Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
novacek7575
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 04 dub 2011 18:57

Prosím o kontrolu logu

#1 Příspěvek od novacek7575 »

Prosím o kontrolu logu.V pc je pár otravnej virů a nejdou odstranit.Děkuji




Logfile of random's system information tool 1.10 (written by random/random)
Run by uzivatel at 2017-04-23 22:18:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 301 GB (75%) free of 400 GB
Total RAM: 4094 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:19:16, on 23.4.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Users\uzivatel\Downloads\AdwCleaner.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files\trend micro\uzivatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... 8920689206
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://search.yahoo.com/web?fr=avira-ds
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... 8920689206
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... 8920689206
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.ourluckysites.com/search/?ty ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ourluckysites.com/search/?ty ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... 8920689206
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD - Unknown owner - C:\Users\uzivatel\AppData\Local\AMD\amd.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8771 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localservice
c:\windows\system32\svchost.exe -k networkservice
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
AvastUI.exe /nogui
c:\windows\system32\svchost.exe -k localservicenonetwork
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
c:\windows\system32\svchost.exe -k snare
c:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
c:\windows\system32\svchost.exe -k localservicepeernet
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
"C:\totalcmd\TOTALCMD.EXE"
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"c:\program files (x86)\teamviewer\TeamViewer_Desktop.exe" --IPCport 5939

"C:\Users\uzivatel\Downloads\AdwCleaner.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\printfilterpipelinesvc.exe -Embedding
taskeng.exe {5E78E916-7B07-4645-B4DA-142182CE1C3F}
"C:\AdwCleaner\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\HP\HPDESK~1\Bin\HPNETW~1.EXE -usePortMonitorGUIDs -Embedding

======Scheduled tasks folder======

C:\Windows\tasks\Online Special Application V2G1.job - C:\Program Files (x86)\Microleaves\Online Special Application\Version 2.6.0\Online-Guardian.exe 1 69
C:\Windows\tasks\Online Special Application V2G2.job - C:\Program Files (x86)\Microleaves\Online Special Application\Version 2.6.0\Online-Guardian.exe 1 70
C:\Windows\tasks\Online Special Application V2G3.job - C:\Program Files (x86)\Microleaves\Online Special Application\Version 2.6.0\Online-Guardian.exe 1 71
C:\Windows\tasks\Updater_Online_Special_Application.job - C:\Program Files (x86)\Microleaves\Online Special Application\Online Special Application Updater.exe /silentall -nofreqcheck

=========Mozilla firefox=========

ProfilePath - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\4ck5i73x.default

prefs.js - "browser.search.useDBForOrder" - false
prefs.js - "browser.startup.homepage" - "http://www.ourluckysites.com/?type=hp&t ... 8920689206"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF48


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.111.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.111.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\4ck5i73x.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\4ck5i73x.default\searchplugins\
amazon.xml
boxnha29.xml
luck.xml
ourluckysites.xml
startpageing123.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-23 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-28 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-23 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-28 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-04-23 213824]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8D2831F6-F448-11E6-B836-64006A5CFC23}"=C:\Program Files (x86)\Perhuspratph\Siwuyqorodom.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-04-23 22:18:58 ----D---- C:\rsit
2017-04-23 22:18:58 ----D---- C:\Program Files\trend micro
2017-04-23 14:18:00 ----HD---- C:\$AV_ASW
2017-04-23 14:16:42 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-04-23 14:11:53 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2017-04-23 14:11:53 ----A---- C:\Windows\system32\drivers\aswStm.sys
2017-04-23 14:11:53 ----A---- C:\Windows\system32\drivers\aswSP.sys
2017-04-23 14:11:52 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-04-23 14:11:52 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-04-23 14:11:52 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-04-23 14:11:52 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-04-23 14:11:51 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2017-04-23 14:11:51 ----A---- C:\Windows\system32\drivers\aswbuniva.sys
2017-04-23 14:11:51 ----A---- C:\Windows\system32\drivers\aswbloga.sys
2017-04-23 14:11:50 ----A---- C:\Windows\system32\drivers\aswbidsha.sys
2017-04-23 14:11:50 ----A---- C:\Windows\system32\drivers\aswbidsdrivera.sys
2017-04-23 14:11:39 ----A---- C:\Windows\system32\aswBoot.exe
2017-04-23 14:09:25 ----D---- C:\Users\uzivatel\AppData\Roaming\TeamViewer
2017-04-23 14:09:05 ----D---- C:\Program Files (x86)\TeamViewer
2017-04-23 14:07:30 ----D---- C:\Program Files\AVAST Software
2017-04-23 12:59:53 ----D---- C:\Users\uzivatel\AppData\Roaming\URSoft
2017-04-23 12:59:53 ----AD---- C:\ProgramData\TEMP
2017-04-23 12:59:49 ----D---- C:\Program Files (x86)\Your Uninstaller! 7
2017-04-23 12:56:48 ----D---- C:\AdwCleaner
2017-04-21 21:25:50 ----D---- C:\Program Files (x86)\58FA5CBEtmp
2017-04-19 10:51:57 ----D---- C:\Program Files (x86)\58F7252D_cacayima
2017-04-19 10:51:50 ----D---- C:\Program Files (x86)\58F72526tmp
2017-04-17 18:40:11 ----D---- C:\Windows\Update
2017-04-17 18:07:55 ----D---- C:\Program Files (x86)\58F4E85B_cacayima
2017-04-17 18:07:48 ----D---- C:\Program Files (x86)\58F4E854tmp
2017-04-16 12:53:15 ----D---- C:\AppData
2017-04-15 12:56:38 ----D---- C:\Program Files (x86)\Terela
2017-04-13 19:25:05 ----D---- C:\Program Files (x86)\58EFB471tmp
2017-04-11 18:40:35 ----D---- C:\Program Files (x86)\58ED0703tmp
2017-04-07 22:30:24 ----HD---- C:\$Windows.~WS
2017-04-07 21:19:37 ----D---- C:\$WINDOWS.~BT
2017-04-07 20:39:41 ----D---- C:\ESD
2017-04-07 19:07:09 ----D---- C:\Users\uzivatel\AppData\Roaming\dvdcss
2017-04-07 14:06:30 ----D---- C:\Program Files (x86)\58E780C6tmp
2017-04-06 18:04:53 ----D---- C:\Users\uzivatel\AppData\Roaming\SNARER
2017-04-05 18:39:00 ----D---- C:\Program Files (x86)\58E51DA4tmp
2017-04-01 12:51:04 ----D---- C:\Program Files (x86)\58DF8618tmp
2017-03-30 14:07:21 ----D---- C:\Update
2017-03-30 14:03:07 ----D---- C:\Program Files (x86)\58DCF3FBtmp
2017-03-29 11:13:09 ----D---- C:\Program Files (x86)\58DB7AA5tmp
2017-03-27 17:52:15 ----D---- C:\Users\uzivatel\AppData\Roaming\clean
2017-03-27 17:51:45 ----D---- C:\Program Files (x86)\58D93511tmp
2017-03-24 21:49:16 ----D---- C:\Program Files (x86)\Hextech Repair Tool

======List of files/folders modified in the last 1 month======

2017-04-23 22:18:58 ----RD---- C:\Program Files
2017-04-23 22:18:37 ----D---- C:\Windows\Temp
2017-04-23 22:16:01 ----D---- C:\Program Files (x86)
2017-04-23 22:14:34 ----D---- C:\ProgramData\NVIDIA
2017-04-23 22:10:27 ----D---- C:\Windows\system32\drivers
2017-04-23 16:07:24 ----HD---- C:\ProgramData
2017-04-23 15:38:17 ----SHD---- C:\Windows\Installer
2017-04-23 15:28:56 ----D---- C:\Windows\system32\LogFiles
2017-04-23 15:06:01 ----D---- C:\Program Files (x86)\MIO
2017-04-23 14:48:04 ----D---- C:\Windows\system32\config
2017-04-23 14:36:50 ----D---- C:\Program Files (x86)\Stersshiwaty Manager
2017-04-23 14:31:50 ----D---- C:\Program Files (x86)\Hi-Rez Studios
2017-04-23 14:19:16 ----SHD---- C:\System Volume Information
2017-04-23 14:18:26 ----D---- C:\Windows\system32\Tasks
2017-04-23 14:16:34 ----D---- C:\ProgramData\AVAST Software
2017-04-23 14:11:39 ----D---- C:\Windows\System32
2017-04-23 14:09:30 ----RSD---- C:\Windows\Fonts
2017-04-23 14:03:53 ----D---- C:\ProgramData\Package Cache
2017-04-23 14:01:37 ----D---- C:\ProgramData\Avira
2017-04-23 13:59:06 ----D---- C:\Windows\system32\catroot
2017-04-23 13:45:58 ----D---- C:\Program Files (x86)\Steam
2017-04-23 13:31:28 ----D---- C:\Users\uzivatel\AppData\Roaming\Seznam.cz
2017-04-23 13:30:16 ----D---- C:\ProgramData\Origin
2017-04-23 13:23:41 ----D---- C:\Windows
2017-04-23 13:21:44 ----D---- C:\Windows\system32\log
2017-04-23 13:13:13 ----D---- C:\Windows\debug
2017-04-23 12:53:37 ----D---- C:\Windows\Tasks
2017-04-23 12:49:58 ----D---- C:\Windows\inf
2017-04-23 12:49:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-23 12:42:51 ----D---- C:\Windows\system32\catroot2
2017-04-21 21:43:11 ----D---- C:\Windows\SysWOW64
2017-04-21 21:29:06 ----D---- C:\Program Files (x86)\MK
2017-04-18 14:24:09 ----D---- C:\Program Files (x86)\Perhuspratph
2017-04-17 18:31:45 ----D---- C:\Program Files\boxnha29
2017-04-13 10:54:08 ----D---- C:\Program Files (x86)\Drakensang Online
2017-04-07 23:04:02 ----D---- C:\Windows\Panther
2017-04-07 21:18:37 ----SD---- C:\ProgramData\Microsoft
2017-04-07 20:34:49 ----D---- C:\Windows\Logs
2017-04-07 19:07:32 ----D---- C:\Users\uzivatel\AppData\Roaming\vlc
2017-04-05 18:49:30 ----D---- C:\Users\uzivatel\AppData\Roaming\Riot Games

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-04-23 189768]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-04-23 334088]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-04-23 48528]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-04-23 75704]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-04-23 339696]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-04 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-04-23 307736]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-04-23 32600]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-04-23 101152]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-04-23 1005048]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-04-23 556784]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2016-05-23 262344]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2016-05-23 110112]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2016-05-23 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-04-23 127112]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-04-23 164064]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2016-11-17 212936]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-11-17 46016]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-04-03 34872]
S1 p104788591am;p104788591am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk2CBB.tmp\p104788591am.sys []
S1 p1148556349am;p1148556349am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkFD43.tmp\p1148556349am.sys []
S1 p1155113411am;p1155113411am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk97AD.tmp\p1155113411am.sys []
S1 p1207305410am;p1207305410am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk92AE.tmp\p1207305410am.sys []
S1 p1325746583am;p1325746583am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkE24.tmp\p1325746583am.sys []
S1 p1487931930am;p1487931930am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkA8B.tmp\p1487931930am.sys []
S1 p1487932075am;p1487932075am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk3929.tmp\p1487932075am.sys []
S1 p1487932690am;p1487932690am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk8CF4.tmp\p1487932690am.sys []
S1 p1487932751am;p1487932751am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk7D4A.tmp\p1487932751am.sys []
S1 p1487932782am;p1487932782am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkF528.tmp\p1487932782am.sys []
S1 p1488288057am;p1488288057am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk78D8.tmp\p1488288057am.sys []
S1 p1488288154am;p1488288154am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkF7D6.tmp\p1488288154am.sys []
S1 p1488288259am;p1488288259am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk8EE7.tmp\p1488288259am.sys []
S1 p1488382572am;p1488382572am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkB08.tmp\p1488382572am.sys []
S1 p1488382716am;p1488382716am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk401C.tmp\p1488382716am.sys []
S1 p1488820131am;p1488820131am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkC4F4.tmp\p1488820131am.sys []
S1 p1488820297am;p1488820297am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk4DB3.tmp\p1488820297am.sys []
S1 p1488905110am;p1488905110am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk1F34.tmp\p1488905110am.sys []
S1 p1488994426am;p1488994426am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk84BA.tmp\p1488994426am.sys []
S1 p1489051183am;p1489051183am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkC19A.tmp\p1489051183am.sys []
S1 p1489051274am;p1489051274am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk2829.tmp\p1489051274am.sys []
S1 p1489128040am;p1489128040am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkC7A3.tmp\p1489128040am.sys []
S1 p1489419159am;p1489419159am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkE475.tmp\p1489419159am.sys []
S1 p1489506412am;p1489506412am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkA026.tmp\p1489506412am.sys []
S1 p1489567875am;p1489567875am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk6A5.tmp\p1489567875am.sys []
S1 p1489567902am;p1489567902am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk70DC.tmp\p1489567902am.sys []
S1 p1489568021am;p1489568021am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk41B2.tmp\p1489568021am.sys []
S1 p1489772919am;p1489772919am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkD5B6.tmp\p1489772919am.sys []
S1 p1490206320am;p1490206320am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkE8AA.tmp\p1490206320am.sys []
S1 p1490206374am;p1490206374am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkBC6C.tmp\p1490206374am.sys []
S1 p1490206401am;p1490206401am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk27BC.tmp\p1490206401am.sys []
S1 p1490206456am;p1490206456am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkFA65.tmp\p1490206456am.sys []
S1 p1490206513am;p1490206513am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkDB03.tmp\p1490206513am.sys []
S1 p1490206571am;p1490206571am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkBE5F.tmp\p1490206571am.sys []
S1 p1490206663am;p1490206663am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk2720.tmp\p1490206663am.sys []
S1 p1490206721am;p1490206721am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk6C4.tmp\p1490206721am.sys []
S1 p1490206805am;p1490206805am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk5090.tmp\p1490206805am.sys []
S1 p1490206918am;p1490206918am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkAE9.tmp\p1490206918am.sys []
S1 p1490206976am;p1490206976am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkED4C.tmp\p1490206976am.sys []
S1 p1490207032am;p1490207032am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkC207.tmp\p1490207032am.sys []
S1 p1490207088am;p1490207088am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkA1BB.tmp\p1490207088am.sys []
S1 p1490207148am;p1490207148am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk8B01.tmp\p1490207148am.sys []
S1 p1490207203am;p1490207203am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk6345.tmp\p1490207203am.sys []
S1 p1490207256am;p1490207256am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk3082.tmp\p1490207256am.sys []
S1 p1490207282am;p1490207282am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk97BD.tmp\p1490207282am.sys []
S1 p1490289418am;p1490289418am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk51F.tmp\p1490289418am.sys []
S1 p1490354921am;p1490354921am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkB04C.tmp\p1490354921am.sys []
S1 p1490354955am;p1490354955am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk2F69.tmp\p1490354955am.sys []
S1 p1490629585am;p1490629585am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkF0F3.tmp\p1490629585am.sys []
S1 p1490629640am;p1490629640am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkCD4D.tmp\p1490629640am.sys []
S1 p1490629693am;p1490629693am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk9E13.tmp\p1490629693am.sys []
S1 p1490629793am;p1490629793am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk204D.tmp\p1490629793am.sys []
S1 p1490629820am;p1490629820am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk8CD4.tmp\p1490629820am.sys []
S1 p1490778394am;p1490778394am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkE6D6.tmp\p1490778394am.sys []
S1 p1490778447am;p1490778447am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkB6B2.tmp\p1490778447am.sys []
S1 p1490778502am;p1490778502am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk8B9C.tmp\p1490778502am.sys []
S1 p1490875184am;p1490875184am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkB2BC.tmp\p1490875184am.sys []
S1 p1491044137am;p1491044137am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk35C0.tmp\p1491044137am.sys []
S1 p1491044163am;p1491044163am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk9C20.tmp\p1491044163am.sys []
S1 p1491044219am;p1491044219am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk75CC.tmp\p1491044219am.sys []
S1 p1491044274am;p1491044274am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk4D46.tmp\p1491044274am.sys []
S1 p1491410034am;p1491410034am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk276E.tmp\p1491410034am.sys []
S1 p1491410060am;p1491410060am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk8D32.tmp\p1491410060am.sys []
S1 p1491410085am;p1491410085am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkF299.tmp\p1491410085am.sys []
S1 p1491410198am;p1491410198am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkA959.tmp\p1491410198am.sys []
S1 p1491410250am;p1491410250am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk758D.tmp\p1491410250am.sys []
S1 p1491410404am;p1491410404am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkCD8C.tmp\p1491410404am.sys []
S1 p1491494739am;p1491494739am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkDAD5.tmp\p1491494739am.sys []
S1 p1673763173am;p1673763173am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk3E67.tmp\p1673763173am.sys []
S1 p1960507948am;p1960507948am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk9981.tmp\p1960507948am.sys []
S1 p2209872182am;p2209872182am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkA86F.tmp\p2209872182am.sys []
S1 p268426126am;p268426126am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkBBD0.tmp\p268426126am.sys []
S1 p2722983304am;p2722983304am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkA4D.tmp\p2722983304am.sys []
S1 p286173417am;p286173417am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk5E65.tmp\p286173417am.sys []
S1 p31378304am;p31378304am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkF9F9.tmp\p31378304am.sys []
S1 p3404466456am;p3404466456am; \??\C:\Users\uzivatel\AppData\Local\Temp\bkB116.tmp\p3404466456am.sys []
S1 p3661401569am;p3661401569am; \??\C:\Users\uzivatel\AppData\Local\Temp\bk3E19.tmp\p3661401569am.sys []
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-04-23 38296]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys []
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-11-17 27584]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-04-23 261712]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2016-12-02 131024]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 462784]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-11-17 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-11-17 1163712]
R2 SNARE;SNARE; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 TeamViewer;TeamViewer 12; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2017-03-17 10883824]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-04-23 7398336]
S2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-02-02 82640]
S2 AMD;AMD; C:\Users\uzivatel\AppData\Local\AMD\amd.exe -s []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-26 153752]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2016-12-09 9728]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-12-21 2180624]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2017-02-01 400656]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-26 153752]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-02-01 172488]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 462784]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-12-21 2119688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-03-23 1590560]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15214
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu logu

#2 Příspěvek od JaRon »

ahoj
1. citat:
Junkware removal tool: http://thisisudax.org/downloads/JRT.exe
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.

2. pokus sa odinstalovat YAC

3. vloz oba logy FRST
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět