Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Stále se vracející malware luckysites123

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Wik24
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 lis 2016 20:24

Stále se vracející malware luckysites123

#1 Příspěvek od Wik24 »

Zdravím,

už několikrát jsem resetoval všechny prohlížeče, upravoval cesty, projížděl anti-malwarovými programy apod. , ale stále se mě to drží.

Odinstaloval jsem a smazal podle návodů na internetu snad vše podezřelé. Zajímavé, ale je, že když jsem to vše udělal, tak mi zmizel úplně Google Chrome.

Pár dní jsem fungoval tedy bez něj (když to bylo už po několikráté) a prohlížel jsem jen přes Firefox.

Před nedávnem, jsem znovu nainstaloval Chrome skrz nějaké záložky, propojené přes Google účet a do dne,dvou to bylo zase zpět.

Chtěl bych Vás požádat o radu :(


LOG:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Viktor at 2017-05-15 18:50:00
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 19 GB (25%) free of 76 GB
Total RAM: 3583 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:50:45, on 15.5.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18666)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\DTAgent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Viktor\Downloads\RSIT.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Viktor.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkI ... id=UE09DHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 4804 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-03 773920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-03 213824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2017-05-04 27716568]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-06-01 6690520]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2017-02-07 3777728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner.exe [2016-06-01 6690520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
C:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1002984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-05-15 18:50:00 ----D---- C:\rsit
2017-05-15 18:50:00 ----D---- C:\Program Files\trend micro
2017-05-15 18:41:03 ----D---- C:\ProgramData\SWCUTemp
2017-05-14 00:05:43 ----D---- C:\Users\Viktor\AppData\Roaming\com.adobe.bridge.PublishPanel
2017-05-11 17:56:50 ----D---- C:\Program Files\Common Files\Skype
2017-05-11 17:33:38 ----D---- C:\Program Files\Mozilla Maintenance Service
2017-05-09 23:14:42 ----D---- C:\Program Files\LightZone 3
2017-05-09 23:10:22 ----D---- C:\Users\Viktor\AppData\Roaming\Jamper
2017-05-09 22:53:17 ----D---- C:\Windows\system32\MRT
2017-05-09 22:45:04 ----D---- C:\ProgramData\Microsoft OneDrive
2017-05-09 22:39:48 ----A---- C:\Windows\system32\drivers\PROCEXP152.SYS
2017-05-09 19:36:52 ----A---- C:\Windows\system32\mshtml.dll
2017-05-09 19:36:51 ----A---- C:\Windows\system32\ieframe.dll
2017-05-09 19:36:50 ----A---- C:\Windows\system32\jscript9.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\wininet.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\win32k.sys
2017-05-09 19:36:49 ----A---- C:\Windows\system32\urlmon.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\iertutil.dll
2017-05-09 19:36:48 ----A---- C:\Windows\system32\vbscript.dll
2017-05-09 19:36:48 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-05-09 19:36:48 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-05-09 19:36:48 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-05-09 19:36:47 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-05-09 19:36:47 ----A---- C:\Windows\system32\crypt32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\oleaut32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\ole32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\drivers\srv.sys
2017-05-09 19:36:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-05-09 19:36:45 ----A---- C:\Windows\system32\iedkcs32.dll
2017-05-09 19:36:45 ----A---- C:\Windows\system32\gdi32.dll
2017-05-09 19:36:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-05-09 19:36:44 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-05-09 19:36:44 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-05-09 19:36:44 ----A---- C:\Windows\system32\mshtmled.dll
2017-05-09 19:36:44 ----A---- C:\Windows\system32\drivers\afd.sys
2017-05-09 19:36:43 ----A---- C:\Windows\system32\rpcss.dll
2017-05-09 19:36:43 ----A---- C:\Windows\system32\ntdll.dll
2017-05-09 19:36:43 ----A---- C:\Windows\system32\drivers\netio.sys
2017-05-09 19:36:43 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-05-09 19:36:42 ----A---- C:\Windows\system32\oleres.dll
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-05-09 19:36:41 ----A---- C:\Windows\system32\webcheck.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\msfeeds.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\jscript.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\ie4uinit.exe
2017-05-09 19:36:41 ----A---- C:\Windows\system32\dxtrans.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\comcat.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\rpcrt4.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\ieui.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\ieapfltr.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-05-09 19:36:40 ----A---- C:\Windows\system32\advapi32.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\smss.exe
2017-05-09 19:36:39 ----A---- C:\Windows\system32\lsasrv.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\kerberos.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-05-09 19:36:38 ----A---- C:\Windows\system32\wdigest.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\srcore.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\schannel.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\rpchttp.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\occache.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\ncrypt.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\msv1_0.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\msrating.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\KernelBase.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\jsproxy.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\jscript9diag.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\ieUnatt.exe
2017-05-09 19:36:38 ----A---- C:\Windows\system32\dxtmsft.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-05-09 19:36:38 ----A---- C:\Windows\system32\cdosys.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\wintrust.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\winsrv.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\TSpkg.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\sspicli.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\srclient.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\lsass.exe
2017-05-09 19:36:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\inseng.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\iesetup.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\iernonce.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-05-09 19:36:37 ----A---- C:\Windows\system32\drivers\appid.sys
2017-05-09 19:36:37 ----A---- C:\Windows\system32\csrsrv.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptsvc.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptnet.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptbase.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\credssp.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\conhost.exe
2017-05-09 19:36:37 ----A---- C:\Windows\system32\bcrypt.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\appidapi.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\apisetschema.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\sspisrv.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\secur32.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\rstrui.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\msaudite.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\kernel32.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\cdd.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\auditpol.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidsvc.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\adtschema.dll
2017-05-09 19:36:35 ----A---- C:\Windows\system32\msobjs.dll
2017-05-09 19:36:35 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-05-07 16:02:25 ----D---- C:\Users\Viktor\AppData\Roaming\Google
2017-05-07 14:48:28 ----D---- C:\Program Files\Microsoft Silverlight
2017-05-07 14:47:20 ----A---- C:\Windows\system32\tzres.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\plasrv.exe
2017-05-07 14:47:20 ----A---- C:\Windows\system32\pla.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\pdh.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-05-07 14:47:20 ----A---- C:\Windows\system32\drivers\exfat.sys
2017-05-07 13:57:02 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-05-07 13:55:29 ----D---- C:\ProgramData\Malwarebytes
2017-05-07 13:55:29 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2017-05-07 12:43:04 ----D---- C:\Users\Viktor\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2017-05-05 20:54:28 ----D---- C:\Users\Viktor\AppData\Roaming\DAEMON Tools Lite
2017-05-05 19:57:00 ----D---- C:\ProgramData\BIT
2017-05-03 23:48:48 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-05-03 23:47:11 ----D---- C:\Users\Viktor\AppData\Roaming\AVAST Software
2017-05-03 23:46:13 ----D---- C:\Program Files\Common Files\AV
2017-05-03 23:45:45 ----A---- C:\Windows\system32\drivers\aswstm.sys
2017-05-03 23:45:44 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2017-05-03 23:45:44 ----A---- C:\Windows\system32\drivers\aswSP.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-05-03 23:45:42 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2017-05-03 23:45:42 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-05-03 23:45:41 ----A---- C:\Windows\system32\drivers\aswbunivx.sys
2017-05-03 23:45:40 ----A---- C:\Windows\system32\drivers\aswblogx.sys
2017-05-03 23:45:40 ----A---- C:\Windows\system32\drivers\aswbidshx.sys
2017-05-03 23:45:39 ----A---- C:\Windows\system32\drivers\aswbidsdriverx.sys
2017-05-03 23:45:12 ----A---- C:\Windows\ucrtbase.dll
2017-05-03 23:45:12 ----A---- C:\Windows\system32\aswBoot.exe
2017-05-03 23:41:48 ----D---- C:\Program Files\AVAST Software
2017-05-03 23:41:21 ----D---- C:\ProgramData\AVAST Software
2017-05-03 19:13:32 ----AD---- C:\Program Files\Firefox
2017-04-30 21:15:53 ----D---- C:\Users\Viktor\AppData\Roaming\DVDVideoSoft
2017-04-30 10:55:50 ----D---- C:\Program Files\DAEMON Tools Lite
2017-04-25 20:02:55 ----D---- C:\Windows\psgo
2017-04-22 02:17:14 ----D---- C:\Users\Viktor\AppData\Roaming\Firefox
2017-04-21 01:06:51 ----D---- C:\Windows\Update
2017-04-19 23:05:04 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-04-19 23:04:01 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-04-19 23:03:38 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-04-16 20:31:10 ----D---- C:\Users\Viktor\AppData\Roaming\LightZone
2017-04-16 20:31:09 ----D---- C:\Windows\system32\EWS

======List of files/folders modified in the last 1 month======

2017-05-15 18:50:12 ----D---- C:\Windows\Prefetch
2017-05-15 18:50:00 ----RD---- C:\Program Files
2017-05-15 18:47:27 ----D---- C:\Windows\Temp
2017-05-15 18:41:03 ----HD---- C:\ProgramData
2017-05-15 18:25:37 ----D---- C:\Users\Viktor\AppData\Roaming\Skype
2017-05-15 18:16:01 ----D---- C:\Windows\system32\config
2017-05-15 01:56:08 ----SD---- C:\Users\Viktor\AppData\Roaming\Microsoft
2017-05-15 01:56:08 ----D---- C:\Users\Viktor\AppData\Roaming\Adobe
2017-05-14 23:19:14 ----D---- C:\Windows\system32\drivers
2017-05-13 20:15:57 ----D---- C:\Windows\System32
2017-05-13 20:15:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-05-13 20:15:56 ----D---- C:\Windows\inf
2017-05-13 12:44:53 ----D---- C:\Windows\tracing
2017-05-12 21:00:37 ----SHD---- C:\Windows\Installer
2017-05-12 19:18:08 ----RD---- C:\Program Files (x86)
2017-05-11 23:35:33 ----D---- C:\Windows\rescache
2017-05-11 23:34:39 ----SHD---- C:\System Volume Information
2017-05-11 23:34:26 ----D---- C:\Windows\Logs
2017-05-11 21:53:02 ----D---- C:\Windows\Microsoft.NET
2017-05-11 21:49:04 ----RSD---- C:\Windows\assembly
2017-05-11 17:56:50 ----RD---- C:\Program Files\Skype
2017-05-11 17:56:50 ----D---- C:\Program Files\Common Files
2017-05-11 17:56:45 ----D---- C:\ProgramData\Skype
2017-05-10 23:53:22 ----D---- C:\Windows\winsxs
2017-05-10 19:40:58 ----D---- C:\Windows\system32\catroot2
2017-05-09 23:21:18 ----SD---- C:\ProgramData\Microsoft
2017-05-09 23:02:21 ----D---- C:\Windows\system32\cs-CZ
2017-05-09 23:02:21 ----D---- C:\Windows\PolicyDefinitions
2017-05-09 23:02:18 ----D---- C:\Windows\system32\en-US
2017-05-09 23:02:06 ----D---- C:\Program Files\Internet Explorer
2017-05-09 23:00:17 ----D---- C:\ProgramData\Microsoft Help
2017-05-09 22:52:51 ----AC---- C:\Windows\system32\MRT.exe
2017-05-09 22:40:16 ----D---- C:\Windows\debug
2017-05-07 21:51:40 ----D---- C:\Users\Viktor\AppData\Roaming\BSplayer
2017-05-07 17:16:43 ----D---- C:\Windows
2017-05-07 16:01:21 ----D---- C:\Windows\system32\Tasks
2017-05-07 16:01:12 ----D---- C:\Program Files\Google
2017-05-07 14:56:52 ----RSD---- C:\Windows\Fonts
2017-05-07 14:55:31 ----D---- C:\Windows\system32\migration
2017-05-07 14:49:51 ----D---- C:\Windows\SoftwareDistribution
2017-05-07 10:28:19 ----D---- C:\Windows\system32\LogFiles
2017-05-05 21:09:51 ----D---- C:\Users\Viktor\AppData\Roaming\Mozilla
2017-05-05 21:04:47 ----D---- C:\Windows\system32\catroot
2017-05-05 20:53:54 ----D---- C:\Windows\system32\spool
2017-05-05 20:53:13 ----D---- C:\Windows\system32\wbem
2017-05-04 17:05:30 ----D---- C:\Windows\system32\NDF
2017-05-02 23:32:47 ----D---- C:\Users\Viktor\AppData\Roaming\uTorrent
2017-04-28 20:23:13 ----D---- C:\Windows\system32\winevt
2017-04-28 20:23:12 ----D---- C:\Windows\system32\sysprep
2017-04-28 20:23:12 ----D---- C:\Windows\system32\SMI
2017-04-28 20:23:12 ----D---- C:\Windows\system32\Setup
2017-04-28 20:23:12 ----D---- C:\Windows\system32\oobe
2017-04-28 20:23:12 ----D---- C:\Windows\system32\MUI
2017-04-28 20:23:12 ----D---- C:\Windows\system32\drivers\UMDF
2017-04-28 20:23:12 ----D---- C:\Windows\system32\com
2017-04-28 20:23:08 ----D---- C:\Windows\security
2017-04-28 20:23:08 ----D---- C:\Windows\Registration
2017-04-28 20:23:08 ----D---- C:\Windows\PLA
2017-04-28 20:23:08 ----D---- C:\Windows\Panther
2017-04-28 20:23:04 ----D---- C:\Windows\IME
2017-04-28 20:23:04 ----D---- C:\Windows\Help
2017-04-28 20:22:59 ----D---- C:\Windows\AppPatch
2017-04-28 20:22:58 ----D---- C:\Users\Viktor\AppData\Roaming\Scribus
2017-04-28 20:22:57 ----D---- C:\Users\Viktor\AppData\Roaming\Nikon
2017-04-28 20:22:38 ----RD---- C:\Users
2017-04-28 20:22:37 ----D---- C:\ProgramData\Adobe
2017-04-28 20:22:32 ----D---- C:\Program Files\Windows Sidebar
2017-04-28 20:22:32 ----D---- C:\Program Files\Windows Media Player
2017-04-28 20:22:32 ----D---- C:\Program Files\Microsoft Visual Studio 8
2017-04-28 20:22:28 ----D---- C:\Program Files\Common Files\System
2017-04-28 20:22:28 ----D---- C:\Program Files\Common Files\microsoft shared
2017-04-25 23:23:14 ----D---- C:\Program Files\IQ Option
2017-04-25 23:22:17 ----D---- C:\Windows\system32\wdi
2017-04-19 23:05:37 ----D---- C:\Windows\system32\DriverStore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [2017-05-03 148696]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswblogx.sys [2017-05-03 268016]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [2017-05-03 41664]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-05-03 62152]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-05-03 279800]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 252808]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2015-03-05 17160]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [2017-05-03 258288]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-05-03 31064]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-05-03 90336]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-05-03 764576]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-05-03 482608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-05-03 107928]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-05-12 115152]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2017-04-19 26168]
R3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2017-04-19 40504]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-08-23 48640]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-03-17 23256]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-05-15 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-03-17 51928]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 105696]
S1 p3521005372am;p3521005372am; \??\C:\Users\Viktor\AppData\Local\Temp\bk9231.tmp\p3521005372am.sys []
S1 p540333084am;p540333084am; \??\C:\Users\Viktor\AppData\Local\Temp\bk9147.tmp\p540333084am.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-05-03 34136]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2015-03-05 13064]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SliceDisk5;SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-03 263304]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2015-03-17 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-03-17 1871160]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 103696]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2017-05-03 5732136]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2017-02-07 1142464]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 280864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-26 105096]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-07 153168]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2017-04-05 317400]
S2 SNARE;SNARE; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-07 153168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-04-16 104960]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-05-12 173512]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-03-26 45688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Stále se vracející malware luckysites123

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Wik24
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 lis 2016 20:24

Re: Stále se vracející malware luckysites123

#3 Příspěvek od Wik24 »

LOG:

# AdwCleaner v6.046 - Log vytvořen 16/05/2017 v 23:57:01
# Aktualizováno dne 24/04/2017 z Malwarebytes
# Databáze : 2017-05-16.1 [Server]
# Operační systém : Windows 7 Professional Service Pack 1 (X86)
# Uživatelské jméno : Viktor - VIKTOR-PC
# Spuštěno z : C:\Users\Viktor\Desktop\adwcleaner_6.046.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****

[-] Služba smazána: SNARE


***** [ Složky ] *****

[-] Složka smazána: C:\Program Files\Firefox
[-] Složka smazána: C:\Users\Viktor\AppData\Roaming\Firefox
[-] Složka smazána: C:\Users\Viktor\AppData\Local\Firefox
[-] Složka smazána: C:\Users\Viktor\AppData\Local\SNARE
[-] Složka smazána: C:\Users\Viktor\AppData\Local\Kitty
[-] Složka smazána: C:\Windows\Update\psgo
[-] Složka smazána: C:\ProgramData\BIT


***** [ Soubory ] *****

[-] Soubor smazán: C:\Program Files\Internet Explorer\iexplore.bat
[-] Soubor smazán: C:\Users\Public\Documents\temp.dat
[-] Soubor smazán: C:\Users\Public\Documents\report.dat


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SNARE
[-] Klíč smazán: HKU\S-1-5-21-2055323181-640332037-3085459343-1000\Software\Conduit
[#] Klíč smazán po restartu: HKCU\Software\Conduit
[-] Klíč smazán: HKLM\SOFTWARE\InterSect Alliance
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost [SNARE]
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [Kitty]
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [SNAREA]
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WANARE]
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [BIT]


***** [ Prohlížeče ] *****

[-] [C:\Users\Viktor\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Web data] [Search Provider] Smazáno: luckystarting.com
[-] [C:\Users\Viktor\AppData\Local\Google\Chrome\User Data\ChromeDefaultData] [startup_urls] Smazáno: hxxp://www.initialpage123.com/?z=ca6a5f598b120 ... 2L&type=hp


*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2582 Bajty] - [16/05/2017 23:57:01]
C:\AdwCleaner\AdwCleaner[S0].txt - [2806 Bajty] - [16/05/2017 23:55:25]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [2728 Bajty] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Stále se vracející malware luckysites123

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Wik24
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 lis 2016 20:24

Re: Stále se vracející malware luckysites123

#5 Příspěvek od Wik24 »

LOG:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Viktor at 2017-05-18 02:39:18
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 18 GB (24%) free of 76 GB
Total RAM: 3583 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:39:56, on 18.5.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18666)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\DTAgent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Viktor\Downloads\RSIT.exe
C:\Program Files\trend micro\Viktor.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkI ... id=UE09DHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 4253 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-03 773920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-03 213824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2017-05-04 27716568]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-06-01 6690520]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2017-02-07 3777728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner.exe [2016-06-01 6690520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
C:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1002984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-05-16 23:53:21 ----D---- C:\AdwCleaner
2017-05-15 18:50:00 ----D---- C:\rsit
2017-05-15 18:50:00 ----D---- C:\Program Files\trend micro
2017-05-14 00:05:43 ----D---- C:\Users\Viktor\AppData\Roaming\com.adobe.bridge.PublishPanel
2017-05-11 17:56:50 ----D---- C:\Program Files\Common Files\Skype
2017-05-11 17:33:38 ----D---- C:\Program Files\Mozilla Maintenance Service
2017-05-09 23:14:42 ----D---- C:\Program Files\LightZone 3
2017-05-09 22:53:17 ----D---- C:\Windows\system32\MRT
2017-05-09 22:45:04 ----D---- C:\ProgramData\Microsoft OneDrive
2017-05-09 22:39:48 ----A---- C:\Windows\system32\drivers\PROCEXP152.SYS
2017-05-09 19:36:52 ----A---- C:\Windows\system32\mshtml.dll
2017-05-09 19:36:51 ----A---- C:\Windows\system32\ieframe.dll
2017-05-09 19:36:50 ----A---- C:\Windows\system32\jscript9.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\wininet.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\win32k.sys
2017-05-09 19:36:49 ----A---- C:\Windows\system32\urlmon.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\iertutil.dll
2017-05-09 19:36:48 ----A---- C:\Windows\system32\vbscript.dll
2017-05-09 19:36:48 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-05-09 19:36:48 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-05-09 19:36:48 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-05-09 19:36:47 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-05-09 19:36:47 ----A---- C:\Windows\system32\crypt32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\oleaut32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\ole32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\drivers\srv.sys
2017-05-09 19:36:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-05-09 19:36:45 ----A---- C:\Windows\system32\iedkcs32.dll
2017-05-09 19:36:45 ----A---- C:\Windows\system32\gdi32.dll
2017-05-09 19:36:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-05-09 19:36:44 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-05-09 19:36:44 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-05-09 19:36:44 ----A---- C:\Windows\system32\mshtmled.dll
2017-05-09 19:36:44 ----A---- C:\Windows\system32\drivers\afd.sys
2017-05-09 19:36:43 ----A---- C:\Windows\system32\rpcss.dll
2017-05-09 19:36:43 ----A---- C:\Windows\system32\ntdll.dll
2017-05-09 19:36:43 ----A---- C:\Windows\system32\drivers\netio.sys
2017-05-09 19:36:43 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-05-09 19:36:42 ----A---- C:\Windows\system32\oleres.dll
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-05-09 19:36:41 ----A---- C:\Windows\system32\webcheck.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\msfeeds.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\jscript.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\ie4uinit.exe
2017-05-09 19:36:41 ----A---- C:\Windows\system32\dxtrans.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\comcat.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\rpcrt4.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\ieui.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\ieapfltr.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-05-09 19:36:40 ----A---- C:\Windows\system32\advapi32.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\smss.exe
2017-05-09 19:36:39 ----A---- C:\Windows\system32\lsasrv.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\kerberos.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-05-09 19:36:38 ----A---- C:\Windows\system32\wdigest.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\srcore.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\schannel.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\rpchttp.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\occache.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\ncrypt.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\msv1_0.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\msrating.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\KernelBase.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\jsproxy.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\jscript9diag.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\ieUnatt.exe
2017-05-09 19:36:38 ----A---- C:\Windows\system32\dxtmsft.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-05-09 19:36:38 ----A---- C:\Windows\system32\cdosys.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\wintrust.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\winsrv.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\TSpkg.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\sspicli.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\srclient.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\lsass.exe
2017-05-09 19:36:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\inseng.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\iesetup.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\iernonce.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-05-09 19:36:37 ----A---- C:\Windows\system32\drivers\appid.sys
2017-05-09 19:36:37 ----A---- C:\Windows\system32\csrsrv.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptsvc.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptnet.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptbase.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\credssp.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\conhost.exe
2017-05-09 19:36:37 ----A---- C:\Windows\system32\bcrypt.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\appidapi.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\apisetschema.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\sspisrv.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\secur32.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\rstrui.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\msaudite.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\kernel32.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\cdd.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\auditpol.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidsvc.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\adtschema.dll
2017-05-09 19:36:35 ----A---- C:\Windows\system32\msobjs.dll
2017-05-09 19:36:35 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-05-07 16:02:25 ----D---- C:\Users\Viktor\AppData\Roaming\Google
2017-05-07 14:48:28 ----D---- C:\Program Files\Microsoft Silverlight
2017-05-07 14:47:20 ----A---- C:\Windows\system32\tzres.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\plasrv.exe
2017-05-07 14:47:20 ----A---- C:\Windows\system32\pla.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\pdh.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-05-07 14:47:20 ----A---- C:\Windows\system32\drivers\exfat.sys
2017-05-07 13:57:02 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-05-07 13:55:29 ----D---- C:\ProgramData\Malwarebytes
2017-05-07 13:55:29 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2017-05-07 12:43:04 ----D---- C:\Users\Viktor\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2017-05-05 20:54:28 ----D---- C:\Users\Viktor\AppData\Roaming\DAEMON Tools Lite
2017-05-03 23:48:48 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-05-03 23:47:11 ----D---- C:\Users\Viktor\AppData\Roaming\AVAST Software
2017-05-03 23:46:13 ----D---- C:\Program Files\Common Files\AV
2017-05-03 23:45:45 ----A---- C:\Windows\system32\drivers\aswstm.sys
2017-05-03 23:45:44 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2017-05-03 23:45:44 ----A---- C:\Windows\system32\drivers\aswSP.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-05-03 23:45:42 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2017-05-03 23:45:42 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-05-03 23:45:41 ----A---- C:\Windows\system32\drivers\aswbunivx.sys
2017-05-03 23:45:40 ----A---- C:\Windows\system32\drivers\aswblogx.sys
2017-05-03 23:45:40 ----A---- C:\Windows\system32\drivers\aswbidshx.sys
2017-05-03 23:45:39 ----A---- C:\Windows\system32\drivers\aswbidsdriverx.sys
2017-05-03 23:45:12 ----A---- C:\Windows\ucrtbase.dll
2017-05-03 23:45:12 ----A---- C:\Windows\system32\aswBoot.exe
2017-05-03 23:41:48 ----D---- C:\Program Files\AVAST Software
2017-05-03 23:41:21 ----D---- C:\ProgramData\AVAST Software
2017-04-30 21:15:53 ----D---- C:\Users\Viktor\AppData\Roaming\DVDVideoSoft
2017-04-30 10:55:50 ----D---- C:\Program Files\DAEMON Tools Lite
2017-04-25 20:02:55 ----D---- C:\Windows\psgo
2017-04-21 01:06:51 ----D---- C:\Windows\Update
2017-04-19 23:05:04 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-04-19 23:04:01 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-04-19 23:03:38 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of files/folders modified in the last 1 month======

2017-05-18 02:39:17 ----D---- C:\Windows\Temp
2017-05-18 02:27:49 ----D---- C:\Users\Viktor\AppData\Roaming\Skype
2017-05-17 23:31:47 ----D---- C:\Windows\system32\drivers
2017-05-17 22:56:14 ----D---- C:\Windows\system32\config
2017-05-17 02:07:01 ----HD---- C:\ProgramData
2017-05-16 23:57:24 ----D---- C:\Windows\Prefetch
2017-05-16 23:56:47 ----D---- C:\Program Files\Internet Explorer
2017-05-16 23:56:28 ----RD---- C:\Program Files
2017-05-15 22:17:54 ----D---- C:\Windows\tracing
2017-05-15 01:56:08 ----SD---- C:\Users\Viktor\AppData\Roaming\Microsoft
2017-05-15 01:56:08 ----D---- C:\Users\Viktor\AppData\Roaming\Adobe
2017-05-13 20:15:57 ----D---- C:\Windows\System32
2017-05-13 20:15:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-05-13 20:15:56 ----D---- C:\Windows\inf
2017-05-12 21:00:37 ----SHD---- C:\Windows\Installer
2017-05-12 19:18:08 ----RD---- C:\Program Files (x86)
2017-05-11 23:35:33 ----D---- C:\Windows\rescache
2017-05-11 23:34:39 ----SHD---- C:\System Volume Information
2017-05-11 23:34:26 ----D---- C:\Windows\Logs
2017-05-11 21:53:02 ----D---- C:\Windows\Microsoft.NET
2017-05-11 21:49:04 ----RSD---- C:\Windows\assembly
2017-05-11 17:56:50 ----RD---- C:\Program Files\Skype
2017-05-11 17:56:50 ----D---- C:\Program Files\Common Files
2017-05-11 17:56:45 ----D---- C:\ProgramData\Skype
2017-05-10 23:53:22 ----D---- C:\Windows\winsxs
2017-05-10 19:40:58 ----D---- C:\Windows\system32\catroot2
2017-05-09 23:21:18 ----SD---- C:\ProgramData\Microsoft
2017-05-09 23:02:21 ----D---- C:\Windows\system32\cs-CZ
2017-05-09 23:02:21 ----D---- C:\Windows\PolicyDefinitions
2017-05-09 23:02:18 ----D---- C:\Windows\system32\en-US
2017-05-09 23:00:17 ----D---- C:\ProgramData\Microsoft Help
2017-05-09 22:52:51 ----AC---- C:\Windows\system32\MRT.exe
2017-05-09 22:40:16 ----D---- C:\Windows\debug
2017-05-07 21:51:40 ----D---- C:\Users\Viktor\AppData\Roaming\BSplayer
2017-05-07 17:16:43 ----D---- C:\Windows
2017-05-07 16:01:21 ----D---- C:\Windows\system32\Tasks
2017-05-07 16:01:12 ----D---- C:\Program Files\Google
2017-05-07 14:56:52 ----RSD---- C:\Windows\Fonts
2017-05-07 14:55:31 ----D---- C:\Windows\system32\migration
2017-05-07 14:49:51 ----D---- C:\Windows\SoftwareDistribution
2017-05-07 10:28:19 ----D---- C:\Windows\system32\LogFiles
2017-05-05 21:09:51 ----D---- C:\Users\Viktor\AppData\Roaming\Mozilla
2017-05-05 21:04:47 ----D---- C:\Windows\system32\catroot
2017-05-05 20:53:54 ----D---- C:\Windows\system32\spool
2017-05-05 20:53:13 ----D---- C:\Windows\system32\wbem
2017-05-04 17:05:30 ----D---- C:\Windows\system32\NDF
2017-05-02 23:32:47 ----D---- C:\Users\Viktor\AppData\Roaming\uTorrent
2017-04-28 20:23:13 ----D---- C:\Windows\system32\winevt
2017-04-28 20:23:12 ----D---- C:\Windows\system32\sysprep
2017-04-28 20:23:12 ----D---- C:\Windows\system32\SMI
2017-04-28 20:23:12 ----D---- C:\Windows\system32\Setup
2017-04-28 20:23:12 ----D---- C:\Windows\system32\oobe
2017-04-28 20:23:12 ----D---- C:\Windows\system32\MUI
2017-04-28 20:23:12 ----D---- C:\Windows\system32\drivers\UMDF
2017-04-28 20:23:12 ----D---- C:\Windows\system32\com
2017-04-28 20:23:08 ----D---- C:\Windows\security
2017-04-28 20:23:08 ----D---- C:\Windows\Registration
2017-04-28 20:23:08 ----D---- C:\Windows\PLA
2017-04-28 20:23:08 ----D---- C:\Windows\Panther
2017-04-28 20:23:04 ----D---- C:\Windows\IME
2017-04-28 20:23:04 ----D---- C:\Windows\Help
2017-04-28 20:22:59 ----D---- C:\Windows\AppPatch
2017-04-28 20:22:58 ----D---- C:\Users\Viktor\AppData\Roaming\Scribus
2017-04-28 20:22:57 ----D---- C:\Users\Viktor\AppData\Roaming\Nikon
2017-04-28 20:22:38 ----RD---- C:\Users
2017-04-28 20:22:37 ----D---- C:\ProgramData\Adobe
2017-04-28 20:22:32 ----D---- C:\Program Files\Windows Sidebar
2017-04-28 20:22:32 ----D---- C:\Program Files\Windows Media Player
2017-04-28 20:22:32 ----D---- C:\Program Files\Microsoft Visual Studio 8
2017-04-28 20:22:28 ----D---- C:\Program Files\Common Files\System
2017-04-28 20:22:28 ----D---- C:\Program Files\Common Files\microsoft shared
2017-04-25 23:23:14 ----D---- C:\Program Files\IQ Option
2017-04-25 23:22:17 ----D---- C:\Windows\system32\wdi
2017-04-19 23:05:37 ----D---- C:\Windows\system32\DriverStore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [2017-05-03 148696]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswblogx.sys [2017-05-03 268016]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [2017-05-03 41664]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-05-03 62152]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-05-03 279800]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 252808]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2015-03-05 17160]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [2017-05-03 258288]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-05-03 31064]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-05-03 90336]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-05-03 764576]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-05-03 482608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-05-03 107928]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-05-12 115152]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2017-04-19 26168]
R3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2017-04-19 40504]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-08-23 48640]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-03-17 23256]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-05-17 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-03-17 51928]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 105696]
S1 p3521005372am;p3521005372am; \??\C:\Users\Viktor\AppData\Local\Temp\bk9231.tmp\p3521005372am.sys []
S1 p540333084am;p540333084am; \??\C:\Users\Viktor\AppData\Local\Temp\bk9147.tmp\p540333084am.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-05-03 34136]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2015-03-05 13064]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SliceDisk5;SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-03 263304]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2015-03-17 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-03-17 1871160]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 103696]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2017-05-03 5732136]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2017-02-07 1142464]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 280864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-26 105096]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-07 153168]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2017-04-05 317400]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-07 153168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-04-16 104960]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-05-12 173512]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-03-26 45688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Stále se vracející malware luckysites123

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Users\Viktor\AppData\Local\Temp\bk9231.tmp\p3521005372am.sys
C:\Users\Viktor\AppData\Local\Temp\bk9147.tmp\p540333084am.sys

:services
p3521005372am
p540333084am

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte Avast a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Wik24
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 16 lis 2016 20:24

Re: Stále se vracející malware luckysites123

#7 Příspěvek od Wik24 »

RSIT LOG po OTM:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Viktor at 2017-05-18 22:23:06
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 22 GB (29%) free of 76 GB
Total RAM: 3583 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:23:41, on 18.5.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18666)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Viktor\Desktop\RSIT.exe
C:\Program Files\trend micro\Viktor.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkI ... id=UE09DHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 4074 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-03 773920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-03 213824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2017-05-04 27716568]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-06-01 6690520]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2017-02-07 3777728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner.exe [2016-06-01 6690520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
C:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1002984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-05-18 22:23:05 ----D---- C:\ProgramData\SWCUTemp
2017-05-18 22:03:59 ----D---- C:\_OTM
2017-05-16 23:53:21 ----D---- C:\AdwCleaner
2017-05-15 18:50:00 ----D---- C:\rsit
2017-05-15 18:50:00 ----D---- C:\Program Files\trend micro
2017-05-14 00:05:43 ----D---- C:\Users\Viktor\AppData\Roaming\com.adobe.bridge.PublishPanel
2017-05-11 17:56:50 ----D---- C:\Program Files\Common Files\Skype
2017-05-11 17:33:38 ----D---- C:\Program Files\Mozilla Maintenance Service
2017-05-09 23:14:42 ----D---- C:\Program Files\LightZone 3
2017-05-09 22:53:17 ----D---- C:\Windows\system32\MRT
2017-05-09 22:45:04 ----D---- C:\ProgramData\Microsoft OneDrive
2017-05-09 22:39:48 ----A---- C:\Windows\system32\drivers\PROCEXP152.SYS
2017-05-09 19:36:52 ----A---- C:\Windows\system32\mshtml.dll
2017-05-09 19:36:51 ----A---- C:\Windows\system32\ieframe.dll
2017-05-09 19:36:50 ----A---- C:\Windows\system32\jscript9.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\wininet.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\win32k.sys
2017-05-09 19:36:49 ----A---- C:\Windows\system32\urlmon.dll
2017-05-09 19:36:49 ----A---- C:\Windows\system32\iertutil.dll
2017-05-09 19:36:48 ----A---- C:\Windows\system32\vbscript.dll
2017-05-09 19:36:48 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-05-09 19:36:48 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-05-09 19:36:48 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-05-09 19:36:47 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-05-09 19:36:47 ----A---- C:\Windows\system32\crypt32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\oleaut32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\ole32.dll
2017-05-09 19:36:46 ----A---- C:\Windows\system32\drivers\srv.sys
2017-05-09 19:36:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-05-09 19:36:45 ----A---- C:\Windows\system32\iedkcs32.dll
2017-05-09 19:36:45 ----A---- C:\Windows\system32\gdi32.dll
2017-05-09 19:36:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-05-09 19:36:44 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-05-09 19:36:44 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-05-09 19:36:44 ----A---- C:\Windows\system32\mshtmled.dll
2017-05-09 19:36:44 ----A---- C:\Windows\system32\drivers\afd.sys
2017-05-09 19:36:43 ----A---- C:\Windows\system32\rpcss.dll
2017-05-09 19:36:43 ----A---- C:\Windows\system32\ntdll.dll
2017-05-09 19:36:43 ----A---- C:\Windows\system32\drivers\netio.sys
2017-05-09 19:36:43 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-05-09 19:36:42 ----A---- C:\Windows\system32\oleres.dll
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-05-09 19:36:42 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-05-09 19:36:41 ----A---- C:\Windows\system32\webcheck.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\msfeeds.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\jscript.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\ie4uinit.exe
2017-05-09 19:36:41 ----A---- C:\Windows\system32\dxtrans.dll
2017-05-09 19:36:41 ----A---- C:\Windows\system32\comcat.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\rpcrt4.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\ieui.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\ieapfltr.dll
2017-05-09 19:36:40 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-05-09 19:36:40 ----A---- C:\Windows\system32\advapi32.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\smss.exe
2017-05-09 19:36:39 ----A---- C:\Windows\system32\lsasrv.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\kerberos.dll
2017-05-09 19:36:39 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-05-09 19:36:38 ----A---- C:\Windows\system32\wdigest.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\srcore.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\schannel.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\rpchttp.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\occache.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\ncrypt.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\msv1_0.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\msrating.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\KernelBase.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\jsproxy.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\jscript9diag.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\ieUnatt.exe
2017-05-09 19:36:38 ----A---- C:\Windows\system32\dxtmsft.dll
2017-05-09 19:36:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-05-09 19:36:38 ----A---- C:\Windows\system32\cdosys.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\wintrust.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\winsrv.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\TSpkg.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\sspicli.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\srclient.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\lsass.exe
2017-05-09 19:36:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\inseng.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\iesetup.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\iernonce.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-05-09 19:36:37 ----A---- C:\Windows\system32\drivers\appid.sys
2017-05-09 19:36:37 ----A---- C:\Windows\system32\csrsrv.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptsvc.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptnet.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\cryptbase.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\credssp.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\conhost.exe
2017-05-09 19:36:37 ----A---- C:\Windows\system32\bcrypt.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\appidapi.dll
2017-05-09 19:36:37 ----A---- C:\Windows\system32\apisetschema.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-09 19:36:36 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\sspisrv.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\secur32.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\rstrui.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\msaudite.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\kernel32.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\cdd.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\auditpol.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidsvc.dll
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-05-09 19:36:36 ----A---- C:\Windows\system32\adtschema.dll
2017-05-09 19:36:35 ----A---- C:\Windows\system32\msobjs.dll
2017-05-09 19:36:35 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-05-07 16:02:25 ----D---- C:\Users\Viktor\AppData\Roaming\Google
2017-05-07 14:48:28 ----D---- C:\Program Files\Microsoft Silverlight
2017-05-07 14:47:20 ----A---- C:\Windows\system32\tzres.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\plasrv.exe
2017-05-07 14:47:20 ----A---- C:\Windows\system32\pla.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\pdh.dll
2017-05-07 14:47:20 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-05-07 14:47:20 ----A---- C:\Windows\system32\drivers\exfat.sys
2017-05-07 13:57:02 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2017-05-07 13:55:30 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-05-07 13:55:29 ----D---- C:\ProgramData\Malwarebytes
2017-05-07 13:55:29 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2017-05-07 12:43:04 ----D---- C:\Users\Viktor\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2017-05-05 20:54:28 ----D---- C:\Users\Viktor\AppData\Roaming\DAEMON Tools Lite
2017-05-03 23:48:48 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-05-03 23:47:11 ----D---- C:\Users\Viktor\AppData\Roaming\AVAST Software
2017-05-03 23:46:13 ----D---- C:\Program Files\Common Files\AV
2017-05-03 23:45:45 ----A---- C:\Windows\system32\drivers\aswstm.sys
2017-05-03 23:45:44 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2017-05-03 23:45:44 ----A---- C:\Windows\system32\drivers\aswSP.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-05-03 23:45:43 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-05-03 23:45:42 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2017-05-03 23:45:42 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-05-03 23:45:41 ----A---- C:\Windows\system32\drivers\aswbunivx.sys
2017-05-03 23:45:40 ----A---- C:\Windows\system32\drivers\aswblogx.sys
2017-05-03 23:45:40 ----A---- C:\Windows\system32\drivers\aswbidshx.sys
2017-05-03 23:45:39 ----A---- C:\Windows\system32\drivers\aswbidsdriverx.sys
2017-05-03 23:45:12 ----A---- C:\Windows\ucrtbase.dll
2017-05-03 23:45:12 ----A---- C:\Windows\system32\aswBoot.exe
2017-05-03 23:41:48 ----D---- C:\Program Files\AVAST Software
2017-05-03 23:41:21 ----D---- C:\ProgramData\AVAST Software
2017-04-30 21:15:53 ----D---- C:\Users\Viktor\AppData\Roaming\DVDVideoSoft
2017-04-30 10:55:50 ----D---- C:\Program Files\DAEMON Tools Lite
2017-04-25 20:02:55 ----D---- C:\Windows\psgo
2017-04-21 01:06:51 ----D---- C:\Windows\Update
2017-04-19 23:05:04 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-04-19 23:04:01 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-04-19 23:03:38 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of files/folders modified in the last 1 month======

2017-05-18 22:23:05 ----HD---- C:\ProgramData
2017-05-18 22:23:02 ----D---- C:\Windows\Temp
2017-05-18 22:22:54 ----D---- C:\Users\Viktor\AppData\Roaming\Skype
2017-05-18 22:04:45 ----D---- C:\Windows\system32\config
2017-05-18 21:44:06 ----SHD---- C:\System Volume Information
2017-05-18 17:13:44 ----D---- C:\Windows\Prefetch
2017-05-18 17:00:41 ----D---- C:\Windows
2017-05-18 02:44:02 ----D---- C:\Windows\inf
2017-05-18 02:44:01 ----D---- C:\Windows\debug
2017-05-17 23:31:47 ----D---- C:\Windows\system32\drivers
2017-05-16 23:56:47 ----D---- C:\Program Files\Internet Explorer
2017-05-16 23:56:28 ----RD---- C:\Program Files
2017-05-15 22:17:54 ----D---- C:\Windows\tracing
2017-05-15 01:56:08 ----SD---- C:\Users\Viktor\AppData\Roaming\Microsoft
2017-05-15 01:56:08 ----D---- C:\Users\Viktor\AppData\Roaming\Adobe
2017-05-13 20:15:57 ----D---- C:\Windows\System32
2017-05-13 20:15:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-05-12 21:00:37 ----SHD---- C:\Windows\Installer
2017-05-12 19:18:08 ----RD---- C:\Program Files (x86)
2017-05-11 23:35:33 ----D---- C:\Windows\rescache
2017-05-11 23:34:26 ----D---- C:\Windows\Logs
2017-05-11 21:53:02 ----D---- C:\Windows\Microsoft.NET
2017-05-11 21:49:04 ----RSD---- C:\Windows\assembly
2017-05-11 17:56:50 ----RD---- C:\Program Files\Skype
2017-05-11 17:56:50 ----D---- C:\Program Files\Common Files
2017-05-11 17:56:45 ----D---- C:\ProgramData\Skype
2017-05-10 23:53:22 ----D---- C:\Windows\winsxs
2017-05-10 19:40:58 ----D---- C:\Windows\system32\catroot2
2017-05-09 23:21:18 ----SD---- C:\ProgramData\Microsoft
2017-05-09 23:02:21 ----D---- C:\Windows\system32\cs-CZ
2017-05-09 23:02:21 ----D---- C:\Windows\PolicyDefinitions
2017-05-09 23:02:18 ----D---- C:\Windows\system32\en-US
2017-05-09 23:00:17 ----D---- C:\ProgramData\Microsoft Help
2017-05-09 22:52:51 ----AC---- C:\Windows\system32\MRT.exe
2017-05-07 21:51:40 ----D---- C:\Users\Viktor\AppData\Roaming\BSplayer
2017-05-07 16:01:21 ----D---- C:\Windows\system32\Tasks
2017-05-07 16:01:12 ----D---- C:\Program Files\Google
2017-05-07 14:56:52 ----RSD---- C:\Windows\Fonts
2017-05-07 14:55:31 ----D---- C:\Windows\system32\migration
2017-05-07 14:49:51 ----D---- C:\Windows\SoftwareDistribution
2017-05-07 10:28:19 ----D---- C:\Windows\system32\LogFiles
2017-05-05 21:09:51 ----D---- C:\Users\Viktor\AppData\Roaming\Mozilla
2017-05-05 21:04:47 ----D---- C:\Windows\system32\catroot
2017-05-05 20:53:54 ----D---- C:\Windows\system32\spool
2017-05-05 20:53:13 ----D---- C:\Windows\system32\wbem
2017-05-04 17:05:30 ----D---- C:\Windows\system32\NDF
2017-05-02 23:32:47 ----D---- C:\Users\Viktor\AppData\Roaming\uTorrent
2017-04-28 20:23:13 ----D---- C:\Windows\system32\winevt
2017-04-28 20:23:12 ----D---- C:\Windows\system32\sysprep
2017-04-28 20:23:12 ----D---- C:\Windows\system32\SMI
2017-04-28 20:23:12 ----D---- C:\Windows\system32\Setup
2017-04-28 20:23:12 ----D---- C:\Windows\system32\oobe
2017-04-28 20:23:12 ----D---- C:\Windows\system32\MUI
2017-04-28 20:23:12 ----D---- C:\Windows\system32\drivers\UMDF
2017-04-28 20:23:12 ----D---- C:\Windows\system32\com
2017-04-28 20:23:08 ----D---- C:\Windows\security
2017-04-28 20:23:08 ----D---- C:\Windows\Registration
2017-04-28 20:23:08 ----D---- C:\Windows\PLA
2017-04-28 20:23:08 ----D---- C:\Windows\Panther
2017-04-28 20:23:04 ----D---- C:\Windows\IME
2017-04-28 20:23:04 ----D---- C:\Windows\Help
2017-04-28 20:22:59 ----D---- C:\Windows\AppPatch
2017-04-28 20:22:58 ----D---- C:\Users\Viktor\AppData\Roaming\Scribus
2017-04-28 20:22:57 ----D---- C:\Users\Viktor\AppData\Roaming\Nikon
2017-04-28 20:22:38 ----RD---- C:\Users
2017-04-28 20:22:37 ----D---- C:\ProgramData\Adobe
2017-04-28 20:22:32 ----D---- C:\Program Files\Windows Sidebar
2017-04-28 20:22:32 ----D---- C:\Program Files\Windows Media Player
2017-04-28 20:22:32 ----D---- C:\Program Files\Microsoft Visual Studio 8
2017-04-28 20:22:28 ----D---- C:\Program Files\Common Files\System
2017-04-28 20:22:28 ----D---- C:\Program Files\Common Files\microsoft shared
2017-04-25 23:23:14 ----D---- C:\Program Files\IQ Option
2017-04-25 23:22:17 ----D---- C:\Windows\system32\wdi
2017-04-19 23:05:37 ----D---- C:\Windows\system32\DriverStore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [2017-05-03 148696]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswblogx.sys [2017-05-03 268016]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [2017-05-03 41664]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-05-03 62152]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-05-03 279800]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 252808]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2015-03-05 17160]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [2017-05-03 258288]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-05-03 31064]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-05-03 90336]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-05-03 764576]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-05-03 482608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 MpKsl0583d51e;MpKsl0583d51e; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3BD3A9F4-FC15-44D4-8E0A-E8CBE0F7BEE5}\MpKsl0583d51e.sys [2017-05-18 39168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-05-03 107928]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-05-12 115152]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2017-04-19 26168]
R3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2017-04-19 40504]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-08-23 48640]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 105696]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-05-03 34136]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-03-17 23256]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-03-17 51928]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2015-03-05 13064]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SliceDisk5;SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-03 263304]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 103696]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2017-05-03 5732136]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2017-02-07 1142464]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 280864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-26 105096]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-07 153168]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2015-03-17 1080120]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-03-17 1871160]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2017-04-05 317400]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-05-07 153168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-04-16 104960]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-05-12 173512]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-03-26 45688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Stále se vracející malware luckysites123

#8 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět