Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
13918
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 06 led 2008 22:10

Prosím o kontrolu PC

#1 Příspěvek od 13918 »

Logfile of random's system information tool 1.10 (written by random/random)
Run by PC at 2017-09-03 11:04:32
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 588 GB (62%) free of 954 GB
Total RAM: 2047 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:05:13, on 3.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18763)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Wargaming.net\GameCenter\wgc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Wargaming.net\GameCenter\dlls\wgc_watchdog.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Program Files\Opera\47.0.2631.71_1\opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\PC\AppData\Local\Temp\scoped_dir1348_31635\RSIT.exe
C:\Program Files\trend micro\PC.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Wargaming.net Game Center] "C:\Program Files\Wargaming.net\GameCenter\wgc.exe" --background ''
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{EDB6633F-59EA-44AC-9BB9-F265341FA7B2}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: Samsung Printer Dianostics Service - Unknown owner - C:\Windows\system32\\spdsvc.exe
O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - C:\Program Files\System Explorer\service\SystemExplorerService.exe

--
End of file - 5819 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Opera scheduled Autoupdate 1479579331.job - C:\Program Files\Opera\launcher.exe --scheduledautoupdate $(Arg0)

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23 184488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23 4452504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-04-30 642304]
"SERVICE"= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Wargaming.net Game Center"=C:\Program Files\Wargaming.net\GameCenter\wgc.exe [2017-08-29 1762040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 10]
C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe /Auto []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wargaming.net Game Center]
C:\Program Files\Wargaming.net\GameCenter\wgc.exe [2017-08-29 1762040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\04800D90.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\04800D90.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"msacm.l3codecp"=l3codecp.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-09-03 11:04:33 ----D---- C:\Program Files\trend micro
2017-09-03 11:04:32 ----D---- C:\rsit
2017-09-03 10:12:11 ----A---- C:\Windows\ntbtlog.txt
2017-09-01 19:25:03 ----A---- C:\Windows\system32\drivers\04800D90.sys
2017-09-01 19:14:14 ----D---- C:\KVRT_Data
2017-09-01 08:44:55 ----D---- C:\AdwCleaner
2017-08-31 11:40:41 ----D---- C:\ProgramData\loceps
2017-08-31 11:40:00 ----D---- C:\ProgramData\locep
2017-08-31 11:19:39 ----A---- C:\Windows\system32\win32spl.dll
2017-08-31 11:19:39 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2017-08-31 11:09:49 ----SHD---- C:\Config.Msi
2017-08-31 10:50:26 ----A---- C:\Windows\system32\drivers\es1371mp.sys
2017-08-31 10:37:02 ----D---- C:\Windows\IObit
2017-08-31 10:36:48 ----A---- C:\Windows\system32\drivers\HWiNFO32.SYS
2017-08-31 08:38:11 ----D---- C:\Program Files\BitTorrent
2017-08-31 08:31:15 ----D---- C:\Users\PC\AppData\Roaming\Mozilla
2017-08-31 08:30:03 ----D---- C:\ProgramData\Plusdaxs
2017-08-31 08:26:05 ----D---- C:\Applications
2017-08-30 17:42:51 ----D---- C:\ProgramData\boost_interprocess
2017-08-30 17:41:13 ----D---- C:\Program Files\Wargaming.net
2017-08-30 17:27:53 ----D---- C:\ProgramData\Wargaming.net
2017-08-27 13:57:25 ----D---- C:\Program Files\Calibre2
2017-08-26 18:08:04 ----D---- C:\Program Files\K-Lite Codec Pack
2017-08-26 09:59:50 ----D---- C:\ProgramData\SystemExplorer
2017-08-26 09:59:43 ----D---- C:\Program Files\System Explorer
2017-08-12 20:47:05 ----D---- C:\Program Files\The KMPlayer
2017-08-12 20:33:20 ----D---- C:\Users\PC\AppData\Roaming\dvdcss
2017-08-12 12:06:12 ----AD---- C:\ProgramData\TEMP
2017-08-12 07:00:27 ----A---- C:\Windows\system32\mshtml.dll
2017-08-12 07:00:26 ----A---- C:\Windows\system32\msrd2x40.dll
2017-08-12 07:00:26 ----A---- C:\Windows\system32\jscript9.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\win32k.sys
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msxbde40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msrepl40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msrd3x40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\mspbde40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msltus40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msjtes40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msjetoledb40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msjet40.dll
2017-08-12 07:00:25 ----A---- C:\Windows\system32\msexcl40.dll
2017-08-12 07:00:24 ----A---- C:\Windows\system32\tquery.dll
2017-08-12 07:00:24 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-08-12 07:00:24 ----A---- C:\Windows\system32\mswstr10.dll
2017-08-12 07:00:24 ----A---- C:\Windows\system32\mswdat10.dll
2017-08-12 07:00:24 ----A---- C:\Windows\system32\msjter40.dll
2017-08-12 07:00:24 ----A---- C:\Windows\system32\msjint40.dll
2017-08-12 07:00:23 ----A---- C:\Windows\system32\wer.dll
2017-08-12 07:00:23 ----A---- C:\Windows\system32\Query.dll
2017-08-12 07:00:23 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-08-12 07:00:23 ----A---- C:\Windows\system32\drivers\volmgrx.sys
2017-08-12 07:00:22 ----A---- C:\Windows\system32\t2embed.dll
2017-08-12 07:00:22 ----A---- C:\Windows\system32\ntdll.dll
2017-08-12 07:00:22 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-08-12 07:00:22 ----A---- C:\Windows\system32\iedkcs32.dll
2017-08-12 07:00:22 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-08-12 07:00:22 ----A---- C:\Windows\system32\clfs.sys
2017-08-12 07:00:21 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-08-12 07:00:21 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-08-12 07:00:20 ----A---- C:\Windows\system32\wermgr.exe
2017-08-12 07:00:20 ----A---- C:\Windows\system32\werdiagcontroller.dll
2017-08-12 07:00:17 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-08-12 07:00:16 ----A---- C:\Windows\system32\wininet.dll
2017-08-12 07:00:16 ----A---- C:\Windows\system32\ieframe.dll
2017-08-12 07:00:15 ----A---- C:\Windows\system32\vbscript.dll
2017-08-12 07:00:15 ----A---- C:\Windows\system32\urlmon.dll
2017-08-12 07:00:15 ----A---- C:\Windows\system32\jscript.dll
2017-08-12 07:00:13 ----A---- C:\Windows\system32\msfeeds.dll
2017-08-12 07:00:13 ----A---- C:\Windows\system32\iertutil.dll
2017-08-12 07:00:11 ----A---- C:\Windows\system32\webcheck.dll
2017-08-12 07:00:11 ----A---- C:\Windows\system32\mssrch.dll
2017-08-12 07:00:11 ----A---- C:\Windows\system32\ieapfltr.dll
2017-08-12 07:00:10 ----A---- C:\Windows\system32\ieui.dll
2017-08-12 07:00:08 ----A---- C:\Windows\system32\mshtmled.dll
2017-08-12 07:00:08 ----A---- C:\Windows\system32\jscript9diag.dll
2017-08-12 07:00:08 ----A---- C:\Windows\system32\dxtrans.dll
2017-08-12 07:00:08 ----A---- C:\Windows\system32\dxtmsft.dll
2017-08-12 07:00:07 ----A---- C:\Windows\system32\occache.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\rpcrt4.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\mssvp.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\mssph.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\msrating.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\lsasrv.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\kerberos.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\jsproxy.dll
2017-08-12 07:00:05 ----A---- C:\Windows\system32\ieUnatt.exe
2017-08-12 07:00:05 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-08-12 07:00:05 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-08-12 07:00:04 ----A---- C:\Windows\system32\wdigest.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\sspicli.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\srcore.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\smss.exe
2017-08-12 07:00:04 ----A---- C:\Windows\system32\schannel.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\rpchttp.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\ncrypt.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\msv1_0.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\mssphtb.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\mssitlb.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\inseng.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\iesetup.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\iernonce.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-08-12 07:00:04 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-08-12 07:00:04 ----A---- C:\Windows\system32\ie4uinit.exe
2017-08-12 07:00:04 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-08-12 07:00:04 ----A---- C:\Windows\system32\advapi32.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\TSpkg.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\secur32.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-08-12 07:00:03 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-08-12 07:00:03 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-08-12 07:00:03 ----A---- C:\Windows\system32\mssprxy.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\msshooks.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\msscntrs.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\lsass.exe
2017-08-12 07:00:03 ----A---- C:\Windows\system32\csrsrv.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\cryptbase.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\bcrypt.dll
2017-08-12 07:00:03 ----A---- C:\Windows\system32\apisetschema.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\sspisrv.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\srclient.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\rstrui.exe
2017-08-12 07:00:02 ----A---- C:\Windows\system32\msaudite.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\drivers\appid.sys
2017-08-12 07:00:02 ----A---- C:\Windows\system32\credssp.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\auditpol.exe
2017-08-12 07:00:02 ----A---- C:\Windows\system32\appidsvc.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-08-12 07:00:02 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-08-12 07:00:02 ----A---- C:\Windows\system32\appidapi.dll
2017-08-12 07:00:02 ----A---- C:\Windows\system32\adtschema.dll
2017-08-12 07:00:01 ----A---- C:\Windows\system32\msobjs.dll
2017-08-12 07:00:01 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-08-12 06:59:59 ----A---- C:\Windows\system32\mstext40.dll
2017-08-12 06:59:59 ----A---- C:\Windows\system32\msexch40.dll
2017-08-05 12:05:14 ----D---- C:\ProgramData\ESET
2017-08-05 12:05:14 ----D---- C:\Program Files\ESET

======List of files/folders modified in the last 1 month======

2017-09-03 11:04:44 ----D---- C:\Windows\Prefetch
2017-09-03 11:04:36 ----D---- C:\Windows\Temp
2017-09-03 11:04:33 ----RD---- C:\Program Files
2017-09-03 10:42:38 ----D---- C:\Windows\system32\config
2017-09-03 10:21:27 ----HD---- C:\ProgramData
2017-09-03 10:12:11 ----D---- C:\Windows
2017-09-03 10:00:45 ----D---- C:\Windows\system32\Tasks
2017-09-03 10:00:43 ----D---- C:\ProgramData\ProductData
2017-09-03 09:51:53 ----D---- C:\Users\PC\AppData\Roaming\vlc
2017-09-03 09:41:32 ----D---- C:\Users\PC\AppData\Roaming\uTorrent
2017-09-03 09:30:44 ----D---- C:\Windows\Tasks
2017-09-03 09:30:38 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2017-09-03 09:30:35 ----D---- C:\Windows\system32\Macromed
2017-09-02 16:32:32 ----SHD---- C:\System Volume Information
2017-09-01 21:08:58 ----D---- C:\Windows\System32
2017-09-01 21:08:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-01 21:08:57 ----D---- C:\Windows\inf
2017-09-01 19:25:03 ----D---- C:\Windows\system32\drivers
2017-08-31 16:50:18 ----D---- C:\Windows\PCHEALTH
2017-08-31 15:02:02 ----D---- C:\Windows\system32\catroot
2017-08-31 14:58:24 ----D---- C:\Program Files\Opera
2017-08-31 12:31:10 ----D---- C:\Windows\SoftwareDistribution
2017-08-31 12:30:22 ----D---- C:\Windows\system32\DriverStore
2017-08-31 12:29:48 ----D---- C:\Windows\system32\catroot2
2017-08-31 12:28:07 ----D---- C:\Windows\winsxs
2017-08-31 12:27:30 ----D---- C:\Windows\debug
2017-08-31 11:55:35 ----D---- C:\Windows\Microsoft.NET
2017-08-31 11:13:37 ----SHD---- C:\Windows\Installer
2017-08-31 11:00:25 ----SHD---- C:\Boot
2017-08-31 09:58:48 ----D---- C:\Program Files\Common Files\IObit
2017-08-31 09:34:12 ----D---- C:\Program Files\Common Files
2017-08-30 17:42:49 ----D---- C:\Games
2017-08-30 17:41:54 ----D---- C:\Users\PC\AppData\Roaming\Wargaming.net
2017-08-20 18:47:47 ----D---- C:\Windows\system32\FxsTmp
2017-08-12 14:00:56 ----D---- C:\Windows\rescache
2017-08-12 07:29:53 ----D---- C:\Program Files\Internet Explorer
2017-08-12 07:29:52 ----D---- C:\Windows\system32\migration
2017-08-12 07:29:52 ----D---- C:\Windows\system32\en-US
2017-08-12 07:29:52 ----D---- C:\Windows\system32\cs-CZ
2017-08-12 07:18:57 ----D---- C:\Windows\system32\MRT
2017-08-12 07:10:12 ----AC---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 04800D90;04800D90; C:\Windows\system32\drivers\04800D90.sys [2017-09-01 153784]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2016-12-21 106296]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2016-11-19 218688]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2017-06-22 113512]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2017-05-04 139384]
R1 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2017-05-04 67712]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO32.SYS [2017-08-31 23840]
R1 mbamchameleon;mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [2014-05-12 74456]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2009-09-10 5120]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-04-30 290304]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2016-12-21 78848]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\Windows\system32\drivers\es1371mp.sys [2017-08-31 37376]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 23256]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2016-12-21 13216]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtl8187.sys [2010-01-07 375808]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 AtiDCM;AtiDCM; \??\C:\Program Files\AMD\CIM\Bin\atidcmxx.sys [2016-04-17 28872]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 10070016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\drivers\bthpan.sys [2017-07-06 94208]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 cpuz138;cpuz138; \??\C:\Users\PC\AppData\Local\Temp\cpuz138\cpuz138_x32.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2017-01-06 25088]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 51928]
S3 mod7700;DiBcom DIB7700 based TV tuner device; C:\Windows\System32\Drivers\mod7700.sys [2010-11-19 914816]
S3 MODRC;PCTV Dib Infrared Receiver; C:\Windows\system32\DRIVERS\modrc.sys [2008-09-17 13824]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2012-06-05 204432]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-20 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 24064]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
S3 usbser;USB Serial Emulation Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 28160]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 wdm_usb;wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [2014-11-24 109824]
S3 WinUSB;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2017-05-28 143776]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-04-30 217088]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2017-06-13 2069936]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-09-03 272384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-04-21 47224]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-07-14 104960]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2016-08-22 6053312]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Samsung Printer Dianostics Service;Samsung Printer Dianostics Service; C:\Windows\system32\\spdsvc.exe [2017-01-19 506680]
S3 SystemExplorerHelpService;System Explorer Service; C:\Program Files\System Explorer\service\SystemExplorerService.exe [2014-12-20 567008]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118272
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu PC

#2 Příspěvek od Rudy »

Zdravím!
Opět na nás zkoušíte váš cracklý OS?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět