čínská aplikace nejde odinstalovat
Napsal: 14 úno 2016 10:39
Ahoj všichni a předem díky za pomoc.
Mám v notebooku nějaké svinstvo s čínskými znaky, kterého se nelze zbavit. vlezlo mi to do browseru, změnilo vyhledávač (což samozřejmě už nejde dát na jiný) a celkově to vyhazuje pop-upy.
adwcleaner log níže
# AdwCleaner v5.033 - Logfile created 12/02/2016 at 17:57:46
# Updated 07/02/2016 by Xplode
# Database : 2016-02-07.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Karolina - KAROLINA-PC
# Running from : C:\Users\Karolina\Desktop\adwcleaner_5.033.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
[-] Service Deleted : QQPCRTP
[-] Service Deleted : TAOAccelerator
[-] Service Deleted : TSDefenseBt
[-] Service Deleted : TSSysKit
[-] Service Deleted : QMUdisk
[-] Service Deleted : QQSysMonX64
[-] Service Deleted : TFsFlt
[-] Service Deleted : TAOKernelDriver
[-] Service Deleted : TSSKX64
[-] Service Deleted : SPS
***** [ Folders ] *****
[-] Folder Deleted : C:\Genius
[#] Folder Deleted : C:\Program Files (x86)\tencent
[-] Folder Deleted : C:\Program Files (x86)\Common Files\tencent
[#] Folder Deleted : C:\Program Files\Common Files\tencent
[#] Folder Deleted : C:\ProgramData\tencent
[-] Folder Deleted : C:\ProgramData\TXQMPC
[-] Folder Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm
[-] Folder Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl
[-] Folder Deleted : C:\Users\Karolina\AppData\Roaming\tencent
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\tencent
***** [ Files ] *****
[-] File Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
[-] File Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nonjdcjchghhkdoolnlbekcfllmednbl_0.localstorage
[-] File Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Karolina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\电脑管家.lnk
[-] File Deleted : C:\Windows\SysNative\drivers\TAOAccelerator64.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TSSKX64.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TAOKernel64.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TFsFltX64.sys
[-] File Deleted : C:\Windows\SysWOW64\SearchProtectService.exe
[-] File Deleted : C:\Windows\SysWOW64\drivers\TsFltMgr.sys
[-] File Deleted : C:\Windows\SysWOW64\drivers\TS888x64.sys
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQPCMgr
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Key Deleted : HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\QMContextUninstall
[-] Key Deleted : HKEY_CLASSES_ROOT\Folder\ShellEx\ContextMenuHandlers\QMContextUninstall
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [Plus-HD-7.6-bg.exe]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14CD42DD-ABCD-3586-DCAB-40E3693E3737}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16EE6530-8649-4F42-A9E4-F6A3295AF975}
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CBDECEF7-7A29-4CBF-A009-2673D82C7BF9}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{63332668-8CE1-445D-A5EE-25929176714E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{D4801E96-E7A1-45F6-B124-7A36DFB40B81}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2AEF02C3-5159-4C81-A688-8D954F0DEE56}_NewSearch
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQPCMgr
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tab]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
***** [ Web browsers ] *****
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : websearch.ask.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : microsoft-office-2010.softonic.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : kindle-to-pdf-converter.en.softonic.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : journey-to-the-center-of-the-earth.en.softonic.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nafaimnnclfjfedmmabolbppcngeolgf
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nonjdcjchghhkdoolnlbekcfllmednbl
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ooebklgpfnbcnpokahmdidgbmlcdepkm
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [7762 bytes] ##########
a tady je combofix
ComboFix 16-02-09.01 - Karolina 13.02.2016 14:30:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4063.1977 [GMT 1:00]
Spuštěný z: c:\users\Karolina\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\Karolina\AppData\Local\assembly\tmp
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\__AssemblyInfo__.ini
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\Microsoft.Office.Tools.Common.v4.0.Utilities.DLL
c:\windows\IsUn0405.exe
c:\windows\msdownld.tmp
c:\windows\SysWow64\tmp144F.tmp
c:\windows\SysWow64\tmp145F.tmp
c:\windows\SysWow64\tmp6F2B.tmp
c:\windows\SysWow64\tmp6F3B.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-01-13 do 2016-02-13 )))))))))))))))))))))))))))))))
.
.
2016-02-13 13:44 . 2016-02-13 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-02-12 16:59 . 2016-02-12 16:59 -------- d-----w- c:\programdata\TXQMPC
2016-02-10 22:10 . 2016-02-10 22:10 210432 ----a-w- c:\windows\system32\aepic.dll
2016-02-10 22:10 . 2016-02-10 22:10 1164800 ----a-w- c:\windows\system32\aeinv.dll
2016-02-10 21:57 . 2016-02-10 21:57 62464 ----a-w- c:\windows\system32\drivers\appid.sys
2016-02-10 21:54 . 2016-02-10 21:54 879616 ----a-w- c:\windows\system32\advapi32.dll
2016-02-10 21:54 . 2016-02-10 21:54 643072 ----a-w- c:\windows\SysWow64\advapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76288 ----a-w- c:\windows\system32\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 67584 ----a-w- c:\windows\SysWow64\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 624640 ----a-w- c:\windows\system32\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 509952 ----a-w- c:\windows\SysWow64\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76800 ----a-w- c:\windows\SysWow64\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 14336 ----a-w- c:\windows\SysWow64\fixmapi.exe
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 17920 ----a-w- c:\windows\system32\fixmapi.exe
2016-02-10 21:51 . 2016-02-10 21:51 3211264 ----a-w- c:\windows\system32\win32k.sys
2016-02-10 21:25 . 2016-02-10 21:25 87864 ------w- c:\windows\system32\drivers\TFsFltX64.sys
2016-02-10 21:24 . 2016-02-12 17:00 -------- d-----w- c:\programdata\Tencent
2016-02-10 09:37 . 2016-02-10 09:37 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.3656.dll
2016-02-09 17:53 . 2016-02-09 17:53 -------- d-----w- c:\users\Karolina\AppData\Roaming\GameMill Entertainment
2016-02-09 17:16 . 2016-02-09 17:16 -------- d-----w- c:\programdata\Big Fish
2016-02-09 17:14 . 2016-02-09 17:16 -------- d-----w- c:\users\Karolina\AppData\Local\Big Fish
2016-02-09 09:05 . 2016-02-09 09:05 398152 ----a-w- c:\windows\system32\aswBoot.exe
2016-02-09 09:05 . 2016-02-09 09:05 52184 ----a-w- c:\windows\avastSS.scr
2016-02-03 11:01 . 2016-02-03 11:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.4380.dll
2016-02-03 10:53 . 2015-12-16 09:15 11154520 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\mpengine.dll
2016-02-03 10:53 . 2016-02-03 10:53 -------- d-----w- C:\4b07b6a08b1f5c3eab3c975b
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZE.DLL
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\SysWow64\nlsbres.dll
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\system32\nlsbres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\system32\tzres.dll
2016-02-03 10:42 . 2016-02-03 10:42 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1180160 ----a-w- c:\windows\system32\FntCache.dll
2016-02-03 10:42 . 2016-02-03 10:42 833024 ----a-w- c:\windows\SysWow64\user32.dll
2016-02-03 10:42 . 2016-02-03 10:42 1648128 ----a-w- c:\windows\system32\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1008640 ----a-w- c:\windows\system32\user32.dll
2016-02-03 10:41 . 2016-02-03 10:41 241664 ----a-w- c:\windows\system32\els.dll
2016-02-03 10:41 . 2016-02-03 10:41 179712 ----a-w- c:\windows\SysWow64\els.dll
2016-02-03 10:39 . 2016-02-03 10:39 17408 ----a-w- c:\windows\system32\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 14848 ----a-w- c:\windows\SysWow64\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 146944 ----a-w- c:\windows\system32\drivers\rmcast.sys
2016-02-03 10:38 . 2016-02-03 10:38 802304 ----a-w- c:\windows\system32\usp10.dll
2016-02-03 10:38 . 2016-02-03 10:38 627712 ----a-w- c:\windows\SysWow64\usp10.dll
2016-02-03 10:37 . 2016-02-03 10:37 487936 ----a-w- c:\windows\SysWow64\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1242624 ----a-w- c:\windows\SysWow64\comsvcs.dll
2016-02-03 10:37 . 2016-02-03 10:37 525312 ----a-w- c:\windows\system32\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1735680 ----a-w- c:\windows\system32\comsvcs.dll
2016-02-03 10:18 . 2016-02-03 10:18 497664 ----a-w- c:\windows\system32\drivers\afd.sys
2016-02-03 10:18 . 2016-02-03 10:18 118272 ----a-w- c:\windows\system32\drivers\tdx.sys
2016-02-03 10:16 . 2016-02-03 10:16 950720 ----a-w- c:\windows\system32\drivers\ndis.sys
2016-02-03 10:11 . 2016-02-03 10:11 939520 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:11 . 2016-02-03 10:11 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 1415168 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 275456 ----a-w- c:\windows\system32\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 2103296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 1372160 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:08 . 2016-02-03 10:08 459344 ----a-w- c:\windows\system32\drivers\cng.sys
2016-02-03 10:08 . 2016-02-03 10:08 298192 ----a-w- c:\windows\system32\bcryptprimitives.dll
2016-02-03 10:08 . 2016-02-03 10:08 251000 ----a-w- c:\windows\SysWow64\bcryptprimitives.dll
2016-02-03 10:06 . 2016-02-03 10:06 72192 ----a-w- c:\windows\system32\aelupsvc.dll
2016-02-03 10:06 . 2016-02-03 10:06 6656 ----a-w- c:\windows\system32\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 342016 ----a-w- c:\windows\system32\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 23552 ----a-w- c:\windows\system32\sdbinst.exe
2016-02-03 10:06 . 2016-02-03 10:06 5120 ----a-w- c:\windows\SysWow64\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 295936 ----a-w- c:\windows\SysWow64\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 20992 ----a-w- c:\windows\SysWow64\sdbinst.exe
2016-02-03 10:02 . 2016-02-03 10:02 634432 ----a-w- c:\windows\system32\winload.exe
2016-02-03 09:56 . 2016-02-03 09:56 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 1498624 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 14176768 ----a-w- c:\windows\system32\shell32.dll
2016-02-03 09:53 . 2016-02-03 09:53 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2016-02-03 09:53 . 2016-02-03 09:53 22528 ----a-w- c:\windows\system32\icaapi.dll
2016-02-03 09:51 . 2016-02-03 09:51 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2016-02-03 09:51 . 2016-02-03 09:51 46080 ----a-w- c:\windows\system32\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 41984 ----a-w- c:\windows\system32\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 372736 ----a-w- c:\windows\system32\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 299520 ----a-w- c:\windows\SysWow64\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 14336 ----a-w- c:\windows\system32\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 100864 ----a-w- c:\windows\system32\fontsub.dll
2016-02-03 09:47 . 2016-02-03 09:47 41984 ----a-w- c:\windows\system32\UtcResources.dll
2016-02-03 09:47 . 2016-02-03 09:47 1390592 ----a-w- c:\windows\system32\diagtrack.dll
2016-02-03 09:47 . 2016-02-03 09:47 879104 ----a-w- c:\windows\system32\tdh.dll
2016-02-03 09:47 . 2016-02-03 09:47 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2016-02-03 09:45 . 2016-02-03 09:45 82944 ----a-w- c:\windows\system32\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 67584 ----a-w- c:\windows\SysWow64\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 1632256 ----a-w- c:\windows\system32\dwmcore.dll
2016-02-03 09:45 . 2016-02-03 09:45 1372160 ----a-w- c:\windows\SysWow64\dwmcore.dll
2016-02-03 09:44 . 2016-02-03 09:44 1941504 ----a-w- c:\windows\system32\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 70656 ----a-w- c:\windows\system32\appinfo.dll
2016-02-03 09:44 . 2016-02-03 09:44 115136 ----a-w- c:\windows\system32\consent.exe
2016-02-03 09:39 . 2016-02-03 09:39 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2004480 ----a-w- c:\windows\system32\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1887232 ----a-w- c:\windows\system32\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-02-03 09:38 . 2016-02-03 09:38 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2016-02-03 09:38 . 2016-02-03 09:38 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2016-02-03 09:37 . 2016-02-03 09:37 82432 ----a-w- c:\windows\SysWow64\davclnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 260096 ----a-w- c:\windows\system32\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 206848 ----a-w- c:\windows\SysWow64\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 102912 ----a-w- c:\windows\system32\davclnt.dll
2016-02-03 09:34 . 2016-02-03 09:34 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\mountmgr.sys.mui
2016-02-03 09:34 . 2016-02-03 09:34 94656 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2016-02-03 09:34 . 2016-02-03 09:34 11264 ----a-w- c:\windows\system32\msmmsp.dll
2016-02-03 09:34 . 2016-02-03 09:34 1743360 ----a-w- c:\windows\system32\sysmain.dll
2016-02-03 09:27 . 2016-02-03 09:27 52736 ----a-w- c:\windows\system32\basesrv.dll
2016-02-03 09:23 . 2016-02-03 09:23 193536 ----a-w- c:\windows\system32\notepad.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-02-10 21:58 . 2016-02-10 21:58 344064 ----a-w- c:\windows\system32\schannel.dll
2016-02-10 21:58 . 2016-02-10 21:58 190464 ----a-w- c:\windows\system32\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 251392 ----a-w- c:\windows\SysWow64\schannel.dll
2016-02-10 21:57 . 2016-02-10 21:57 141312 ----a-w- c:\windows\SysWow64\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-02-10 21:53 . 2009-07-14 00:22 1393152 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2016-02-10 21:06 . 2013-03-01 13:47 287016 ----a-w- c:\windows\system32\drivers\aswvmm.sys
2016-02-09 09:05 . 2013-12-18 16:31 165344 ----a-w- c:\windows\system32\drivers\aswStm.sys
2016-02-09 09:05 . 2014-04-18 14:08 37656 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2016-02-09 09:05 . 2013-03-01 13:47 74544 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2016-02-09 09:05 . 2012-02-24 13:42 103064 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2016-02-09 09:05 . 2010-05-11 15:30 463744 ----a-w- c:\windows\system32\drivers\aswSP.sys
2016-02-09 09:05 . 2010-05-11 15:30 107792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2016-02-09 09:04 . 2011-03-26 21:32 1065720 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2016-02-03 10:35 . 2016-02-03 10:35 230400 ----a-w- c:\windows\SysWow64\webcheck.dll
2016-02-03 10:35 . 2016-02-03 10:35 262144 ----a-w- c:\windows\system32\webcheck.dll
2016-02-03 10:06 . 2016-02-03 10:06 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2016-02-03 10:06 . 2016-02-03 10:06 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-02-03 10:06 . 2016-02-03 10:06 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-01-17 22:46 . 2016-01-07 16:10 3571488 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2015-12-30 15:05 . 2015-12-30 15:05 0 ---ha-w- c:\users\Karolina\AppData\Local\BITF621.tmp
2015-12-02 12:18 . 2010-05-11 15:58 301728 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2015-11-06 2010912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-02 98304]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2016-02-09 7139768]
"Magic Desktop for HP notification"="c:\programdata\Easybits Magic Desktop for HP\mdhpSUN.exe" [2015-11-22 1444880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 athsgt;athsgt;c:\windows\system32\DRIVERS\athsgt.sys;c:\windows\SYSNATIVE\DRIVERS\athsgt.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 limsgt;limsgt;c:\windows\system32\DRIVERS\limsgt.sys;c:\windows\SYSNATIVE\DRIVERS\limsgt.sys [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 QQPCRTP;QQPCMgr RTP Service;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe [x]
R3 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [x]
R3 cmshusbser;Mobile Connector USB Device for Legacy Serial Communication IN ANDROID DEVICE;c:\windows\system32\DRIVERS\cmshusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmshusbser.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x]
R3 GGSAFERDriver;GGSAFER Driver; [x]
R3 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [x]
R3 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 ClickToRunSvc;Microsoft Office Click-to-Run Service;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe;c:\windows\SYSNATIVE\vfsFPService.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AVerAF15;HP DVB-T TV Tuner;c:\windows\system32\Drivers\AVerAF15.sys;c:\windows\SYSNATIVE\Drivers\AVerAF15.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys;c:\windows\SYSNATIVE\DRIVERS\enecir.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-02-09 20:45 1090376 ----a-w- c:\program files (x86)\Google\Chrome\Application\48.0.2564.109\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2016-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
2016-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-02-09 09:05 905248 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.Google.com/
uCustomizeSearch = hxxp://www.Google.com/
mCustomizeSearch = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-QQPCTray - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCTRAY.EXE
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{95080B13-AA71-4EE8-B951-7E98221E1ED5} - (no file)
ShellIconOverlayIdentifiers-{B7667919-3765-4815-A66D-98A09BE662D6} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
AddRemove-QQPCMgr - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\Uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
" QQPCTray"="\"c:\\Program Files (x86)\\Tencent\\QQPCMgr\\11.1.16923.222\\QQPCTRAY.EXE\" /regrun /qqrepair"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,ba,2f,57,c4,3d,3c,4d,b7,4e,f0,28,c9,05,a3,75,4c,df,80,02,6c,cf,14,
e4,17,c1,82,17,16,6a,4a,c6,2e,05,58,2c,e6,b3,c2,4d,88,91,81,74,d2,9a,c7,bf,\
"??"=hex:d8,90,4b,a3,73,2d,6c,95,da,79,42,27,2f,a3,90,1c
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\License information*]
"datasecu"=hex:c1,15,d3,e7,d1,15,1e,fd,a3,87,d5,4c,34,ca,7e,5b,85,0f,7c,3d,bc,
3d,01,64,a0,8b,6a,e6,f5,e5,39,fa,08,91,21,8d,e8,0a,a3,ab,1a,29,53,e5,5b,86,\
"rkeysecu"=hex:e2,1c,9c,ff,e4,ff,7d,03,23,9a,e2,72,39,73,4a,a3
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000_Classes\.*MSWIM*]
@Allowed: (Read) (RestrictedCode)
@="ExtractNow"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\IObit\Advanced SystemCare\Monitor.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
.
**************************************************************************
.
Celkový čas: 2016-02-13 14:58:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2016-02-13 13:58
.
Před spuštěním: Volných bajtů: 176 704 249 856
Po spuštění: Volných bajtů: 176 011 694 080
.
- - End Of File - - 234C3C3338667905295849FD57660DEE
E6317055AD057D25F3037CDC5F95CCAC
Ohlásit tento příspěvek
Nahoru Profil Upravit příspěvek Odpovědět s citací
skorpo
Předmět příspěvku: Re: čínský šmejd iqiyi-nejde odinstalovatPříspěvekNapsal: včera, 15:03
Online
Návštěvník
Návštěvník
Registrován: 12 úno 2016 18:12
Příspěvky: 3
Log z Combofix. Prosím o pomoc. Děkuji.
ComboFix 16-02-09.01 - Karolina 13.02.2016 14:30:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4063.1977 [GMT 1:00]
Spuštěný z: c:\users\Karolina\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\Karolina\AppData\Local\assembly\tmp
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\__AssemblyInfo__.ini
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\Microsoft.Office.Tools.Common.v4.0.Utilities.DLL
c:\windows\IsUn0405.exe
c:\windows\msdownld.tmp
c:\windows\SysWow64\tmp144F.tmp
c:\windows\SysWow64\tmp145F.tmp
c:\windows\SysWow64\tmp6F2B.tmp
c:\windows\SysWow64\tmp6F3B.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-01-13 do 2016-02-13 )))))))))))))))))))))))))))))))
.
.
2016-02-13 13:44 . 2016-02-13 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-02-12 16:59 . 2016-02-12 16:59 -------- d-----w- c:\programdata\TXQMPC
2016-02-10 22:10 . 2016-02-10 22:10 210432 ----a-w- c:\windows\system32\aepic.dll
2016-02-10 22:10 . 2016-02-10 22:10 1164800 ----a-w- c:\windows\system32\aeinv.dll
2016-02-10 21:57 . 2016-02-10 21:57 62464 ----a-w- c:\windows\system32\drivers\appid.sys
2016-02-10 21:54 . 2016-02-10 21:54 879616 ----a-w- c:\windows\system32\advapi32.dll
2016-02-10 21:54 . 2016-02-10 21:54 643072 ----a-w- c:\windows\SysWow64\advapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76288 ----a-w- c:\windows\system32\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 67584 ----a-w- c:\windows\SysWow64\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 624640 ----a-w- c:\windows\system32\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 509952 ----a-w- c:\windows\SysWow64\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76800 ----a-w- c:\windows\SysWow64\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 14336 ----a-w- c:\windows\SysWow64\fixmapi.exe
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 17920 ----a-w- c:\windows\system32\fixmapi.exe
2016-02-10 21:51 . 2016-02-10 21:51 3211264 ----a-w- c:\windows\system32\win32k.sys
2016-02-10 21:25 . 2016-02-10 21:25 87864 ------w- c:\windows\system32\drivers\TFsFltX64.sys
2016-02-10 21:24 . 2016-02-12 17:00 -------- d-----w- c:\programdata\Tencent
2016-02-10 09:37 . 2016-02-10 09:37 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.3656.dll
2016-02-09 17:53 . 2016-02-09 17:53 -------- d-----w- c:\users\Karolina\AppData\Roaming\GameMill Entertainment
2016-02-09 17:16 . 2016-02-09 17:16 -------- d-----w- c:\programdata\Big Fish
2016-02-09 17:14 . 2016-02-09 17:16 -------- d-----w- c:\users\Karolina\AppData\Local\Big Fish
2016-02-09 09:05 . 2016-02-09 09:05 398152 ----a-w- c:\windows\system32\aswBoot.exe
2016-02-09 09:05 . 2016-02-09 09:05 52184 ----a-w- c:\windows\avastSS.scr
2016-02-03 11:01 . 2016-02-03 11:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.4380.dll
2016-02-03 10:53 . 2015-12-16 09:15 11154520 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\mpengine.dll
2016-02-03 10:53 . 2016-02-03 10:53 -------- d-----w- C:\4b07b6a08b1f5c3eab3c975b
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZE.DLL
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\SysWow64\nlsbres.dll
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\system32\nlsbres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\system32\tzres.dll
2016-02-03 10:42 . 2016-02-03 10:42 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1180160 ----a-w- c:\windows\system32\FntCache.dll
2016-02-03 10:42 . 2016-02-03 10:42 833024 ----a-w- c:\windows\SysWow64\user32.dll
2016-02-03 10:42 . 2016-02-03 10:42 1648128 ----a-w- c:\windows\system32\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1008640 ----a-w- c:\windows\system32\user32.dll
2016-02-03 10:41 . 2016-02-03 10:41 241664 ----a-w- c:\windows\system32\els.dll
2016-02-03 10:41 . 2016-02-03 10:41 179712 ----a-w- c:\windows\SysWow64\els.dll
2016-02-03 10:39 . 2016-02-03 10:39 17408 ----a-w- c:\windows\system32\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 14848 ----a-w- c:\windows\SysWow64\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 146944 ----a-w- c:\windows\system32\drivers\rmcast.sys
2016-02-03 10:38 . 2016-02-03 10:38 802304 ----a-w- c:\windows\system32\usp10.dll
2016-02-03 10:38 . 2016-02-03 10:38 627712 ----a-w- c:\windows\SysWow64\usp10.dll
2016-02-03 10:37 . 2016-02-03 10:37 487936 ----a-w- c:\windows\SysWow64\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1242624 ----a-w- c:\windows\SysWow64\comsvcs.dll
2016-02-03 10:37 . 2016-02-03 10:37 525312 ----a-w- c:\windows\system32\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1735680 ----a-w- c:\windows\system32\comsvcs.dll
2016-02-03 10:18 . 2016-02-03 10:18 497664 ----a-w- c:\windows\system32\drivers\afd.sys
2016-02-03 10:18 . 2016-02-03 10:18 118272 ----a-w- c:\windows\system32\drivers\tdx.sys
2016-02-03 10:16 . 2016-02-03 10:16 950720 ----a-w- c:\windows\system32\drivers\ndis.sys
2016-02-03 10:11 . 2016-02-03 10:11 939520 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:11 . 2016-02-03 10:11 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 1415168 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 275456 ----a-w- c:\windows\system32\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 2103296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 1372160 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:08 . 2016-02-03 10:08 459344 ----a-w- c:\windows\system32\drivers\cng.sys
2016-02-03 10:08 . 2016-02-03 10:08 298192 ----a-w- c:\windows\system32\bcryptprimitives.dll
2016-02-03 10:08 . 2016-02-03 10:08 251000 ----a-w- c:\windows\SysWow64\bcryptprimitives.dll
2016-02-03 10:06 . 2016-02-03 10:06 72192 ----a-w- c:\windows\system32\aelupsvc.dll
2016-02-03 10:06 . 2016-02-03 10:06 6656 ----a-w- c:\windows\system32\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 342016 ----a-w- c:\windows\system32\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 23552 ----a-w- c:\windows\system32\sdbinst.exe
2016-02-03 10:06 . 2016-02-03 10:06 5120 ----a-w- c:\windows\SysWow64\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 295936 ----a-w- c:\windows\SysWow64\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 20992 ----a-w- c:\windows\SysWow64\sdbinst.exe
2016-02-03 10:02 . 2016-02-03 10:02 634432 ----a-w- c:\windows\system32\winload.exe
2016-02-03 09:56 . 2016-02-03 09:56 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 1498624 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 14176768 ----a-w- c:\windows\system32\shell32.dll
2016-02-03 09:53 . 2016-02-03 09:53 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2016-02-03 09:53 . 2016-02-03 09:53 22528 ----a-w- c:\windows\system32\icaapi.dll
2016-02-03 09:51 . 2016-02-03 09:51 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2016-02-03 09:51 . 2016-02-03 09:51 46080 ----a-w- c:\windows\system32\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 41984 ----a-w- c:\windows\system32\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 372736 ----a-w- c:\windows\system32\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 299520 ----a-w- c:\windows\SysWow64\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 14336 ----a-w- c:\windows\system32\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 100864 ----a-w- c:\windows\system32\fontsub.dll
2016-02-03 09:47 . 2016-02-03 09:47 41984 ----a-w- c:\windows\system32\UtcResources.dll
2016-02-03 09:47 . 2016-02-03 09:47 1390592 ----a-w- c:\windows\system32\diagtrack.dll
2016-02-03 09:47 . 2016-02-03 09:47 879104 ----a-w- c:\windows\system32\tdh.dll
2016-02-03 09:47 . 2016-02-03 09:47 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2016-02-03 09:45 . 2016-02-03 09:45 82944 ----a-w- c:\windows\system32\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 67584 ----a-w- c:\windows\SysWow64\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 1632256 ----a-w- c:\windows\system32\dwmcore.dll
2016-02-03 09:45 . 2016-02-03 09:45 1372160 ----a-w- c:\windows\SysWow64\dwmcore.dll
2016-02-03 09:44 . 2016-02-03 09:44 1941504 ----a-w- c:\windows\system32\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 70656 ----a-w- c:\windows\system32\appinfo.dll
2016-02-03 09:44 . 2016-02-03 09:44 115136 ----a-w- c:\windows\system32\consent.exe
2016-02-03 09:39 . 2016-02-03 09:39 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2004480 ----a-w- c:\windows\system32\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1887232 ----a-w- c:\windows\system32\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-02-03 09:38 . 2016-02-03 09:38 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2016-02-03 09:38 . 2016-02-03 09:38 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2016-02-03 09:37 . 2016-02-03 09:37 82432 ----a-w- c:\windows\SysWow64\davclnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 260096 ----a-w- c:\windows\system32\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 206848 ----a-w- c:\windows\SysWow64\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 102912 ----a-w- c:\windows\system32\davclnt.dll
2016-02-03 09:34 . 2016-02-03 09:34 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\mountmgr.sys.mui
2016-02-03 09:34 . 2016-02-03 09:34 94656 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2016-02-03 09:34 . 2016-02-03 09:34 11264 ----a-w- c:\windows\system32\msmmsp.dll
2016-02-03 09:34 . 2016-02-03 09:34 1743360 ----a-w- c:\windows\system32\sysmain.dll
2016-02-03 09:27 . 2016-02-03 09:27 52736 ----a-w- c:\windows\system32\basesrv.dll
2016-02-03 09:23 . 2016-02-03 09:23 193536 ----a-w- c:\windows\system32\notepad.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-02-10 21:58 . 2016-02-10 21:58 344064 ----a-w- c:\windows\system32\schannel.dll
2016-02-10 21:58 . 2016-02-10 21:58 190464 ----a-w- c:\windows\system32\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 251392 ----a-w- c:\windows\SysWow64\schannel.dll
2016-02-10 21:57 . 2016-02-10 21:57 141312 ----a-w- c:\windows\SysWow64\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-02-10 21:53 . 2009-07-14 00:22 1393152 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2016-02-10 21:06 . 2013-03-01 13:47 287016 ----a-w- c:\windows\system32\drivers\aswvmm.sys
2016-02-09 09:05 . 2013-12-18 16:31 165344 ----a-w- c:\windows\system32\drivers\aswStm.sys
2016-02-09 09:05 . 2014-04-18 14:08 37656 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2016-02-09 09:05 . 2013-03-01 13:47 74544 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2016-02-09 09:05 . 2012-02-24 13:42 103064 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2016-02-09 09:05 . 2010-05-11 15:30 463744 ----a-w- c:\windows\system32\drivers\aswSP.sys
2016-02-09 09:05 . 2010-05-11 15:30 107792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2016-02-09 09:04 . 2011-03-26 21:32 1065720 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2016-02-03 10:35 . 2016-02-03 10:35 230400 ----a-w- c:\windows\SysWow64\webcheck.dll
2016-02-03 10:35 . 2016-02-03 10:35 262144 ----a-w- c:\windows\system32\webcheck.dll
2016-02-03 10:06 . 2016-02-03 10:06 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2016-02-03 10:06 . 2016-02-03 10:06 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-02-03 10:06 . 2016-02-03 10:06 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-01-17 22:46 . 2016-01-07 16:10 3571488 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2015-12-30 15:05 . 2015-12-30 15:05 0 ---ha-w- c:\users\Karolina\AppData\Local\BITF621.tmp
2015-12-02 12:18 . 2010-05-11 15:58 301728 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2015-11-06 2010912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-02 98304]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2016-02-09 7139768]
"Magic Desktop for HP notification"="c:\programdata\Easybits Magic Desktop for HP\mdhpSUN.exe" [2015-11-22 1444880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 athsgt;athsgt;c:\windows\system32\DRIVERS\athsgt.sys;c:\windows\SYSNATIVE\DRIVERS\athsgt.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 limsgt;limsgt;c:\windows\system32\DRIVERS\limsgt.sys;c:\windows\SYSNATIVE\DRIVERS\limsgt.sys [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 QQPCRTP;QQPCMgr RTP Service;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe [x]
R3 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [x]
R3 cmshusbser;Mobile Connector USB Device for Legacy Serial Communication IN ANDROID DEVICE;c:\windows\system32\DRIVERS\cmshusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmshusbser.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x]
R3 GGSAFERDriver;GGSAFER Driver; [x]
R3 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [x]
R3 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 ClickToRunSvc;Microsoft Office Click-to-Run Service;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe;c:\windows\SYSNATIVE\vfsFPService.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AVerAF15;HP DVB-T TV Tuner;c:\windows\system32\Drivers\AVerAF15.sys;c:\windows\SYSNATIVE\Drivers\AVerAF15.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys;c:\windows\SYSNATIVE\DRIVERS\enecir.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-02-09 20:45 1090376 ----a-w- c:\program files (x86)\Google\Chrome\Application\48.0.2564.109\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2016-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
2016-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-02-09 09:05 905248 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.Google.com/
uCustomizeSearch = hxxp://www.Google.com/
mCustomizeSearch = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-QQPCTray - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCTRAY.EXE
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{95080B13-AA71-4EE8-B951-7E98221E1ED5} - (no file)
ShellIconOverlayIdentifiers-{B7667919-3765-4815-A66D-98A09BE662D6} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
AddRemove-QQPCMgr - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\Uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
" QQPCTray"="\"c:\\Program Files (x86)\\Tencent\\QQPCMgr\\11.1.16923.222\\QQPCTRAY.EXE\" /regrun /qqrepair"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,ba,2f,57,c4,3d,3c,4d,b7,4e,f0,28,c9,05,a3,75,4c,df,80,02,6c,cf,14,
e4,17,c1,82,17,16,6a,4a,c6,2e,05,58,2c,e6,b3,c2,4d,88,91,81,74,d2,9a,c7,bf,\
"??"=hex:d8,90,4b,a3,73,2d,6c,95,da,79,42,27,2f,a3,90,1c
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\License information*]
"datasecu"=hex:c1,15,d3,e7,d1,15,1e,fd,a3,87,d5,4c,34,ca,7e,5b,85,0f,7c,3d,bc,
3d,01,64,a0,8b,6a,e6,f5,e5,39,fa,08,91,21,8d,e8,0a,a3,ab,1a,29,53,e5,5b,86,\
"rkeysecu"=hex:e2,1c,9c,ff,e4,ff,7d,03,23,9a,e2,72,39,73,4a,a3
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000_Classes\.*MSWIM*]
@Allowed: (Read) (RestrictedCode)
@="ExtractNow"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\IObit\Advanced SystemCare\Monitor.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
.
**************************************************************************
.
Celkový čas: 2016-02-13 14:58:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2016-02-13 13:58
.
Před spuštěním: Volných bajtů: 176 704 249 856
Po spuštění: Volných bajtů: 176 011 694 080
.
- - End Of File - - 234C3C3338667905295849FD57660DEE
E6317055AD057D25F3037CDC5F95CCAC
díky
Mám v notebooku nějaké svinstvo s čínskými znaky, kterého se nelze zbavit. vlezlo mi to do browseru, změnilo vyhledávač (což samozřejmě už nejde dát na jiný) a celkově to vyhazuje pop-upy.
adwcleaner log níže
# AdwCleaner v5.033 - Logfile created 12/02/2016 at 17:57:46
# Updated 07/02/2016 by Xplode
# Database : 2016-02-07.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Karolina - KAROLINA-PC
# Running from : C:\Users\Karolina\Desktop\adwcleaner_5.033.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
[-] Service Deleted : QQPCRTP
[-] Service Deleted : TAOAccelerator
[-] Service Deleted : TSDefenseBt
[-] Service Deleted : TSSysKit
[-] Service Deleted : QMUdisk
[-] Service Deleted : QQSysMonX64
[-] Service Deleted : TFsFlt
[-] Service Deleted : TAOKernelDriver
[-] Service Deleted : TSSKX64
[-] Service Deleted : SPS
***** [ Folders ] *****
[-] Folder Deleted : C:\Genius
[#] Folder Deleted : C:\Program Files (x86)\tencent
[-] Folder Deleted : C:\Program Files (x86)\Common Files\tencent
[#] Folder Deleted : C:\Program Files\Common Files\tencent
[#] Folder Deleted : C:\ProgramData\tencent
[-] Folder Deleted : C:\ProgramData\TXQMPC
[-] Folder Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm
[-] Folder Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl
[-] Folder Deleted : C:\Users\Karolina\AppData\Roaming\tencent
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\tencent
***** [ Files ] *****
[-] File Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
[-] File Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nonjdcjchghhkdoolnlbekcfllmednbl_0.localstorage
[-] File Deleted : C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File Deleted : C:\Users\Karolina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\电脑管家.lnk
[-] File Deleted : C:\Windows\SysNative\drivers\TAOAccelerator64.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TSSKX64.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TAOKernel64.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TFsFltX64.sys
[-] File Deleted : C:\Windows\SysWOW64\SearchProtectService.exe
[-] File Deleted : C:\Windows\SysWOW64\drivers\TsFltMgr.sys
[-] File Deleted : C:\Windows\SysWOW64\drivers\TS888x64.sys
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQPCMgr
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Key Deleted : HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\QMContextUninstall
[-] Key Deleted : HKEY_CLASSES_ROOT\Folder\ShellEx\ContextMenuHandlers\QMContextUninstall
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [Plus-HD-7.6-bg.exe]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14CD42DD-ABCD-3586-DCAB-40E3693E3737}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16EE6530-8649-4F42-A9E4-F6A3295AF975}
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CBDECEF7-7A29-4CBF-A009-2673D82C7BF9}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{63332668-8CE1-445D-A5EE-25929176714E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{D4801E96-E7A1-45F6-B124-7A36DFB40B81}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2AEF02C3-5159-4C81-A688-8D954F0DEE56}_NewSearch
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQPCMgr
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tab]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
***** [ Web browsers ] *****
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : websearch.ask.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : microsoft-office-2010.softonic.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : kindle-to-pdf-converter.en.softonic.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : journey-to-the-center-of-the-earth.en.softonic.com
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nafaimnnclfjfedmmabolbppcngeolgf
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nonjdcjchghhkdoolnlbekcfllmednbl
[-] [C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ooebklgpfnbcnpokahmdidgbmlcdepkm
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [7762 bytes] ##########
a tady je combofix
ComboFix 16-02-09.01 - Karolina 13.02.2016 14:30:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4063.1977 [GMT 1:00]
Spuštěný z: c:\users\Karolina\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\Karolina\AppData\Local\assembly\tmp
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\__AssemblyInfo__.ini
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\Microsoft.Office.Tools.Common.v4.0.Utilities.DLL
c:\windows\IsUn0405.exe
c:\windows\msdownld.tmp
c:\windows\SysWow64\tmp144F.tmp
c:\windows\SysWow64\tmp145F.tmp
c:\windows\SysWow64\tmp6F2B.tmp
c:\windows\SysWow64\tmp6F3B.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-01-13 do 2016-02-13 )))))))))))))))))))))))))))))))
.
.
2016-02-13 13:44 . 2016-02-13 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-02-12 16:59 . 2016-02-12 16:59 -------- d-----w- c:\programdata\TXQMPC
2016-02-10 22:10 . 2016-02-10 22:10 210432 ----a-w- c:\windows\system32\aepic.dll
2016-02-10 22:10 . 2016-02-10 22:10 1164800 ----a-w- c:\windows\system32\aeinv.dll
2016-02-10 21:57 . 2016-02-10 21:57 62464 ----a-w- c:\windows\system32\drivers\appid.sys
2016-02-10 21:54 . 2016-02-10 21:54 879616 ----a-w- c:\windows\system32\advapi32.dll
2016-02-10 21:54 . 2016-02-10 21:54 643072 ----a-w- c:\windows\SysWow64\advapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76288 ----a-w- c:\windows\system32\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 67584 ----a-w- c:\windows\SysWow64\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 624640 ----a-w- c:\windows\system32\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 509952 ----a-w- c:\windows\SysWow64\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76800 ----a-w- c:\windows\SysWow64\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 14336 ----a-w- c:\windows\SysWow64\fixmapi.exe
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 17920 ----a-w- c:\windows\system32\fixmapi.exe
2016-02-10 21:51 . 2016-02-10 21:51 3211264 ----a-w- c:\windows\system32\win32k.sys
2016-02-10 21:25 . 2016-02-10 21:25 87864 ------w- c:\windows\system32\drivers\TFsFltX64.sys
2016-02-10 21:24 . 2016-02-12 17:00 -------- d-----w- c:\programdata\Tencent
2016-02-10 09:37 . 2016-02-10 09:37 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.3656.dll
2016-02-09 17:53 . 2016-02-09 17:53 -------- d-----w- c:\users\Karolina\AppData\Roaming\GameMill Entertainment
2016-02-09 17:16 . 2016-02-09 17:16 -------- d-----w- c:\programdata\Big Fish
2016-02-09 17:14 . 2016-02-09 17:16 -------- d-----w- c:\users\Karolina\AppData\Local\Big Fish
2016-02-09 09:05 . 2016-02-09 09:05 398152 ----a-w- c:\windows\system32\aswBoot.exe
2016-02-09 09:05 . 2016-02-09 09:05 52184 ----a-w- c:\windows\avastSS.scr
2016-02-03 11:01 . 2016-02-03 11:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.4380.dll
2016-02-03 10:53 . 2015-12-16 09:15 11154520 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\mpengine.dll
2016-02-03 10:53 . 2016-02-03 10:53 -------- d-----w- C:\4b07b6a08b1f5c3eab3c975b
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZE.DLL
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\SysWow64\nlsbres.dll
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\system32\nlsbres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\system32\tzres.dll
2016-02-03 10:42 . 2016-02-03 10:42 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1180160 ----a-w- c:\windows\system32\FntCache.dll
2016-02-03 10:42 . 2016-02-03 10:42 833024 ----a-w- c:\windows\SysWow64\user32.dll
2016-02-03 10:42 . 2016-02-03 10:42 1648128 ----a-w- c:\windows\system32\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1008640 ----a-w- c:\windows\system32\user32.dll
2016-02-03 10:41 . 2016-02-03 10:41 241664 ----a-w- c:\windows\system32\els.dll
2016-02-03 10:41 . 2016-02-03 10:41 179712 ----a-w- c:\windows\SysWow64\els.dll
2016-02-03 10:39 . 2016-02-03 10:39 17408 ----a-w- c:\windows\system32\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 14848 ----a-w- c:\windows\SysWow64\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 146944 ----a-w- c:\windows\system32\drivers\rmcast.sys
2016-02-03 10:38 . 2016-02-03 10:38 802304 ----a-w- c:\windows\system32\usp10.dll
2016-02-03 10:38 . 2016-02-03 10:38 627712 ----a-w- c:\windows\SysWow64\usp10.dll
2016-02-03 10:37 . 2016-02-03 10:37 487936 ----a-w- c:\windows\SysWow64\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1242624 ----a-w- c:\windows\SysWow64\comsvcs.dll
2016-02-03 10:37 . 2016-02-03 10:37 525312 ----a-w- c:\windows\system32\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1735680 ----a-w- c:\windows\system32\comsvcs.dll
2016-02-03 10:18 . 2016-02-03 10:18 497664 ----a-w- c:\windows\system32\drivers\afd.sys
2016-02-03 10:18 . 2016-02-03 10:18 118272 ----a-w- c:\windows\system32\drivers\tdx.sys
2016-02-03 10:16 . 2016-02-03 10:16 950720 ----a-w- c:\windows\system32\drivers\ndis.sys
2016-02-03 10:11 . 2016-02-03 10:11 939520 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:11 . 2016-02-03 10:11 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 1415168 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 275456 ----a-w- c:\windows\system32\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 2103296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 1372160 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:08 . 2016-02-03 10:08 459344 ----a-w- c:\windows\system32\drivers\cng.sys
2016-02-03 10:08 . 2016-02-03 10:08 298192 ----a-w- c:\windows\system32\bcryptprimitives.dll
2016-02-03 10:08 . 2016-02-03 10:08 251000 ----a-w- c:\windows\SysWow64\bcryptprimitives.dll
2016-02-03 10:06 . 2016-02-03 10:06 72192 ----a-w- c:\windows\system32\aelupsvc.dll
2016-02-03 10:06 . 2016-02-03 10:06 6656 ----a-w- c:\windows\system32\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 342016 ----a-w- c:\windows\system32\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 23552 ----a-w- c:\windows\system32\sdbinst.exe
2016-02-03 10:06 . 2016-02-03 10:06 5120 ----a-w- c:\windows\SysWow64\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 295936 ----a-w- c:\windows\SysWow64\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 20992 ----a-w- c:\windows\SysWow64\sdbinst.exe
2016-02-03 10:02 . 2016-02-03 10:02 634432 ----a-w- c:\windows\system32\winload.exe
2016-02-03 09:56 . 2016-02-03 09:56 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 1498624 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 14176768 ----a-w- c:\windows\system32\shell32.dll
2016-02-03 09:53 . 2016-02-03 09:53 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2016-02-03 09:53 . 2016-02-03 09:53 22528 ----a-w- c:\windows\system32\icaapi.dll
2016-02-03 09:51 . 2016-02-03 09:51 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2016-02-03 09:51 . 2016-02-03 09:51 46080 ----a-w- c:\windows\system32\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 41984 ----a-w- c:\windows\system32\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 372736 ----a-w- c:\windows\system32\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 299520 ----a-w- c:\windows\SysWow64\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 14336 ----a-w- c:\windows\system32\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 100864 ----a-w- c:\windows\system32\fontsub.dll
2016-02-03 09:47 . 2016-02-03 09:47 41984 ----a-w- c:\windows\system32\UtcResources.dll
2016-02-03 09:47 . 2016-02-03 09:47 1390592 ----a-w- c:\windows\system32\diagtrack.dll
2016-02-03 09:47 . 2016-02-03 09:47 879104 ----a-w- c:\windows\system32\tdh.dll
2016-02-03 09:47 . 2016-02-03 09:47 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2016-02-03 09:45 . 2016-02-03 09:45 82944 ----a-w- c:\windows\system32\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 67584 ----a-w- c:\windows\SysWow64\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 1632256 ----a-w- c:\windows\system32\dwmcore.dll
2016-02-03 09:45 . 2016-02-03 09:45 1372160 ----a-w- c:\windows\SysWow64\dwmcore.dll
2016-02-03 09:44 . 2016-02-03 09:44 1941504 ----a-w- c:\windows\system32\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 70656 ----a-w- c:\windows\system32\appinfo.dll
2016-02-03 09:44 . 2016-02-03 09:44 115136 ----a-w- c:\windows\system32\consent.exe
2016-02-03 09:39 . 2016-02-03 09:39 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2004480 ----a-w- c:\windows\system32\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1887232 ----a-w- c:\windows\system32\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-02-03 09:38 . 2016-02-03 09:38 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2016-02-03 09:38 . 2016-02-03 09:38 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2016-02-03 09:37 . 2016-02-03 09:37 82432 ----a-w- c:\windows\SysWow64\davclnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 260096 ----a-w- c:\windows\system32\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 206848 ----a-w- c:\windows\SysWow64\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 102912 ----a-w- c:\windows\system32\davclnt.dll
2016-02-03 09:34 . 2016-02-03 09:34 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\mountmgr.sys.mui
2016-02-03 09:34 . 2016-02-03 09:34 94656 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2016-02-03 09:34 . 2016-02-03 09:34 11264 ----a-w- c:\windows\system32\msmmsp.dll
2016-02-03 09:34 . 2016-02-03 09:34 1743360 ----a-w- c:\windows\system32\sysmain.dll
2016-02-03 09:27 . 2016-02-03 09:27 52736 ----a-w- c:\windows\system32\basesrv.dll
2016-02-03 09:23 . 2016-02-03 09:23 193536 ----a-w- c:\windows\system32\notepad.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-02-10 21:58 . 2016-02-10 21:58 344064 ----a-w- c:\windows\system32\schannel.dll
2016-02-10 21:58 . 2016-02-10 21:58 190464 ----a-w- c:\windows\system32\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 251392 ----a-w- c:\windows\SysWow64\schannel.dll
2016-02-10 21:57 . 2016-02-10 21:57 141312 ----a-w- c:\windows\SysWow64\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-02-10 21:53 . 2009-07-14 00:22 1393152 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2016-02-10 21:06 . 2013-03-01 13:47 287016 ----a-w- c:\windows\system32\drivers\aswvmm.sys
2016-02-09 09:05 . 2013-12-18 16:31 165344 ----a-w- c:\windows\system32\drivers\aswStm.sys
2016-02-09 09:05 . 2014-04-18 14:08 37656 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2016-02-09 09:05 . 2013-03-01 13:47 74544 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2016-02-09 09:05 . 2012-02-24 13:42 103064 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2016-02-09 09:05 . 2010-05-11 15:30 463744 ----a-w- c:\windows\system32\drivers\aswSP.sys
2016-02-09 09:05 . 2010-05-11 15:30 107792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2016-02-09 09:04 . 2011-03-26 21:32 1065720 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2016-02-03 10:35 . 2016-02-03 10:35 230400 ----a-w- c:\windows\SysWow64\webcheck.dll
2016-02-03 10:35 . 2016-02-03 10:35 262144 ----a-w- c:\windows\system32\webcheck.dll
2016-02-03 10:06 . 2016-02-03 10:06 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2016-02-03 10:06 . 2016-02-03 10:06 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-02-03 10:06 . 2016-02-03 10:06 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-01-17 22:46 . 2016-01-07 16:10 3571488 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2015-12-30 15:05 . 2015-12-30 15:05 0 ---ha-w- c:\users\Karolina\AppData\Local\BITF621.tmp
2015-12-02 12:18 . 2010-05-11 15:58 301728 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2015-11-06 2010912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-02 98304]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2016-02-09 7139768]
"Magic Desktop for HP notification"="c:\programdata\Easybits Magic Desktop for HP\mdhpSUN.exe" [2015-11-22 1444880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 athsgt;athsgt;c:\windows\system32\DRIVERS\athsgt.sys;c:\windows\SYSNATIVE\DRIVERS\athsgt.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 limsgt;limsgt;c:\windows\system32\DRIVERS\limsgt.sys;c:\windows\SYSNATIVE\DRIVERS\limsgt.sys [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 QQPCRTP;QQPCMgr RTP Service;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe [x]
R3 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [x]
R3 cmshusbser;Mobile Connector USB Device for Legacy Serial Communication IN ANDROID DEVICE;c:\windows\system32\DRIVERS\cmshusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmshusbser.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x]
R3 GGSAFERDriver;GGSAFER Driver; [x]
R3 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [x]
R3 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 ClickToRunSvc;Microsoft Office Click-to-Run Service;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe;c:\windows\SYSNATIVE\vfsFPService.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AVerAF15;HP DVB-T TV Tuner;c:\windows\system32\Drivers\AVerAF15.sys;c:\windows\SYSNATIVE\Drivers\AVerAF15.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys;c:\windows\SYSNATIVE\DRIVERS\enecir.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-02-09 20:45 1090376 ----a-w- c:\program files (x86)\Google\Chrome\Application\48.0.2564.109\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2016-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
2016-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-02-09 09:05 905248 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.Google.com/
uCustomizeSearch = hxxp://www.Google.com/
mCustomizeSearch = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-QQPCTray - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCTRAY.EXE
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{95080B13-AA71-4EE8-B951-7E98221E1ED5} - (no file)
ShellIconOverlayIdentifiers-{B7667919-3765-4815-A66D-98A09BE662D6} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
AddRemove-QQPCMgr - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\Uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
" QQPCTray"="\"c:\\Program Files (x86)\\Tencent\\QQPCMgr\\11.1.16923.222\\QQPCTRAY.EXE\" /regrun /qqrepair"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,ba,2f,57,c4,3d,3c,4d,b7,4e,f0,28,c9,05,a3,75,4c,df,80,02,6c,cf,14,
e4,17,c1,82,17,16,6a,4a,c6,2e,05,58,2c,e6,b3,c2,4d,88,91,81,74,d2,9a,c7,bf,\
"??"=hex:d8,90,4b,a3,73,2d,6c,95,da,79,42,27,2f,a3,90,1c
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\License information*]
"datasecu"=hex:c1,15,d3,e7,d1,15,1e,fd,a3,87,d5,4c,34,ca,7e,5b,85,0f,7c,3d,bc,
3d,01,64,a0,8b,6a,e6,f5,e5,39,fa,08,91,21,8d,e8,0a,a3,ab,1a,29,53,e5,5b,86,\
"rkeysecu"=hex:e2,1c,9c,ff,e4,ff,7d,03,23,9a,e2,72,39,73,4a,a3
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000_Classes\.*MSWIM*]
@Allowed: (Read) (RestrictedCode)
@="ExtractNow"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\IObit\Advanced SystemCare\Monitor.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
.
**************************************************************************
.
Celkový čas: 2016-02-13 14:58:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2016-02-13 13:58
.
Před spuštěním: Volných bajtů: 176 704 249 856
Po spuštění: Volných bajtů: 176 011 694 080
.
- - End Of File - - 234C3C3338667905295849FD57660DEE
E6317055AD057D25F3037CDC5F95CCAC
Ohlásit tento příspěvek
Nahoru Profil Upravit příspěvek Odpovědět s citací
skorpo
Předmět příspěvku: Re: čínský šmejd iqiyi-nejde odinstalovatPříspěvekNapsal: včera, 15:03
Online
Návštěvník
Návštěvník
Registrován: 12 úno 2016 18:12
Příspěvky: 3
Log z Combofix. Prosím o pomoc. Děkuji.
ComboFix 16-02-09.01 - Karolina 13.02.2016 14:30:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4063.1977 [GMT 1:00]
Spuštěný z: c:\users\Karolina\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\Karolina\AppData\Local\assembly\tmp
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\__AssemblyInfo__.ini
c:\users\Karolina\AppData\Local\assembly\tmp\OXA3633N\Microsoft.Office.Tools.Common.v4.0.Utilities.DLL
c:\windows\IsUn0405.exe
c:\windows\msdownld.tmp
c:\windows\SysWow64\tmp144F.tmp
c:\windows\SysWow64\tmp145F.tmp
c:\windows\SysWow64\tmp6F2B.tmp
c:\windows\SysWow64\tmp6F3B.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-01-13 do 2016-02-13 )))))))))))))))))))))))))))))))
.
.
2016-02-13 13:44 . 2016-02-13 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-02-12 16:59 . 2016-02-12 16:59 -------- d-----w- c:\programdata\TXQMPC
2016-02-10 22:10 . 2016-02-10 22:10 210432 ----a-w- c:\windows\system32\aepic.dll
2016-02-10 22:10 . 2016-02-10 22:10 1164800 ----a-w- c:\windows\system32\aeinv.dll
2016-02-10 21:57 . 2016-02-10 21:57 62464 ----a-w- c:\windows\system32\drivers\appid.sys
2016-02-10 21:54 . 2016-02-10 21:54 879616 ----a-w- c:\windows\system32\advapi32.dll
2016-02-10 21:54 . 2016-02-10 21:54 643072 ----a-w- c:\windows\SysWow64\advapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76288 ----a-w- c:\windows\system32\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 67584 ----a-w- c:\windows\SysWow64\devenum.dll
2016-02-10 21:52 . 2016-02-10 21:52 624640 ----a-w- c:\windows\system32\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 509952 ----a-w- c:\windows\SysWow64\qedit.dll
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapi32.dll
2016-02-10 21:52 . 2016-02-10 21:52 76800 ----a-w- c:\windows\SysWow64\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 14336 ----a-w- c:\windows\SysWow64\fixmapi.exe
2016-02-10 21:52 . 2016-02-10 21:52 91648 ----a-w- c:\windows\system32\mapistub.dll
2016-02-10 21:52 . 2016-02-10 21:52 17920 ----a-w- c:\windows\system32\fixmapi.exe
2016-02-10 21:51 . 2016-02-10 21:51 3211264 ----a-w- c:\windows\system32\win32k.sys
2016-02-10 21:25 . 2016-02-10 21:25 87864 ------w- c:\windows\system32\drivers\TFsFltX64.sys
2016-02-10 21:24 . 2016-02-12 17:00 -------- d-----w- c:\programdata\Tencent
2016-02-10 09:37 . 2016-02-10 09:37 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.3656.dll
2016-02-09 17:53 . 2016-02-09 17:53 -------- d-----w- c:\users\Karolina\AppData\Roaming\GameMill Entertainment
2016-02-09 17:16 . 2016-02-09 17:16 -------- d-----w- c:\programdata\Big Fish
2016-02-09 17:14 . 2016-02-09 17:16 -------- d-----w- c:\users\Karolina\AppData\Local\Big Fish
2016-02-09 09:05 . 2016-02-09 09:05 398152 ----a-w- c:\windows\system32\aswBoot.exe
2016-02-09 09:05 . 2016-02-09 09:05 52184 ----a-w- c:\windows\avastSS.scr
2016-02-03 11:01 . 2016-02-03 11:01 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\offreg.4380.dll
2016-02-03 10:53 . 2015-12-16 09:15 11154520 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B2259791-36CE-43F6-A778-7F540B49C3CE}\mpengine.dll
2016-02-03 10:53 . 2016-02-03 10:53 -------- d-----w- C:\4b07b6a08b1f5c3eab3c975b
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 7168 ----a-w- c:\windows\system32\KBDAZE.DLL
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\kbdgeoqw.dll
2016-02-03 10:50 . 2016-02-03 10:50 6656 ----a-w- c:\windows\SysWow64\KBDAZEL.DLL
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\SysWow64\nlsbres.dll
2016-02-03 10:50 . 2016-02-03 10:50 69120 ----a-w- c:\windows\system32\nlsbres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2016-02-03 10:47 . 2016-02-03 10:47 2048 ----a-w- c:\windows\system32\tzres.dll
2016-02-03 10:42 . 2016-02-03 10:42 1251328 ----a-w- c:\windows\SysWow64\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1180160 ----a-w- c:\windows\system32\FntCache.dll
2016-02-03 10:42 . 2016-02-03 10:42 833024 ----a-w- c:\windows\SysWow64\user32.dll
2016-02-03 10:42 . 2016-02-03 10:42 1648128 ----a-w- c:\windows\system32\DWrite.dll
2016-02-03 10:42 . 2016-02-03 10:42 1008640 ----a-w- c:\windows\system32\user32.dll
2016-02-03 10:41 . 2016-02-03 10:41 241664 ----a-w- c:\windows\system32\els.dll
2016-02-03 10:41 . 2016-02-03 10:41 179712 ----a-w- c:\windows\SysWow64\els.dll
2016-02-03 10:39 . 2016-02-03 10:39 17408 ----a-w- c:\windows\system32\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 14848 ----a-w- c:\windows\SysWow64\wshrm.dll
2016-02-03 10:39 . 2016-02-03 10:39 146944 ----a-w- c:\windows\system32\drivers\rmcast.sys
2016-02-03 10:38 . 2016-02-03 10:38 802304 ----a-w- c:\windows\system32\usp10.dll
2016-02-03 10:38 . 2016-02-03 10:38 627712 ----a-w- c:\windows\SysWow64\usp10.dll
2016-02-03 10:37 . 2016-02-03 10:37 487936 ----a-w- c:\windows\SysWow64\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1242624 ----a-w- c:\windows\SysWow64\comsvcs.dll
2016-02-03 10:37 . 2016-02-03 10:37 525312 ----a-w- c:\windows\system32\catsrvut.dll
2016-02-03 10:37 . 2016-02-03 10:37 1735680 ----a-w- c:\windows\system32\comsvcs.dll
2016-02-03 10:18 . 2016-02-03 10:18 497664 ----a-w- c:\windows\system32\drivers\afd.sys
2016-02-03 10:18 . 2016-02-03 10:18 118272 ----a-w- c:\windows\system32\drivers\tdx.sys
2016-02-03 10:16 . 2016-02-03 10:16 950720 ----a-w- c:\windows\system32\drivers\ndis.sys
2016-02-03 10:11 . 2016-02-03 10:11 939520 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:11 . 2016-02-03 10:11 274944 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 1415168 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 126464 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 353280 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkDiv.dll
2016-02-03 10:11 . 2016-02-03 10:11 275456 ----a-w- c:\windows\system32\InkEd.dll
2016-02-03 10:11 . 2016-02-03 10:11 2103296 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2016-02-03 10:11 . 2016-02-03 10:11 169984 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\rtscom.dll
2016-02-03 10:11 . 2016-02-03 10:11 1372160 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2016-02-03 10:08 . 2016-02-03 10:08 459344 ----a-w- c:\windows\system32\drivers\cng.sys
2016-02-03 10:08 . 2016-02-03 10:08 298192 ----a-w- c:\windows\system32\bcryptprimitives.dll
2016-02-03 10:08 . 2016-02-03 10:08 251000 ----a-w- c:\windows\SysWow64\bcryptprimitives.dll
2016-02-03 10:06 . 2016-02-03 10:06 72192 ----a-w- c:\windows\system32\aelupsvc.dll
2016-02-03 10:06 . 2016-02-03 10:06 6656 ----a-w- c:\windows\system32\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 342016 ----a-w- c:\windows\system32\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 23552 ----a-w- c:\windows\system32\sdbinst.exe
2016-02-03 10:06 . 2016-02-03 10:06 5120 ----a-w- c:\windows\SysWow64\shimeng.dll
2016-02-03 10:06 . 2016-02-03 10:06 295936 ----a-w- c:\windows\SysWow64\apphelp.dll
2016-02-03 10:06 . 2016-02-03 10:06 20992 ----a-w- c:\windows\SysWow64\sdbinst.exe
2016-02-03 10:02 . 2016-02-03 10:02 634432 ----a-w- c:\windows\system32\winload.exe
2016-02-03 09:56 . 2016-02-03 09:56 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 1498624 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-02-03 09:56 . 2016-02-03 09:56 14176768 ----a-w- c:\windows\system32\shell32.dll
2016-02-03 09:53 . 2016-02-03 09:53 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2016-02-03 09:53 . 2016-02-03 09:53 22528 ----a-w- c:\windows\system32\icaapi.dll
2016-02-03 09:51 . 2016-02-03 09:51 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2016-02-03 09:51 . 2016-02-03 09:51 46080 ----a-w- c:\windows\system32\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 41984 ----a-w- c:\windows\system32\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 372736 ----a-w- c:\windows\system32\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2016-02-03 09:51 . 2016-02-03 09:51 299520 ----a-w- c:\windows\SysWow64\atmfd.dll
2016-02-03 09:51 . 2016-02-03 09:51 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2016-02-03 09:51 . 2016-02-03 09:51 14336 ----a-w- c:\windows\system32\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2016-02-03 09:51 . 2016-02-03 09:51 100864 ----a-w- c:\windows\system32\fontsub.dll
2016-02-03 09:47 . 2016-02-03 09:47 41984 ----a-w- c:\windows\system32\UtcResources.dll
2016-02-03 09:47 . 2016-02-03 09:47 1390592 ----a-w- c:\windows\system32\diagtrack.dll
2016-02-03 09:47 . 2016-02-03 09:47 879104 ----a-w- c:\windows\system32\tdh.dll
2016-02-03 09:47 . 2016-02-03 09:47 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2016-02-03 09:45 . 2016-02-03 09:45 82944 ----a-w- c:\windows\system32\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 67584 ----a-w- c:\windows\SysWow64\dwmapi.dll
2016-02-03 09:45 . 2016-02-03 09:45 1632256 ----a-w- c:\windows\system32\dwmcore.dll
2016-02-03 09:45 . 2016-02-03 09:45 1372160 ----a-w- c:\windows\SysWow64\dwmcore.dll
2016-02-03 09:44 . 2016-02-03 09:44 1941504 ----a-w- c:\windows\system32\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2016-02-03 09:44 . 2016-02-03 09:44 70656 ----a-w- c:\windows\system32\appinfo.dll
2016-02-03 09:44 . 2016-02-03 09:44 115136 ----a-w- c:\windows\system32\consent.exe
2016-02-03 09:39 . 2016-02-03 09:39 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml6r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2048 ----a-w- c:\windows\system32\msxml3r.dll
2016-02-03 09:39 . 2016-02-03 09:39 2004480 ----a-w- c:\windows\system32\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1887232 ----a-w- c:\windows\system32\msxml3.dll
2016-02-03 09:39 . 2016-02-03 09:39 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-02-03 09:38 . 2016-02-03 09:38 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2016-02-03 09:38 . 2016-02-03 09:38 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2016-02-03 09:37 . 2016-02-03 09:37 82432 ----a-w- c:\windows\SysWow64\davclnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 260096 ----a-w- c:\windows\system32\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 206848 ----a-w- c:\windows\SysWow64\WebClnt.dll
2016-02-03 09:37 . 2016-02-03 09:37 102912 ----a-w- c:\windows\system32\davclnt.dll
2016-02-03 09:34 . 2016-02-03 09:34 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\mountmgr.sys.mui
2016-02-03 09:34 . 2016-02-03 09:34 94656 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2016-02-03 09:34 . 2016-02-03 09:34 11264 ----a-w- c:\windows\system32\msmmsp.dll
2016-02-03 09:34 . 2016-02-03 09:34 1743360 ----a-w- c:\windows\system32\sysmain.dll
2016-02-03 09:27 . 2016-02-03 09:27 52736 ----a-w- c:\windows\system32\basesrv.dll
2016-02-03 09:23 . 2016-02-03 09:23 193536 ----a-w- c:\windows\system32\notepad.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-02-10 21:58 . 2016-02-10 21:58 344064 ----a-w- c:\windows\system32\schannel.dll
2016-02-10 21:58 . 2016-02-10 21:58 190464 ----a-w- c:\windows\system32\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 251392 ----a-w- c:\windows\SysWow64\schannel.dll
2016-02-10 21:57 . 2016-02-10 21:57 141312 ----a-w- c:\windows\SysWow64\rpchttp.dll
2016-02-10 21:57 . 2016-02-10 21:57 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-02-10 21:53 . 2009-07-14 00:22 1393152 ----a-w- c:\windows\system32\WMALFXGFXDSP.dll
2016-02-10 21:06 . 2013-03-01 13:47 287016 ----a-w- c:\windows\system32\drivers\aswvmm.sys
2016-02-09 09:05 . 2013-12-18 16:31 165344 ----a-w- c:\windows\system32\drivers\aswStm.sys
2016-02-09 09:05 . 2014-04-18 14:08 37656 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2016-02-09 09:05 . 2013-03-01 13:47 74544 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2016-02-09 09:05 . 2012-02-24 13:42 103064 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2016-02-09 09:05 . 2010-05-11 15:30 463744 ----a-w- c:\windows\system32\drivers\aswSP.sys
2016-02-09 09:05 . 2010-05-11 15:30 107792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2016-02-09 09:04 . 2011-03-26 21:32 1065720 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2016-02-03 10:35 . 2016-02-03 10:35 230400 ----a-w- c:\windows\SysWow64\webcheck.dll
2016-02-03 10:35 . 2016-02-03 10:35 262144 ----a-w- c:\windows\system32\webcheck.dll
2016-02-03 10:06 . 2016-02-03 10:06 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2016-02-03 10:06 . 2016-02-03 10:06 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2016-02-03 10:06 . 2016-02-03 10:06 309248 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2016-02-03 10:06 . 2016-02-03 10:06 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2016-02-03 10:06 . 2016-02-03 10:06 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2016-02-03 10:06 . 2016-02-03 10:06 103424 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2016-02-03 09:39 . 2016-02-03 09:39 1110016 ----a-w- c:\windows\system32\schedsvc.dll
2016-01-17 22:46 . 2016-01-07 16:10 3571488 ----a-w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2015-12-30 15:05 . 2015-12-30 15:05 0 ---ha-w- c:\users\Karolina\AppData\Local\BITF621.tmp
2015-12-02 12:18 . 2010-05-11 15:58 301728 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:18 329376 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 22:01 1536296 ----a-w- c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"="c:\program files (x86)\IObit\Advanced SystemCare\ASCTray.exe" [2015-11-06 2010912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-02 98304]
"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"AvastUI.exe"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2016-02-09 7139768]
"Magic Desktop for HP notification"="c:\programdata\Easybits Magic Desktop for HP\mdhpSUN.exe" [2015-11-22 1444880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 athsgt;athsgt;c:\windows\system32\DRIVERS\athsgt.sys;c:\windows\SYSNATIVE\DRIVERS\athsgt.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
R2 limsgt;limsgt;c:\windows\system32\DRIVERS\limsgt.sys;c:\windows\SYSNATIVE\DRIVERS\limsgt.sys [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 QQPCRTP;QQPCMgr RTP Service;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe;c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCRtp.exe [x]
R3 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe;c:\windows\SYSNATIVE\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [x]
R3 cmshusbser;Mobile Connector USB Device for Legacy Serial Communication IN ANDROID DEVICE;c:\windows\system32\DRIVERS\cmshusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmshusbser.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x]
R3 GGSAFERDriver;GGSAFER Driver; [x]
R3 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [x]
R3 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe;c:\program files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVSched.exe [x]
R3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
R4 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AdvancedSystemCareService9;Advanced SystemCare Service 9;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 ClickToRunSvc;Microsoft Office Click-to-Run Service;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe;c:\program files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe;c:\windows\SYSNATIVE\vfsFPService.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 AVerAF15;HP DVB-T TV Tuner;c:\windows\system32\Drivers\AVerAF15.sys;c:\windows\SYSNATIVE\Drivers\AVerAF15.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys;c:\windows\SYSNATIVE\DRIVERS\enecir.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys;c:\windows\SYSNATIVE\DRIVERS\johci.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-02-09 20:45 1090376 ----a-w- c:\program files (x86)\Google\Chrome\Application\48.0.2564.109\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2016-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
2016-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-24 09:17]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2016-01-07 16:19 358064 ----a-w- c:\users\Karolina\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2016-01-17 23:08 2093360 ----a-w- c:\program files\Microsoft Office\root\Office16\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-02-09 09:05 905248 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.Google.com/
uCustomizeSearch = hxxp://www.Google.com/
mCustomizeSearch = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Se&nd to OneNote - c:\program files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - c:\program files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-QQPCTray - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\QQPCTRAY.EXE
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
WebBrowser-{95080B13-AA71-4EE8-B951-7E98221E1ED5} - (no file)
ShellIconOverlayIdentifiers-{B7667919-3765-4815-A66D-98A09BE662D6} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
AddRemove-QQPCMgr - c:\program files (x86)\Tencent\QQPCMgr\11.1.16923.222\Uninst.exe
.
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
" QQPCTray"="\"c:\\Program Files (x86)\\Tencent\\QQPCMgr\\11.1.16923.222\\QQPCTRAY.EXE\" /regrun /qqrepair"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,80,41,4b,da,7c,15,4b,8e,74,d4,\
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,ba,2f,57,c4,3d,3c,4d,b7,4e,f0,28,c9,05,a3,75,4c,df,80,02,6c,cf,14,
e4,17,c1,82,17,16,6a,4a,c6,2e,05,58,2c,e6,b3,c2,4d,88,91,81,74,d2,9a,c7,bf,\
"??"=hex:d8,90,4b,a3,73,2d,6c,95,da,79,42,27,2f,a3,90,1c
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000\Software\SecuROM\License information*]
"datasecu"=hex:c1,15,d3,e7,d1,15,1e,fd,a3,87,d5,4c,34,ca,7e,5b,85,0f,7c,3d,bc,
3d,01,64,a0,8b,6a,e6,f5,e5,39,fa,08,91,21,8d,e8,0a,a3,ab,1a,29,53,e5,5b,86,\
"rkeysecu"=hex:e2,1c,9c,ff,e4,ff,7d,03,23,9a,e2,72,39,73,4a,a3
.
[HKEY_USERS\S-1-5-21-417890151-1962072562-667573049-1000_Classes\.*MSWIM*]
@Allowed: (Read) (RestrictedCode)
@="ExtractNow"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\DigitalPersona\Bin\DpHostW.exe
c:\program files (x86)\IObit\Advanced SystemCare\Monitor.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
c:\program files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
.
**************************************************************************
.
Celkový čas: 2016-02-13 14:58:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2016-02-13 13:58
.
Před spuštěním: Volných bajtů: 176 704 249 856
Po spuštění: Volných bajtů: 176 011 694 080
.
- - End Of File - - 234C3C3338667905295849FD57660DEE
E6317055AD057D25F3037CDC5F95CCAC
díky