Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zavirovaný pc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Lucifix
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 23 říj 2008 19:53

Zavirovaný pc

#1 Příspěvek od Lucifix »

Dobrý večer,

obracím se na vás opět o pomoc, předevčírem - z ničeho nic - pc přestal fungovat tak jako vždy, byl zpomalený, spíše zasekaný, nic se nechtělo načíst, samovolně vypadávala wifi, pročistila jsem Ccleanerem, spustila AVG - našel nějaké trojany....snad je zlikvidoval....nevím, při dalším spuštění testu se test při 86% kousl cca na půl hodiny, nato se objevil modrý monitor s nějakými hláškami - anglicky moc neumím - po 2min se sám restartoval....moc díky za pomoc.....jedu tedy jen na nouzovým režimu momentálně, v normálním se mi nic neotevře :-(

Logfile of random's system information tool 1.10 (written by random/random)
Run by Jára at 2014-11-05 21:52:04
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 171 GB (69%) free of 250 GB
Total RAM: 4094 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:52:09, on 5.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jára.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Jára\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - c:\Windows\system32\vfsFPService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7547 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
ctfmon.exe
"C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="528.4.1632184678\1744696135" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\Jára\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=1,16 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gpu-driver-version --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_99/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --disable-gpu-compositing --channel="528.6.712535095\1546878939" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_99/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --disable-gpu-compositing --channel="528.9.69522262\1014623569" /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_99/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --disable-gpu-compositing --channel="528.11.114497803\63993416" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_99/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --disable-gpu-compositing --channel="528.12.1608077843\1029309162" /prefetch:673131151
"C:\Users\Jára\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-09 462248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-09 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-04-30 1794344]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-01-26 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"=C:\Users\Jára\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-07-27 321080]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2014-10-16 3649040]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-11-05 21:52:05 ----D---- C:\Program Files\trend micro
2014-11-05 21:52:04 ----D---- C:\rsit
2014-11-04 20:58:33 ----A---- C:\autoexec.bat
2014-11-04 20:58:02 ----A---- C:\Windows\system32\drivers\EsgScanner.sys
2014-11-04 20:57:57 ----D---- C:\sh4ldr
2014-11-04 20:57:57 ----D---- C:\Program Files\Enigma Software Group
2014-11-04 19:23:02 ----D---- C:\AdwCleaner
2014-11-04 19:21:44 ----SHD---- C:\$RECYCLE.BIN
2014-11-04 19:21:40 ----D---- C:\Windows\temp
2014-11-04 19:21:38 ----A---- C:\ComboFix.txt
2014-11-04 19:01:05 ----D---- C:\ComboFix
2014-11-04 17:01:01 ----A---- C:\Windows\system32\FNTCACHE.DAT
2014-11-04 16:58:17 ----A---- C:\Windows\ntbtlog.txt
2014-10-26 20:28:24 ----D---- C:\Program Files (x86)\Photo-Brush 5
2014-10-19 14:41:30 ----D---- C:\Users\Jára\AppData\Roaming\AVG2015
2014-10-19 14:40:19 ----D---- C:\Users\Jára\AppData\Roaming\TuneUp Software
2014-10-19 14:39:05 ----D---- C:\ProgramData\AVG2015
2014-10-19 14:39:05 ----D---- C:\$AVG
2014-10-19 14:38:01 ----D---- C:\Program Files (x86)\AVG
2014-10-19 14:35:28 ----HD---- C:\ProgramData\Common Files
2014-10-19 14:35:28 ----D---- C:\ProgramData\MFAData
2014-10-18 20:42:46 ----D---- C:\ProgramData\FreeWorldApp
2014-10-18 20:42:27 ----D---- C:\ProgramData\InstallMate
2014-10-15 21:23:27 ----A---- C:\Windows\SYSWOW64\winsta.dll
2014-10-15 21:23:27 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-10-15 21:23:27 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2014-10-15 21:23:26 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-10-15 21:23:26 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-10-15 21:23:26 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-10-15 21:23:19 ----A---- C:\Windows\system32\winlogon.exe
2014-10-15 21:23:18 ----A---- C:\Windows\system32\winsta.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\termsrv.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\mstscax.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\mstsc.exe
2014-10-15 21:23:18 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-15 21:23:18 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-15 21:23:17 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-15 21:23:17 ----A---- C:\Windows\system32\credssp.dll
2014-10-15 21:23:07 ----A---- C:\Windows\system32\win32k.sys
2014-10-15 21:23:04 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2014-10-15 21:23:04 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-10-15 21:23:04 ----A---- C:\Windows\system32\mscorier.dll
2014-10-15 21:23:04 ----A---- C:\Windows\system32\dfshim.dll
2014-10-15 21:23:03 ----A---- C:\Windows\SYSWOW64\mscories.dll
2014-10-15 21:23:03 ----A---- C:\Windows\system32\mscories.dll
2014-10-15 21:22:57 ----A---- C:\Windows\system32\generaltel.dll
2014-10-15 21:22:57 ----A---- C:\Windows\system32\aepdu.dll
2014-10-15 21:22:56 ----A---- C:\Windows\system32\aeinv.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-10-15 21:22:53 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-10-15 21:22:53 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-10-15 21:22:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\iernonce.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\ie4uinit.exe
2014-10-15 21:22:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-10-15 21:22:52 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-10-15 21:22:52 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-10-15 21:22:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-10-15 21:22:50 ----A---- C:\Windows\system32\iedkcs32.dll
2014-10-15 21:22:49 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-10-15 21:22:49 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-10-15 21:22:49 ----A---- C:\Windows\system32\urlmon.dll
2014-10-15 21:22:49 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 21:22:48 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-10-15 21:22:48 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-10-15 21:22:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-10-15 21:22:48 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-15 21:22:48 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-10-15 21:22:48 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-15 21:22:47 ----A---- C:\Windows\system32\iesetup.dll
2014-10-15 21:22:46 ----A---- C:\Windows\system32\iertutil.dll
2014-10-15 21:22:45 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-10-15 21:22:45 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-10-15 21:22:44 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-15 21:22:43 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-10-15 21:22:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-10-15 21:22:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-15 21:22:41 ----A---- C:\Windows\system32\ieui.dll
2014-10-15 21:22:41 ----A---- C:\Windows\system32\ieframe.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\jscript9diag.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-15 21:22:39 ----A---- C:\Windows\system32\wininet.dll
2014-10-15 21:22:39 ----A---- C:\Windows\system32\vbscript.dll
2014-10-15 21:22:39 ----A---- C:\Windows\system32\jscript9.dll
2014-10-15 21:22:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-10-15 21:22:38 ----A---- C:\Windows\system32\msrating.dll
2014-10-15 21:22:38 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-10-15 21:22:37 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 21:22:36 ----A---- C:\Windows\system32\mshtml.dll
2014-10-15 21:21:27 ----A---- C:\Windows\system32\msi.dll
2014-10-15 21:21:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-10-15 21:21:21 ----A---- C:\Windows\SYSWOW64\rastls.dll
2014-10-15 21:21:21 ----A---- C:\Windows\system32\rastls.dll
2014-10-15 21:19:02 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-10-15 21:19:02 ----A---- C:\Windows\system32\packager.dll
2014-10-15 19:01:15 ----D---- C:\Users\Jára\AppData\Roaming\TS3Client
2014-10-10 15:14:32 ----A---- C:\Windows\system32\drivers\avgtdia.sys
2014-10-07 21:43:06 ----A---- C:\Windows\system32\drivers\avgidsdrivera.sys

======List of files/folders modified in the last 1 month======

2014-11-05 21:52:05 ----RD---- C:\Program Files
2014-11-05 17:49:53 ----D---- C:\Windows\System32
2014-11-05 17:49:53 ----D---- C:\Windows\inf
2014-11-05 17:49:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-05 17:46:50 ----D---- C:\Windows
2014-11-04 21:35:58 ----D---- C:\Windows\system32\LogFiles
2014-11-04 21:02:39 ----SHD---- C:\System Volume Information
2014-11-04 20:58:07 ----SHD---- C:\Windows\Installer
2014-11-04 20:58:02 ----D---- C:\Windows\system32\Tasks
2014-11-04 20:58:02 ----D---- C:\Windows\system32\drivers
2014-11-04 20:57:59 ----D---- C:\Config.Msi
2014-11-04 19:43:23 ----D---- C:\Windows\Prefetch
2014-11-04 19:39:27 ----D---- C:\Users\Jára\AppData\Roaming\Seznam.cz
2014-11-04 19:34:25 ----D---- C:\Windows\system32\NDF
2014-11-04 19:29:32 ----D---- C:\Windows\system32\catroot
2014-11-04 19:28:47 ----RD---- C:\Program Files (x86)
2014-11-04 19:28:44 ----D---- C:\ProgramData
2014-11-04 19:21:42 ----D---- C:\Qoobox
2014-11-04 19:20:09 ----D---- C:\Windows\Tasks
2014-11-04 19:17:40 ----A---- C:\Windows\system.ini
2014-11-04 19:17:32 ----D---- C:\Windows\system32\drivers\etc
2014-11-04 19:12:37 ----D---- C:\Windows\SYSWOW64\drivers
2014-11-04 19:12:37 ----D---- C:\Windows\SysWOW64
2014-11-04 19:12:37 ----D---- C:\Windows\AppPatch
2014-11-04 19:12:35 ----D---- C:\Program Files (x86)\Common Files
2014-11-04 18:53:44 ----AD---- C:\ProgramData\TEMP
2014-11-04 18:53:20 ----D---- C:\Windows\Minidump
2014-11-04 17:17:01 ----D---- C:\Windows\system32\config
2014-11-04 17:16:33 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2014-11-04 17:11:54 ----D---- C:\Windows\system32\pt-PT
2014-11-04 17:11:54 ----D---- C:\Windows\system32\nl-NL
2014-11-04 17:11:53 ----D---- C:\Windows\system32\pt-BR
2014-11-04 17:11:52 ----D---- C:\Windows\system32\zh-TW
2014-11-04 17:11:52 ----D---- C:\Windows\system32\zh-CN
2014-11-04 17:11:52 ----D---- C:\Windows\system32\en-US
2014-11-04 17:11:51 ----D---- C:\Windows\SYSWOW64\pt-PT
2014-11-04 17:11:51 ----D---- C:\Windows\SYSWOW64\nl-NL
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\zh-TW
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\zh-CN
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\pt-BR
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\en-US
2014-11-04 17:11:37 ----D---- C:\Windows\system32\DriverStore
2014-11-04 17:09:57 ----D---- C:\Program Files (x86)\MediaCoder
2014-11-04 17:09:54 ----D---- C:\Users\Jára\AppData\Roaming\Mediatronic
2014-11-04 17:09:37 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-04 17:08:25 ----D---- C:\Program Files (x86)\VideoLAN
2014-11-04 17:07:59 ----D---- C:\ProgramData\Skype
2014-11-04 17:04:09 ----D---- C:\Users\Jára\AppData\Roaming\Skype
2014-11-04 17:02:36 ----D---- C:\Windows\SoftwareDistribution
2014-11-04 17:00:56 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-11-04 16:59:35 ----D---- C:\Windows\system32\catroot2
2014-11-04 16:57:42 ----D---- C:\Program Files (x86)\AVerMedia
2014-10-27 20:27:19 ----D---- C:\Windows\rescache
2014-10-27 18:24:06 ----D---- C:\Windows\debug
2014-10-27 16:13:48 ----D---- C:\Users\Jára\AppData\Roaming\.minecraft
2014-10-18 00:35:06 ----D---- C:\Windows\Microsoft.NET
2014-10-18 00:29:57 ----RSD---- C:\Windows\assembly
2014-10-16 11:11:53 ----D---- C:\Windows\winsxs
2014-10-16 11:08:32 ----SD---- C:\Windows\system32\CompatTel
2014-10-16 11:08:31 ----D---- C:\Program Files\Internet Explorer
2014-10-16 11:08:29 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-16 11:08:25 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-16 11:08:25 ----D---- C:\Windows\system32\cs-CZ
2014-10-15 22:00:03 ----D---- C:\ProgramData\Microsoft Help
2014-10-15 21:54:26 ----D---- C:\Windows\system32\MRT
2014-10-15 21:27:03 ----A---- C:\Windows\system32\MRT.exe
2014-10-14 20:53:55 ----SD---- C:\Users\Jára\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-06-18 190744]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2014-07-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2014-10-05 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2013-09-26 57144]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2014-10-10 274200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-09 1394176]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2008-09-04 64000]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 18432]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-04-30 267312]
S1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
S1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2014-10-07 262424]
S1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2011-05-13 36328]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
S3 ATP;Comodo Unite Miniport Driver; C:\Windows\system32\DRIVERS\cmdatp.sys []
S3 AVerAF15;HP DVB-T TV Tuner; C:\Windows\System32\Drivers\AVerAF15.sys [2008-07-04 306688]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz135;cpuz135; \??\C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [2012-08-11 24368]
S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2012-06-22 22704]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-10-23 128352]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 vfs101a;vfs101a; C:\Windows\system32\drivers\vfs101a.sys [2008-09-16 49968]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
S2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2014-10-16 1486664]
S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-10-16 3487248]
S2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-10-16 298080]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-05 116648]
S2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
S2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2014-01-09 1025408]
S2 vfsFPService;Validity Fingerprint Service; c:\Windows\system32\vfsFPService.exe [2008-09-16 719152]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 Com4QLBEx;Com4QLBEx; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-05 116648]
S3 hpqwmiex;hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 111616]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-05 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovaný pc

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lucifix
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 23 říj 2008 19:53

Re: Zavirovaný pc

#3 Příspěvek od Lucifix »

:-) díky, že jste se ozval, Rudy :-)

Scan proveden, nevím ale, zda správně....pc se restaroval....ted naskočil do normálního režimu...

# AdwCleaner v3.311 - Report created 05/11/2014 at 22:11:39
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jára - JÁRA-PC
# Running from : C:\Users\Jára\Desktop\adwcleaner_3.311 (1).exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17344


-\\ Mozilla Firefox v

[ File : C:\Users\Jára\AppData\Roaming\Mozilla\Firefox\Profiles\el4n319l.default\prefs.js ]


-\\ Google Chrome v38.0.2125.111

[ File : C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [8853 octets] - [04/11/2014 19:23:04]
AdwCleaner[R1].txt - [1046 octets] - [05/11/2014 22:09:56]
AdwCleaner[S0].txt - [8084 octets] - [04/11/2014 19:28:43]
AdwCleaner[S1].txt - [969 octets] - [05/11/2014 22:11:39]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1028 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovaný pc

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:commands
Purity
Emptytemp
Emptyflash
a klikněte na >MoveIt!<. Před skenem vypnět antivir a po něm restartujte PC. Dejte nový log RSIT. Také bych rád věděl, proč jste včera spouštěl ComboFix, utiltiu určenou pouze profesionálům? Hodláte si nabořit systém, nebo některé aplikace?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lucifix
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 23 říj 2008 19:53

Re: Zavirovaný pc

#5 Příspěvek od Lucifix »

Hotovo..... Combofix mi poradil kamarád a jednou nebo dvakrát jsme ho používali tady na foru, tak jsem myslela, že by mi to třeba pomohlo zbavit se problému.....omlouvám se...

Logfile of random's system information tool 1.10 (written by random/random)
Run by Jára at 2014-11-05 23:11:35
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 171 GB (68%) free of 250 GB
Total RAM: 4094 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:11:40, on 5.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Users\Jára\AppData\Roaming\Seznam.cz\szninstall.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files\trend micro\Jára.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Jára\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - c:\Windows\system32\vfsFPService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7367 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-0a73-c75c1160b92d /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

atieclxx
C:\Windows\system32\Hpservice.exe
c:\Windows\system32\vfsFPService.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
taskeng.exe {A7E02D78-2CF2-4316-A5F0-DF4ECFF2395D}
taskeng.exe {FE1564F9-B556-49CC-BAEE-16068CB6FAF1}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
WLIDSvcM.exe 1528
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Users\Jára\AppData\Roaming\Seznam.cz\szninstall.exe" -c
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe" /Start
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
ctfmon.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe"
C:\Windows\system32\sppsvc.exe
taskhost.exe $(Arg0)
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Jára\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-09 462248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-09 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-04-30 1794344]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-01-26 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"=C:\Users\Jára\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-07-27 321080]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2014-10-16 3649040]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-11-05 23:05:50 ----D---- C:\_OTM
2014-11-05 21:52:05 ----D---- C:\Program Files\trend micro
2014-11-05 21:52:04 ----D---- C:\rsit
2014-11-04 20:58:33 ----A---- C:\autoexec.bat
2014-11-04 20:58:02 ----A---- C:\Windows\system32\drivers\EsgScanner.sys
2014-11-04 20:57:57 ----D---- C:\sh4ldr
2014-11-04 20:57:57 ----D---- C:\Program Files\Enigma Software Group
2014-11-04 19:23:02 ----D---- C:\AdwCleaner
2014-11-04 19:21:44 ----SHD---- C:\$RECYCLE.BIN
2014-11-04 19:21:40 ----D---- C:\Windows\temp
2014-11-04 19:21:38 ----A---- C:\ComboFix.txt
2014-11-04 19:01:05 ----D---- C:\ComboFix
2014-11-04 17:01:01 ----A---- C:\Windows\system32\FNTCACHE.DAT
2014-11-04 16:58:17 ----A---- C:\Windows\ntbtlog.txt
2014-10-26 20:28:24 ----D---- C:\Program Files (x86)\Photo-Brush 5
2014-10-19 14:41:30 ----D---- C:\Users\Jára\AppData\Roaming\AVG2015
2014-10-19 14:40:19 ----D---- C:\Users\Jára\AppData\Roaming\TuneUp Software
2014-10-19 14:39:05 ----D---- C:\ProgramData\AVG2015
2014-10-19 14:39:05 ----D---- C:\$AVG
2014-10-19 14:38:01 ----D---- C:\Program Files (x86)\AVG
2014-10-19 14:35:28 ----HD---- C:\ProgramData\Common Files
2014-10-19 14:35:28 ----D---- C:\ProgramData\MFAData
2014-10-18 20:42:46 ----D---- C:\ProgramData\FreeWorldApp
2014-10-18 20:42:27 ----D---- C:\ProgramData\InstallMate
2014-10-15 21:23:27 ----A---- C:\Windows\SYSWOW64\winsta.dll
2014-10-15 21:23:27 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-10-15 21:23:27 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2014-10-15 21:23:26 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-10-15 21:23:26 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-10-15 21:23:26 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-10-15 21:23:19 ----A---- C:\Windows\system32\winlogon.exe
2014-10-15 21:23:18 ----A---- C:\Windows\system32\winsta.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\termsrv.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\mstscax.dll
2014-10-15 21:23:18 ----A---- C:\Windows\system32\mstsc.exe
2014-10-15 21:23:18 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-15 21:23:18 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-15 21:23:17 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-15 21:23:17 ----A---- C:\Windows\system32\credssp.dll
2014-10-15 21:23:07 ----A---- C:\Windows\system32\win32k.sys
2014-10-15 21:23:04 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2014-10-15 21:23:04 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-10-15 21:23:04 ----A---- C:\Windows\system32\mscorier.dll
2014-10-15 21:23:04 ----A---- C:\Windows\system32\dfshim.dll
2014-10-15 21:23:03 ----A---- C:\Windows\SYSWOW64\mscories.dll
2014-10-15 21:23:03 ----A---- C:\Windows\system32\mscories.dll
2014-10-15 21:22:57 ----A---- C:\Windows\system32\generaltel.dll
2014-10-15 21:22:57 ----A---- C:\Windows\system32\aepdu.dll
2014-10-15 21:22:56 ----A---- C:\Windows\system32\aeinv.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-10-15 21:22:54 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-10-15 21:22:53 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-10-15 21:22:53 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-10-15 21:22:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\iernonce.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-10-15 21:22:53 ----A---- C:\Windows\system32\ie4uinit.exe
2014-10-15 21:22:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-10-15 21:22:52 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-10-15 21:22:52 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-10-15 21:22:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-10-15 21:22:50 ----A---- C:\Windows\system32\iedkcs32.dll
2014-10-15 21:22:49 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-10-15 21:22:49 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-10-15 21:22:49 ----A---- C:\Windows\system32\urlmon.dll
2014-10-15 21:22:49 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 21:22:48 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-10-15 21:22:48 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-10-15 21:22:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-10-15 21:22:48 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-15 21:22:48 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-10-15 21:22:48 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-15 21:22:47 ----A---- C:\Windows\system32\iesetup.dll
2014-10-15 21:22:46 ----A---- C:\Windows\system32\iertutil.dll
2014-10-15 21:22:45 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-10-15 21:22:45 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-10-15 21:22:44 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-10-15 21:22:44 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-15 21:22:43 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-10-15 21:22:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-10-15 21:22:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-15 21:22:41 ----A---- C:\Windows\system32\ieui.dll
2014-10-15 21:22:41 ----A---- C:\Windows\system32\ieframe.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\jscript9diag.dll
2014-10-15 21:22:40 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-15 21:22:39 ----A---- C:\Windows\system32\wininet.dll
2014-10-15 21:22:39 ----A---- C:\Windows\system32\vbscript.dll
2014-10-15 21:22:39 ----A---- C:\Windows\system32\jscript9.dll
2014-10-15 21:22:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-10-15 21:22:38 ----A---- C:\Windows\system32\msrating.dll
2014-10-15 21:22:38 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-10-15 21:22:37 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 21:22:36 ----A---- C:\Windows\system32\mshtml.dll
2014-10-15 21:21:27 ----A---- C:\Windows\system32\msi.dll
2014-10-15 21:21:26 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-10-15 21:21:21 ----A---- C:\Windows\SYSWOW64\rastls.dll
2014-10-15 21:21:21 ----A---- C:\Windows\system32\rastls.dll
2014-10-15 21:19:02 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-10-15 21:19:02 ----A---- C:\Windows\system32\packager.dll
2014-10-15 19:01:15 ----D---- C:\Users\Jára\AppData\Roaming\TS3Client
2014-10-10 15:14:32 ----A---- C:\Windows\system32\drivers\avgtdia.sys
2014-10-07 21:43:06 ----A---- C:\Windows\system32\drivers\avgidsdrivera.sys

======List of files/folders modified in the last 1 month======

2014-11-05 23:11:40 ----D---- C:\Windows\Prefetch
2014-11-05 23:06:52 ----D---- C:\Windows\system32\config
2014-11-05 23:05:51 ----D---- C:\Windows\Tasks
2014-11-05 23:02:30 ----D---- C:\Windows\System32
2014-11-05 23:02:30 ----D---- C:\Windows\inf
2014-11-05 23:02:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-05 23:01:03 ----D---- C:\Users\Jára\AppData\Roaming\Seznam.cz
2014-11-05 21:52:05 ----RD---- C:\Program Files
2014-11-05 17:46:50 ----D---- C:\Windows
2014-11-04 21:35:58 ----D---- C:\Windows\system32\LogFiles
2014-11-04 21:02:39 ----SHD---- C:\System Volume Information
2014-11-04 20:58:07 ----SHD---- C:\Windows\Installer
2014-11-04 20:58:02 ----D---- C:\Windows\system32\Tasks
2014-11-04 20:58:02 ----D---- C:\Windows\system32\drivers
2014-11-04 20:57:59 ----D---- C:\Config.Msi
2014-11-04 19:34:25 ----D---- C:\Windows\system32\NDF
2014-11-04 19:29:32 ----D---- C:\Windows\system32\catroot
2014-11-04 19:28:47 ----RD---- C:\Program Files (x86)
2014-11-04 19:28:44 ----D---- C:\ProgramData
2014-11-04 19:21:42 ----D---- C:\Qoobox
2014-11-04 19:17:40 ----A---- C:\Windows\system.ini
2014-11-04 19:17:32 ----D---- C:\Windows\system32\drivers\etc
2014-11-04 19:12:37 ----D---- C:\Windows\SYSWOW64\drivers
2014-11-04 19:12:37 ----D---- C:\Windows\SysWOW64
2014-11-04 19:12:37 ----D---- C:\Windows\AppPatch
2014-11-04 19:12:35 ----D---- C:\Program Files (x86)\Common Files
2014-11-04 18:53:44 ----AD---- C:\ProgramData\TEMP
2014-11-04 18:53:20 ----D---- C:\Windows\Minidump
2014-11-04 17:16:33 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2014-11-04 17:11:54 ----D---- C:\Windows\system32\pt-PT
2014-11-04 17:11:54 ----D---- C:\Windows\system32\nl-NL
2014-11-04 17:11:53 ----D---- C:\Windows\system32\pt-BR
2014-11-04 17:11:52 ----D---- C:\Windows\system32\zh-TW
2014-11-04 17:11:52 ----D---- C:\Windows\system32\zh-CN
2014-11-04 17:11:52 ----D---- C:\Windows\system32\en-US
2014-11-04 17:11:51 ----D---- C:\Windows\SYSWOW64\pt-PT
2014-11-04 17:11:51 ----D---- C:\Windows\SYSWOW64\nl-NL
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\zh-TW
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\zh-CN
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\pt-BR
2014-11-04 17:11:49 ----D---- C:\Windows\SYSWOW64\en-US
2014-11-04 17:11:37 ----D---- C:\Windows\system32\DriverStore
2014-11-04 17:09:57 ----D---- C:\Program Files (x86)\MediaCoder
2014-11-04 17:09:54 ----D---- C:\Users\Jára\AppData\Roaming\Mediatronic
2014-11-04 17:09:37 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-04 17:08:25 ----D---- C:\Program Files (x86)\VideoLAN
2014-11-04 17:07:59 ----D---- C:\ProgramData\Skype
2014-11-04 17:04:09 ----D---- C:\Users\Jára\AppData\Roaming\Skype
2014-11-04 17:02:36 ----D---- C:\Windows\SoftwareDistribution
2014-11-04 17:00:56 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-11-04 16:59:35 ----D---- C:\Windows\system32\catroot2
2014-11-04 16:57:42 ----D---- C:\Program Files (x86)\AVerMedia
2014-10-27 20:27:19 ----D---- C:\Windows\rescache
2014-10-27 18:24:06 ----D---- C:\Windows\debug
2014-10-27 16:13:48 ----D---- C:\Users\Jára\AppData\Roaming\.minecraft
2014-10-18 00:35:06 ----D---- C:\Windows\Microsoft.NET
2014-10-18 00:29:57 ----RSD---- C:\Windows\assembly
2014-10-16 11:11:53 ----D---- C:\Windows\winsxs
2014-10-16 11:08:32 ----SD---- C:\Windows\system32\CompatTel
2014-10-16 11:08:31 ----D---- C:\Program Files\Internet Explorer
2014-10-16 11:08:29 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-16 11:08:25 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-16 11:08:25 ----D---- C:\Windows\system32\cs-CZ
2014-10-15 22:00:03 ----D---- C:\ProgramData\Microsoft Help
2014-10-15 21:54:26 ----D---- C:\Windows\system32\MRT
2014-10-15 21:27:03 ----A---- C:\Windows\system32\MRT.exe
2014-10-14 20:53:55 ----SD---- C:\Users\Jára\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-06-18 190744]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2014-07-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2014-10-05 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2013-09-26 57144]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2014-10-07 262424]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2014-10-10 274200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-09 1394176]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2008-09-04 64000]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 18432]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-10-23 128352]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-04-30 267312]
R3 vfs101a;vfs101a; C:\Windows\system32\drivers\vfs101a.sys [2008-09-16 49968]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2011-05-13 36328]
S3 ATP;Comodo Unite Miniport Driver; C:\Windows\system32\DRIVERS\cmdatp.sys []
S3 AVerAF15;HP DVB-T TV Tuner; C:\Windows\System32\Drivers\AVerAF15.sys [2008-07-04 306688]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz135;cpuz135; \??\C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [2012-08-11 24368]
S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2012-06-22 22704]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2014-10-16 1486664]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-10-16 3487248]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-10-16 298080]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2014-01-09 1025408]
R2 vfsFPService;Validity Fingerprint Service; c:\Windows\system32\vfsFPService.exe [2008-09-16 719152]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-05 116648]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-05 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 111616]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-05 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovaný pc

#6 Příspěvek od Rudy »

Laik si ComboFixem může poškodit systém, nebo aplikace. My ho tu nespouštíme dříve, dokud se nepřesvědčíme, co všechno v systému běží. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lucifix
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 23 říj 2008 19:53

Re: Zavirovaný pc

#7 Příspěvek od Lucifix »

Dobrý večer, tak jsem provedla, pc už včera běžel lépe, dnes zatím šlapě, občas se trošku sekne, ale je to o 90% lepší :-) Děkuji...Combofix tedy používat bez vás nebudu :-)

Ještě jednou moc díky a přeji příjemný zbytek večera

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Zavirovaný pc

#8 Příspěvek od Rudy »

Hezký den i vám a nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno