C:\windows\PFRO.log
2015-08-16 11:29 - 2015-08-16 11:29 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\06015E49.sys
2015-08-16 08:11 - 2015-08-16 22:57 - 00000000 ____D C:\Program Files\trend micro
2015-08-16 08:11 - 2015-08-16 12:14 - 00000000 ____D C:\rsit
2015-08-16 08:10 - 2015-08-16 08:10 - 01222144 _____ C:\Users\nada\Desktop\RSITx64.exe
2015-08-15 22:09 - 2014-03-02 23:33 - 02347384 _____ (ESET) C:\Users\nada\Desktop\esetsmartinstaller_csy.exe
2015-08-15 09:22 - 2015-08-15 09:22 - 00001759 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-08-15 09:22 - 2015-08-15 09:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-08-15 09:20 - 2015-08-15 09:22 - 00000000 ____D C:\Program Files\iTunes
2015-08-15 09:20 - 2015-08-15 09:20 - 00000000 ____D C:\Program Files\iPod
2015-08-15 09:20 - 2015-08-15 09:20 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-08-15 08:49 - 2015-08-16 11:52 - 00000000 ____D C:\windows\Minidump
2015-08-13 09:45 - 2015-07-30 15:13 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:45 - 2015-07-30 15:13 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 09:20 - 2015-06-15 23:50 - 00112064 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-08-13 09:20 - 2015-06-15 23:45 - 03242496 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-08-13 09:20 - 2015-06-15 23:45 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-08-13 09:20 - 2015-06-15 23:45 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-08-13 09:20 - 2015-06-15 23:45 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-08-13 09:20 - 2015-06-15 23:44 - 00128000 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2015-08-13 09:20 - 2015-06-15 23:43 - 02364416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-08-13 09:20 - 2015-06-15 23:43 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-08-13 09:20 - 2015-06-15 23:43 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2015-08-13 09:20 - 2015-06-15 23:42 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2015-08-13 09:20 - 2015-06-15 23:42 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2015-08-13 09:20 - 2015-06-15 23:37 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2015-08-13 09:19 - 2015-07-21 02:39 - 00389840 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-08-13 09:19 - 2015-07-21 02:12 - 00342736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-08-13 09:19 - 2015-07-16 23:14 - 25192448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-08-13 09:19 - 2015-07-16 22:54 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-08-13 09:19 - 2015-07-16 22:54 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-08-13 09:19 - 2015-07-16 22:37 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-08-13 09:19 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-08-13 09:19 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-08-13 09:19 - 2015-07-16 22:36 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-08-13 09:19 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-08-13 09:19 - 2015-07-16 22:35 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-08-13 09:19 - 2015-07-16 22:27 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-08-13 09:19 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-08-13 09:19 - 2015-07-16 22:26 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-08-13 09:19 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-08-13 09:19 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-08-13 09:19 - 2015-07-16 22:21 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-08-13 09:19 - 2015-07-16 22:21 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-08-13 09:19 - 2015-07-16 22:21 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-08-13 09:19 - 2015-07-16 22:20 - 19870208 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-08-13 09:19 - 2015-07-16 22:12 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-08-13 09:19 - 2015-07-16 22:08 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-08-13 09:19 - 2015-07-16 22:06 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-08-13 09:19 - 2015-07-16 22:00 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 09:19 - 2015-07-16 21:55 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-08-13 09:19 - 2015-07-16 21:54 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-08-13 09:19 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-08-13 09:19 - 2015-07-16 21:51 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-08-13 09:19 - 2015-07-16 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-08-13 09:19 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-08-13 09:19 - 2015-07-16 21:50 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-08-13 09:19 - 2015-07-16 21:49 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-08-13 09:19 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-08-13 09:19 - 2015-07-16 21:43 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-08-13 09:19 - 2015-07-16 21:43 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-08-13 09:19 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-08-13 09:19 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-08-13 09:19 - 2015-07-16 21:39 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-08-13 09:19 - 2015-07-16 21:38 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-08-13 09:19 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-08-13 09:19 - 2015-07-16 21:35 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-08-13 09:19 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-08-13 09:19 - 2015-07-16 21:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-08-13 09:19 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-08-13 09:19 - 2015-07-16 21:29 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-08-13 09:19 - 2015-07-16 21:24 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-13 09:19 - 2015-07-16 21:20 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-08-13 09:19 - 2015-07-16 21:19 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-08-13 09:19 - 2015-07-16 21:17 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-08-13 09:19 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-08-13 09:19 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-08-13 09:19 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-08-13 09:19 - 2015-07-16 21:06 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-08-13 09:19 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-08-13 09:19 - 2015-07-16 21:05 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-08-13 09:19 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-08-13 09:19 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-08-13 09:19 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-08-13 09:19 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-08-13 09:19 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-08-13 09:19 - 2015-07-10 19:51 - 14177280 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-08-13 09:19 - 2015-07-10 19:34 - 12875776 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-08-13 09:19 - 2015-07-04 20:07 - 02087424 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2015-08-13 09:19 - 2015-07-04 19:48 - 01414656 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2015-08-13 09:19 - 2015-06-17 19:47 - 00404992 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-08-13 09:19 - 2015-06-17 19:37 - 00312320 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-08-13 09:19 - 2015-04-27 21:23 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-08-13 09:19 - 2015-04-27 21:23 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-08-13 09:19 - 2015-04-27 21:23 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-08-13 09:19 - 2015-04-27 21:23 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-08-13 09:19 - 2015-04-27 21:05 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-08-13 09:19 - 2015-04-27 21:04 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-08-13 09:19 - 2015-04-27 21:04 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-08-13 09:19 - 2015-04-27 21:04 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2015-08-13 09:18 - 2015-07-15 20:15 - 05568960 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-08-13 09:18 - 2015-07-15 20:15 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-08-13 09:18 - 2015-07-15 20:15 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-08-13 09:18 - 2015-07-15 20:15 - 00094656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-08-13 09:18 - 2015-07-15 20:12 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-08-13 09:18 - 2015-07-15 20:11 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-08-13 09:18 - 2015-07-15 20:11 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-08-13 09:18 - 2015-07-15 20:11 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-08-13 09:18 - 2015-07-15 20:11 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-08-13 09:18 - 2015-07-15 20:11 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 01743360 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 01216512 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-08-13 09:18 - 2015-07-15 20:10 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-08-13 09:18 - 2015-07-15 20:10 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-08-13 09:18 - 2015-07-15 20:10 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-08-13 09:18 - 2015-07-15 20:10 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-08-13 09:18 - 2015-07-15 20:09 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-08-13 09:18 - 2015-07-15 20:09 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-08-13 09:18 - 2015-07-15 20:05 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-08-13 09:18 - 2015-07-15 20:05 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 20:00 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:59 - 03989952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-08-13 09:18 - 2015-07-15 19:59 - 03934656 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-08-13 09:18 - 2015-07-15 19:56 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-08-13 09:18 - 2015-07-15 19:55 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-08-13 09:18 - 2015-07-15 19:55 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-08-13 09:18 - 2015-07-15 19:55 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-08-13 09:18 - 2015-07-15 19:55 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-08-13 09:18 - 2015-07-15 19:55 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-08-13 09:18 - 2015-07-15 19:54 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-08-13 09:18 - 2015-07-15 19:54 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-08-13 09:18 - 2015-07-15 19:54 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-08-13 09:18 - 2015-07-15 19:54 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2015-08-13 09:18 - 2015-07-15 19:54 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-08-13 09:18 - 2015-07-15 19:54 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-08-13 09:18 - 2015-07-15 19:54 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-08-13 09:18 - 2015-07-15 19:53 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-08-13 09:18 - 2015-07-15 19:53 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-08-13 09:18 - 2015-07-15 19:53 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-08-13 09:18 - 2015-07-15 19:53 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-08-13 09:18 - 2015-07-15 19:53 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-08-13 09:18 - 2015-07-15 19:53 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-08-13 09:18 - 2015-07-15 19:49 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-08-13 09:18 - 2015-07-15 19:48 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 19:44 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 18:46 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-08-13 09:18 - 2015-07-15 18:46 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-08-13 09:18 - 2015-07-15 18:46 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-08-13 09:18 - 2015-07-15 18:37 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-08-13 09:18 - 2015-07-15 18:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-08-13 09:18 - 2015-07-15 18:34 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 18:34 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 18:34 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 18:34 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 09:18 - 2015-07-15 05:19 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 02565120 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-08-13 09:17 - 2015-07-30 20:06 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-08-13 09:17 - 2015-07-30 19:57 - 01987584 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
2015-08-13 09:17 - 2015-07-30 19:57 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-08-13 09:17 - 2015-07-30 19:57 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2015-08-13 09:17 - 2015-07-30 19:57 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-08-13 09:17 - 2015-07-30 19:57 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2015-08-13 09:17 - 2015-07-30 19:55 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2015-08-13 09:17 - 2015-07-30 18:56 - 03208192 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-08-13 09:17 - 2015-07-30 18:52 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-08-13 09:17 - 2015-07-30 18:49 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-08-13 09:17 - 2015-07-28 22:09 - 00017344 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-08-13 09:17 - 2015-07-28 22:05 - 01116672 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-13 09:17 - 2015-07-28 22:05 - 00774656 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-08-13 09:17 - 2015-07-28 22:05 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-08-13 09:17 - 2015-07-28 22:05 - 00437760 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-08-13 09:17 - 2015-07-28 22:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-08-13 09:17 - 2015-07-28 22:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-08-13 09:17 - 2015-07-28 21:55 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 03154944 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 02606080 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-08-13 09:17 - 2015-07-20 20:12 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-08-13 09:17 - 2015-07-20 20:12 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-08-13 09:17 - 2015-07-20 20:12 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-08-13 09:17 - 2015-07-20 19:56 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-08-13 09:17 - 2015-07-20 19:56 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-08-13 09:17 - 2015-07-20 19:56 - 00093184 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-08-13 09:17 - 2015-07-20 19:56 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-08-13 09:17 - 2015-07-20 19:56 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-08-13 09:17 - 2015-07-16 21:12 - 06131200 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-08-13 09:17 - 2015-07-16 21:12 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-08-13 09:17 - 2015-07-16 21:12 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2015-08-13 09:17 - 2015-07-16 21:11 - 07077376 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-08-13 09:17 - 2015-07-16 21:11 - 01057792 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-08-13 09:17 - 2015-07-16 21:11 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-08-13 09:17 - 2015-07-15 05:19 - 02004992 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-08-13 09:17 - 2015-07-15 05:19 - 01887232 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-08-13 09:17 - 2015-07-15 05:14 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-08-13 09:17 - 2015-07-15 05:13 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-08-13 09:17 - 2015-07-15 04:55 - 01390592 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-08-13 09:17 - 2015-07-15 04:55 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-08-13 09:17 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2015-08-13 09:17 - 2015-07-15 04:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-08-13 09:17 - 2015-07-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-08-13 09:17 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-08-13 09:17 - 2015-07-09 19:57 - 00193536 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-08-13 09:17 - 2015-07-09 19:42 - 00179712 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-08-13 09:17 - 2015-07-01 22:49 - 00260096 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-08-13 09:17 - 2015-07-01 22:48 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-08-13 09:17 - 2015-07-01 22:30 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-08-13 09:17 - 2015-07-01 22:30 - 00082432 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-08-13 09:17 - 2015-06-09 20:03 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-08-13 09:17 - 2015-06-09 20:03 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-08-13 09:17 - 2015-06-02 02:07 - 00254976 _____ (Microsoft Corporation) C:\windows\system32\cewmdm.dll
2015-08-13 09:17 - 2015-06-02 01:47 - 00210432 _____ (Microsoft Corporation) C:\windows\SysWOW64\cewmdm.dll
2015-08-13 09:06 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-08-13 08:31 - 2015-08-13 09:31 - 09284296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2015-07-28 00:58 - 2015-07-28 00:58 - 00000875 _____ C:\Users\Public\Desktop\AIMP3.lnk
2015-07-28 00:58 - 2015-07-28 00:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-17 08:55 - 2011-10-14 21:33 - 00000000 __HDC C:\ProgramData\~0
2015-08-17 08:55 - 2011-10-02 19:14 - 00000000 ____D C:\Program Files (x86)\Stardock
2015-08-17 08:50 - 2011-05-10 22:06 - 00000000 ____D C:\ProgramData\HPQLOG
2015-08-17 08:49 - 2015-04-30 19:55 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-17 08:43 - 2009-07-14 06:45 - 00022704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-17 08:43 - 2009-07-14 06:45 - 00022704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-17 08:41 - 2011-05-10 22:12 - 00669116 _____ C:\windows\system32\perfh005.dat
2015-08-17 08:41 - 2011-05-10 22:12 - 00141744 _____ C:\windows\system32\perfc005.dat
2015-08-17 08:41 - 2009-07-14 07:13 - 01584554 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-17 08:38 - 2011-08-31 21:33 - 00000948 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-17 08:31 - 2012-05-03 17:28 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-08-17 08:27 - 2013-06-12 23:04 - 00000000 ____D C:\Users\nada\AppData\Roaming\AIMP3
2015-08-17 08:19 - 2011-07-28 12:41 - 01393916 _____ C:\windows\WindowsUpdate.log
2015-08-17 08:18 - 2011-08-22 21:48 - 00000000 ____D C:\Users\nada\AppData\Roaming\Skype
2015-08-17 08:17 - 2011-07-28 12:56 - 00000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2015-08-17 08:16 - 2011-08-31 21:32 - 00000944 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-17 08:16 - 2011-05-10 22:10 - 00000000 ____D C:\ProgramData\PDFC
2015-08-17 08:14 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-17 00:18 - 2012-07-25 13:18 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2015-08-16 23:48 - 2011-10-14 20:15 - 00000000 ____D C:\windows\pss
2015-08-16 23:07 - 2011-08-22 14:11 - 00000000 ____D C:\instalace
2015-08-16 11:55 - 2014-12-29 20:16 - 00000000 __SHD C:\Users\nada\AppData\Local\EmieUserList
2015-08-16 11:55 - 2014-12-29 20:16 - 00000000 __SHD C:\Users\nada\AppData\Local\EmieSiteList
2015-08-16 11:55 - 2014-12-29 20:16 - 00000000 __SHD C:\Users\nada\AppData\Local\EmieBrowserModeList
2015-08-16 07:52 - 2014-01-03 14:00 - 00009328 _____ C:\windows\SysWOW64\Fireplace.log
2015-08-15 09:20 - 2015-05-19 17:37 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-08-15 09:20 - 2015-03-31 20:31 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-08-15 08:05 - 2009-07-14 07:08 - 00032548 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-08-13 19:16 - 2011-08-19 19:53 - 00000000 ____D C:\windows\rescache
2015-08-13 17:25 - 2011-12-01 21:56 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-13 17:25 - 2011-07-28 13:06 - 00000000 ____D C:\ProgramData\Skype
2015-08-13 11:56 - 2011-10-30 17:26 - 00000000 ____D C:\Users\nada\AppData\Local\CrashDumps
2015-08-13 11:48 - 2015-04-12 13:31 - 00000000 ___SD C:\windows\system32\GWX
2015-08-13 11:47 - 2015-04-12 13:31 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-08-13 10:13 - 2014-08-14 06:40 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-13 10:04 - 2013-03-12 21:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 10:04 - 2013-03-12 21:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 10:04 - 2009-07-14 06:45 - 00410128 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-13 09:58 - 2014-12-21 18:09 - 00000000 ____D C:\windows\system32\appraiser
2015-08-13 09:58 - 2014-05-24 13:22 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-13 09:47 - 2011-09-18 10:38 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 09:47 - 2009-07-14 04:34 - 00000478 _____ C:\windows\win.ini
2015-08-13 09:45 - 2013-03-12 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 09:32 - 2013-07-13 10:31 - 00000000 ____D C:\windows\system32\MRT
2015-08-13 09:31 - 2012-05-03 17:28 - 00778440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-08-13 09:31 - 2012-05-03 17:28 - 00003852 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-08-13 09:31 - 2011-08-31 21:13 - 00142536 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-13 07:59 - 2015-07-08 21:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-07-28 20:29 - 2014-12-21 23:31 - 00007543 _____ C:\windows\SysWOW64\Ice Clock.log
2015-07-28 10:59 - 2011-08-22 08:04 - 132483416 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-07-28 00:58 - 2013-06-12 23:04 - 00000000 ____D C:\Program Files (x86)\AIMP3
2015-07-28 00:27 - 2015-04-30 19:54 - 00001072 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-28 00:27 - 2015-04-30 19:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-28 00:27 - 2015-04-30 19:54 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-25 17:15 - 2015-07-09 19:45 - 00000000 ____D C:\Users\nada\Projekty ProShow_Producer

==================== Files in the root of some directories =======

2014-12-20 23:53 - 2014-12-20 23:33 - 0303402 _____ () C:\Users\nada\AppData\Roaming\Koontz Dean Ray - Tv_ strachu - Neznamy.mobi
2011-10-14 21:03 - 2011-10-14 21:03 - 0000000 _____ () C:\Users\nada\AppData\Roaming\Stardockfences_debug_snapshot.dat
2012-04-02 19:45 - 2012-04-02 19:45 - 0000017 _____ () C:\Users\nada\AppData\Local\resmon.resmoncfg

Files to move or delete:
====================
C:\Users\nada\jxpiinstall.exe


Some files in TEMP:
====================
C:\Users\nada\AppData\Local\Temp\avgnt.exe
C:\Users\nada\AppData\Local\Temp\sfamcc00001.dll
C:\Users\nada\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\nada\Desktop" je 1287 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACPW07EN
"C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc
C:\Users\nada\AppData\Local\Microsoft\BingSvc\BingSvc.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun
c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPConnectionManager
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPQuickWebProxy
"c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
"C:\Program Files\iTunes\iTunesHelper.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MfeEpePcMonitor
"C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete
C:\Program Files (x86)\PDF Complete\pdfsty.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QLBController
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001


==================== End Of Log ==============================
Přílohy
Addition.rar
(7.52 KiB) Staženo 39 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: zpomalený notebook

#14 Příspěvek od Márty84 »

:arrow: Pokud stale bezi oba antiviry, nezapomnte jeden odinstalovat.

***** Velikost "Plochy" *****

Velikost slozky "C:\Users\nada\Desktop" je 1287 MB.
:arrow: Velikost plochy by nemela presahovat 200 - 300 MB! Brzdi to chod pc. Cili ji trosku uklidte a na plochu dejte jen zastupce. Jen pozor na obcasnou chybu, ze uzivatele maji na plose slozku, v ni dalsi a v ni dalsi a do te to schovaji. To je sice hezke, ale plochu to nezmensi, jen je to v jinem supliku :)



:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AutoKMS] => C:\windows\AutoKMS.exe [615936 2012-07-25] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [AIMP3] => C:\Program Files (x86)\AIMP3\AIMP3.exe [1441864 2015-07-28] (AIMP DevTeam)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File

HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=CMNTDF
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> DefaultScope {0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> {0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&q={searchTerms}&src=IE-SearchBox
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: No Name -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> No File
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)

FF Extension: Bing Search - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\bingsearch.full@microsoft.com [2015-07-05]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-07]

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {3C54F56F-7047-4418-89AB-4C3B677E03B2} - System32\Tasks\AutoKMS => C:\windows\AutoKMS.exe [2012-07-25] ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000

DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

canonnn_nn
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 20 zář 2010 08:06
Bydliště: Bochty na Hané

Re: zpomalený notebook

#15 Příspěvek od canonnn_nn »

jj plocha máte pravdu, manželka si nechala na ploše složky s foto. Už je vyřešeno. 2,5 MB
Fix result of Farbar Recovery Scan Tool (x64) Version:16-08-2015
Ran by nada (2015-08-17 14:57:16) Run:1
Running from C:\Users\nada\Desktop
Loaded Profiles: nada (Available Profiles: nada)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AutoKMS] => C:\windows\AutoKMS.exe [615936 2012-07-25] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [AIMP3] => C:\Program Files (x86)\AIMP3\AIMP3.exe [1441864 2015-07-28] (AIMP DevTeam)
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File

HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=CMNTDF
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> DefaultScope {0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97 ... -SearchBox
SearchScopes: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> {0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97 ... -SearchBox
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: No Name -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> No File
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-1287106222-1829384790-4251411741-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)

FF Extension: Bing Search - C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\bingsearch.full@microsoft.com [2015-07-05]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-07]

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {3C54F56F-7047-4418-89AB-4C3B677E03B2} - System32\Tasks\AutoKMS => C:\windows\AutoKMS.exe [2012-07-25] ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000

DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AutoKMS => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AIMP3 => value removed successfully
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}" => key removed successfully
HKCR\Wow6432Node\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => key not found.
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0DD8BAD3-4514-476F-ADD4-AC1272D6B16C}" => key removed successfully
HKCR\CLSID\{0DD8BAD3-4514-476F-ADD4-AC1272D6B16C} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => key removed successfully
"HKCR\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => key removed successfully
HKCR\Wow6432Node\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => key removed successfully
HKU\S-1-5-21-1287106222-1829384790-4251411741-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value removed successfully
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => key not found.
"HKCR\PROTOCOLS\Handler\skypec2c" => key removed successfully
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => key removed successfully
HKCR\Wow6432Node\PROTOCOLS\Handler\skypec2c => key not found.
"HKCR\Wow6432Node\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => key removed successfully
C:\Users\nada\AppData\Roaming\Mozilla\Firefox\Profiles\zhqa0sp2.default\Extensions\bingsearch.full@microsoft.com => moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => moved successfully.
c2cautoupdatesvc => service removed successfully
c2cpnrsvc => service removed successfully
SkypeUpdate => service removed successfully
AdobeFlashPlayerUpdateSvc => service removed successfully
C:\windows\Tasks\Adobe Flash Player Updater.job => moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3C54F56F-7047-4418-89AB-4C3B677E03B2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C54F56F-7047-4418-89AB-4C3B677E03B2}" => key removed successfully
C:\windows\System32\Tasks\AutoKMS => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => key removed successfully
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] => Error: No automatic fix found for this entry.
"Generalize_DisableSR"=dword:00000000 => Error: No automatic fix found for this entry.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DTRun => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete => key removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 302.8 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 15:01:28 ====

Zamčeno