Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pro Rudy prosím o ko logu

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Uživatelský avatar
jaruneczka
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 417
Registrován: 09 čer 2008 11:45
Bydliště: Ostrava

Pro Rudy prosím o ko logu

#1 Příspěvek od jaruneczka »

ESS našel 3 Trojany, vyléčil je, adwcleaner čistý, nejde win update 9-11/2016, vše možné zkoušeno, nic
Logfile of random's system information tool 1.10 (written by random/random)
Run by Asus at 2016-12-02 21:34:50
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 264 GB (87%) free of 305 GB
Total RAM: 4000 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:34:56, on 2.12.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18427)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\trend micro\Asus.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Rapport Management Service (RapportMgmtService) - IBM Corp. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7006 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
ATKOSD.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
taskeng.exe {EC54BBAE-E66B-4B4A-8B9C-B797721D4F7E}
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\msiexec.exe /V
taskeng.exe {8591CA76-89B0-40D5-9175-32C9414A1A6D}
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
WDC.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1382494234-2938470400-2156763435-10002_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1382494234-2938470400-2156763435-10002 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524

"C:\Users\Asus\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\o09oei0j.default-1480641429522

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.207 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.207 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmIcoSinglun64]
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKMEDIA]
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKOSD2]
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-25 322208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc]
C:\Users\Asus\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-12-01 144008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControlUser]
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2000-01-01 399856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2000-01-01 172016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWirelessWiMAX]
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe /tasktray /nosplash []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2000-01-01 442352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg]
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2011-08-16 2277480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-09-05 12850792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicMasterTray]
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [2010-07-09 984400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~1\MCAFEE~1\311~1.266\SSSCHE~1.EXE []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2000-01-01 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-12-02 21:34:51 ----D---- C:\Program Files\trend micro
2016-12-02 21:34:50 ----D---- C:\rsit
2016-12-02 21:29:53 ----A---- C:\Windows\SYSWOW64\log.txt
2016-12-02 21:09:26 ----D---- C:\3d701750773c1929d0c83be87d5a
2016-12-02 09:09:58 ----D---- C:\Windows\SoftwareDistribution
2016-12-02 02:15:48 ----D---- C:\Users\Asus\AppData\Roaming\Mozilla
2016-12-02 02:15:27 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-02 02:14:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-12-02 02:11:12 ----D---- C:\Users\Asus\AppData\Roaming\ESET
2016-12-02 02:04:11 ----D---- C:\ProgramData\ESET
2016-12-02 02:04:11 ----D---- C:\Program Files\ESET
2016-12-02 01:52:36 ----SD---- C:\Windows\SYSWOW64\Microsoft
2016-12-01 21:59:33 ----A---- C:\Windows\woubak-pwrscheme-temp.txt
2016-12-01 21:59:33 ----A---- C:\Windows\woubak-pwrscheme-act.txt
2016-12-01 19:12:32 ----D---- C:\ProgramData\~0
2016-12-01 14:21:04 ----D---- C:\zamčené
2016-12-01 14:05:17 ----A---- C:\Windows\system32\drivers\RapportHades64.sys
2016-12-01 14:05:14 ----A---- C:\Windows\system32\drivers\RapportKE64.sys
2016-12-01 14:02:58 ----D---- C:\Program Files (x86)\Trusteer
2016-12-01 14:01:32 ----D---- C:\ProgramData\Trusteer
2016-12-01 13:27:25 ----D---- C:\ProgramData\Package Cache
2016-12-01 12:37:05 ----D---- C:\Users\Asus\AppData\Roaming\Intel Corporation
2016-12-01 11:46:10 ----D---- C:\Windows\SYSWOW64\Atheros_L1e
2016-12-01 11:44:59 ----A---- C:\Windows\system32\drivers\L1C62x64.sys
2016-12-01 11:18:21 ----A---- C:\Windows\system32\OpenCL.dll
2016-12-01 11:18:21 ----A---- C:\Windows\system32\IntelOpenCL64.dll
2016-12-01 11:18:11 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-12-01 11:18:11 ----A---- C:\Windows\SYSWOW64\IntelOpenCL32.dll
2016-12-01 10:52:12 ----A---- C:\Windows\system32\drivers\IntcDAud.sys
2016-12-01 10:52:11 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2016-12-01 10:52:08 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll
2016-12-01 10:52:08 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\IntcDAuC.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\iglhsip64.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\iglhcp64.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\igfxTMM.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\igfxsrvc.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\igfxCoIn_v3223.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxcmjit32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfx11cmrt32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxress.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxpph.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxexps.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxdo.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\IGFXDEVLib.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxdev.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxcmrt64.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxcmjit64.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfx11cmrt64.dll
2016-12-01 10:52:05 ----A---- C:\Windows\SYSWOW64\igdumd32.dll
2016-12-01 10:52:05 ----A---- C:\Windows\system32\igdumd64.dll
2016-12-01 10:51:59 ----A---- C:\Windows\SYSWOW64\igdde32.dll
2016-12-01 10:51:59 ----A---- C:\Windows\system32\igdde64.dll
2016-12-01 10:51:58 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll
2016-12-01 10:51:55 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll
2016-12-01 10:51:55 ----A---- C:\Windows\system32\ig4icd64.dll
2016-12-01 10:51:55 ----A---- C:\Windows\system32\hccutils.dll
2016-12-01 10:51:55 ----A---- C:\Windows\system32\gfxSrvc.dll
2016-12-01 10:51:53 ----A---- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxtray.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxsrvc.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxpers.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxext.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\hkcmd.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\GfxUI.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\difx64.exe
2016-12-01 08:10:28 ----D---- C:\Program Files\Common Files\AV
2016-12-01 08:08:07 ----D---- C:\ProgramData\AVAST Software
2016-12-01 07:06:23 ----D---- C:\AdwCleaner
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\ucrtbase.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-11-30 15:20:18 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-11-30 15:19:15 ----D---- C:\zálohy
2016-11-30 14:29:48 ----A---- C:\Windows\system32\drivers\semav6msr64.sys
2016-11-30 14:20:54 ----D---- C:\Users\Asus\AppData\Roaming\WinRAR
2016-11-30 14:20:12 ----D---- C:\Program Files\WinRAR
2016-11-30 13:55:53 ----D---- C:\Users\Asus\AppData\Roaming\Easeware
2016-11-30 13:11:56 ----D---- C:\Users\Asus\AppData\Roaming\Wise Euask

======List of files/folders modified in the last 1 month======

2016-12-02 21:34:51 ----RD---- C:\Program Files
2016-12-02 21:32:56 ----D---- C:\Windows\Temp
2016-12-02 21:29:53 ----D---- C:\Windows\SysWOW64
2016-12-02 21:29:16 ----D---- C:\Users\Asus\AppData\Roaming\Wise Disk Cleaner
2016-12-02 21:29:13 ----D---- C:\Windows\system32\catroot2
2016-12-02 21:29:00 ----D---- C:\Windows\system32\config
2016-12-02 21:28:51 ----D---- C:\Windows\System32
2016-12-02 21:28:51 ----D---- C:\Windows\inf
2016-12-02 21:28:51 ----D---- C:\Windows\debug
2016-12-02 21:28:51 ----D---- C:\Windows
2016-12-02 21:10:17 ----AC---- C:\Windows\system32\MRT.exe
2016-12-02 12:06:09 ----D---- C:\Windows\system32\LogFiles
2016-12-02 11:35:15 ----SD---- C:\Users\Asus\AppData\Roaming\Microsoft
2016-12-02 11:34:29 ----D---- C:\Windows\system32\Tasks
2016-12-02 09:20:49 ----SHD---- C:\System Volume Information
2016-12-02 02:15:27 ----RD---- C:\Program Files (x86)
2016-12-02 02:05:15 ----D---- C:\Windows\system32\drivers
2016-12-02 02:05:14 ----D---- C:\Windows\system32\DriverStore
2016-12-02 02:05:02 ----SHD---- C:\Windows\Installer
2016-12-02 02:04:11 ----HD---- C:\ProgramData
2016-12-01 22:57:25 ----D---- C:\Windows\Microsoft.NET
2016-12-01 22:32:58 ----D---- C:\Program Files\Common Files\Microsoft Shared
2016-12-01 22:23:54 ----D---- C:\Program Files\Microsoft Silverlight
2016-12-01 22:23:52 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-12-01 22:13:46 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2016-12-01 22:13:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-12-01 21:01:43 ----D---- C:\Program Files (x86)\ASUS
2016-12-01 19:34:48 ----D---- C:\Windows\Tasks
2016-12-01 18:10:15 ----D---- C:\Windows\winsxs
2016-12-01 14:19:21 ----D---- C:\Program Files\Intel
2016-12-01 14:17:53 ----D---- C:\Windows\system32\cs-CZ
2016-12-01 12:43:30 ----D---- C:\Program Files (x86)\Common Files
2016-12-01 12:36:47 ----D---- C:\ProgramData\Intel
2016-12-01 12:36:46 ----D---- C:\Windows\system32\catroot
2016-12-01 12:04:05 ----HD---- C:\Program Files (x86)\Temp
2016-12-01 11:46:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-12-01 11:18:57 ----D---- C:\Program Files (x86)\Intel
2016-12-01 10:36:46 ----D---- C:\Windows\Prefetch
2016-12-01 08:10:28 ----D---- C:\Program Files\Common Files
2016-11-30 15:13:06 ----D---- C:\Windows\SYSWOW64\config
2016-11-30 14:07:41 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-11-30 14:07:30 ----D---- C:\Windows\system32\Macromed
2016-11-30 14:07:22 ----D---- C:\Windows\SYSWOW64\Macromed
2016-11-30 13:21:04 ----D---- C:\Users\Asus\AppData\Roaming\vlc
2016-11-30 13:15:16 ----D---- C:\Users\Asus\AppData\Roaming\WiseUpdate
2016-11-30 12:31:07 ----RSD---- C:\Windows\Fonts
2016-11-30 12:29:46 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2016-10-13 212096]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-11-21 632168]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-11-21 28008]
R0 RapportHades64;RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [2016-11-22 235688]
R0 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [2016-11-22 489704]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-10-13 232072]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-10-13 177792]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-10-13 76416]
R1 EpfwLWF;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-10-13 59528]
R1 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-10-13 91784]
R1 RapportCerberus_1609053;RapportCerberus_1609053; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1609053.sys [2016-12-01 1181672]
R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2016-11-22 566248]
R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2016-11-22 548008]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-10-13 48768]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2015-02-12 139992]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2015-02-12 431832]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2000-01-01 5361920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-09-06 3074536]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2000-01-01 342528]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2000-01-01 129224]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2013-04-09 2430224]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 bpenum;Intel(R) Centrino(R) WiMAX Enumerator; C:\Windows\system32\DRIVERS\bpenum.sys [2012-07-03 84480]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 semav6msr64;semav6msr64; \??\C:\Windows\system32\drivers\semav6msr64.sys [2015-06-04 21984]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-10-21 82128]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-10-11 2815520]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-20 325656]
R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2016-11-22 2387952]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-07-14 107192]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-07-14 128696]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-30 270016]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2000-01-01 279024]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-08-02 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-30 172488]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-12-01 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-14 52920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pro Rudy prosím o ko logu

#2 Příspěvek od Rudy »

Zdravím!
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Users\Asus\AppData\Local\Microsoft\BingSvc
C:\PROGRA~1\MCAFEE~1\311~1.266

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]/64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc]/64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]/64

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
jaruneczka
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 417
Registrován: 09 čer 2008 11:45
Bydliště: Ostrava

Re: Pro Rudy prosím o ko logu

#3 Příspěvek od jaruneczka »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Asus at 2016-12-02 21:59:52
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 264 GB (87%) free of 305 GB
Total RAM: 4000 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:59:57, on 2.12.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18427)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\trend micro\Asus.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Rapport Management Service (RapportMgmtService) - IBM Corp. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7006 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
taskeng.exe {2D0163F3-A12C-4B49-A25A-6A2A269D5727}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\msiexec.exe /V
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
ATKOSD.exe
taskeng.exe {FDE9E578-99BA-41E3-A73C-74AB4F5B3E57}
taskeng.exe {C6006A44-C951-4B6C-99BE-0CC01BF5035B}
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
WDC.exe
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Asus\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\o09oei0j.default-1480641429522

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.207 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.207 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll


======Registry dump======

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmIcoSinglun64]
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKMEDIA]
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKOSD2]
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-25 322208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControlUser]
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2000-01-01 399856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAStorIcon]
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2000-01-01 172016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWirelessWiMAX]
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe /tasktray /nosplash []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2000-01-01 442352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg]
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2011-08-16 2277480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-09-05 12850792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicMasterTray]
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [2010-07-09 984400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2000-01-01 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-12-02 21:58:16 ----A---- C:\Windows\system32\FNTCACHE.DAT
2016-12-02 21:57:24 ----D---- C:\_OTM
2016-12-02 21:34:51 ----D---- C:\Program Files\trend micro
2016-12-02 21:34:50 ----D---- C:\rsit
2016-12-02 21:29:53 ----A---- C:\Windows\SYSWOW64\log.txt
2016-12-02 21:09:26 ----D---- C:\3d701750773c1929d0c83be87d5a
2016-12-02 09:09:58 ----D---- C:\Windows\SoftwareDistribution
2016-12-02 02:15:48 ----D---- C:\Users\Asus\AppData\Roaming\Mozilla
2016-12-02 02:15:27 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-02 02:14:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-12-02 02:11:12 ----D---- C:\Users\Asus\AppData\Roaming\ESET
2016-12-02 02:04:11 ----D---- C:\ProgramData\ESET
2016-12-02 02:04:11 ----D---- C:\Program Files\ESET
2016-12-02 01:52:36 ----SD---- C:\Windows\SYSWOW64\Microsoft
2016-12-01 21:59:33 ----A---- C:\Windows\woubak-pwrscheme-temp.txt
2016-12-01 21:59:33 ----A---- C:\Windows\woubak-pwrscheme-act.txt
2016-12-01 19:12:32 ----D---- C:\ProgramData\~0
2016-12-01 14:21:04 ----D---- C:\zamčené
2016-12-01 14:05:17 ----A---- C:\Windows\system32\drivers\RapportHades64.sys
2016-12-01 14:05:14 ----A---- C:\Windows\system32\drivers\RapportKE64.sys
2016-12-01 14:02:58 ----D---- C:\Program Files (x86)\Trusteer
2016-12-01 14:01:32 ----D---- C:\ProgramData\Trusteer
2016-12-01 13:27:25 ----D---- C:\ProgramData\Package Cache
2016-12-01 12:37:05 ----D---- C:\Users\Asus\AppData\Roaming\Intel Corporation
2016-12-01 11:46:10 ----D---- C:\Windows\SYSWOW64\Atheros_L1e
2016-12-01 11:44:59 ----A---- C:\Windows\system32\drivers\L1C62x64.sys
2016-12-01 11:18:21 ----A---- C:\Windows\system32\OpenCL.dll
2016-12-01 11:18:21 ----A---- C:\Windows\system32\IntelOpenCL64.dll
2016-12-01 11:18:11 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-12-01 11:18:11 ----A---- C:\Windows\SYSWOW64\IntelOpenCL32.dll
2016-12-01 10:52:12 ----A---- C:\Windows\system32\drivers\IntcDAud.sys
2016-12-01 10:52:11 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2016-12-01 10:52:08 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll
2016-12-01 10:52:08 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\IntcDAuC.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\iglhsip64.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\iglhcp64.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\igfxTMM.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\igfxsrvc.dll
2016-12-01 10:52:08 ----A---- C:\Windows\system32\igfxCoIn_v3223.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfxcmjit32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\SYSWOW64\igfx11cmrt32.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxress.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxpph.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxexps.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxdo.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\IGFXDEVLib.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxdev.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxcmrt64.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfxcmjit64.dll
2016-12-01 10:52:06 ----A---- C:\Windows\system32\igfx11cmrt64.dll
2016-12-01 10:52:05 ----A---- C:\Windows\SYSWOW64\igdumd32.dll
2016-12-01 10:52:05 ----A---- C:\Windows\system32\igdumd64.dll
2016-12-01 10:51:59 ----A---- C:\Windows\SYSWOW64\igdde32.dll
2016-12-01 10:51:59 ----A---- C:\Windows\system32\igdde64.dll
2016-12-01 10:51:58 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll
2016-12-01 10:51:55 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll
2016-12-01 10:51:55 ----A---- C:\Windows\system32\ig4icd64.dll
2016-12-01 10:51:55 ----A---- C:\Windows\system32\hccutils.dll
2016-12-01 10:51:55 ----A---- C:\Windows\system32\gfxSrvc.dll
2016-12-01 10:51:53 ----A---- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxtray.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxsrvc.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxpers.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\igfxext.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\hkcmd.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\GfxUI.exe
2016-12-01 10:51:53 ----A---- C:\Windows\system32\difx64.exe
2016-12-01 08:10:28 ----D---- C:\Program Files\Common Files\AV
2016-12-01 08:08:07 ----D---- C:\ProgramData\AVAST Software
2016-12-01 07:06:23 ----D---- C:\AdwCleaner
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\ucrtbase.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-11-30 15:20:21 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-11-30 15:20:18 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-11-30 15:19:15 ----D---- C:\zálohy
2016-11-30 14:29:48 ----A---- C:\Windows\system32\drivers\semav6msr64.sys
2016-11-30 14:20:54 ----D---- C:\Users\Asus\AppData\Roaming\WinRAR
2016-11-30 14:20:12 ----D---- C:\Program Files\WinRAR
2016-11-30 13:55:53 ----D---- C:\Users\Asus\AppData\Roaming\Easeware
2016-11-30 13:11:56 ----D---- C:\Users\Asus\AppData\Roaming\Wise Euask

======List of files/folders modified in the last 1 month======

2016-12-02 21:59:02 ----D---- C:\Windows\inf
2016-12-02 21:58:30 ----D---- C:\Windows
2016-12-02 21:58:27 ----D---- C:\Windows\debug
2016-12-02 21:58:16 ----D---- C:\Windows\System32
2016-12-02 21:57:43 ----D---- C:\Windows\Temp
2016-12-02 21:57:41 ----D---- C:\Windows\system32\catroot2
2016-12-02 21:40:05 ----D---- C:\Windows\system32\config
2016-12-02 21:34:51 ----RD---- C:\Program Files
2016-12-02 21:29:53 ----D---- C:\Windows\SysWOW64
2016-12-02 21:29:16 ----D---- C:\Users\Asus\AppData\Roaming\Wise Disk Cleaner
2016-12-02 21:10:17 ----AC---- C:\Windows\system32\MRT.exe
2016-12-02 12:06:09 ----D---- C:\Windows\system32\LogFiles
2016-12-02 11:35:15 ----SD---- C:\Users\Asus\AppData\Roaming\Microsoft
2016-12-02 11:34:29 ----D---- C:\Windows\system32\Tasks
2016-12-02 09:20:49 ----SHD---- C:\System Volume Information
2016-12-02 02:15:27 ----RD---- C:\Program Files (x86)
2016-12-02 02:05:15 ----D---- C:\Windows\system32\drivers
2016-12-02 02:05:14 ----D---- C:\Windows\system32\DriverStore
2016-12-02 02:05:02 ----SHD---- C:\Windows\Installer
2016-12-02 02:04:11 ----HD---- C:\ProgramData
2016-12-01 22:57:25 ----D---- C:\Windows\Microsoft.NET
2016-12-01 22:32:58 ----D---- C:\Program Files\Common Files\Microsoft Shared
2016-12-01 22:23:54 ----D---- C:\Program Files\Microsoft Silverlight
2016-12-01 22:23:52 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-12-01 22:13:46 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2016-12-01 22:13:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-12-01 21:01:43 ----D---- C:\Program Files (x86)\ASUS
2016-12-01 19:34:48 ----D---- C:\Windows\Tasks
2016-12-01 18:10:15 ----D---- C:\Windows\winsxs
2016-12-01 14:19:21 ----D---- C:\Program Files\Intel
2016-12-01 14:17:53 ----D---- C:\Windows\system32\cs-CZ
2016-12-01 12:43:30 ----D---- C:\Program Files (x86)\Common Files
2016-12-01 12:36:47 ----D---- C:\ProgramData\Intel
2016-12-01 12:36:46 ----D---- C:\Windows\system32\catroot
2016-12-01 12:04:05 ----HD---- C:\Program Files (x86)\Temp
2016-12-01 11:46:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-12-01 11:18:57 ----D---- C:\Program Files (x86)\Intel
2016-12-01 10:36:46 ----D---- C:\Windows\Prefetch
2016-12-01 08:10:28 ----D---- C:\Program Files\Common Files
2016-11-30 15:13:06 ----D---- C:\Windows\SYSWOW64\config
2016-11-30 14:07:41 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-11-30 14:07:30 ----D---- C:\Windows\system32\Macromed
2016-11-30 14:07:22 ----D---- C:\Windows\SYSWOW64\Macromed
2016-11-30 13:21:04 ----D---- C:\Users\Asus\AppData\Roaming\vlc
2016-11-30 13:15:16 ----D---- C:\Users\Asus\AppData\Roaming\WiseUpdate
2016-11-30 12:31:07 ----RSD---- C:\Windows\Fonts
2016-11-30 12:29:46 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2016-10-13 212096]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-11-21 632168]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-11-21 28008]
R0 RapportHades64;RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [2016-11-22 235688]
R0 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [2016-11-22 489704]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-10-13 232072]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-10-13 177792]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-10-13 76416]
R1 EpfwLWF;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-10-13 59528]
R1 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-10-13 91784]
R1 RapportCerberus_1609053;RapportCerberus_1609053; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1609053.sys [2016-12-01 1181672]
R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2016-11-22 566248]
R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2016-11-22 548008]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-10-13 48768]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2015-02-12 139992]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2015-02-12 431832]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2000-01-01 5361920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-09-06 3074536]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2000-01-01 342528]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2000-01-01 129224]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2013-04-09 2430224]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 bpenum;Intel(R) Centrino(R) WiMAX Enumerator; C:\Windows\system32\DRIVERS\bpenum.sys [2012-07-03 84480]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 semav6msr64;semav6msr64; \??\C:\Windows\system32\drivers\semav6msr64.sys [2015-06-04 21984]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-10-21 82128]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-10-11 2815520]
R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2016-11-22 2387952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-07-14 107192]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-07-14 128696]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-20 325656]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-30 270016]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2000-01-01 279024]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-08-02 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-30 172488]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-12-01 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-14 52920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pro Rudy prosím o ko logu

#4 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
jaruneczka
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 417
Registrován: 09 čer 2008 11:45
Bydliště: Ostrava

Re: Pro Rudy prosím o ko logu

#5 Příspěvek od jaruneczka »

win update stále nejde, hláška může být spuštěna jen jedna instalace wusa.exe... počkám tedy na prosincové update, jestli půjdou aspon ty, díky za pomoc

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pro Rudy prosím o ko logu

#6 Příspěvek od Rudy »

OK, rádo se stalo. Dejte pak vědět. :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
jaruneczka
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 417
Registrován: 09 čer 2008 11:45
Bydliště: Ostrava

Re: Pro Rudy prosím o ko logu

#7 Příspěvek od jaruneczka »

... mnohem horší věc, strašně to hřálo, myslela AC adaptér, odepla ho a furt horké, stáhla prográmek na teploty a žasnu!! nepoužitelné, bez opravy v servisu, za dost penízků, takže posílám zpět- odesílateli, na tomto by Luba nemohl dlouho hrát své hry ..no a dospořit penízky, až dostanu tyto zpět, na nový NTB. :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pro Rudy prosím o ko logu

#8 Příspěvek od Rudy »

Tak to je špatné. Muselo by se to vyčistit, což znamená kompletní rozborku.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
jaruneczka
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 417
Registrován: 09 čer 2008 11:45
Bydliště: Ostrava

Re: Pro Rudy prosím o ko logu

#9 Příspěvek od jaruneczka »

..a peníze...další, NTB jel bez baterie, imrvere v zásuvce, v servise říkali, pokud pomůže jen vyčištění a nová hmota, ale dle údajů, to může býti i něco vážnějšího. :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118241
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pro Rudy prosím o ko logu

#10 Příspěvek od Rudy »

Tak jistě, může. Pokud ale nepadá, nebo nedělá jiné nepřístojnosti, bude to jen znečištěné.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět