Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Kontrola logu

#1 Příspěvek od synologic »

Dobrý den, prosím o kontrolu logu.
Přestal mi fungovat Avast a přestaly se mi zobrazovat některý skrytý složky a soubory.
Děkuji.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Synologic at 2017-07-05 15:20:33
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 382 GB (88%) free of 432 GB
Total RAM: 4040 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:20:37, on 5.7.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18698)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe
C:\Program Files\trend micro\Synologic.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7431 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2008
taskeng.exe {3ABDD75B-9D17-43D5-8C0C-17D51C554309}
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
AvastUI.exe /nogui
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Synologic\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Synologic\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=58.0.3029.110 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef4682968,0x7fef4682980,0x7fef4682990
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2056 --on-initialized-event-handle=308 --parent-handle=320 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1136 --disable-d3d11 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,16,18,19,20,23,26,41,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.813.3.2000 --gpu-driver-date=3-24-2011 --gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0106 --gpu-active-vendor-id=0x1002 --gpu-active-device-id=0x68e4 --service-request-channel-token=3ABAA3E5F332F3DF8DE4AE4C67071AAD --mojo-platform-channel-handle=1160 --ignored=" --type=renderer " /prefetch:2
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1136 --primordial-pipe-token=8DC8DFF0B49F38A3910BBD3D62A1D724 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=8DC8DFF0B49F38A3910BBD3D62A1D724 --renderer-client-id=6 --mojo-platform-channel-handle=2956 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1136 --primordial-pipe-token=5D7FA75B001B78C5C4C76D0B517FC2A8 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=5D7FA75B001B78C5C4C76D0B517FC2A8 --renderer-client-id=8 --mojo-platform-channel-handle=3764 /prefetch:1
taskeng.exe {A0D40B50-1A60-44A7-A416-49D20DB565DB}
"C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Reader_sl.exe"

"C:\Users\Synologic\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2017-02-26 2471744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-25 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-02 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-25 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-02 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-04 213824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-03-25 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbset.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filedecrypt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iastorui.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javacpl.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaw.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaws.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\open energymanagement.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstaler_skipuac.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstalldisplay.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\veriface.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\youcam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-07-05 15:20:33 ----D---- C:\rsit
2017-07-05 15:20:33 ----D---- C:\Program Files\trend micro
2017-07-04 16:33:57 ----D---- C:\Program Files\Recuva
2017-07-04 15:34:32 ----A---- C:\windows\system32\drivers\aswHdsKe.sys
2017-07-04 15:29:07 ----A---- C:\windows\system32\aswBoot.exe
2017-06-18 18:38:56 ----D---- C:\4ed65882c333fde3716f9b084e141b
2017-06-18 16:43:25 ----D---- C:\Users\Synologic\AppData\Roaming\vlc
2017-06-14 18:00:49 ----A---- C:\windows\SYSWOW64\D3DCompiler_47.dll
2017-06-14 18:00:49 ----A---- C:\windows\system32\D3DCompiler_47.dll
2017-06-14 18:00:48 ----A---- C:\windows\system32\mshtml.dll
2017-06-14 18:00:47 ----A---- C:\windows\SYSWOW64\mshtml.dll
2017-06-14 18:00:46 ----A---- C:\windows\system32\ieframe.dll
2017-06-14 18:00:45 ----A---- C:\windows\SYSWOW64\ieframe.dll
2017-06-14 18:00:44 ----A---- C:\windows\SYSWOW64\jscript9.dll
2017-06-14 18:00:44 ----A---- C:\windows\system32\jscript9.dll
2017-06-14 18:00:43 ----A---- C:\windows\SYSWOW64\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\ntoskrnl.exe
2017-06-14 18:00:42 ----A---- C:\windows\system32\wuaueng.dll
2017-06-14 18:00:42 ----A---- C:\windows\system32\win32k.sys
2017-06-14 18:00:41 ----A---- C:\windows\system32\tquery.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\shell32.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\mssrch.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\shell32.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\tquery.dll
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\mssrch.dll
2017-06-14 18:00:39 ----A---- C:\windows\system32\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\ExplorerFrame.dll
2017-06-14 18:00:38 ----A---- C:\windows\HelpPane.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchProtocolHost.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchIndexer.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssvp.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssphtb.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssph.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\localspl.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\tdx.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\mountmgr.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\jscript.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\iedkcs32.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchProtocolHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchIndexer.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssvp.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssphtb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssph.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\certcli.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\urlmon.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mshtmlmedia.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msfeeds.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\iertutil.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\DWrite.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecdd.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\certcli.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\urlmon.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\jscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\iertutil.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\webcheck.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\rpcrt4.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\jsproxy.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\ieui.dll
2017-06-14 18:00:33 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wuwebv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wucltux.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\occache.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\mshtmled.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\lsasrv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieUnatt.exe
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieapfltr.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\FntCache.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\wuapi.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\smss.exe
2017-06-14 18:00:32 ----A---- C:\windows\system32\msrating.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\kerberos.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\jscript9diag.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtrans.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtmsft.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2017-06-14 18:00:32 ----A---- C:\windows\system32\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\wuapi.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\webcheck.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\occache.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msrating.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\kerberos.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieui.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wudriver.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64win.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\winsrv.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wdigest.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\TSpkg.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\srcore.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\schannel.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\rpchttp.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ncrypt.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\kernel32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iesetup.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iernonce.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwcollector.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\ie4uinit.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2017-06-14 18:00:31 ----A---- C:\windows\system32\conhost.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\bcrypt.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wudriver.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wow32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wdigest.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\schannel.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\kernel32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iesetup.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iernonce.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\bcrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\appidapi.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups2.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuauclt.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wow64cpu.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\WinSetupUI.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\sspisrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\setbcdlocale.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\rstrui.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\msmmsp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\lsass.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\appid.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\csrsrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidsvc.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidpolicyconverter.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidcertstorecheck.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidapi.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\user.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\setup16.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\instnm.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\adtschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\adtschema.dll
2017-06-14 18:00:28 ----A---- C:\windows\SYSWOW64\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\ieetwcollectorres.dll

======List of files/folders modified in the last 1 month======

2017-07-05 15:20:37 ----D---- C:\windows\Prefetch
2017-07-05 15:20:33 ----RD---- C:\Program Files
2017-07-05 15:14:38 ----D---- C:\windows\system32\config
2017-07-05 15:14:29 ----D---- C:\windows\System32
2017-07-05 15:14:29 ----D---- C:\windows\inf
2017-07-05 15:14:29 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-07-05 15:11:20 ----D---- C:\windows\Temp
2017-07-05 06:35:29 ----D---- C:\windows\Minidump
2017-07-05 06:35:25 ----D---- C:\Windows
2017-07-04 18:11:28 ----SHD---- C:\System Volume Information
2017-07-04 16:26:03 ----D---- C:\windows\SysWOW64
2017-07-04 16:25:40 ----D---- C:\windows\Tasks
2017-07-04 16:25:40 ----D---- C:\windows\system32\wfp
2017-07-04 16:25:38 ----D---- C:\windows\system32\wbem
2017-07-04 16:24:22 ----D---- C:\windows\system32\Tasks
2017-07-04 16:24:22 ----D---- C:\windows\system32\DriverStore
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\UMDF
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\etc
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers
2017-07-04 16:24:22 ----D---- C:\windows\system32\catroot2
2017-07-04 16:24:21 ----D---- C:\windows\Microsoft.NET
2017-07-04 16:24:13 ----SHD---- C:\windows\Installer
2017-07-04 16:24:03 ----D---- C:\Users\Synologic\AppData\Roaming\ProductData
2017-07-04 16:23:59 ----RD---- C:\Program Files (x86)
2017-07-04 16:23:59 ----D---- C:\Program Files (x86)\Atheros
2017-07-04 16:23:39 ----D---- C:\windows\registration
2017-07-04 16:21:36 ----HD---- C:\ProgramData
2017-07-04 16:21:35 ----D---- C:\ProgramData\AVAST Software
2017-07-04 15:31:42 ----D---- C:\windows\Help
2017-06-28 16:21:23 ----D---- C:\ProgramData\ProductData
2017-06-19 16:16:21 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2017-06-18 16:31:22 ----D---- C:\windows\rescache
2017-06-18 13:51:33 ----SD---- C:\ProgramData\Microsoft
2017-06-18 13:51:24 ----SD---- C:\Users\Synologic\AppData\Roaming\Microsoft
2017-06-16 20:14:05 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2017-06-16 20:14:02 ----D---- C:\windows\system32\Macromed
2017-06-16 20:14:01 ----D---- C:\windows\SYSWOW64\Macromed
2017-06-16 20:04:31 ----D---- C:\windows\winsxs
2017-06-16 20:00:05 ----D---- C:\Program Files\Internet Explorer
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migwiz
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migration
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\cs-CZ
2017-06-16 20:00:04 ----D---- C:\Program Files (x86)\Internet Explorer
2017-06-16 20:00:03 ----D---- C:\windows\SYSWOW64\en-US
2017-06-16 19:59:59 ----D---- C:\windows\system32\migwiz
2017-06-16 19:59:59 ----D---- C:\windows\system32\migration
2017-06-16 19:59:59 ----D---- C:\windows\system32\cs-CZ
2017-06-16 19:59:58 ----D---- C:\windows\system32\en-US
2017-06-16 19:59:51 ----D---- C:\windows\AppPatch
2017-06-16 19:59:50 ----D---- C:\windows\system32\Boot
2017-06-14 21:46:34 ----D---- C:\windows\system32\MRT
2017-06-14 21:42:26 ----AC---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [2017-07-04 198944]
R0 aswblog;aswblog; C:\windows\system32\drivers\aswbloga.sys [2017-07-04 343264]
R0 aswbuniv;aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [2017-07-04 57704]
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2017-07-04 84392]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2017-07-04 361336]
R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-08-07 57952]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-02-18 439320]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2011-08-07 39008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswbidsdriver;aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [2017-07-04 319984]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2017-07-04 41800]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2017-07-04 110352]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2017-07-04 1015848]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2017-07-04 585608]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-08-07 13408]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2017-07-04 146664]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2017-07-04 198768]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-08-07 29792]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-25 8284672]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-25 296960]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2010-11-24 2673664]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT64.sys [2011-02-14 1581184]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-03-26 12262336]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-10-21 76912]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2017-02-26 25816]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-04-08 1430576]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2013-09-18 14112]
R3 vm2uvcflt;Vimicro USB Camera Filter 2; C:\windows\System32\Drivers\vm2uvcflt.sys [2010-09-22 15056]
R3 vm332avs;Lenovo Camera2; C:\windows\System32\Drivers\vm332avs.sys [2010-12-10 234960]
S3 aswHdsKe;aswHdsKe; \??\C:\windows\system32\drivers\aswHdsKe.sys [2017-07-04 104600]
S3 aswHwid;aswHwid; C:\windows\system32\drivers\aswHwid.sys [2017-07-04 46984]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-03-25 12262336]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2017-02-26 136408]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2017-02-26 63704]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-09-30 299520]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-25 203776]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2017-02-26 1080120]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2013-10-08 2099000]
S2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-04 263304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2017-02-26 2631456]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16 272384]
S3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-05-04 7346208]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2017-05-14 116224]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-02-26 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2017-02-26 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-01-19 1464096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2017-02-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-02-18 13336]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2017-02-26 30969208]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#3 Příspěvek od synologic »

Tak hotovo, zde vkládám log.
Jinak stále beze změny.

# AdwCleaner v6.047 - Log vytvořen 06/07/2017 v 14:19:38
# Aktualizováno dne 19/05/2017 z Malwarebytes
# Databáze : 2017-07-06.1 [Server]
# Operační systém : Windows 7 Home Premium Service Pack 1 (X64)
# Uživatelské jméno : Synologic - PC-SYNOLOGIC
# Spuštěno z : C:\Users\Synologic\Downloads\adwcleaner_6.047.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****

[-] Složka smazána: C:\ProgramData\Partner
[-] Složka smazána: C:\ProgramData\IObit\ASCDownloader
[#] Složka smazána po restartu: C:\ProgramData\Application Data\Partner
[#] Složka smazána po restartu: C:\ProgramData\Application Data\IObit\ASCDownloader


***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
[#] Klíč smazán po restartu: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1295 Bajty] - [06/07/2017 14:19:38]
C:\AdwCleaner\AdwCleaner[S0].txt - [1708 Bajty] - [06/07/2017 14:15:13]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1441 Bajty] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#5 Příspěvek od synologic »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Synologic at 2017-07-07 13:36:34
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 380 GB (88%) free of 432 GB
Total RAM: 4040 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:36:35, on 7.7.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18698)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\trend micro\Synologic.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7362 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {531C0DB7-D79E-4AFF-9E2F-05B4E11507E9}
"taskhost.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2040
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE

AvastUI.exe /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskeng.exe {B9BF541B-E5D9-434F-981F-36A8D57D4FBD}
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\windows\system32\wbem\wmiprvse.exe
"C:\windows\system32\NOTEPAD.EXE" C:\rsit\log.txt
C:\windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Synologic\Downloads\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2017-02-26 2471744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-25 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-02 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-25 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-02 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-04 213824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-03-25 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbset.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filedecrypt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iastorui.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javacpl.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaw.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaws.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\open energymanagement.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstaler_skipuac.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstalldisplay.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\veriface.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\youcam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-07-06 14:03:30 ----D---- C:\AdwCleaner
2017-07-05 15:20:33 ----D---- C:\rsit
2017-07-05 15:20:33 ----D---- C:\Program Files\trend micro
2017-07-04 16:33:57 ----D---- C:\Program Files\Recuva
2017-07-04 15:34:32 ----A---- C:\windows\system32\drivers\aswHdsKe.sys
2017-07-04 15:29:07 ----A---- C:\windows\system32\aswBoot.exe
2017-06-18 18:38:56 ----D---- C:\4ed65882c333fde3716f9b084e141b
2017-06-18 16:43:25 ----D---- C:\Users\Synologic\AppData\Roaming\vlc
2017-06-14 18:00:49 ----A---- C:\windows\SYSWOW64\D3DCompiler_47.dll
2017-06-14 18:00:49 ----A---- C:\windows\system32\D3DCompiler_47.dll
2017-06-14 18:00:48 ----A---- C:\windows\system32\mshtml.dll
2017-06-14 18:00:47 ----A---- C:\windows\SYSWOW64\mshtml.dll
2017-06-14 18:00:46 ----A---- C:\windows\system32\ieframe.dll
2017-06-14 18:00:45 ----A---- C:\windows\SYSWOW64\ieframe.dll
2017-06-14 18:00:44 ----A---- C:\windows\SYSWOW64\jscript9.dll
2017-06-14 18:00:44 ----A---- C:\windows\system32\jscript9.dll
2017-06-14 18:00:43 ----A---- C:\windows\SYSWOW64\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\ntoskrnl.exe
2017-06-14 18:00:42 ----A---- C:\windows\system32\wuaueng.dll
2017-06-14 18:00:42 ----A---- C:\windows\system32\win32k.sys
2017-06-14 18:00:41 ----A---- C:\windows\system32\tquery.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\shell32.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\mssrch.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\shell32.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\tquery.dll
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\mssrch.dll
2017-06-14 18:00:39 ----A---- C:\windows\system32\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\ExplorerFrame.dll
2017-06-14 18:00:38 ----A---- C:\windows\HelpPane.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchProtocolHost.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchIndexer.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssvp.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssphtb.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssph.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\localspl.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\tdx.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\mountmgr.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\jscript.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\iedkcs32.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchProtocolHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchIndexer.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssvp.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssphtb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssph.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\certcli.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\urlmon.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mshtmlmedia.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msfeeds.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\iertutil.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\DWrite.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecdd.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\certcli.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\urlmon.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\jscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\iertutil.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\webcheck.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\rpcrt4.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\jsproxy.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\ieui.dll
2017-06-14 18:00:33 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wuwebv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wucltux.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\occache.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\mshtmled.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\lsasrv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieUnatt.exe
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieapfltr.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\FntCache.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\wuapi.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\smss.exe
2017-06-14 18:00:32 ----A---- C:\windows\system32\msrating.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\kerberos.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\jscript9diag.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtrans.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtmsft.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2017-06-14 18:00:32 ----A---- C:\windows\system32\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\wuapi.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\webcheck.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\occache.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msrating.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\kerberos.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieui.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wudriver.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64win.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\winsrv.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wdigest.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\TSpkg.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\srcore.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\schannel.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\rpchttp.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ncrypt.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\kernel32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iesetup.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iernonce.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwcollector.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\ie4uinit.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2017-06-14 18:00:31 ----A---- C:\windows\system32\conhost.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\bcrypt.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wudriver.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wow32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wdigest.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\schannel.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\kernel32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iesetup.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iernonce.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\bcrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\appidapi.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups2.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuauclt.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wow64cpu.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\WinSetupUI.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\sspisrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\setbcdlocale.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\rstrui.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\msmmsp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\lsass.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\appid.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\csrsrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidsvc.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidpolicyconverter.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidcertstorecheck.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidapi.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\user.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\setup16.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\instnm.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\adtschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\adtschema.dll
2017-06-14 18:00:28 ----A---- C:\windows\SYSWOW64\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\ieetwcollectorres.dll

======List of files/folders modified in the last 1 month======

2017-07-07 13:35:22 ----D---- C:\windows\system32\config
2017-07-07 13:24:00 ----D---- C:\windows\System32
2017-07-07 13:24:00 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-07-07 13:23:59 ----D---- C:\windows\inf
2017-07-07 13:21:10 ----D---- C:\windows\Temp
2017-07-06 14:37:02 ----D---- C:\windows\Prefetch
2017-07-06 14:21:54 ----D---- C:\ProgramData\IObit
2017-07-06 14:19:35 ----HD---- C:\ProgramData
2017-07-06 13:57:42 ----D---- C:\ProgramData\ProductData
2017-07-05 15:20:33 ----RD---- C:\Program Files
2017-07-05 06:35:29 ----D---- C:\windows\Minidump
2017-07-05 06:35:25 ----D---- C:\Windows
2017-07-04 18:11:28 ----SHD---- C:\System Volume Information
2017-07-04 16:26:03 ----D---- C:\windows\SysWOW64
2017-07-04 16:25:40 ----D---- C:\windows\Tasks
2017-07-04 16:25:40 ----D---- C:\windows\system32\wfp
2017-07-04 16:25:38 ----D---- C:\windows\system32\wbem
2017-07-04 16:24:22 ----D---- C:\windows\system32\Tasks
2017-07-04 16:24:22 ----D---- C:\windows\system32\DriverStore
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\UMDF
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\etc
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers
2017-07-04 16:24:22 ----D---- C:\windows\system32\catroot2
2017-07-04 16:24:21 ----D---- C:\windows\Microsoft.NET
2017-07-04 16:24:13 ----SHD---- C:\windows\Installer
2017-07-04 16:24:03 ----D---- C:\Users\Synologic\AppData\Roaming\ProductData
2017-07-04 16:23:59 ----RD---- C:\Program Files (x86)
2017-07-04 16:23:59 ----D---- C:\Program Files (x86)\Atheros
2017-07-04 16:23:39 ----D---- C:\windows\registration
2017-07-04 16:21:35 ----D---- C:\ProgramData\AVAST Software
2017-07-04 15:31:42 ----D---- C:\windows\Help
2017-06-19 16:16:21 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2017-06-18 16:31:22 ----D---- C:\windows\rescache
2017-06-18 13:51:33 ----SD---- C:\ProgramData\Microsoft
2017-06-18 13:51:24 ----SD---- C:\Users\Synologic\AppData\Roaming\Microsoft
2017-06-16 20:14:05 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2017-06-16 20:14:02 ----D---- C:\windows\system32\Macromed
2017-06-16 20:14:01 ----D---- C:\windows\SYSWOW64\Macromed
2017-06-16 20:04:31 ----D---- C:\windows\winsxs
2017-06-16 20:00:05 ----D---- C:\Program Files\Internet Explorer
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migwiz
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migration
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\cs-CZ
2017-06-16 20:00:04 ----D---- C:\Program Files (x86)\Internet Explorer
2017-06-16 20:00:03 ----D---- C:\windows\SYSWOW64\en-US
2017-06-16 19:59:59 ----D---- C:\windows\system32\migwiz
2017-06-16 19:59:59 ----D---- C:\windows\system32\migration
2017-06-16 19:59:59 ----D---- C:\windows\system32\cs-CZ
2017-06-16 19:59:58 ----D---- C:\windows\system32\en-US
2017-06-16 19:59:51 ----D---- C:\windows\AppPatch
2017-06-16 19:59:50 ----D---- C:\windows\system32\Boot
2017-06-14 21:46:34 ----D---- C:\windows\system32\MRT
2017-06-14 21:42:26 ----AC---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [2017-07-04 198944]
R0 aswblog;aswblog; C:\windows\system32\drivers\aswbloga.sys [2017-07-04 343264]
R0 aswbuniv;aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [2017-07-04 57704]
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2017-07-04 84392]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2017-07-04 361336]
R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-08-07 57952]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-02-18 439320]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2011-08-07 39008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswbidsdriver;aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [2017-07-04 319984]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2017-07-04 41800]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2017-07-04 110352]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2017-07-04 1015848]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2017-07-04 585608]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-08-07 13408]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2017-07-04 146664]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2017-07-04 198768]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-08-07 29792]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-25 8284672]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-25 296960]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2010-11-24 2673664]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT64.sys [2011-02-14 1581184]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-03-26 12262336]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-10-21 76912]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2017-02-26 25816]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-04-08 1430576]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2013-09-18 14112]
R3 vm2uvcflt;Vimicro USB Camera Filter 2; C:\windows\System32\Drivers\vm2uvcflt.sys [2010-09-22 15056]
R3 vm332avs;Lenovo Camera2; C:\windows\System32\Drivers\vm332avs.sys [2010-12-10 234960]
S3 aswHdsKe;aswHdsKe; \??\C:\windows\system32\drivers\aswHdsKe.sys [2017-07-04 104600]
S3 aswHwid;aswHwid; C:\windows\system32\drivers\aswHwid.sys [2017-07-04 46984]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-03-25 12262336]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2017-02-26 136408]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2017-02-26 63704]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-09-30 299520]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-25 203776]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2017-02-26 1080120]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2013-10-08 2099000]
S2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-04 263304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2017-02-26 2631456]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16 272384]
S3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-05-04 7346208]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2017-05-14 116224]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-02-26 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2017-02-26 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-01-19 1464096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2017-02-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-02-18 13336]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2017-02-26 30969208]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#7 Příspěvek od synologic »

Log zde:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Synologic at 2017-07-09 18:34:05
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 380 GB (88%) free of 432 GB
Total RAM: 4040 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:34:10, on 9.7.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18698)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Synologic.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7362 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2036
taskeng.exe {E7FA4C01-D651-47C3-B395-C7B6DC1DDB50}
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\sppsvc.exe
AvastUI.exe /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Synologic\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Synologic\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=58.0.3029.110 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef4f12968,0x7fef4f12980,0x7fef4f12990
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1996 --on-initialized-event-handle=308 --parent-handle=320 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1212 --disable-d3d11 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,16,18,19,20,23,26,41,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.813.3.2000 --gpu-driver-date=3-24-2011 --gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0106 --gpu-active-vendor-id=0x1002 --gpu-active-device-id=0x68e4 --service-request-channel-token=532D36F07260131F89D702AB47FADE4B --mojo-platform-channel-handle=1232 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1212 --primordial-pipe-token=F1DA20A46C5DAD722985E78AEE24C86E --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=F1DA20A46C5DAD722985E78AEE24C86E --renderer-client-id=6 --mojo-platform-channel-handle=4300 /prefetch:1
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\Synologic\Desktop\RSITx64.exe"
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2017-02-26 2471744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-25 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-02 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-25 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-02 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-04 213824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-03-25 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbset.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filedecrypt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iastorui.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javacpl.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaw.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaws.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\open energymanagement.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstaler_skipuac.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstalldisplay.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\veriface.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\youcam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-07-09 18:27:00 ----D---- C:\_OTM
2017-07-06 14:03:30 ----D---- C:\AdwCleaner
2017-07-05 15:20:33 ----D---- C:\rsit
2017-07-05 15:20:33 ----D---- C:\Program Files\trend micro
2017-07-04 16:33:57 ----D---- C:\Program Files\Recuva
2017-07-04 15:34:32 ----A---- C:\windows\system32\drivers\aswHdsKe.sys
2017-07-04 15:29:07 ----A---- C:\windows\system32\aswBoot.exe
2017-06-18 18:38:56 ----D---- C:\4ed65882c333fde3716f9b084e141b
2017-06-18 16:43:25 ----D---- C:\Users\Synologic\AppData\Roaming\vlc
2017-06-14 18:00:49 ----A---- C:\windows\SYSWOW64\D3DCompiler_47.dll
2017-06-14 18:00:49 ----A---- C:\windows\system32\D3DCompiler_47.dll
2017-06-14 18:00:48 ----A---- C:\windows\system32\mshtml.dll
2017-06-14 18:00:47 ----A---- C:\windows\SYSWOW64\mshtml.dll
2017-06-14 18:00:46 ----A---- C:\windows\system32\ieframe.dll
2017-06-14 18:00:45 ----A---- C:\windows\SYSWOW64\ieframe.dll
2017-06-14 18:00:44 ----A---- C:\windows\SYSWOW64\jscript9.dll
2017-06-14 18:00:44 ----A---- C:\windows\system32\jscript9.dll
2017-06-14 18:00:43 ----A---- C:\windows\SYSWOW64\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\ntoskrnl.exe
2017-06-14 18:00:42 ----A---- C:\windows\system32\wuaueng.dll
2017-06-14 18:00:42 ----A---- C:\windows\system32\win32k.sys
2017-06-14 18:00:41 ----A---- C:\windows\system32\tquery.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\shell32.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\mssrch.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\shell32.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\tquery.dll
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\mssrch.dll
2017-06-14 18:00:39 ----A---- C:\windows\system32\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\ExplorerFrame.dll
2017-06-14 18:00:38 ----A---- C:\windows\HelpPane.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchProtocolHost.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchIndexer.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssvp.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssphtb.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssph.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\localspl.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\tdx.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\mountmgr.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\jscript.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\iedkcs32.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchProtocolHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchIndexer.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssvp.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssphtb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssph.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\certcli.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\urlmon.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mshtmlmedia.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msfeeds.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\iertutil.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\DWrite.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecdd.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\certcli.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\urlmon.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\jscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\iertutil.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\webcheck.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\rpcrt4.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\jsproxy.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\ieui.dll
2017-06-14 18:00:33 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wuwebv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wucltux.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\occache.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\mshtmled.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\lsasrv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieUnatt.exe
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieapfltr.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\FntCache.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\wuapi.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\smss.exe
2017-06-14 18:00:32 ----A---- C:\windows\system32\msrating.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\kerberos.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\jscript9diag.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtrans.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtmsft.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2017-06-14 18:00:32 ----A---- C:\windows\system32\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\wuapi.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\webcheck.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\occache.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msrating.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\kerberos.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieui.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wudriver.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64win.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\winsrv.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wdigest.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\TSpkg.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\srcore.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\schannel.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\rpchttp.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ncrypt.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\kernel32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iesetup.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iernonce.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwcollector.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\ie4uinit.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2017-06-14 18:00:31 ----A---- C:\windows\system32\conhost.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\bcrypt.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wudriver.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wow32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wdigest.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\schannel.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\kernel32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iesetup.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iernonce.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\bcrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\appidapi.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups2.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuauclt.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wow64cpu.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\WinSetupUI.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\sspisrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\setbcdlocale.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\rstrui.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\msmmsp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\lsass.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\appid.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\csrsrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidsvc.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidpolicyconverter.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidcertstorecheck.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidapi.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\user.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\setup16.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\instnm.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\adtschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\adtschema.dll
2017-06-14 18:00:28 ----A---- C:\windows\SYSWOW64\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\ieetwcollectorres.dll

======List of files/folders modified in the last 1 month======

2017-07-09 18:33:21 ----D---- C:\windows\System32
2017-07-09 18:33:21 ----D---- C:\windows\inf
2017-07-09 18:33:21 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-07-09 18:32:29 ----D---- C:\windows\Prefetch
2017-07-09 18:31:14 ----D---- C:\windows\Temp
2017-07-09 18:27:33 ----D---- C:\windows\system32\config
2017-07-06 14:21:54 ----D---- C:\ProgramData\IObit
2017-07-06 14:19:35 ----HD---- C:\ProgramData
2017-07-06 13:57:42 ----D---- C:\ProgramData\ProductData
2017-07-05 15:20:33 ----RD---- C:\Program Files
2017-07-05 06:35:29 ----D---- C:\windows\Minidump
2017-07-05 06:35:25 ----D---- C:\Windows
2017-07-04 18:11:28 ----SHD---- C:\System Volume Information
2017-07-04 16:26:03 ----D---- C:\windows\SysWOW64
2017-07-04 16:25:40 ----D---- C:\windows\Tasks
2017-07-04 16:25:40 ----D---- C:\windows\system32\wfp
2017-07-04 16:25:38 ----D---- C:\windows\system32\wbem
2017-07-04 16:24:22 ----D---- C:\windows\system32\Tasks
2017-07-04 16:24:22 ----D---- C:\windows\system32\DriverStore
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\UMDF
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\etc
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers
2017-07-04 16:24:22 ----D---- C:\windows\system32\catroot2
2017-07-04 16:24:21 ----D---- C:\windows\Microsoft.NET
2017-07-04 16:24:13 ----SHD---- C:\windows\Installer
2017-07-04 16:24:03 ----D---- C:\Users\Synologic\AppData\Roaming\ProductData
2017-07-04 16:23:59 ----RD---- C:\Program Files (x86)
2017-07-04 16:23:59 ----D---- C:\Program Files (x86)\Atheros
2017-07-04 16:23:39 ----D---- C:\windows\registration
2017-07-04 16:21:35 ----D---- C:\ProgramData\AVAST Software
2017-07-04 15:31:42 ----D---- C:\windows\Help
2017-06-19 16:16:21 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2017-06-18 16:31:22 ----D---- C:\windows\rescache
2017-06-18 13:51:33 ----SD---- C:\ProgramData\Microsoft
2017-06-18 13:51:24 ----SD---- C:\Users\Synologic\AppData\Roaming\Microsoft
2017-06-16 20:14:05 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2017-06-16 20:14:02 ----D---- C:\windows\system32\Macromed
2017-06-16 20:14:01 ----D---- C:\windows\SYSWOW64\Macromed
2017-06-16 20:04:31 ----D---- C:\windows\winsxs
2017-06-16 20:00:05 ----D---- C:\Program Files\Internet Explorer
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migwiz
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migration
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\cs-CZ
2017-06-16 20:00:04 ----D---- C:\Program Files (x86)\Internet Explorer
2017-06-16 20:00:03 ----D---- C:\windows\SYSWOW64\en-US
2017-06-16 19:59:59 ----D---- C:\windows\system32\migwiz
2017-06-16 19:59:59 ----D---- C:\windows\system32\migration
2017-06-16 19:59:59 ----D---- C:\windows\system32\cs-CZ
2017-06-16 19:59:58 ----D---- C:\windows\system32\en-US
2017-06-16 19:59:51 ----D---- C:\windows\AppPatch
2017-06-16 19:59:50 ----D---- C:\windows\system32\Boot
2017-06-14 21:46:34 ----D---- C:\windows\system32\MRT
2017-06-14 21:42:26 ----AC---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [2017-07-04 198944]
R0 aswblog;aswblog; C:\windows\system32\drivers\aswbloga.sys [2017-07-04 343264]
R0 aswbuniv;aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [2017-07-04 57704]
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2017-07-04 84392]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2017-07-04 361336]
R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-08-07 57952]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-02-18 439320]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2011-08-07 39008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswbidsdriver;aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [2017-07-04 319984]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2017-07-04 41800]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2017-07-04 110352]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2017-07-04 1015848]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2017-07-04 585608]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-08-07 13408]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2017-07-04 146664]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2017-07-04 198768]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-08-07 29792]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-25 8284672]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-25 296960]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2010-11-24 2673664]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT64.sys [2011-02-14 1581184]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-03-26 12262336]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-10-21 76912]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2017-02-26 25816]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-04-08 1430576]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2013-09-18 14112]
R3 vm2uvcflt;Vimicro USB Camera Filter 2; C:\windows\System32\Drivers\vm2uvcflt.sys [2010-09-22 15056]
R3 vm332avs;Lenovo Camera2; C:\windows\System32\Drivers\vm332avs.sys [2010-12-10 234960]
S3 aswHdsKe;aswHdsKe; \??\C:\windows\system32\drivers\aswHdsKe.sys [2017-07-04 104600]
S3 aswHwid;aswHwid; C:\windows\system32\drivers\aswHwid.sys [2017-07-04 46984]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-03-25 12262336]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2017-02-26 136408]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2017-02-26 63704]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-09-30 299520]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-25 203776]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2017-02-26 1080120]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2013-10-08 2099000]
S2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-04 263304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2017-02-26 2631456]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16 272384]
S3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-05-04 7346208]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2017-05-14 116224]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-02-26 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2017-02-26 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-01-19 1464096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2017-02-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-02-18 13336]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2017-02-26 30969208]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#8 Příspěvek od Rudy »

OK. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#9 Příspěvek od synologic »

Zatím stále beze změny.
Antivir stále hlásí tu samou chybu - viz obrázek.
I při spuštění RESTART SERVICE se vůbec nic nestane
(to by vyřešila přeinstalace), ale stále se mi nezobrazují
některý skrytý soubory, což mě trápí mnohém více.
Přílohy
xx.jpg
xx.jpg (18.49 KiB) Zobrazeno 3858 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#10 Příspěvek od Rudy »

Udělejte ještě kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#11 Příspěvek od synologic »

Tak sken dokončen - viz obrázek a přikádám log.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Synologic at 2017-07-11 17:32:18
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 380 GB (88%) free of 432 GB
Total RAM: 4040 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:32:20, on 11.7.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18698)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\trend micro\Synologic.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7300 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:896
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
AvastUI.exe /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"
taskeng.exe {11E0E3E8-F17A-471F-92C4-DB6E04BDBF54}
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Synologic\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Synologic\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=58.0.3029.110 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef68d2968,0x7fef68d2980,0x7fef68d2990
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3780 --on-initialized-event-handle=308 --parent-handle=320 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1148 --disable-d3d11 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,16,18,19,20,23,26,41,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.813.3.2000 --gpu-driver-date=3-24-2011 --gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0106 --gpu-active-vendor-id=0x1002 --gpu-active-device-id=0x68e4 --service-request-channel-token=8C03DAA317A60E1EA570C94562F6026B --mojo-platform-channel-handle=1164 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1148 --primordial-pipe-token=C5AD2863011BE231B627D28ADF6A54E4 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=C5AD2863011BE231B627D28ADF6A54E4 --renderer-client-id=5 --mojo-platform-channel-handle=4060 /prefetch:1
C:\windows\system32\svchost.exe -k imgsvc

"C:\windows\system32\mspaint.exe" "C:\Users\Synologic\Documents\Bez názvu.png"
C:\windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Synologic\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2017-02-26 2471744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-25 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-02 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-25 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-02 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-04 213824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-03-25 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fbset.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filedecrypt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iastorui.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javacpl.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaw.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javaws.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\open energymanagement.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstaler_skipuac.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninstalldisplay.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\veriface.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\youcam.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-07-11 13:03:29 ----A---- C:\windows\system32\drivers\MBAMSwissArmy.sys
2017-07-11 12:55:12 ----A---- C:\windows\system32\drivers\mwac.sys
2017-07-11 12:55:12 ----A---- C:\windows\system32\drivers\mbamchameleon.sys
2017-07-11 12:55:11 ----A---- C:\windows\system32\drivers\mbam.sys
2017-07-09 18:27:00 ----D---- C:\_OTM
2017-07-06 14:03:30 ----D---- C:\AdwCleaner
2017-07-05 15:20:33 ----D---- C:\rsit
2017-07-05 15:20:33 ----D---- C:\Program Files\trend micro
2017-07-04 16:33:57 ----D---- C:\Program Files\Recuva
2017-07-04 15:34:32 ----A---- C:\windows\system32\drivers\aswHdsKe.sys
2017-07-04 15:29:07 ----A---- C:\windows\system32\aswBoot.exe
2017-06-18 18:38:56 ----D---- C:\4ed65882c333fde3716f9b084e141b
2017-06-18 16:43:25 ----D---- C:\Users\Synologic\AppData\Roaming\vlc
2017-06-14 18:00:49 ----A---- C:\windows\SYSWOW64\D3DCompiler_47.dll
2017-06-14 18:00:49 ----A---- C:\windows\system32\D3DCompiler_47.dll
2017-06-14 18:00:48 ----A---- C:\windows\system32\mshtml.dll
2017-06-14 18:00:47 ----A---- C:\windows\SYSWOW64\mshtml.dll
2017-06-14 18:00:46 ----A---- C:\windows\system32\ieframe.dll
2017-06-14 18:00:45 ----A---- C:\windows\SYSWOW64\ieframe.dll
2017-06-14 18:00:44 ----A---- C:\windows\SYSWOW64\jscript9.dll
2017-06-14 18:00:44 ----A---- C:\windows\system32\jscript9.dll
2017-06-14 18:00:43 ----A---- C:\windows\SYSWOW64\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\wininet.dll
2017-06-14 18:00:43 ----A---- C:\windows\system32\ntoskrnl.exe
2017-06-14 18:00:42 ----A---- C:\windows\system32\wuaueng.dll
2017-06-14 18:00:42 ----A---- C:\windows\system32\win32k.sys
2017-06-14 18:00:41 ----A---- C:\windows\system32\tquery.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\shell32.dll
2017-06-14 18:00:41 ----A---- C:\windows\system32\mssrch.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\shell32.dll
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2017-06-14 18:00:40 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\tquery.dll
2017-06-14 18:00:39 ----A---- C:\windows\SYSWOW64\mssrch.dll
2017-06-14 18:00:39 ----A---- C:\windows\system32\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\SYSWOW64\usp10.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\win32spl.dll
2017-06-14 18:00:38 ----A---- C:\windows\system32\ExplorerFrame.dll
2017-06-14 18:00:38 ----A---- C:\windows\HelpPane.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\SYSWOW64\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchProtocolHost.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\SearchIndexer.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssvp.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssphtb.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\mssph.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\MigAutoPlay.exe
2017-06-14 18:00:37 ----A---- C:\windows\system32\localspl.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\gdi32.dll
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\tdx.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\drivers\mountmgr.sys
2017-06-14 18:00:37 ----A---- C:\windows\system32\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2017-06-14 18:00:36 ----A---- C:\windows\SYSWOW64\atmfd.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\jscript.dll
2017-06-14 18:00:36 ----A---- C:\windows\system32\iedkcs32.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchProtocolHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchIndexer.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssvp.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssphtb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssph.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\SYSWOW64\certcli.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\urlmon.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\SearchFilterHost.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\rundll32.exe
2017-06-14 18:00:35 ----A---- C:\windows\system32\ntdll.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssprxy.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mssitlb.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msshooks.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msscntrs.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\mshtmlmedia.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\msfeeds.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\iertutil.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\DWrite.dll
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\drivers\ksecdd.sys
2017-06-14 18:00:35 ----A---- C:\windows\system32\certcli.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\urlmon.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\jscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\SYSWOW64\iertutil.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\webcheck.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\vbscript.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\rpcrt4.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\jsproxy.dll
2017-06-14 18:00:34 ----A---- C:\windows\system32\ieui.dll
2017-06-14 18:00:33 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wuwebv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\wucltux.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\occache.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\mshtmled.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\lsasrv.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieUnatt.exe
2017-06-14 18:00:33 ----A---- C:\windows\system32\ieapfltr.dll
2017-06-14 18:00:33 ----A---- C:\windows\system32\FntCache.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2017-06-14 18:00:32 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\wuapi.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\smss.exe
2017-06-14 18:00:32 ----A---- C:\windows\system32\msrating.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\kerberos.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\jscript9diag.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtrans.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\dxtmsft.dll
2017-06-14 18:00:32 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2017-06-14 18:00:32 ----A---- C:\windows\system32\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\wuapi.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\webcheck.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\occache.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\msrating.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\kerberos.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieui.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2017-06-14 18:00:31 ----A---- C:\windows\SYSWOW64\advapi32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wudriver.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64win.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wow64.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\winsrv.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\wdigest.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\TSpkg.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\sspicli.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\srcore.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\schannel.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\rpchttp.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ncrypt.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\msv1_0.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\MshtmlDac.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\KernelBase.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\kernel32.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\inseng.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iesetup.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\iernonce.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwproxystub.dll
2017-06-14 18:00:31 ----A---- C:\windows\system32\ieetwcollector.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\ie4uinit.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2017-06-14 18:00:31 ----A---- C:\windows\system32\conhost.exe
2017-06-14 18:00:31 ----A---- C:\windows\system32\bcrypt.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-14 18:00:30 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wudriver.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wow32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\wdigest.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\schannel.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\kernel32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iesetup.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\iernonce.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\bcrypt.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\SYSWOW64\appidapi.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups2.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wups.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuauclt.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wuapp.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\wow64cpu.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\WinSetupUI.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\sspisrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\srclient.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\setbcdlocale.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\secur32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\rstrui.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\ntvdm64.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\msmmsp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\lsass.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\lpk.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\fontsub.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\drivers\appid.sys
2017-06-14 18:00:30 ----A---- C:\windows\system32\dciman32.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\csrsrv.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\cryptbase.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\credssp.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\auditpol.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\atmlib.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidsvc.dll
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidpolicyconverter.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidcertstorecheck.exe
2017-06-14 18:00:30 ----A---- C:\windows\system32\appidapi.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-14 18:00:29 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\user.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\setup16.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\instnm.exe
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\SYSWOW64\adtschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\msaudite.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\apisetschema.dll
2017-06-14 18:00:29 ----A---- C:\windows\system32\adtschema.dll
2017-06-14 18:00:28 ----A---- C:\windows\SYSWOW64\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\msobjs.dll
2017-06-14 18:00:28 ----A---- C:\windows\system32\ieetwcollectorres.dll

======List of files/folders modified in the last 1 month======

2017-07-11 17:32:20 ----D---- C:\windows\Prefetch
2017-07-11 16:49:02 ----D---- C:\windows\Temp
2017-07-11 16:49:01 ----SHD---- C:\windows\Installer
2017-07-11 16:46:59 ----D---- C:\windows\SysWOW64
2017-07-11 13:10:56 ----D---- C:\windows\system32\config
2017-07-11 13:03:29 ----D---- C:\windows\system32\drivers
2017-07-11 13:01:06 ----D---- C:\windows\System32
2017-07-11 13:01:06 ----D---- C:\windows\inf
2017-07-11 13:01:06 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-07-11 12:56:33 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-07-11 12:54:38 ----RD---- C:\Program Files
2017-07-11 12:54:37 ----D---- C:\ProgramData\Malwarebytes
2017-07-06 14:21:54 ----D---- C:\ProgramData\IObit
2017-07-06 14:19:35 ----HD---- C:\ProgramData
2017-07-06 13:57:42 ----D---- C:\ProgramData\ProductData
2017-07-05 06:35:29 ----D---- C:\windows\Minidump
2017-07-05 06:35:25 ----D---- C:\Windows
2017-07-04 18:11:28 ----SHD---- C:\System Volume Information
2017-07-04 16:25:40 ----D---- C:\windows\Tasks
2017-07-04 16:25:40 ----D---- C:\windows\system32\wfp
2017-07-04 16:25:38 ----D---- C:\windows\system32\wbem
2017-07-04 16:24:22 ----D---- C:\windows\system32\Tasks
2017-07-04 16:24:22 ----D---- C:\windows\system32\DriverStore
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\UMDF
2017-07-04 16:24:22 ----D---- C:\windows\system32\drivers\etc
2017-07-04 16:24:22 ----D---- C:\windows\system32\catroot2
2017-07-04 16:24:21 ----D---- C:\windows\Microsoft.NET
2017-07-04 16:24:03 ----D---- C:\Users\Synologic\AppData\Roaming\ProductData
2017-07-04 16:23:59 ----RD---- C:\Program Files (x86)
2017-07-04 16:23:59 ----D---- C:\Program Files (x86)\Atheros
2017-07-04 16:23:39 ----D---- C:\windows\registration
2017-07-04 16:21:35 ----D---- C:\ProgramData\AVAST Software
2017-07-04 15:31:42 ----D---- C:\windows\Help
2017-06-19 16:16:21 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2017-06-18 16:31:22 ----D---- C:\windows\rescache
2017-06-18 13:51:33 ----SD---- C:\ProgramData\Microsoft
2017-06-18 13:51:24 ----SD---- C:\Users\Synologic\AppData\Roaming\Microsoft
2017-06-16 20:14:05 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2017-06-16 20:14:02 ----D---- C:\windows\system32\Macromed
2017-06-16 20:14:01 ----D---- C:\windows\SYSWOW64\Macromed
2017-06-16 20:04:31 ----D---- C:\windows\winsxs
2017-06-16 20:00:05 ----D---- C:\Program Files\Internet Explorer
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migwiz
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\migration
2017-06-16 20:00:04 ----D---- C:\windows\SYSWOW64\cs-CZ
2017-06-16 20:00:04 ----D---- C:\Program Files (x86)\Internet Explorer
2017-06-16 20:00:03 ----D---- C:\windows\SYSWOW64\en-US
2017-06-16 19:59:59 ----D---- C:\windows\system32\migwiz
2017-06-16 19:59:59 ----D---- C:\windows\system32\migration
2017-06-16 19:59:59 ----D---- C:\windows\system32\cs-CZ
2017-06-16 19:59:58 ----D---- C:\windows\system32\en-US
2017-06-16 19:59:51 ----D---- C:\windows\AppPatch
2017-06-16 19:59:50 ----D---- C:\windows\system32\Boot
2017-06-14 21:46:34 ----D---- C:\windows\system32\MRT
2017-06-14 21:42:26 ----AC---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [2017-07-04 198944]
R0 aswblog;aswblog; C:\windows\system32\drivers\aswbloga.sys [2017-07-04 343264]
R0 aswbuniv;aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [2017-07-04 57704]
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2017-07-04 84392]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2017-07-04 361336]
R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-08-07 57952]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-02-18 439320]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2011-08-07 39008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswbidsdriver;aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [2017-07-04 319984]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2017-07-04 41800]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2017-07-04 110352]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2017-07-04 1015848]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2017-07-04 585608]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-08-07 13408]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2017-07-04 146664]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2017-07-04 198768]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-08-07 29792]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-25 8284672]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-25 296960]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2010-11-24 2673664]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT64.sys [2011-02-14 1581184]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-03-26 12262336]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-10-21 76912]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2017-07-11 192216]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-04-08 1430576]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2013-09-18 14112]
R3 vm2uvcflt;Vimicro USB Camera Filter 2; C:\windows\System32\Drivers\vm2uvcflt.sys [2010-09-22 15056]
R3 vm332avs;Lenovo Camera2; C:\windows\System32\Drivers\vm332avs.sys [2010-12-10 234960]
S3 aswHdsKe;aswHdsKe; \??\C:\windows\system32\drivers\aswHdsKe.sys [2017-07-04 104600]
S3 aswHwid;aswHwid; C:\windows\system32\drivers\aswHwid.sys [2017-07-04 46984]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-03-25 12262336]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-09-30 299520]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-25 203776]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2013-10-08 2099000]
S2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-04 263304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2017-02-26 2631456]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16 272384]
S3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-05-04 7346208]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-25 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2017-05-14 116224]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-02-26 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2017-02-26 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-01-19 1464096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2017-02-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-02-18 13336]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2017-02-26 30969208]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

-----------------EOF-----------------
Přílohy
Bez názvu.png
Bez názvu.png (89.04 KiB) Zobrazeno 3826 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#12 Příspěvek od Rudy »

Smažte všechny nálezy. Pokud v souvislosti s MBAM si říkám o log, mám na mysli log MBAM.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#13 Příspěvek od synologic »

Omlouvám se za nepochopení.
Po odstranění položek z MBAM jsem musel restartovat počítač,
tak se chci zeptat. Kde teď ten log z MBAM najdu?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#14 Příspěvek od Rudy »

Měl by sám vyskočit po restartu. Jinak návod zde: https://forum.viry.cz/viewtopic.php?f=29&t=144868 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

synologic
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 28 říj 2008 09:14

Re: Kontrola logu

#15 Příspěvek od synologic »

Po restartu se nic nezobrazilo.
Jediný, co se mi podařilo vydolovat je s příponou XML.
Jen netuším, jestli to k něčemu bude.

<?xml version="1.0" encoding="UTF-8"?>

-<logs>

<record message="IsLicensed" last_modified_tag="ae8645b1-6cc0-4ed2-8ec7-705bb90acd57" code="13" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Error" source="Protection" datetime="2017-07-11T12:55:19.622502+02:00" LoggingEventType="4" severity="debug"/>

<record last_modified_tag="0a6d0d4a-697a-4472-b4f2-a488c837b9c1" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-07-11T12:55:19.911518+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopping"/>

<record last_modified_tag="45e3a0b7-17df-4167-bbcb-b48276838abf" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-07-11T12:55:19.917519+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopped"/>

<record last_modified_tag="d61c788d-d2d9-4336-b930-a23c5791b6d3" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T13:04:03.610994+02:00" LoggingEventType="1" severity="debug" toVersion="2017.7.7.1" name="Remediation Database" fromVersion="2016.2.12.1"/>

<record last_modified_tag="519608e8-d317-4dbc-be63-e16e0b018811" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T13:04:03.720194+02:00" LoggingEventType="1" severity="debug" toVersion="2017.5.27.1" name="Rootkit Database" fromVersion="2016.2.8.1"/>

<record last_modified_tag="c9b61a03-b67a-4676-8fc7-f79631891356" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T13:04:03.829394+02:00" LoggingEventType="1" severity="debug" toVersion="2017.7.11.1" name="IP Database" fromVersion="2016.2.8.1"/>

<record last_modified_tag="c66f29ff-1587-4f0e-9c01-f67886fd63bf" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T13:04:07.573401+02:00" LoggingEventType="1" severity="debug" toVersion="2017.7.11.1" name="Domain Database" fromVersion="2016.2.16.8"/>

<record last_modified_tag="92d9f242-df0c-4a9f-af7d-11fc1dd22e40" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T13:04:09.866605+02:00" LoggingEventType="1" severity="debug" toVersion="2017.7.11.4" name="Malware Database" fromVersion="2016.2.16.6"/>

<record last_modified_tag="3c63c5a6-07b0-4980-97ae-c8a3417f8fb6" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-07-11T13:04:09.975805+02:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Starting"/>

<record last_modified_tag="9c91deed-cc5b-4f0e-b192-786138d76c6e" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-07-11T13:04:17.245418+02:00" LoggingEventType="2" severity="debug" subtype="Refresh" result="Success"/>

<record last_modified_tag="99a9e662-7dce-4da8-9546-223a51022963" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-07-11T13:33:39.482807+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopping"/>

<record last_modified_tag="d57fc5bc-b30f-4e67-b524-e3e2eaf79596" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Protection" source="Protection" datetime="2017-07-11T13:33:40.153608+02:00" LoggingEventType="2" severity="debug" subtype="Malware Protection" result="Stopped"/>

<record last_modified_tag="28027e06-c52c-43cb-a0e6-c0ee12d742ca" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-07-11T17:53:20.281008+02:00" LoggingEventType="6" severity="debug" scanresult="completed" nonmalwaredetections="5" malwaredetections="0" duration="14484" starttime="2017-07-11T13:04:51+02:00" scantype="custom"/>

<record last_modified_tag="0b0ccae9-a7f5-4a3c-a85c-3b3ff13af5d9" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T18:03:02.115272+02:00" LoggingEventType="1" severity="debug" toVersion="2017.7.11.6" name="Malware Database" fromVersion="2017.7.11.4"/>

<record last_modified_tag="5718fbc6-5daa-4c09-96cb-66416c97904b" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Update" source="Manual" datetime="2017-07-11T18:03:02.239280+02:00" LoggingEventType="1" severity="debug" toVersion="2017.7.11.6" name="Domain Database" fromVersion="2017.7.11.1"/>

<record last_modified_tag="5629a699-68e2-4ccd-9022-eb9445c80be8" systemname="PC-SYNOLOGIC" username="SYSTEM" type="Scan" source="Manual" datetime="2017-07-11T18:07:59.460627+02:00" LoggingEventType="6" severity="debug" scanresult="canceled" nonmalwaredetections="0" malwaredetections="0" duration="296" starttime="2017-07-11T18:03:02+02:00" scantype="threat"/>

</logs>

Odpovědět