Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventívka + divne chovajúci sa ntb

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Narfyk
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 208
Registrován: 07 čer 2010 17:54
Bydliště: SK
Kontaktovat uživatele:

Preventívka + divne chovajúci sa ntb

#1 Příspěvek od Narfyk »

RSIT log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by andrej at 2015-07-19 16:02:43
Microsoft Windows 8.1 Pro
System drive C: has 60 GB (58%) free of 103 GB
Total RAM: 3001 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:04:09, on 19/07/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Avira\Antivirus\avgnt.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\GWX\GWX.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe
C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\cpl2\HDJSeries2CPL.exe
C:\Program Files\Avira\Launcher\Avira.Systray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17499_x86__8wekyb3d8bbwe\glcnd.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
D:\Program Files\Image-Line\FL Studio 11\FL.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchFilterHost.exe
E:\Skype\SkypePortable.exe
E:\Skype\App\Skype\Phone\Skype.exe
E:\RSIT.exe
C:\Program Files\trend micro\andrej.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Antivirus\avgnt.exe" /min
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Hercules DJ Series TrayAgent] C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe /boot
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\Launcher\Avira.Systray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-21-3945625924-3680027116-1249801073-500\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun (User 'Administrator')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Guillemot Corporation ® - C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\drivers\x86\HerculesDJControlMP3.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @oem26.inf,%hpservice_desc%;HP Service (hpsrv) - Hewlett-Packard Company - C:\WINDOWS\system32\Hpservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service: NVIDIA WMI Provider (NVWMI) - NVIDIA Corporation - C:\WINDOWS\system32\nvwmi.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @oem9.inf,%WBFService_SvcDesc%;Validity WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\WINDOWS\system32\valWBFPolicyService.exe

--
End of file - 8021 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\andrej\AppData\Roaming\Mozilla\Firefox\Profiles\NtHAaP5l.default

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.203 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_203.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll


C:\Users\andrej\AppData\Roaming\Mozilla\Firefox\Profiles\NtHAaP5l.default\extensions\
abs@avira.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-09-25 2602784]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-11 287800]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2011-08-01 1821576]
"avgnt"=C:\Program Files\Avira\Antivirus\avgnt.exe [2015-06-16 730416]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2010-09-08 495708]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"Hercules DJ Series TrayAgent"=C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe [2015-05-21 1669792]
"Avira Systray"=C:\Program Files\Avira\Launcher\Avira.Systray.exe [2015-06-02 134368]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2015-03-31 4557552]
"AdobeBridge"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
wlnotify.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=SbHpNp
scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"mixer5"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
"msacm.vorbis"=vorbis.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"wave6"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"midi6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-19 16:02:43 ----D---- C:\rsit
2015-07-19 16:02:43 ----D---- C:\Program Files\trend micro
2015-07-19 16:02:25 ----D---- C:\Users\andrej\AppData\Roaming\SkypePM
2015-07-18 14:13:36 ----D---- C:\Users\andrej\AppData\Roaming\Skype
2015-07-18 13:32:23 ----D---- C:\Program Files\CCleaner
2015-07-15 11:19:31 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-07-15 11:19:31 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-15 11:19:29 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-15 11:19:27 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 11:19:25 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-15 11:19:24 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 11:19:09 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 11:18:44 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 11:18:43 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-15 11:18:42 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 11:18:38 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 11:18:09 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 11:18:06 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 11:18:06 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 11:17:56 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-07-15 11:17:45 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-15 11:17:44 ----AC---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-15 11:17:44 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-15 11:17:43 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 11:17:43 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 11:17:43 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 11:17:42 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 11:17:42 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 11:17:40 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 11:17:40 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-14 14:54:50 ----D---- C:\Users\andrej\AppData\Roaming\MMFApplications
2015-07-14 14:08:50 ----D---- C:\Users\andrej\AppData\Roaming\Among the sleep
2015-07-10 23:58:24 ----D---- C:\WINDOWS\Minidump
2015-07-08 11:36:50 ----D---- C:\Program Files\Yamaha
2015-07-06 18:27:30 ----D---- C:\Users\andrej\AppData\Roaming\Jpeg Resampler
2015-06-30 23:32:01 ----D---- C:\ProgramData\Lexmark MS310 Series v2 XL
2015-06-25 23:13:53 ----D---- C:\Program Files\VirtualDJ
2015-06-25 23:10:05 ----D---- C:\WINDOWS\system32\appmgmt
2015-06-25 22:59:17 ----A---- C:\WINDOWS\system32\HDJusbaudioapi.dll
2015-06-25 22:57:41 ----A---- C:\WINDOWS\system32\HDJcustom.ini
2015-06-25 22:57:40 ----A---- C:\WINDOWS\system32\DJHerculesMixUSBAudioDevices.dll
2015-06-25 22:57:39 ----D---- C:\Program Files\Guillemot
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HRFDongle.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HDJSAPI.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HDJAsiou.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HDJAsioCpl.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJMidi.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJCtrl.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJBulk.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJAsioK.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\DJHerculesMixDevices.dll
2015-06-25 22:57:37 ----D---- C:\Program Files\DJHERCULESMIX
2015-06-25 22:57:37 ----A---- C:\WINDOWS\system32\HDJAPI.dll
2015-06-25 22:57:06 ----D---- C:\Users\andrej\AppData\Roaming\InstallShield

======List of files/folders modified in the last 1 month======

2015-07-19 16:03:13 ----D---- C:\WINDOWS\Prefetch
2015-07-19 16:03:02 ----D---- C:\WINDOWS\Temp
2015-07-19 16:02:43 ----RD---- C:\Program Files
2015-07-19 16:02:01 ----D---- C:\WINDOWS\system32\sru
2015-07-19 16:01:46 ----RD---- C:\WINDOWS\System32
2015-07-19 16:01:46 ----D---- C:\WINDOWS\inf
2015-07-19 16:01:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-19 15:32:21 ----SHD---- C:\WINDOWS\Installer
2015-07-19 15:32:21 ----D---- C:\Program Files\Mozilla Firefox
2015-07-19 15:32:11 ----SHD---- C:\System Volume Information
2015-07-19 12:01:10 ----D---- C:\WINDOWS\system32\catroot
2015-07-18 23:06:17 ----D---- C:\WINDOWS\system32\NDF
2015-07-18 21:49:21 ----D---- C:\Users\andrej\AppData\Roaming\vlc
2015-07-18 16:25:57 ----D---- C:\WINDOWS\system32\Tasks
2015-07-18 16:25:56 ----D---- C:\ProgramData\Skype
2015-07-18 16:25:56 ----D---- C:\Program Files\Common Files
2015-07-18 14:13:22 ----D---- C:\Users\andrej\AppData\Roaming\Skype_old
2015-07-18 02:00:09 ----A---- C:\Users\andrej\AppData\Roaming\msvcr90-ruby191.dll
2015-07-17 17:10:59 ----D---- C:\Users\andrej\AppData\Roaming\uTorrent
2015-07-17 15:48:20 ----D---- C:\WINDOWS\system32\config
2015-07-17 15:28:14 ----D---- C:\WINDOWS\system32\DriverStore
2015-07-17 15:28:05 ----D---- C:\WINDOWS\WinSxS
2015-07-17 12:36:34 ----D---- C:\WINDOWS\system32\catroot2
2015-07-17 12:34:19 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-16 20:18:53 ----D---- C:\WINDOWS\rescache
2015-07-16 19:56:09 ----D---- C:\WINDOWS\CbsTemp
2015-07-16 19:55:26 ----SD---- C:\WINDOWS\system32\GWX
2015-07-16 13:04:46 ----D---- C:\ProgramData\NVIDIA
2015-07-16 12:48:12 ----RD---- C:\WINDOWS\ToastData
2015-07-16 12:48:12 ----D---- C:\WINDOWS\system32\Drivers
2015-07-16 12:48:11 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-16 12:48:10 ----D---- C:\WINDOWS\WinStore
2015-07-16 12:48:10 ----D---- C:\WINDOWS\apppatch
2015-07-16 12:48:09 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-16 12:48:09 ----D---- C:\WINDOWS\system32\wbem
2015-07-16 12:48:09 ----D---- C:\WINDOWS\system32\appraiser
2015-07-16 12:48:08 ----D---- C:\WINDOWS\system32\en-GB
2015-07-16 12:48:08 ----D---- C:\WINDOWS\PolicyDefinitions
2015-07-16 12:48:07 ----D---- C:\Program Files\Internet Explorer
2015-07-15 22:49:17 ----D---- C:\WINDOWS\Tasks
2015-07-15 16:34:14 ----D---- C:\WINDOWS\system32\MRT
2015-07-15 16:28:46 ----RSD---- C:\WINDOWS\assembly
2015-07-15 15:35:37 ----D---- C:\Windows
2015-07-15 11:19:33 ----D---- C:\WINDOWS\AppReadiness
2015-07-14 21:38:05 ----HD---- C:\Program Files\WindowsApps
2015-07-13 23:10:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-08 11:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
2015-07-07 18:45:53 ----D---- C:\ProgramData\Package Cache
2015-07-07 18:45:48 ----D---- C:\Program Files\Avira
2015-07-05 13:16:25 ----D---- C:\efekty
2015-07-04 10:32:15 ----D---- C:\WINDOWS\system32\wdi
2015-07-03 08:49:12 ----A---- C:\WINDOWS\system32\MRT.exe
2015-06-30 23:32:01 ----HD---- C:\ProgramData
2015-06-30 17:06:29 ----D---- C:\WINDOWS\ModemLogs
2015-06-25 23:13:57 ----RSD---- C:\WINDOWS\Fonts
2015-06-25 14:34:36 ----SD---- C:\Users\andrej\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;@oem26.inf,%service_desc%;HP Filter; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2011-05-13 25656]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2015-06-16 136728]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2015-05-07 37896]
R1 MpKslf5325cda;MpKslf5325cda; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8CFD16DC-D4FA-42D0-9D44-B962D588931D}\MpKslf5325cda.sys [2015-07-19 39168]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2015-06-16 31848]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2013-08-22 57344]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2015-06-16 108448]
R2 avnetflt;avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [2015-03-24 37384]
R2 rimmptsk;rimmptsk; C:\WINDOWS\System32\drivers\rimmptsk.sys [2008-11-06 48128]
R2 rimsptsk;rimsptsk; C:\WINDOWS\System32\drivers\rimsptsk.sys [2008-10-11 45056]
R2 rismxdp;@oem28.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\WINDOWS\System32\drivers\rixdptsk.sys [2006-11-14 37376]
R3 Accelerometer;@oem26.inf,%accelerometer_desc%;HP Mobile Data Protection Sensor; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2011-05-13 35896]
R3 dg_ssudbus;@oem33.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
R3 dtlitescsibus;@oem41.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2015-05-09 25104]
R3 e1iexpress;@net1i32.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\system32\DRIVERS\e1i6332.sys [2013-06-18 379904]
R3 HECI;@oem8.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface; C:\WINDOWS\System32\drivers\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;@oem25.inf,%HpqKbFiltr.SvcDesc%;HpqKbFilter Driver; C:\WINDOWS\System32\drivers\HpqKbFiltr.sys [2009-04-29 15872]
R3 NETwNe32;@oem21.inf,___ %NIC_Service_DispName_WIN8%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 32 Bit; C:\WINDOWS\system32\DRIVERS\NETwen00.sys [2014-03-07 2677728]
R3 NVHDA;@oem14.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32v.sys [2013-09-05 161056]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-25 9257248]
R3 RICOH SmartCard Reader;@oem23.inf,%RICOH.DeviceDesc%;RICOH SmartCard Reader; C:\WINDOWS\system32\DRIVERS\rismc32.sys [2006-10-03 47488]
R3 ssudmdm;@oem34.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
R3 STHDA;@%SystemRoot%\system32\stlang.dll,-10301; C:\WINDOWS\system32\DRIVERS\stwrt.sys [2010-09-08 431616]
R3 SynTP;@oem27.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2010-06-04 1303728]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-22 177152]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2013-08-22 29184]
R3 WinUsb;@oem9.inf,%WinUsb_SvcDesc%;WinUSB Driver; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2013-08-22 64000]
S3 Bulk;@oem1.inf,%SvcDesc%;HDJBulk; C:\WINDOWS\System32\Drivers\HDJBulk.sys [2015-05-26 282784]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 HDJAsioK;@oem11.inf,%SvcDesc%;HDJAsioK; C:\WINDOWS\System32\Drivers\HDJAsioK.sys [2015-05-26 279200]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 netr28u;@netr28u.inf,%Generic.Service.DispName%;RT2870 USB Extensible Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\netr28u.sys [2013-06-18 1696528]
S3 ssudserd;@oem52.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys [2014-01-22 184192]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2014-11-22 88192]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\aestsrv.exe [2009-03-02 81920]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\Antivirus\sched.exe [2015-06-16 450808]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\Antivirus\avguard.exe [2015-06-16 450808]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [2015-06-02 217280]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-11-22 33088]
R2 HerculesDJControlMP3;Hercules DJ Control MP3; C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\drivers\x86\HerculesDJControlMP3.EXE [2015-04-17 76800]
R2 hpsrv;@oem26.inf,%hpservice_desc%;HP Service; C:\WINDOWS\system32\Hpservice.exe [2011-05-13 26168]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-09-18 662816]
R2 NVWMI;NVIDIA WMI Provider; C:\WINDOWS\system32\nvwmi.exe [2013-09-25 1027872]
R2 STacSV;@%SystemRoot%\system32\stlang.dll,-10101; C:\Program Files\IDT\WDM\STacSV.exe [2010-09-08 254034]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-09-18 414496]
R2 valWBFPolicyService;@oem9.inf,%WBFService_SvcDesc%;Validity WBF Policy Service; C:\WINDOWS\system32\valWBFPolicyService.exe [2013-10-17 24064]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-03-31 1023728]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files\Avira\Antivirus\avmailc7.exe [2015-06-16 827184]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\Antivirus\avwebg7.exe [2015-06-16 1188360]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-26 116648]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-11-22 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-26 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------
Notebook je občas až podivne moc spomalený (na to že by mal byť "výkonovo" lepší než predchádzajúci) + poslednou dobou mi blbne skype, neviem či to má spolu nejaký súvis.
Vopred díky za odpoveď a váš čas :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118274
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventívka + divne chovajúci sa ntb

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Narfyk
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 208
Registrován: 07 čer 2010 17:54
Bydliště: SK
Kontaktovat uživatele:

Re: Preventívka + divne chovajúci sa ntb

#3 Příspěvek od Narfyk »

Nech sa páči:
# AdwCleaner v4.208 - Logfile created 19/07/2015 at 22:00:09
# Updated 09/07/2015 by Xplode
# Database : 2015-07-15.1 [Server]
# Operating system : Windows 8.1 Pro (x86)
# Username : andrej - ELITEBOOK
# Running from : C:\Users\andrej\Desktop\adwcleaner_4.208.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v38.0.5 (x86 en-US)


-\\ Google Chrome v43.0.2357.134

[C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
[C:\Users\andrej\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
[C:\Users\martin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [1604 bytes] - [19/07/2015 21:59:03]
AdwCleaner[S0].txt - [1541 bytes] - [19/07/2015 22:00:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1600 bytes] ##########

Inak chcel by som sa spýtať, či môžem PC "prečistiť" s CCleanerom + či je možné pri "prechode" z Win8.1 na Win10 zmeniť 32bit systém na 64bit (nakolko mám 8gb RAM a aj procesor je vhodný pre 64bit systém, pôvodne tu bola 64b W7, ale odišla doska a neviem aké veci a mám tu nainštalovaný 32bit (legálny!!)). Díky za help zatial :)
Naposledy upravil(a) Narfyk dne 19 črc 2015 22:12, celkem upraveno 1 x.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118274
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventívka + divne chovajúci sa ntb

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Narfyk
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 208
Registrován: 07 čer 2010 17:54
Bydliště: SK
Kontaktovat uživatele:

Re: Preventívka + divne chovajúci sa ntb

#5 Příspěvek od Narfyk »

Log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by andrej at 2015-07-19 23:10:05
Microsoft Windows 8.1 Pro
System drive C: has 59 GB (57%) free of 103 GB
Total RAM: 3001 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:10:10, on 19/07/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\system32\GWX\GWX.exe
C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17499_x86__8wekyb3d8bbwe\glcnd.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Avira\Antivirus\avgnt.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe
C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\cpl2\HDJSeries2CPL.exe
C:\Program Files\Avira\Launcher\Avira.Systray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
E:\Skype\SkypePortable.exe
E:\Skype\App\Skype\Phone\Skype.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
E:\RSIT.exe
C:\Program Files\trend micro\andrej.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Antivirus\avgnt.exe" /min
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Hercules DJ Series TrayAgent] C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe /boot
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\Launcher\Avira.Systray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Guillemot Corporation ® - C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\drivers\x86\HerculesDJControlMP3.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @oem26.inf,%hpservice_desc%;HP Service (hpsrv) - Hewlett-Packard Company - C:\WINDOWS\system32\Hpservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service: NVIDIA WMI Provider (NVWMI) - NVIDIA Corporation - C:\WINDOWS\system32\nvwmi.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @oem9.inf,%WBFService_SvcDesc%;Validity WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\WINDOWS\system32\valWBFPolicyService.exe

--
End of file - 7862 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\andrej\AppData\Roaming\Mozilla\Firefox\Profiles\NtHAaP5l.default

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.203 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_203.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll


C:\Users\andrej\AppData\Roaming\Mozilla\Firefox\Profiles\NtHAaP5l.default\extensions\
abs@avira.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2013-09-25 2602784]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-11 287800]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2011-08-01 1821576]
"avgnt"=C:\Program Files\Avira\Antivirus\avgnt.exe [2015-06-16 730416]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2010-09-08 495708]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"Hercules DJ Series TrayAgent"=C:\Program Files\Guillemot\HDJTray\HDJSeries2TrayBar.exe [2015-05-21 1669792]
"Avira Systray"=C:\Program Files\Avira\Launcher\Avira.Systray.exe [2015-06-02 134368]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2015-03-31 4557552]
"AdobeBridge"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
wlnotify.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=SbHpNp
scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"mixer5"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
"msacm.vorbis"=vorbis.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"wave6"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"midi6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-19 22:40:16 ----D---- C:\Users\andrej\AppData\Roaming\SkypePM
2015-07-19 21:59:01 ----D---- C:\AdwCleaner
2015-07-19 16:02:43 ----D---- C:\rsit
2015-07-19 16:02:43 ----D---- C:\Program Files\trend micro
2015-07-19 16:02:25 ----D---- C:\Users\andrej\AppData\Roaming\SkypePM-BackupBySkypePortable
2015-07-18 14:13:36 ----D---- C:\Users\andrej\AppData\Roaming\Skype
2015-07-18 13:32:23 ----D---- C:\Program Files\CCleaner
2015-07-15 11:19:31 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-07-15 11:19:31 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 11:19:30 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-15 11:19:29 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-15 11:19:27 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 11:19:25 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-15 11:19:24 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 11:19:11 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 11:19:10 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 11:19:09 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 11:18:44 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 11:18:43 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-15 11:18:42 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 11:18:38 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 11:18:09 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 11:18:06 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 11:18:06 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 11:17:56 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 11:17:55 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-07-15 11:17:53 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-15 11:17:48 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-07-15 11:17:45 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-15 11:17:44 ----AC---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-15 11:17:44 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-15 11:17:43 ----AC---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-15 11:17:43 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 11:17:43 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 11:17:43 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 11:17:42 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 11:17:42 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 11:17:41 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 11:17:40 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 11:17:40 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 11:17:39 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-14 14:54:50 ----D---- C:\Users\andrej\AppData\Roaming\MMFApplications
2015-07-14 14:08:50 ----D---- C:\Users\andrej\AppData\Roaming\Among the sleep
2015-07-10 23:58:24 ----D---- C:\WINDOWS\Minidump
2015-07-08 11:36:50 ----D---- C:\Program Files\Yamaha
2015-07-06 18:27:30 ----D---- C:\Users\andrej\AppData\Roaming\Jpeg Resampler
2015-06-30 23:32:01 ----D---- C:\ProgramData\Lexmark MS310 Series v2 XL
2015-06-25 23:13:53 ----D---- C:\Program Files\VirtualDJ
2015-06-25 23:10:05 ----D---- C:\WINDOWS\system32\appmgmt
2015-06-25 22:59:17 ----A---- C:\WINDOWS\system32\HDJusbaudioapi.dll
2015-06-25 22:57:41 ----A---- C:\WINDOWS\system32\HDJcustom.ini
2015-06-25 22:57:40 ----A---- C:\WINDOWS\system32\DJHerculesMixUSBAudioDevices.dll
2015-06-25 22:57:39 ----D---- C:\Program Files\Guillemot
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HRFDongle.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HDJSAPI.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HDJAsiou.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\HDJAsioCpl.dll
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJMidi.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJCtrl.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJBulk.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\drivers\HDJAsioK.sys
2015-06-25 22:57:38 ----A---- C:\WINDOWS\system32\DJHerculesMixDevices.dll
2015-06-25 22:57:37 ----D---- C:\Program Files\DJHERCULESMIX
2015-06-25 22:57:37 ----A---- C:\WINDOWS\system32\HDJAPI.dll
2015-06-25 22:57:06 ----D---- C:\Users\andrej\AppData\Roaming\InstallShield

======List of files/folders modified in the last 1 month======

2015-07-19 23:10:10 ----D---- C:\WINDOWS\Temp
2015-07-19 23:00:01 ----D---- C:\WINDOWS\system32\sru
2015-07-19 22:40:16 ----D---- C:\WINDOWS\Prefetch
2015-07-19 22:29:36 ----D---- C:\WINDOWS\system32\catroot
2015-07-19 22:21:58 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-19 22:07:13 ----RD---- C:\WINDOWS\System32
2015-07-19 22:07:13 ----D---- C:\WINDOWS\inf
2015-07-19 22:07:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-19 22:01:53 ----D---- C:\ProgramData\NVIDIA
2015-07-19 16:02:43 ----RD---- C:\Program Files
2015-07-19 15:32:21 ----SHD---- C:\WINDOWS\Installer
2015-07-19 15:32:21 ----D---- C:\Program Files\Mozilla Firefox
2015-07-19 15:32:11 ----SHD---- C:\System Volume Information
2015-07-18 23:06:17 ----D---- C:\WINDOWS\system32\NDF
2015-07-18 21:49:21 ----D---- C:\Users\andrej\AppData\Roaming\vlc
2015-07-18 16:25:57 ----D---- C:\WINDOWS\system32\Tasks
2015-07-18 16:25:56 ----D---- C:\ProgramData\Skype
2015-07-18 16:25:56 ----D---- C:\Program Files\Common Files
2015-07-18 14:13:22 ----D---- C:\Users\andrej\AppData\Roaming\Skype_old
2015-07-18 02:00:09 ----A---- C:\Users\andrej\AppData\Roaming\msvcr90-ruby191.dll
2015-07-17 17:10:59 ----D---- C:\Users\andrej\AppData\Roaming\uTorrent
2015-07-17 15:48:20 ----D---- C:\WINDOWS\system32\config
2015-07-17 15:28:14 ----D---- C:\WINDOWS\system32\DriverStore
2015-07-17 15:28:05 ----D---- C:\WINDOWS\WinSxS
2015-07-17 12:36:34 ----D---- C:\WINDOWS\system32\catroot2
2015-07-16 20:18:53 ----D---- C:\WINDOWS\rescache
2015-07-16 19:56:52 ----D---- C:\WINDOWS\CbsTemp
2015-07-16 19:55:26 ----SD---- C:\WINDOWS\system32\GWX
2015-07-16 12:48:12 ----RD---- C:\WINDOWS\ToastData
2015-07-16 12:48:12 ----D---- C:\WINDOWS\system32\Drivers
2015-07-16 12:48:11 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-16 12:48:10 ----D---- C:\WINDOWS\WinStore
2015-07-16 12:48:10 ----D---- C:\WINDOWS\apppatch
2015-07-16 12:48:09 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-16 12:48:09 ----D---- C:\WINDOWS\system32\wbem
2015-07-16 12:48:09 ----D---- C:\WINDOWS\system32\appraiser
2015-07-16 12:48:08 ----D---- C:\WINDOWS\system32\en-GB
2015-07-16 12:48:08 ----D---- C:\WINDOWS\PolicyDefinitions
2015-07-16 12:48:07 ----D---- C:\Program Files\Internet Explorer
2015-07-15 22:49:17 ----D---- C:\WINDOWS\Tasks
2015-07-15 16:34:14 ----D---- C:\WINDOWS\system32\MRT
2015-07-15 16:28:46 ----RSD---- C:\WINDOWS\assembly
2015-07-15 15:35:37 ----D---- C:\Windows
2015-07-15 11:19:33 ----D---- C:\WINDOWS\AppReadiness
2015-07-14 21:38:05 ----HD---- C:\Program Files\WindowsApps
2015-07-13 23:10:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-08 11:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
2015-07-07 18:45:53 ----D---- C:\ProgramData\Package Cache
2015-07-07 18:45:48 ----D---- C:\Program Files\Avira
2015-07-05 13:16:25 ----D---- C:\efekty
2015-07-04 10:32:15 ----D---- C:\WINDOWS\system32\wdi
2015-07-03 08:49:12 ----A---- C:\WINDOWS\system32\MRT.exe
2015-06-30 23:32:01 ----HD---- C:\ProgramData
2015-06-30 17:06:29 ----D---- C:\WINDOWS\ModemLogs
2015-06-25 23:13:57 ----RSD---- C:\WINDOWS\Fonts
2015-06-25 14:34:36 ----SD---- C:\Users\andrej\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;@oem26.inf,%service_desc%;HP Filter; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2011-05-13 25656]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2015-06-16 136728]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2015-05-07 37896]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2015-06-16 31848]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2013-08-22 57344]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2015-06-16 108448]
R2 avnetflt;avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [2015-03-24 37384]
R2 rimmptsk;rimmptsk; C:\WINDOWS\System32\drivers\rimmptsk.sys [2008-11-06 48128]
R2 rimsptsk;rimsptsk; C:\WINDOWS\System32\drivers\rimsptsk.sys [2008-10-11 45056]
R2 rismxdp;@oem28.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\WINDOWS\System32\drivers\rixdptsk.sys [2006-11-14 37376]
R3 Accelerometer;@oem26.inf,%accelerometer_desc%;HP Mobile Data Protection Sensor; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2011-05-13 35896]
R3 dg_ssudbus;@oem33.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
R3 dtlitescsibus;@oem41.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2015-05-09 25104]
R3 e1iexpress;@net1i32.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\system32\DRIVERS\e1i6332.sys [2013-06-18 379904]
R3 HECI;@oem8.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface; C:\WINDOWS\System32\drivers\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;@oem25.inf,%HpqKbFiltr.SvcDesc%;HpqKbFilter Driver; C:\WINDOWS\System32\drivers\HpqKbFiltr.sys [2009-04-29 15872]
R3 NETwNe32;@oem21.inf,___ %NIC_Service_DispName_WIN8%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 32 Bit; C:\WINDOWS\system32\DRIVERS\NETwen00.sys [2014-03-07 2677728]
R3 NVHDA;@oem14.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32v.sys [2013-09-05 161056]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-25 9257248]
R3 RICOH SmartCard Reader;@oem23.inf,%RICOH.DeviceDesc%;RICOH SmartCard Reader; C:\WINDOWS\system32\DRIVERS\rismc32.sys [2006-10-03 47488]
R3 ssudmdm;@oem34.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
R3 STHDA;@%SystemRoot%\system32\stlang.dll,-10301; C:\WINDOWS\system32\DRIVERS\stwrt.sys [2010-09-08 431616]
R3 SynTP;@oem27.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2010-06-04 1303728]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-22 177152]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2013-08-22 29184]
R3 WinUsb;@oem9.inf,%WinUsb_SvcDesc%;WinUSB Driver; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2013-08-22 64000]
S3 Bulk;@oem1.inf,%SvcDesc%;HDJBulk; C:\WINDOWS\System32\Drivers\HDJBulk.sys [2015-05-26 282784]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 HDJAsioK;@oem11.inf,%SvcDesc%;HDJAsioK; C:\WINDOWS\System32\Drivers\HDJAsioK.sys [2015-05-26 279200]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 netr28u;@netr28u.inf,%Generic.Service.DispName%;RT2870 USB Extensible Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\netr28u.sys [2013-06-18 1696528]
S3 ssudserd;@oem52.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys [2014-01-22 184192]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2014-11-22 88192]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\aestsrv.exe [2009-03-02 81920]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\Antivirus\sched.exe [2015-06-16 450808]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\Antivirus\avguard.exe [2015-06-16 450808]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [2015-06-02 217280]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-11-22 33088]
R2 HerculesDJControlMP3;Hercules DJ Control MP3; C:\Program Files\DJHERCULESMIX\Audio\DJ Console Series\drivers\x86\HerculesDJControlMP3.EXE [2015-04-17 76800]
R2 hpsrv;@oem26.inf,%hpservice_desc%;HP Service; C:\WINDOWS\system32\Hpservice.exe [2011-05-13 26168]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-09-18 662816]
R2 NVWMI;NVIDIA WMI Provider; C:\WINDOWS\system32\nvwmi.exe [2013-09-25 1027872]
R2 STacSV;@%SystemRoot%\system32\stlang.dll,-10101; C:\Program Files\IDT\WDM\STacSV.exe [2010-09-08 254034]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-09-18 414496]
R2 valWBFPolicyService;@oem9.inf,%WBFService_SvcDesc%;Validity WBF Policy Service; C:\WINDOWS\system32\valWBFPolicyService.exe [2013-10-17 24064]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-01-12 227896]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-03-31 1023728]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files\Avira\Antivirus\avmailc7.exe [2015-06-16 827184]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\Antivirus\avwebg7.exe [2015-06-16 1188360]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-26 116648]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-11-22 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-26 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Až je to možné, poprosil by som odpoveď na dotaz v predošlom príspevku (pre lepšiu viditeľnosť som ho zvýraznil).

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118274
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventívka + divne chovajúci sa ntb

#6 Příspěvek od Rudy »

CCleanerem čistit můžete a zda je možné přejít na 64bit. systém, záleží na podmínkách, které si MS stanovil. Toto byste se tam měl dočíst.

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět