Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

CMD.exe samo vykonává příkazy atd.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

CMD.exe samo vykonává příkazy atd.

#1 Příspěvek od detox »

Dobrý den,

dnes přes den se PC sám zrestartoval po vždy po zadání hesla někam (seznam, banka) atd. Vyskočilo černé okno CMD.exe, něco se spustilo a PC se restartoval.
Celkově zpomalený internet a práce PC.
Děkuji předem za pomoc :worship:

Logfile of random's system information tool 1.16 (written by random/random)
Run by User at 2017-07-24 17:38:38
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 60 GB (47%) free of 128 GB
Total RAM: 3318 MB (49% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:38:51, on 24.7.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18739)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Nuance\PaperPort\pptd40nt.exe
C:\Program Files\Browny02\Brother\BrStMonW.exe
C:\Program Files\ControlCenter4\BrCtrlCntr.exe
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\AVG\Antivirus\AVGUI.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\ControlCenter4\BrCcUxSys.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_20_0_0_270_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskhost.exe
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WC4DYMP5\RSIT.exe
C:\Program Files\trend micro\User_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [AVGUI.exe] "C:\Program Files\AVG\Antivirus\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [Malwarebytes TrayApp] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil32_20_0_0_270_ActiveX.exe -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AVG Antivirus - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\AVGSvc.exe
O23 - Service: AVG Firewall Service (AVG Firewall) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\afwServ.exe
O23 - Service: avgbIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\aswidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 6804 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d14c9cf9e165dd.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Antivirus Emergency Update - C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
C:\Windows\system32\tasks\AVG EUpdate Task - avgsetupx.exe /eu
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore1d14c9cf9e165dd - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore1d15d9c74904d9 - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA1d14c9cfac7ce52 - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Google Chrome=========

C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Vyhledávání Google 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension ilfoopambfaclfjmpiaijnccgcmbeigi 1 FormApps Extension 2.5.0.27
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.3
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5917.424.0.7
Homepage:
default_search_provider.search_url:
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-02 193136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-02 193136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-11 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-11 150552]
"IndexSearch"=C:\Program Files\Nuance\PaperPort\IndexSearch.exe [2010-03-09 46368]
"PaperPort PTD"=C:\Program Files\Nuance\PaperPort\pptd40nt.exe [2010-03-09 29984]
"PPort12reminder"=C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [2010-02-09 328992]
"ControlCenter4"=C:\Program Files\ControlCenter4\BrCcBoot.exe [2012-09-06 143360]
"BrStsMon00"=C:\Program Files\Browny02\Brother\BrStMonW.exe [2012-06-06 3076096]
"AvgUi"=C:\Program Files\AVG\Framework\Common\avguirnx.exe [2017-07-03 220288]
"AVGUI.exe"=C:\Program Files\AVG\Antivirus\AvLaunch.exe [2017-07-23 263232]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2017-05-09 3146704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-12-08 6602152]
"ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2009-05-05 222496]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\system32\Macromed\Flash\FlashUtil32_20_0_0_270_ActiveX.exe [2016-01-11 1163968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2015-03-25 31682144]

C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2017-07-24 17:38:38 ----D---- C:\rsit
2017-07-24 17:38:38 ----D---- C:\Program Files\trend micro
2017-07-24 17:10:37 ----A---- C:\Windows\system32\drivers\MBAMChameleon.sys
2017-07-24 17:10:24 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-07-24 17:10:24 ----A---- C:\Windows\system32\drivers\farflt.sys
2017-07-24 17:10:17 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-07-24 17:10:08 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-07-24 17:10:01 ----A---- C:\Windows\system32\drivers\mbae.sys
2017-07-24 17:09:56 ----D---- C:\ProgramData\Malwarebytes
2017-07-24 17:09:56 ----D---- C:\Program Files\Malwarebytes
2017-07-24 16:47:59 ----D---- C:\AdwCleaner
2017-07-24 07:50:21 ----A---- C:\Windows\system32\drivers\avgNetSec.sys
2017-07-24 07:50:18 ----A---- C:\Windows\system32\avgBoot.exe
2017-07-24 07:50:13 ----A---- C:\Windows\system32\drivers\avgNetNd6.sys
2017-07-12 11:20:46 ----A---- C:\Windows\system32\mshtml.dll
2017-07-12 11:20:45 ----A---- C:\Windows\system32\ieframe.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\win32k.sys
2017-07-12 11:20:44 ----A---- C:\Windows\system32\vbscript.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\urlmon.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\tquery.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\Query.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\kerberos.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\jscript9.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\wvc.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\Wldap32.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\wininet.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\wdc.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\perfmon.exe
2017-07-12 11:20:43 ----A---- C:\Windows\system32\pdhui.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-07-12 11:20:43 ----A---- C:\Windows\system32\msrating.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\msinfo32.exe
2017-07-12 11:20:43 ----A---- C:\Windows\system32\iedkcs32.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\dxtmsft.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\netio.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\http.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\clfs.sys
2017-07-12 11:20:42 ----A---- C:\Windows\system32\webcheck.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\resmon.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\occache.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\mshtmled.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\msfeeds.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\jsproxy.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\jscript9diag.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\jscript.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\inseng.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieUnatt.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieui.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\iesetup.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\iertutil.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\iernonce.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieapfltr.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ie4uinit.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\dxtrans.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\wdigest.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\tzres.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\TSpkg.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\sspisrv.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\sspicli.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\schannel.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\secur32.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\rpchttp.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\rpcrt4.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\ncrypt.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msv1_0.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssvp.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssrch.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssprxy.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssphtb.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssph.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssitlb.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msshooks.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msscntrs.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msobjs.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msaudite.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\lsass.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\lsasrv.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-07-12 11:20:41 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-07-12 11:20:41 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-07-12 11:20:41 ----A---- C:\Windows\system32\cryptbase.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\credssp.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\cdd.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\bcrypt.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\auditpol.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\adtschema.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\invagent.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\generaltel.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\devinv.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-07-12 11:19:34 ----A---- C:\Windows\system32\centel.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\appraiser.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\aitstatic.exe
2017-07-12 11:19:34 ----A---- C:\Windows\system32\aepic.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\aeinv.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\acmigration.dll
2017-06-14 07:46:56 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2017-06-14 07:46:54 ----A---- C:\Windows\system32\wuaueng.dll
2017-06-14 07:46:54 ----A---- C:\Windows\system32\shell32.dll
2017-06-14 07:46:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-06-14 07:46:54 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-06-14 07:46:53 ----A---- C:\Windows\system32\win32spl.dll
2017-06-14 07:46:53 ----A---- C:\Windows\system32\usp10.dll
2017-06-14 07:46:53 ----A---- C:\Windows\system32\gdi32.dll
2017-06-14 07:46:53 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2017-06-14 07:46:53 ----A---- C:\Windows\HelpPane.exe
2017-06-14 07:46:51 ----A---- C:\Windows\system32\rundll32.exe
2017-06-14 07:46:51 ----A---- C:\Windows\system32\PrintBrmUi.exe
2017-06-14 07:46:51 ----A---- C:\Windows\system32\ntdll.dll
2017-06-14 07:46:51 ----A---- C:\Windows\system32\MigAutoPlay.exe
2017-06-14 07:46:51 ----A---- C:\Windows\system32\localspl.dll
2017-06-14 07:46:51 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-06-14 07:46:51 ----A---- C:\Windows\system32\atmfd.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\wuwebv.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\wucltux.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\wuapi.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\srcore.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\smss.exe
2017-06-14 07:46:50 ----A---- C:\Windows\system32\FntCache.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\DWrite.dll
2017-06-14 07:46:50 ----A---- C:\Windows\system32\advapi32.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\wups2.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\wups.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\wudriver.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\wuauclt.exe
2017-06-14 07:46:49 ----A---- C:\Windows\system32\wuapp.exe
2017-06-14 07:46:49 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\WinSetupUI.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\srclient.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\rstrui.exe
2017-06-14 07:46:49 ----A---- C:\Windows\system32\msmmsp.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\lpk.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\fontsub.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\drivers\appid.sys
2017-06-14 07:46:49 ----A---- C:\Windows\system32\dciman32.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\csrsrv.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\atmlib.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\appidsvc.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-06-14 07:46:49 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-06-14 07:46:49 ----A---- C:\Windows\system32\appidapi.dll
2017-06-14 07:46:49 ----A---- C:\Windows\system32\apisetschema.dll
2017-05-10 08:07:27 ----A---- C:\Windows\system32\rpcss.dll
2017-05-10 08:07:27 ----A---- C:\Windows\system32\pla.dll
2017-05-10 08:07:27 ----A---- C:\Windows\system32\pdh.dll
2017-05-10 08:07:27 ----A---- C:\Windows\system32\oleaut32.dll
2017-05-10 08:07:27 ----A---- C:\Windows\system32\ole32.dll
2017-05-10 08:07:27 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-05-10 08:07:27 ----A---- C:\Windows\system32\drivers\srv.sys
2017-05-10 08:07:27 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-05-10 08:07:27 ----A---- C:\Windows\system32\drivers\exfat.sys
2017-05-10 08:07:27 ----A---- C:\Windows\system32\crypt32.dll
2017-05-10 08:07:25 ----A---- C:\Windows\system32\plasrv.exe
2017-05-10 08:07:25 ----A---- C:\Windows\system32\oleres.dll
2017-05-10 08:07:25 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-05-10 08:07:25 ----A---- C:\Windows\system32\drivers\afd.sys
2017-05-10 08:07:25 ----A---- C:\Windows\system32\comcat.dll
2017-05-10 08:07:24 ----A---- C:\Windows\system32\wintrust.dll
2017-05-10 08:07:24 ----A---- C:\Windows\system32\winsrv.dll
2017-05-10 08:07:24 ----A---- C:\Windows\system32\KernelBase.dll
2017-05-10 08:07:24 ----A---- C:\Windows\system32\cryptsvc.dll
2017-05-10 08:07:24 ----A---- C:\Windows\system32\cryptnet.dll
2017-05-10 08:07:24 ----A---- C:\Windows\system32\conhost.exe
2017-05-10 08:07:24 ----A---- C:\Windows\system32\cdosys.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 08:07:23 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-10 08:07:23 ----A---- C:\Windows\system32\kernel32.dll

======List of files/folders modified in the last 3 months======

2017-07-24 17:38:38 ----RD---- C:\Program Files
2017-07-24 17:37:46 ----D---- C:\Windows\Temp
2017-07-24 17:35:53 ----D---- C:\Windows\system32\config
2017-07-24 17:28:58 ----D---- C:\Windows\system32\drivers
2017-07-24 17:27:28 ----D---- C:\Windows\System32
2017-07-24 17:27:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-07-24 17:27:27 ----D---- C:\Windows\inf
2017-07-24 17:09:56 ----HD---- C:\ProgramData
2017-07-24 15:38:41 ----SHD---- C:\System Volume Information
2017-07-24 15:14:28 ----D---- C:\STEREO26
2017-07-24 08:11:34 ----D---- C:\UCTO2017
2017-07-24 07:50:35 ----D---- C:\Windows\system32\DriverStore
2017-07-24 07:50:22 ----D---- C:\Windows\system32\Tasks
2017-07-21 09:49:09 ----D---- C:\Windows\system32\FxsTmp
2017-07-17 11:30:40 ----SHD---- C:\Windows\Installer
2017-07-14 14:14:29 ----D---- C:\Windows\system32\NDF
2017-07-14 12:21:31 ----D---- C:\Windows\rescache
2017-07-12 15:43:31 ----D---- C:\Windows\winsxs
2017-07-12 15:42:16 ----D---- C:\Program Files\Internet Explorer
2017-07-12 15:42:15 ----D---- C:\Windows\system32\migration
2017-07-12 15:42:15 ----D---- C:\Windows\system32\en-US
2017-07-12 15:42:15 ----D---- C:\Windows\system32\cs-CZ
2017-07-12 15:42:15 ----D---- C:\Windows\system32\appraiser
2017-07-12 15:42:15 ----D---- C:\Windows\AppPatch
2017-07-12 13:16:26 ----D---- C:\Windows\system32\MRT
2017-07-12 13:14:30 ----AC---- C:\Windows\system32\MRT.exe
2017-07-12 13:14:17 ----D---- C:\ProgramData\Microsoft Help
2017-07-12 11:18:59 ----D---- C:\Windows\system32\catroot2
2017-06-24 21:08:53 ----D---- C:\Program Files\HappyFoto-Designer
2017-06-15 18:54:35 ----D---- C:\Windows\system32\migwiz
2017-06-15 18:54:34 ----D---- C:\Windows
2017-06-14 14:27:29 ----D---- C:\Program Files\Microsoft Silverlight
2017-06-12 12:06:45 ----D---- C:\Windows\system32\wdi
2017-05-12 09:54:21 ----D---- C:\Windows\Microsoft.NET
2017-05-12 09:51:28 ----RSD---- C:\Windows\assembly
2017-05-12 07:20:37 ----D---- C:\Windows\PolicyDefinitions
2017-04-26 16:03:16 ----D---- C:\Users\User\AppData\Roaming\Google

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 avgbidsh;avgbidsh; C:\Windows\system32\drivers\avgbidshx.sys [2017-07-23 151024]
R0 avgblog;avgblog; C:\Windows\system32\drivers\avgblogx.sys [2017-07-23 270344]
R0 avgbuniv;avgbuniv; C:\Windows\system32\drivers\avgbunivx.sys [2017-07-23 43992]
R0 avgRvrt;avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [2017-07-23 63280]
R0 avgVmm;avgVmm; C:\Windows\system32\drivers\avgVmm.sys [2017-07-23 288728]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2015-09-18 173400]
R1 avgbdisk;avgbdisk; C:\Windows\system32\drivers\avgbdiskx.sys [2017-07-23 135872]
R1 avgbidsdriver;avgbidsdriver; C:\Windows\system32\drivers\avgbidsdriverx.sys [2017-07-23 260616]
R1 avgNetSec;avgNetSec; C:\Windows\system32\drivers\avgNetSec.sys [2017-07-24 399976]
R1 avgRdr;avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [2017-07-23 91976]
R1 avgSnx;avgSnx; C:\Windows\system32\drivers\avgSnx.sys [2017-07-23 766728]
R1 avgSP;avgSP; C:\Windows\system32\drivers\avgSP.sys [2017-07-23 489416]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2015-09-18 389632]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Windows\system32\drivers\mbae.sys [2017-07-24 59936]
R2 avgMonFlt;avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [2017-07-23 116344]
R2 avgStm;avgStm; C:\Windows\system32\drivers\avgStm.sys [2017-07-23 140136]
R2 MBAMChameleon;MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [2017-07-24 162240]
R3 avgNetNd6;AVG Firewall NDIS6 Helper; C:\Windows\system32\DRIVERS\avgNetNd6.sys [2017-07-24 28408]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-11 4805120]
R3 MBAMFarflt;MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [2017-07-24 85400]
R3 MBAMProtection;MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [2017-07-24 40352]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-07-24 221600]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [2017-07-24 65824]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2014-12-10 584920]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2015-09-18 36352]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 avgHwid;avgHwid; C:\Windows\system32\drivers\avgHwid.sys [2017-07-23 35264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 MHIKEY10;MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10.sys [2010-10-01 52096]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2015-09-18 14848]
S3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2015-09-18 24064]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2015-09-18 27136]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S4 RsFx0153;RsFx0153 Driver; C:\Windows\system32\DRIVERS\RsFx0153.sys [2015-03-30 250152]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AVG Antivirus;AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [2017-07-23 264432]
R2 AVG Firewall;AVG Firewall Service; C:\Program Files\AVG\Antivirus\afwServ.exe [2017-07-24 312712]
R2 avgsvc;AVG Service; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [2017-07-03 1189720]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\cscsvc.dll
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-05-09 3398608]
R2 MSSQL$DUEL;SQL Server (DUEL); c:\Program Files\Microsoft SQL Server\MSSQL10_50.DUEL\MSSQL\Binn\sqlservr.exe [2015-03-30 43130032]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-09 144672]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2015-03-30 278704]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 97632]
R2 TeamViewer;TeamViewer 11; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2015-12-14 6889232]
R3 avgbIDSAgent;avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [2017-07-23 5866488]
R3 BrYNSvc;BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [2012-06-05 266240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-26 105096]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-11 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 AppMgmt;@appmgmts.dll,-3250; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll"=%SystemRoot%\System32\appmgmts.dll
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-11 107848]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2016-01-11 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-06-29 104960]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; %SystemRoot%\System32\svchost.exe -k PeerDist;"ServiceDll"=%SystemRoot%\system32\peerdistsvc.dll
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\system32\storsvc.dll
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\umrdp.dll
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-03-26 45688]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 SQLAgent$DUEL;SQL Server Agent (DUEL); c:\Program Files\Microsoft SQL Server\MSSQL10_50.DUEL\MSSQL\Binn\SQLAGENT.EXE [2015-03-30 381104]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: CMD.exe samo vykonává příkazy atd.

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: CMD.exe samo vykonává příkazy atd.

#3 Příspěvek od detox »

Zapomněl jsem dodat ze jsem to jiz prohnal mbam a adw.. mbam nic a adw nasel a smazal 1x PopUpToolbar ci tak neco..
Mam dat adw znovu pro log?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: CMD.exe samo vykonává příkazy atd.

#4 Příspěvek od Rudy »

Není třeba. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Google\Google Toolbar
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d14c9cf9e165dd.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore1d14c9cf9e165dd
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore1d15d9c74904d9
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA1d14c9cfac7ce52

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]/64

:comnmands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: CMD.exe samo vykonává příkazy atd.

#5 Příspěvek od detox »

Logfile of random's system information tool 1.16 (written by random/random)
Run by User at 2017-07-24 21:22:49
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 60 GB (47%) free of 128 GB
Total RAM: 3318 MB (36% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:22:52, on 24.7.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18739)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Nuance\PaperPort\pptd40nt.exe
C:\Program Files\Browny02\Brother\BrStMonW.exe
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\ControlCenter4\BrCtrlCntr.exe
C:\Program Files\AVG\Antivirus\AVGUI.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\ControlCenter4\BrCcUxSys.exe
C:\Program Files\TeamViewer\TeamViewer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q6L2XZU6\RSIT.exe
C:\Program Files\trend micro\User_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [AVGUI.exe] "C:\Program Files\AVG\Antivirus\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [Malwarebytes TrayApp] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AVG Antivirus - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\AVGSvc.exe
O23 - Service: AVG Firewall Service (AVG Firewall) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\afwServ.exe
O23 - Service: avgbIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\aswidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 6501 bytes

======Scheduled tasks folder======

C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Antivirus Emergency Update - C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
C:\Windows\system32\tasks\AVG EUpdate Task - avgsetupx.exe /eu
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Google Chrome=========

C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Vyhledávání Google 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension ilfoopambfaclfjmpiaijnccgcmbeigi 1 FormApps Extension 2.5.0.27
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.3
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5917.424.0.7
Homepage:
default_search_provider.search_url:
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-11 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-11 150552]
"IndexSearch"=C:\Program Files\Nuance\PaperPort\IndexSearch.exe [2010-03-09 46368]
"PaperPort PTD"=C:\Program Files\Nuance\PaperPort\pptd40nt.exe [2010-03-09 29984]
"PPort12reminder"=C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe [2010-02-09 328992]
"ControlCenter4"=C:\Program Files\ControlCenter4\BrCcBoot.exe [2012-09-06 143360]
"BrStsMon00"=C:\Program Files\Browny02\Brother\BrStMonW.exe [2012-06-06 3076096]
"AvgUi"=C:\Program Files\AVG\Framework\Common\avguirnx.exe [2017-07-03 220288]
"AVGUI.exe"=C:\Program Files\AVG\Antivirus\AvLaunch.exe [2017-07-23 263232]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2017-05-09 3146704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-12-08 6602152]
"ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2009-05-05 222496]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2015-03-25 31682144]

C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-07-24 21:06:07 ----D---- C:\_OTM
2017-07-24 17:38:38 ----D---- C:\rsit
2017-07-24 17:38:38 ----D---- C:\Program Files\trend micro
2017-07-24 17:10:37 ----A---- C:\Windows\system32\drivers\MBAMChameleon.sys
2017-07-24 17:10:24 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-07-24 17:10:24 ----A---- C:\Windows\system32\drivers\farflt.sys
2017-07-24 17:10:17 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-07-24 17:10:08 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-07-24 17:10:01 ----A---- C:\Windows\system32\drivers\mbae.sys
2017-07-24 17:09:56 ----D---- C:\ProgramData\Malwarebytes
2017-07-24 17:09:56 ----D---- C:\Program Files\Malwarebytes
2017-07-24 16:47:59 ----D---- C:\AdwCleaner
2017-07-24 07:50:21 ----A---- C:\Windows\system32\drivers\avgNetSec.sys
2017-07-24 07:50:18 ----A---- C:\Windows\system32\avgBoot.exe
2017-07-24 07:50:13 ----A---- C:\Windows\system32\drivers\avgNetNd6.sys
2017-07-12 11:20:46 ----A---- C:\Windows\system32\mshtml.dll
2017-07-12 11:20:45 ----A---- C:\Windows\system32\ieframe.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\win32k.sys
2017-07-12 11:20:44 ----A---- C:\Windows\system32\vbscript.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\urlmon.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\tquery.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\Query.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\kerberos.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\jscript9.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-07-12 11:20:44 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\wvc.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\Wldap32.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\wininet.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\wdc.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\perfmon.exe
2017-07-12 11:20:43 ----A---- C:\Windows\system32\pdhui.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-07-12 11:20:43 ----A---- C:\Windows\system32\msrating.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\msinfo32.exe
2017-07-12 11:20:43 ----A---- C:\Windows\system32\iedkcs32.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\dxtmsft.dll
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\netio.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\http.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-07-12 11:20:43 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-07-12 11:20:43 ----A---- C:\Windows\system32\clfs.sys
2017-07-12 11:20:42 ----A---- C:\Windows\system32\webcheck.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\resmon.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\occache.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\mshtmled.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\msfeeds.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\jsproxy.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\jscript9diag.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\jscript.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\inseng.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieUnatt.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieui.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\iesetup.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\iertutil.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\iernonce.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ieapfltr.dll
2017-07-12 11:20:42 ----A---- C:\Windows\system32\ie4uinit.exe
2017-07-12 11:20:42 ----A---- C:\Windows\system32\dxtrans.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\wdigest.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\tzres.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\TSpkg.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\sspisrv.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\sspicli.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\schannel.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\secur32.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\rpchttp.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\rpcrt4.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\ncrypt.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msv1_0.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssvp.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssrch.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssprxy.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssphtb.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssph.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\mssitlb.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msshooks.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msscntrs.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msobjs.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\msaudite.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\lsass.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\lsasrv.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-07-12 11:20:41 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-07-12 11:20:41 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-07-12 11:20:41 ----A---- C:\Windows\system32\cryptbase.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\credssp.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\cdd.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\bcrypt.dll
2017-07-12 11:20:41 ----A---- C:\Windows\system32\auditpol.exe
2017-07-12 11:20:41 ----A---- C:\Windows\system32\adtschema.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\invagent.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\generaltel.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\devinv.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-07-12 11:19:34 ----A---- C:\Windows\system32\centel.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\appraiser.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\aitstatic.exe
2017-07-12 11:19:34 ----A---- C:\Windows\system32\aepic.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\aeinv.dll
2017-07-12 11:19:34 ----A---- C:\Windows\system32\acmigration.dll

======List of files/folders modified in the last 1 month======

2017-07-24 21:20:11 ----D---- C:\Windows\system32\config
2017-07-24 21:17:33 ----D---- C:\Windows\system32\drivers
2017-07-24 21:17:02 ----D---- C:\Windows\Temp
2017-07-24 21:06:09 ----D---- C:\Windows\Tasks
2017-07-24 21:06:09 ----D---- C:\Windows\system32\Tasks
2017-07-24 21:06:09 ----D---- C:\Program Files\Google
2017-07-24 21:06:08 ----D---- C:\Program Files\TeamViewer
2017-07-24 17:38:38 ----RD---- C:\Program Files
2017-07-24 17:27:28 ----D---- C:\Windows\System32
2017-07-24 17:27:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-07-24 17:27:27 ----D---- C:\Windows\inf
2017-07-24 17:09:56 ----HD---- C:\ProgramData
2017-07-24 15:38:41 ----SHD---- C:\System Volume Information
2017-07-24 15:14:28 ----D---- C:\STEREO26
2017-07-24 08:11:34 ----D---- C:\UCTO2017
2017-07-24 07:50:35 ----D---- C:\Windows\system32\DriverStore
2017-07-21 09:49:09 ----D---- C:\Windows\system32\FxsTmp
2017-07-17 11:30:40 ----SHD---- C:\Windows\Installer
2017-07-14 14:14:29 ----D---- C:\Windows\system32\NDF
2017-07-14 12:21:31 ----D---- C:\Windows\rescache
2017-07-12 15:43:31 ----D---- C:\Windows\winsxs
2017-07-12 15:42:16 ----D---- C:\Program Files\Internet Explorer
2017-07-12 15:42:15 ----D---- C:\Windows\system32\migration
2017-07-12 15:42:15 ----D---- C:\Windows\system32\en-US
2017-07-12 15:42:15 ----D---- C:\Windows\system32\cs-CZ
2017-07-12 15:42:15 ----D---- C:\Windows\system32\appraiser
2017-07-12 15:42:15 ----D---- C:\Windows\AppPatch
2017-07-12 13:16:26 ----D---- C:\Windows\system32\MRT
2017-07-12 13:14:30 ----AC---- C:\Windows\system32\MRT.exe
2017-07-12 13:14:17 ----D---- C:\ProgramData\Microsoft Help
2017-07-12 11:18:59 ----D---- C:\Windows\system32\catroot2

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 avgbidsh;avgbidsh; C:\Windows\system32\drivers\avgbidshx.sys [2017-07-23 151024]
R0 avgblog;avgblog; C:\Windows\system32\drivers\avgblogx.sys [2017-07-23 270344]
R0 avgbuniv;avgbuniv; C:\Windows\system32\drivers\avgbunivx.sys [2017-07-23 43992]
R0 avgRvrt;avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [2017-07-23 63280]
R0 avgVmm;avgVmm; C:\Windows\system32\drivers\avgVmm.sys [2017-07-23 288728]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2015-09-18 173400]
R1 avgbdisk;avgbdisk; C:\Windows\system32\drivers\avgbdiskx.sys [2017-07-23 135872]
R1 avgbidsdriver;avgbidsdriver; C:\Windows\system32\drivers\avgbidsdriverx.sys [2017-07-23 260616]
R1 avgNetSec;avgNetSec; C:\Windows\system32\drivers\avgNetSec.sys [2017-07-24 399976]
R1 avgRdr;avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [2017-07-23 91976]
R1 avgSnx;avgSnx; C:\Windows\system32\drivers\avgSnx.sys [2017-07-23 766728]
R1 avgSP;avgSP; C:\Windows\system32\drivers\avgSP.sys [2017-07-23 489416]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2015-09-18 389632]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Windows\system32\drivers\mbae.sys [2017-07-24 59936]
R2 avgMonFlt;avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [2017-07-23 116344]
R2 avgStm;avgStm; C:\Windows\system32\drivers\avgStm.sys [2017-07-23 140136]
R2 MBAMChameleon;MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [2017-07-24 162240]
R3 avgNetNd6;AVG Firewall NDIS6 Helper; C:\Windows\system32\DRIVERS\avgNetNd6.sys [2017-07-24 28408]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-11 4805120]
R3 MBAMFarflt;MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [2017-07-24 85400]
R3 MBAMProtection;MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [2017-07-24 40352]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-07-24 221600]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [2017-07-24 65824]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2014-12-10 584920]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2015-09-18 36352]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 avgHwid;avgHwid; C:\Windows\system32\drivers\avgHwid.sys [2017-07-23 35264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 MHIKEY10;MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10.sys [2010-10-01 52096]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2015-09-18 14848]
S3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2015-09-18 24064]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2015-09-18 27136]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S4 RsFx0153;RsFx0153 Driver; C:\Windows\system32\DRIVERS\RsFx0153.sys [2015-03-30 250152]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AVG Antivirus;AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [2017-07-23 264432]
R2 AVG Firewall;AVG Firewall Service; C:\Program Files\AVG\Antivirus\afwServ.exe [2017-07-24 312712]
R2 avgsvc;AVG Service; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [2017-07-03 1189720]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\cscsvc.dll
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-05-09 3398608]
R2 MSSQL$DUEL;SQL Server (DUEL); c:\Program Files\Microsoft SQL Server\MSSQL10_50.DUEL\MSSQL\Binn\sqlservr.exe [2015-03-30 43130032]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-09 144672]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2015-03-30 278704]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 97632]
R2 TeamViewer;TeamViewer 11; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2017-04-06 7757040]
R3 avgbIDSAgent;avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [2017-07-23 5866488]
R3 BrYNSvc;BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [2012-06-05 266240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-26 105096]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-11 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 AppMgmt;@appmgmts.dll,-3250; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll"=%SystemRoot%\System32\appmgmts.dll
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-11 107848]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2016-01-11 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-06-29 104960]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; %SystemRoot%\System32\svchost.exe -k PeerDist;"ServiceDll"=%SystemRoot%\system32\peerdistsvc.dll
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\system32\storsvc.dll
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\umrdp.dll
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-03-26 45688]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-03-26 135800]
S4 SQLAgent$DUEL;SQL Server Agent (DUEL); c:\Program Files\Microsoft SQL Server\MSSQL10_50.DUEL\MSSQL\Binn\SQLAGENT.EXE [2015-03-30 381104]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: CMD.exe samo vykonává příkazy atd.

#6 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\User_RSIT.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: CMD.exe samo vykonává příkazy atd.

#7 Příspěvek od detox »

Ok, hotovo.

Toť vše?:-)

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: CMD.exe samo vykonává příkazy atd.

#8 Příspěvek od detox »

Všiml jsem si jedné věci:

Po přihlašování v prohlížeči do určitých služeb (seznam, oriflame, banka) to vyhazuje samo od sebe CMD okno, které něco provede, ale je to tak rychlé, že nevidím co.

Pokusím se to vyfotit. Nebo není způsob jak na to přijít ?

Nevím co dělá, jestli neposílá údaje skrze nějaký tunel kamsi..

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: CMD.exe samo vykonává příkazy atd.

#9 Příspěvek od Rudy »

Může patřit něčemu, co jste nainstaloval a může to být regulérní aplikace. Pro jistotu ještě udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět