Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o preventivku, děkuji

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Prosím o preventivku, děkuji

#1 Příspěvek od Hanss1982 »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Othala at 2017-09-09 10:19:06
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 424 GB (44%) free of 953 GB
Total RAM: 8146 MB (78% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:19:10, on 9.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files\trend micro\Othala.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'Default user')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://192.168.0.1
O15 - ESC Trusted IP range: http://192.168.0.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 7551 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {C53A4013-8A99-4970-8EB1-CECD11473D2D}
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {A10DE261-6193-4FC5-9972-7F58C99EEEFC}
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_0000072c
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Othala\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Othala\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=60.0.3112.113 --initial-client-data=0x80,0x84,0x88,0x7c,0x8c,0x7fef20429b8,0x7fef20429f8,0x7fef20429d0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3236 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1104,2743658693216711453,5173115737625201608,131072 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,11,19,20,21,24,28,43,77 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x6719 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.300.1025.0 --gpu-driver-date=11-17-2015 --service-request-channel-token=6CA966F8DFF80C9F652408C214808393 --mojo-platform-channel-handle=1128 --ignored=" --type=renderer " /prefetch:2
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
taskeng.exe {9D054403-C87C-4357-9A14-05A8A1123048}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1104,2743658693216711453,5173115737625201608,131072 --service-pipe-token=C4A4F65EC701210AADD63F5383202350 --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=C4A4F65EC701210AADD63F5383202350 --renderer-client-id=6 --mojo-platform-channel-handle=4372 /prefetch:1
"C:\Users\Othala\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-07-11 229064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-08-05 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 2351920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-05 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-06-13 163536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 1743664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-06-12 6548112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avira SystrayStartTrigger]
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2017-08-30 97512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe /MONITOR []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLLSuite2016]
C:\Program Files (x86)\DLL Suite\DLLSuite.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe --startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2017-09-07 3071776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\World of Tanks]
C:\Games\World_of_Tanks\WargamingGameUpdater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Display Manager.lnk]
C:\PROGRA~2\Dell\DELLDI~1\ddm.exe [2017-05-03 747280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk]
C:\Windows\Installer\{A2D1D1B3-2C94-4E3A-BCD3-268F93010169}\app_icon.ico []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-09-08 12:25:46 ----D---- C:\Program Files (x86)\Spyware Terminator
2017-09-08 12:12:59 ----A---- C:\Windows\system32\WavesGUILib.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tosade.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tepeqapo64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo264.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSWOW64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSX64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSH64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSHP64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFSS_APO.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFNHK64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFCOM64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFAPO64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtPgEx64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2017-09-08 12:12:53 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCfg64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkAPO64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkApi64.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEP64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEL64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEG64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEED64A.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RTCOM64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DHT64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DAA64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoRes64.dat
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoInstII64.dll
2017-09-08 12:12:46 ----A---- C:\Windows\system32\R4EEP64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEL64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEG64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EED64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEA64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2017-09-08 12:12:43 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\KAAPORT64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\FMAPO64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2017-09-08 12:12:30 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2017-09-08 12:12:27 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-09-08 12:12:25 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-09-08 12:12:19 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2017-09-08 12:12:17 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAR64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAC64.dll
2017-09-08 11:56:07 ----D---- C:\Program Files\Realtek
2017-09-08 11:56:06 ----D---- C:\Windows\SYSWOW64\RTCOM
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE3.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE2.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\WavesGUILib64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\toseaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tosasfapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tbb_waves.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRRPTR64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRCOM64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRAPO64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sltech64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slprp64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slcnt64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sl3apo64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SEHDHF32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SECOMN32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDRA64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDHF64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SECOMN64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEAPO64.dll
2017-09-08 11:55:11 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2017-09-08 11:55:10 ----A---- C:\Windows\system32\drivers\rtkSSTsetting.dat
2017-09-08 11:55:08 ----A---- C:\Windows\system32\RtDataProc64.dll
2017-09-08 11:55:07 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2017-09-08 11:55:07 ----A---- C:\Windows\system32\RltkAPO64.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\MISS_APO.dll
2017-09-08 11:55:03 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2017-09-08 11:55:02 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2017-09-08 11:55:01 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2017-09-08 11:55:00 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2017-09-08 11:54:55 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2017-09-08 11:54:54 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2017-09-08 11:54:53 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2017-09-08 11:54:52 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMUI.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMLimiter.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMHVS.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMClariFi.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2APIPCLL.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2017-09-08 11:54:44 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2017-09-08 11:54:43 ----A---- C:\Windows\system32\DolbyDAX2APOvlldp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64A.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64AF3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64F3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DAX3APOv251.dll
2017-09-08 11:54:40 ----A---- C:\Windows\system32\DAX3APOProp.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64Proxy.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64APO.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CAF64APO2.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\Caf64api.dll
2017-09-08 11:54:33 ----A---- C:\Windows\system32\AudysseyEfx.dll
2017-09-08 11:54:31 ----A---- C:\Windows\system32\audioLibVc.dll
2017-09-08 11:54:30 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2017-09-08 11:11:17 ----D---- C:\ProgramData\Simply Super Software
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avipbb.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avdevprot.sys
2017-09-08 10:55:42 ----D---- C:\Program Files (x86)\Avira
2017-09-08 10:55:41 ----D---- C:\ProgramData\Avira
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RtNicProp64.dll
2017-09-08 10:42:25 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2017-09-02 19:22:55 ----D---- C:\Program Files (x86)\Steam
2017-08-24 10:49:59 ----D---- C:\Users\Othala\AppData\Roaming\R-Link 2 Toolbox
2017-08-11 19:18:18 ----D---- C:\Program Files\Common Files\McAfee
2017-08-11 19:18:17 ----D---- C:\Program Files (x86)\McAfee

======List of files/folders modified in the last 1 month======

2017-09-09 10:19:10 ----D---- C:\Windows\Prefetch
2017-09-09 10:19:08 ----D---- C:\Windows\Temp
2017-09-09 10:19:08 ----D---- C:\Program Files\trend micro
2017-09-09 10:15:32 ----AHD---- C:\ProgramData
2017-09-09 10:15:15 ----RD---- C:\Program Files (x86)
2017-09-09 10:15:00 ----SHD---- C:\Windows\Installer
2017-09-09 10:14:41 ----SHD---- C:\System Volume Information
2017-09-09 09:01:28 ----D---- C:\Windows\system32\config
2017-09-08 20:06:54 ----D---- C:\Users\Othala\AppData\Roaming\uTorrent
2017-09-08 19:37:56 ----RD---- C:\## Torrent
2017-09-08 19:36:19 ----D---- C:\Users\Othala\AppData\Roaming\MPC-HC
2017-09-08 12:25:49 ----D---- C:\Windows\system32\drivers
2017-09-08 12:18:39 ----D---- C:\Windows
2017-09-08 12:16:17 ----D---- C:\Windows\System32
2017-09-08 12:14:53 ----HD---- C:\Program Files (x86)\Temp
2017-09-08 12:14:12 ----D---- C:\Windows\SysWOW64
2017-09-08 12:14:07 ----D---- C:\Windows\inf
2017-09-08 12:13:25 ----D---- C:\Windows\system32\DriverStore
2017-09-08 12:12:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-09-08 12:07:31 ----D---- C:\Program Files (x86)\Common Files
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX3
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX2
2017-09-08 11:56:14 ----D---- C:\ProgramData\Audyssey Labs
2017-09-08 11:56:07 ----RD---- C:\Program Files
2017-09-08 11:51:40 ----D---- C:\Windows\system32\catroot
2017-09-08 11:49:00 ----D---- C:\Program Files (x86)\Realtek
2017-09-08 11:48:50 ----D---- C:\Windows\system32\catroot2
2017-09-08 11:06:37 ----D---- C:\Windows\system32\Tasks
2017-09-08 10:55:16 ----D---- C:\ProgramData\Package Cache
2017-09-08 10:52:57 ----D---- C:\ProgramData\MFAData
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RTNUninst64.dll
2017-09-08 10:22:23 ----D---- C:\Users\Othala\AppData\Roaming\IObit
2017-09-08 10:18:39 ----D---- C:\Windows\Logs
2017-09-08 10:18:07 ----RD---- C:\##FOTKY
2017-09-08 10:18:03 ----D---- C:\##RŮZNÉ
2017-09-07 16:18:37 ----D---- C:\ProgramData\CanonIJPLM
2017-09-04 17:12:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-02 19:48:00 ----RSD---- C:\Windows\assembly
2017-09-02 12:06:53 ----D---- C:\Program Files (x86)\OSCAR Editor X7
2017-08-23 17:53:04 ----D---- C:\##POHÁDKY
2017-08-23 10:51:20 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-08-23 10:17:03 ----RD---- C:\##HUDBA
2017-08-19 15:30:29 ----D---- C:\Windows\rescache
2017-08-12 09:10:59 ----D---- C:\Program Files\Common Files\AV
2017-08-11 19:18:18 ----D---- C:\Program Files\Common Files
2017-08-11 19:09:48 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-08-11 19:09:46 ----D---- C:\Windows\system32\Macromed
2017-08-11 19:09:44 ----D---- C:\Windows\SYSWOW64\Macromed
2017-08-11 18:57:52 ----D---- C:\Windows\debug
2017-08-11 16:43:19 ----D---- C:\Windows\Microsoft.NET
2017-08-10 12:58:00 ----D---- C:\Windows\winsxs
2017-08-10 12:54:14 ----D---- C:\Windows\SYSWOW64\migration
2017-08-10 12:54:14 ----D---- C:\Windows\SYSWOW64\en-US
2017-08-10 12:54:14 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-08-10 12:54:14 ----D---- C:\Program Files\Internet Explorer
2017-08-10 12:54:14 ----D---- C:\Program Files (x86)\Internet Explorer
2017-08-10 12:54:13 ----D---- C:\Windows\system32\migration
2017-08-10 12:54:13 ----D---- C:\Windows\system32\en-US
2017-08-10 12:54:13 ----D---- C:\Windows\system32\cs-CZ
2017-08-10 12:54:11 ----D---- C:\Windows\system32\Boot
2017-08-10 12:54:11 ----D---- C:\Windows\AppPatch
2017-08-10 12:37:52 ----D---- C:\ProgramData\Microsoft Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2016-06-13 85704]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2016-06-13 43720]
R0 avdevprot;avdevprot; C:\Windows\system32\DRIVERS\avdevprot.sys [2017-08-17 64504]
R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2017-08-17 34128]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2017-08-17 151128]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2017-08-17 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-06-13 26528]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2017-08-17 194912]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2017-08-17 78600]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2017-09-08 1049056]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
S1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys []
S3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 AtiDCM;AtiDCM; \??\C:\AMD\AMD-Catalyst-15.7.1-Without-DOTNet45-Win7-64bit\Bin64\atdcm64a.sys [2015-08-04 33992]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_usbccgpfilter;HwHandSet_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbccgpfilter.sys [2017-04-11 18944]
S3 GeneStor;Genesys Logic Storage Driver; C:\Windows\system32\DRIVERS\GeneStor.sys [2016-09-03 60928]
S3 MSICDSetup;MSICDSetup; \??\E:\CDriver64.sys []
S3 MWAC;MWAC; \??\C:\Windows\system32\drivers\ []
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys []
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2017-08-17 490968]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2017-08-17 490968]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-08-30 402768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [2017-04-11 192200]
R2 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2017-08-17 1128432]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2017-08-17 1525240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-07-14 116224]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-09-07 1610016]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-06-15 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-11 272384]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
S4 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2016-07-29 3046688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118199
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o preventivku, děkuji

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Prosím o preventivku, děkuji

#3 Příspěvek od Hanss1982 »

Děkuji, zde je log

# AdwCleaner 7.0.2.1 - Logfile created on Mon Sep 11 10:31:20 2017
# Updated on 2017/29/08 by Malwarebytes
# Database: 09-08-2017.1
# Running on Windows 7 Professional (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.AdvancedSystemCare, C:\Windows\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.Legacy, C:\ProgramData\IObit\ASCDownloader
PUP.Optional.Legacy, C:\ProgramData\Application Data\IObit\ASCDownloader
PUP.Optional.Legacy, C:\Users\All Users\IObit\ASCDownloader


***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

PUP.Optional.Legacy, Driver Booster Scheduler


***** [ Registry ] *****

PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IOBIT\ASC


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Legacy, Plugin found: Avira SafeSearch Plus -

/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271


*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [1395 B] - [2016/12/18 10:31:39]
C:/AdwCleaner/AdwCleaner[C2].txt - [1347 B] - [2017/1/1 15:15:59]
C:/AdwCleaner/AdwCleaner[S0].txt - [1595 B] - [2016/12/18 10:30:9]
C:/AdwCleaner/AdwCleaner[S1].txt - [1533 B] - [2016/12/21 9:31:18]
C:/AdwCleaner/AdwCleaner[S2].txt - [1634 B] - [2017/1/1 15:15:24]


########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt ##########
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118199
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o preventivku, děkuji

#4 Příspěvek od Rudy »

Pokud jste nálezy ADW smazal, dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Prosím o preventivku, děkuji

#5 Příspěvek od Hanss1982 »

děkuji,

Logfile of random's system information tool 1.10 (written by random/random)
Run by Othala at 2017-09-13 12:40:29
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 420 GB (44%) free of 953 GB
Total RAM: 8146 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:40:34, on 13.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files\trend micro\Othala.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'Default user')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://192.168.0.1
O15 - ESC Trusted IP range: http://192.168.0.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 7552 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
taskeng.exe {C2AADC15-A791-40F8-B19B-ACDAF26277FB}
"taskhost.exe"
taskeng.exe {F45A1B66-A943-4387-ADB2-A893C82C3EA9}
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_00000458
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Othala\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-07-11 229064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-08-05 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 2351920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-05 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-06-13 163536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 1743664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-06-12 6548112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avira SystrayStartTrigger]
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2017-08-30 97512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe /MONITOR []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLLSuite2016]
C:\Program Files (x86)\DLL Suite\DLLSuite.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe --startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2017-09-07 3071776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\World of Tanks]
C:\Games\World_of_Tanks\WargamingGameUpdater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Display Manager.lnk]
C:\PROGRA~2\Dell\DELLDI~1\ddm.exe [2017-05-03 747280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk]
C:\Windows\Installer\{A2D1D1B3-2C94-4E3A-BCD3-268F93010169}\app_icon.ico []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-09-09 10:21:00 ----D---- C:\Users\Othala\AppData\Roaming\Avira
2017-09-08 12:25:46 ----D---- C:\Program Files (x86)\Spyware Terminator
2017-09-08 12:12:59 ----A---- C:\Windows\system32\WavesGUILib.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tosade.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tepeqapo64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo264.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSWOW64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSX64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSH64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSHP64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFSS_APO.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFNHK64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFCOM64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFAPO64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtPgEx64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2017-09-08 12:12:53 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCfg64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkAPO64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkApi64.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEP64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEL64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEG64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEED64A.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RTCOM64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DHT64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DAA64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoRes64.dat
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoInstII64.dll
2017-09-08 12:12:46 ----A---- C:\Windows\system32\R4EEP64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEL64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEG64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EED64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEA64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2017-09-08 12:12:43 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\KAAPORT64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\FMAPO64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2017-09-08 12:12:30 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2017-09-08 12:12:27 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-09-08 12:12:25 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-09-08 12:12:19 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2017-09-08 12:12:17 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAR64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAC64.dll
2017-09-08 11:56:07 ----D---- C:\Program Files\Realtek
2017-09-08 11:56:06 ----D---- C:\Windows\SYSWOW64\RTCOM
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE3.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE2.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\WavesGUILib64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\toseaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tosasfapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tbb_waves.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRRPTR64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRCOM64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRAPO64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sltech64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slprp64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slcnt64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sl3apo64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SEHDHF32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SECOMN32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDRA64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDHF64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SECOMN64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEAPO64.dll
2017-09-08 11:55:11 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2017-09-08 11:55:10 ----A---- C:\Windows\system32\drivers\rtkSSTsetting.dat
2017-09-08 11:55:08 ----A---- C:\Windows\system32\RtDataProc64.dll
2017-09-08 11:55:07 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2017-09-08 11:55:07 ----A---- C:\Windows\system32\RltkAPO64.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\MISS_APO.dll
2017-09-08 11:55:03 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2017-09-08 11:55:02 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2017-09-08 11:55:01 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2017-09-08 11:55:00 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2017-09-08 11:54:55 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2017-09-08 11:54:54 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2017-09-08 11:54:53 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2017-09-08 11:54:52 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMUI.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMLimiter.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMHVS.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMClariFi.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2APIPCLL.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2017-09-08 11:54:44 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2017-09-08 11:54:43 ----A---- C:\Windows\system32\DolbyDAX2APOvlldp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64A.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64AF3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64F3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DAX3APOv251.dll
2017-09-08 11:54:40 ----A---- C:\Windows\system32\DAX3APOProp.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64Proxy.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64APO.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CAF64APO2.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\Caf64api.dll
2017-09-08 11:54:33 ----A---- C:\Windows\system32\AudysseyEfx.dll
2017-09-08 11:54:31 ----A---- C:\Windows\system32\audioLibVc.dll
2017-09-08 11:54:30 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2017-09-08 11:11:17 ----D---- C:\ProgramData\Simply Super Software
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avipbb.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avdevprot.sys
2017-09-08 10:55:42 ----D---- C:\Program Files (x86)\Avira
2017-09-08 10:55:41 ----D---- C:\ProgramData\Avira
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RtNicProp64.dll
2017-09-08 10:42:25 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2017-09-02 19:22:55 ----D---- C:\Program Files (x86)\Steam
2017-08-24 10:49:59 ----D---- C:\Users\Othala\AppData\Roaming\R-Link 2 Toolbox

======List of files/folders modified in the last 1 month======

2017-09-13 12:40:34 ----D---- C:\Windows\Temp
2017-09-13 12:40:32 ----D---- C:\Program Files\trend micro
2017-09-13 12:38:55 ----D---- C:\Windows\Prefetch
2017-09-13 12:38:46 ----D---- C:\ProgramData\IObit
2017-09-13 12:38:06 ----D---- C:\Windows\system32\config
2017-09-13 12:37:54 ----D---- C:\AdwCleaner
2017-09-11 12:33:06 ----D---- C:\Users\Othala\AppData\Roaming\uTorrent
2017-09-11 12:29:39 ----RD---- C:\## Torrent
2017-09-10 18:56:05 ----D---- C:\Windows\System32
2017-09-10 18:56:05 ----D---- C:\Windows\inf
2017-09-10 18:56:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-09 10:15:32 ----AHD---- C:\ProgramData
2017-09-09 10:15:15 ----RD---- C:\Program Files (x86)
2017-09-09 10:15:00 ----SHD---- C:\Windows\Installer
2017-09-09 10:14:41 ----SHD---- C:\System Volume Information
2017-09-08 19:36:19 ----D---- C:\Users\Othala\AppData\Roaming\MPC-HC
2017-09-08 12:25:49 ----D---- C:\Windows\system32\drivers
2017-09-08 12:18:39 ----D---- C:\Windows
2017-09-08 12:14:53 ----HD---- C:\Program Files (x86)\Temp
2017-09-08 12:14:12 ----D---- C:\Windows\SysWOW64
2017-09-08 12:13:25 ----D---- C:\Windows\system32\DriverStore
2017-09-08 12:12:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-09-08 12:07:31 ----D---- C:\Program Files (x86)\Common Files
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX3
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX2
2017-09-08 11:56:14 ----D---- C:\ProgramData\Audyssey Labs
2017-09-08 11:56:07 ----RD---- C:\Program Files
2017-09-08 11:51:40 ----D---- C:\Windows\system32\catroot
2017-09-08 11:49:00 ----D---- C:\Program Files (x86)\Realtek
2017-09-08 11:48:50 ----D---- C:\Windows\system32\catroot2
2017-09-08 11:06:37 ----D---- C:\Windows\system32\Tasks
2017-09-08 10:55:16 ----D---- C:\ProgramData\Package Cache
2017-09-08 10:52:57 ----D---- C:\ProgramData\MFAData
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RTNUninst64.dll
2017-09-08 10:22:23 ----D---- C:\Users\Othala\AppData\Roaming\IObit
2017-09-08 10:18:39 ----D---- C:\Windows\Logs
2017-09-08 10:18:07 ----RD---- C:\##FOTKY
2017-09-08 10:18:03 ----D---- C:\##RŮZNÉ
2017-09-07 16:18:37 ----D---- C:\ProgramData\CanonIJPLM
2017-09-02 19:48:00 ----RSD---- C:\Windows\assembly
2017-09-02 12:06:53 ----D---- C:\Program Files (x86)\OSCAR Editor X7
2017-08-23 17:53:04 ----D---- C:\##POHÁDKY
2017-08-23 10:51:20 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-08-23 10:17:03 ----RD---- C:\##HUDBA
2017-08-19 15:30:29 ----D---- C:\Windows\rescache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2016-06-13 85704]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2016-06-13 43720]
R0 avdevprot;avdevprot; C:\Windows\system32\DRIVERS\avdevprot.sys [2017-08-17 64504]
R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2017-08-17 34128]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2017-08-17 151128]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2017-08-17 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-06-13 26528]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2017-08-17 194912]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2017-08-17 78600]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2017-09-08 1049056]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
S1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys []
S3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 AtiDCM;AtiDCM; \??\C:\AMD\AMD-Catalyst-15.7.1-Without-DOTNet45-Win7-64bit\Bin64\atdcm64a.sys [2015-08-04 33992]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_usbccgpfilter;HwHandSet_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbccgpfilter.sys [2017-04-11 18944]
S3 GeneStor;Genesys Logic Storage Driver; C:\Windows\system32\DRIVERS\GeneStor.sys [2016-09-03 60928]
S3 MSICDSetup;MSICDSetup; \??\E:\CDriver64.sys []
S3 MWAC;MWAC; \??\C:\Windows\system32\drivers\ []
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys []
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2017-08-17 490968]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2017-08-17 490968]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-08-30 402768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [2017-04-11 192200]
R2 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2017-08-17 1128432]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2017-08-17 1525240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-07-14 116224]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-09-07 1610016]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-06-15 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-11 272384]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
S4 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2016-07-29 3046688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118199
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o preventivku, děkuji

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:

:reg
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Prosím o preventivku, děkuji

#7 Příspěvek od Hanss1982 »

Děkuji,

Logfile of random's system information tool 1.10 (written by random/random)
Run by Othala at 2017-09-14 21:28:40
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 412 GB (43%) free of 953 GB
Total RAM: 8146 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:28:51, on 14.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files\trend micro\Othala.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'Default user')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://192.168.0.1
O15 - ESC Trusted IP range: http://192.168.0.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 7564 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {95D953CD-C1CA-48A6-865F-2A0208873891}
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
taskeng.exe {1D5284A9-C4A2-4C64-8433-EBDAD8876A95}
"C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_000007dc
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Othala\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-08-24 229072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-08-05 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 2351920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-05 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24 163536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 1743664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-06-12 6548112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avira SystrayStartTrigger]
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2017-08-30 97512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe /MONITOR []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLLSuite2016]
C:\Program Files (x86)\DLL Suite\DLLSuite.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe --startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2017-09-07 3071776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\World of Tanks]
C:\Games\World_of_Tanks\WargamingGameUpdater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Display Manager.lnk]
C:\PROGRA~2\Dell\DELLDI~1\ddm.exe [2017-05-03 747280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk]
C:\Windows\Installer\{A2D1D1B3-2C94-4E3A-BCD3-268F93010169}\app_icon.ico []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-09-13 12:55:27 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-09-13 12:55:27 ----A---- C:\Windows\system32\mshtml.dll
2017-09-13 12:55:26 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-09-13 12:55:26 ----A---- C:\Windows\system32\ieframe.dll
2017-09-13 12:55:25 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-09-13 12:55:25 ----A---- C:\Windows\system32\jscript9.dll
2017-09-13 12:55:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-09-13 12:55:24 ----A---- C:\Windows\system32\wininet.dll
2017-09-13 12:55:23 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-09-13 12:55:23 ----A---- C:\Windows\system32\iertutil.dll
2017-09-13 12:55:22 ----A---- C:\Windows\system32\win32k.sys
2017-09-13 12:55:22 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2017-09-13 12:55:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-09-13 12:55:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2017-09-13 12:55:21 ----A---- C:\Windows\SYSWOW64\DXPTaskRingtone.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\urlmon.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\shell32.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\mmcndmgr.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\mmc.exe
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-09-13 12:55:20 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-09-13 12:55:20 ----A---- C:\Windows\system32\msfeeds.dll
2017-09-13 12:55:20 ----A---- C:\Windows\system32\localspl.dll
2017-09-13 12:55:19 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2017-09-13 12:55:19 ----A---- C:\Windows\SYSWOW64\mmc.exe
2017-09-13 12:55:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-09-13 12:55:19 ----A---- C:\Windows\system32\win32spl.dll
2017-09-13 12:55:19 ----A---- C:\Windows\system32\iedkcs32.dll
2017-09-13 12:55:18 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2017-09-13 12:55:18 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2017-09-13 12:55:18 ----A---- C:\Windows\SYSWOW64\usp10.dll
2017-09-13 12:55:18 ----A---- C:\Windows\system32\Wldap32.dll
2017-09-13 12:55:18 ----A---- C:\Windows\system32\usp10.dll
2017-09-13 12:55:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-09-13 12:55:18 ----A---- C:\Windows\system32\ie4uinit.exe
2017-09-13 12:55:18 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-09-13 12:55:18 ----A---- C:\Windows\system32\cic.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\ntprint.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\mmcshext.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\mmcbase.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\cic.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\winnsi.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\webcheck.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\shdocvw.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\ntprint.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\ntdll.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\nsisvc.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\msrating.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\mshtmled.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\mmcshext.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\mmcbase.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\dxtrans.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\dxtmsft.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\nsiproxy.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\netbt.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\certcli.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\winnsi.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ole32.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\nsi.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\vbscript.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\smss.exe
2017-09-13 12:55:16 ----A---- C:\Windows\system32\rpcss.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\rpcrt4.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ole32.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\occache.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\nsi.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\lsasrv.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\kerberos.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\jsproxy.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\jscript9diag.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\jscript.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\inseng.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieUnatt.exe
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieui.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\iesetup.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\iernonce.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieapfltr.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-09-13 12:55:16 ----A---- C:\Windows\system32\drivers\srv.sys
2017-09-13 12:55:16 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ntprint.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\netbtugc.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\comcat.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wpnpinst.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wow64win.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wow64cpu.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wow64.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\winsrv.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wdigest.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\TSpkg.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\sspisrv.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\sspicli.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\srcore.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\srclient.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\schannel.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\secur32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\rstrui.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\rpchttp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ntvdm64.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ntprint.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\netbtugc.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ncrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\msv1_0.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\lsass.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\KernelBase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\kernel32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\inetppui.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\inetpp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-09-13 12:55:15 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-09-13 12:55:15 ----A---- C:\Windows\system32\drivers\appid.sys
2017-09-13 12:55:15 ----A---- C:\Windows\system32\csrsrv.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\cryptbase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\credssp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\conhost.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\comcat.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\bcrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\auditpol.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidsvc.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidapi.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\apisetschema.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\advapi32.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\user.exe
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\oleres.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\PrintBrmUi.exe
2017-09-13 12:55:14 ----A---- C:\Windows\system32\oleres.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\msobjs.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\msaudite.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\adtschema.dll
2017-09-09 10:21:00 ----D---- C:\Users\Othala\AppData\Roaming\Avira
2017-09-08 12:25:46 ----D---- C:\Program Files (x86)\Spyware Terminator
2017-09-08 12:12:59 ----A---- C:\Windows\system32\WavesGUILib.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tosade.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tepeqapo64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo264.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSWOW64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSX64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSH64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSHP64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFSS_APO.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFNHK64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFCOM64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFAPO64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtPgEx64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2017-09-08 12:12:53 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCfg64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkAPO64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkApi64.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEP64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEL64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEG64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEED64A.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RTCOM64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DHT64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DAA64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoRes64.dat
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoInstII64.dll
2017-09-08 12:12:46 ----A---- C:\Windows\system32\R4EEP64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEL64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEG64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EED64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEA64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2017-09-08 12:12:43 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\KAAPORT64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\FMAPO64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2017-09-08 12:12:30 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2017-09-08 12:12:27 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-09-08 12:12:25 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-09-08 12:12:19 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2017-09-08 12:12:17 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAR64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAC64.dll
2017-09-08 11:56:07 ----D---- C:\Program Files\Realtek
2017-09-08 11:56:06 ----D---- C:\Windows\SYSWOW64\RTCOM
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE3.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE2.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\WavesGUILib64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\toseaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tosasfapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tbb_waves.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRRPTR64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRCOM64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRAPO64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sltech64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slprp64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slcnt64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sl3apo64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SEHDHF32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SECOMN32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDRA64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDHF64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SECOMN64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEAPO64.dll
2017-09-08 11:55:11 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2017-09-08 11:55:10 ----A---- C:\Windows\system32\drivers\rtkSSTsetting.dat
2017-09-08 11:55:08 ----A---- C:\Windows\system32\RtDataProc64.dll
2017-09-08 11:55:07 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2017-09-08 11:55:07 ----A---- C:\Windows\system32\RltkAPO64.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\MISS_APO.dll
2017-09-08 11:55:03 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2017-09-08 11:55:02 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2017-09-08 11:55:01 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2017-09-08 11:55:00 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2017-09-08 11:54:55 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2017-09-08 11:54:54 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2017-09-08 11:54:53 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2017-09-08 11:54:52 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMUI.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMLimiter.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMHVS.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMClariFi.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2APIPCLL.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2017-09-08 11:54:44 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2017-09-08 11:54:43 ----A---- C:\Windows\system32\DolbyDAX2APOvlldp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64A.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64AF3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64F3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DAX3APOv251.dll
2017-09-08 11:54:40 ----A---- C:\Windows\system32\DAX3APOProp.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64Proxy.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64APO.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CAF64APO2.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\Caf64api.dll
2017-09-08 11:54:33 ----A---- C:\Windows\system32\AudysseyEfx.dll
2017-09-08 11:54:31 ----A---- C:\Windows\system32\audioLibVc.dll
2017-09-08 11:54:30 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2017-09-08 11:11:17 ----D---- C:\ProgramData\Simply Super Software
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avipbb.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avdevprot.sys
2017-09-08 10:55:42 ----D---- C:\Program Files (x86)\Avira
2017-09-08 10:55:41 ----D---- C:\ProgramData\Avira
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RtNicProp64.dll
2017-09-08 10:42:25 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2017-09-02 19:22:55 ----D---- C:\Program Files (x86)\Steam
2017-08-24 10:49:59 ----D---- C:\Users\Othala\AppData\Roaming\R-Link 2 Toolbox

======List of files/folders modified in the last 1 month======

2017-09-14 21:28:49 ----D---- C:\Windows\Temp
2017-09-14 21:28:49 ----D---- C:\Program Files\trend micro
2017-09-14 18:02:38 ----D---- C:\Windows\system32\config
2017-09-14 17:49:13 ----SHD---- C:\Windows\Installer
2017-09-14 17:49:04 ----D---- C:\ProgramData\Microsoft Help
2017-09-14 17:45:06 ----D---- C:\Windows\system32\MRT
2017-09-14 17:40:34 ----D---- C:\Windows\debug
2017-09-14 17:40:22 ----AC---- C:\Windows\system32\MRT.exe
2017-09-14 17:39:17 ----RSD---- C:\Windows\Fonts
2017-09-14 17:33:31 ----D---- C:\Windows\System32
2017-09-14 17:33:31 ----D---- C:\Windows\inf
2017-09-14 17:33:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-14 17:33:01 ----SHD---- C:\System Volume Information
2017-09-14 17:28:00 ----D---- C:\Windows\winsxs
2017-09-14 17:24:54 ----D---- C:\Windows\SYSWOW64\en-US
2017-09-14 17:24:54 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-09-14 17:24:54 ----D---- C:\Program Files\Internet Explorer
2017-09-14 17:24:54 ----D---- C:\Program Files (x86)\Internet Explorer
2017-09-14 17:24:53 ----D---- C:\Windows\SysWOW64
2017-09-14 17:24:52 ----D---- C:\Windows\system32\en-US
2017-09-14 17:24:52 ----D---- C:\Windows\system32\drivers
2017-09-14 17:24:52 ----D---- C:\Windows\system32\cs-CZ
2017-09-14 17:24:49 ----D---- C:\Windows\AppPatch
2017-09-14 17:24:48 ----D---- C:\Windows\system32\Boot
2017-09-13 20:10:43 ----RSD---- C:\Windows\assembly
2017-09-13 20:07:44 ----D---- C:\Windows\Microsoft.NET
2017-09-13 20:02:32 ----A---- C:\Windows\win.ini
2017-09-13 20:02:03 ----D---- C:\Windows\system32\catroot2
2017-09-13 20:00:26 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-09-13 19:59:58 ----D---- C:\Windows\Prefetch
2017-09-13 19:46:28 ----D---- C:\Users\Othala\AppData\Roaming\uTorrent
2017-09-13 18:19:24 ----RD---- C:\## Torrent
2017-09-13 12:38:46 ----D---- C:\ProgramData\IObit
2017-09-13 12:37:54 ----D---- C:\AdwCleaner
2017-09-09 10:15:32 ----AHD---- C:\ProgramData
2017-09-09 10:15:15 ----RD---- C:\Program Files (x86)
2017-09-08 19:36:19 ----D---- C:\Users\Othala\AppData\Roaming\MPC-HC
2017-09-08 12:18:39 ----D---- C:\Windows
2017-09-08 12:14:53 ----HD---- C:\Program Files (x86)\Temp
2017-09-08 12:13:25 ----D---- C:\Windows\system32\DriverStore
2017-09-08 12:12:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-09-08 12:07:31 ----D---- C:\Program Files (x86)\Common Files
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX3
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX2
2017-09-08 11:56:14 ----D---- C:\ProgramData\Audyssey Labs
2017-09-08 11:56:07 ----RD---- C:\Program Files
2017-09-08 11:51:40 ----D---- C:\Windows\system32\catroot
2017-09-08 11:49:00 ----D---- C:\Program Files (x86)\Realtek
2017-09-08 11:06:37 ----D---- C:\Windows\system32\Tasks
2017-09-08 10:55:16 ----D---- C:\ProgramData\Package Cache
2017-09-08 10:52:57 ----D---- C:\ProgramData\MFAData
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RTNUninst64.dll
2017-09-08 10:22:23 ----D---- C:\Users\Othala\AppData\Roaming\IObit
2017-09-08 10:18:39 ----D---- C:\Windows\Logs
2017-09-08 10:18:07 ----RD---- C:\##FOTKY
2017-09-08 10:18:03 ----D---- C:\##RŮZNÉ
2017-09-07 16:18:37 ----D---- C:\ProgramData\CanonIJPLM
2017-09-02 12:06:53 ----D---- C:\Program Files (x86)\OSCAR Editor X7
2017-08-23 17:53:04 ----D---- C:\##POHÁDKY
2017-08-23 10:17:03 ----RD---- C:\##HUDBA
2017-08-19 15:30:29 ----D---- C:\Windows\rescache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2016-06-13 85704]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2016-06-13 43720]
R0 avdevprot;avdevprot; C:\Windows\system32\DRIVERS\avdevprot.sys [2017-08-17 64504]
R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2017-08-17 34128]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2017-08-17 151128]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2017-08-17 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-06-13 26528]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2017-08-17 194912]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2017-08-17 78600]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2017-09-08 1049056]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
S1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys []
S3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 AtiDCM;AtiDCM; \??\C:\AMD\AMD-Catalyst-15.7.1-Without-DOTNet45-Win7-64bit\Bin64\atdcm64a.sys [2015-08-04 33992]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_usbccgpfilter;HwHandSet_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbccgpfilter.sys [2017-04-11 18944]
S3 GeneStor;Genesys Logic Storage Driver; C:\Windows\system32\DRIVERS\GeneStor.sys [2016-09-03 60928]
S3 MSICDSetup;MSICDSetup; \??\E:\CDriver64.sys []
S3 MWAC;MWAC; \??\C:\Windows\system32\drivers\ []
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys []
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2017-08-17 490968]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2017-08-17 490968]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-08-30 402768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [2017-04-11 192200]
R2 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2017-08-17 1128432]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2017-08-17 1525240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-08-13 116224]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-09-07 1610016]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-06-15 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-11 272384]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
S4 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2016-07-29 3046688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118199
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o preventivku, děkuji

#8 Příspěvek od Rudy »

PTM nemazal. Zkuste to ještě jednou, ale v nouz. režimu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Prosím o preventivku, děkuji

#9 Příspěvek od Hanss1982 »

Zdravím, zde je LOG od OTM

All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Othala
->Temp folder emptied: 1020214161 bytes
->Temporary Internet Files folder emptied: 11487924 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 389565721 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 1597280 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 777739337 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 1161 bytes
RecycleBin emptied: 997753039 bytes

Total Files Cleaned = 3 050,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Othala

User: Public

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 09152017_083956

Files moved on Reboot...
C:\Users\Othala\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Othala\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

Registry entries deleted on Reboot...
Obrázek

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Prosím o preventivku, děkuji

#10 Příspěvek od Hanss1982 »

A zde LOG RSIT

Logfile of random's system information tool 1.10 (written by random/random)
Run by Othala at 2017-09-15 08:43:34
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 415 GB (44%) free of 953 GB
Total RAM: 8146 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:43:42, on 15.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files\trend micro\Othala.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [AOD] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe AutoTune (User 'Default user')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://192.168.0.1
O15 - ESC Trusted IP range: http://192.168.0.1
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 7378 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {FF1FE318-0248-4A9A-8FB0-CB827344D69B}
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {2ED42C30-A6C5-4748-B27A-09C447B873A6}
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_00000740
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-356554100-59139773-4143874188-10002_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-356554100-59139773-4143874188-10002 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Othala\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Othala\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=60.0.3112.113 --initial-client-data=0x80,0x84,0x88,0x7c,0x8c,0x7fef18229b8,0x7fef18229f8,0x7fef18229d0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3000 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1100,8159685484317975129,11012603678776338872,131072 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,11,19,20,21,24,28,43,77 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x6719 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.300.1025.0 --gpu-driver-date=11-17-2015 --service-request-channel-token=8A431C5B77E057A5413A42C7212081C5 --mojo-platform-channel-handle=1140 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1100,8159685484317975129,11012603678776338872,131072 --service-pipe-token=7F63275F621F81770865DAD73EF204CA --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=7F63275F621F81770865DAD73EF204CA --renderer-client-id=5 --mojo-platform-channel-handle=3640 /prefetch:1
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
"C:\Users\Othala\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-08-24 229072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-08-05 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 2351920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-05 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24 163536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2017-02-23 1743664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-06-12 6548112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Avira SystrayStartTrigger]
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2017-08-30 97512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe /MONITOR []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLLSuite2016]
C:\Program Files (x86)\DLL Suite\DLLSuite.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe --startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2017-09-07 3071776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\World of Tanks]
C:\Games\World_of_Tanks\WargamingGameUpdater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Display Manager.lnk]
C:\PROGRA~2\Dell\DELLDI~1\ddm.exe [2017-05-03 747280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk]
C:\Windows\Installer\{A2D1D1B3-2C94-4E3A-BCD3-268F93010169}\app_icon.ico []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-08-17 919032]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-09-15 08:38:46 ----A---- C:\Windows\ntbtlog.txt
2017-09-13 12:55:27 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-09-13 12:55:27 ----A---- C:\Windows\system32\mshtml.dll
2017-09-13 12:55:26 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-09-13 12:55:26 ----A---- C:\Windows\system32\ieframe.dll
2017-09-13 12:55:25 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-09-13 12:55:25 ----A---- C:\Windows\system32\jscript9.dll
2017-09-13 12:55:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-09-13 12:55:24 ----A---- C:\Windows\system32\wininet.dll
2017-09-13 12:55:23 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-09-13 12:55:23 ----A---- C:\Windows\system32\iertutil.dll
2017-09-13 12:55:22 ----A---- C:\Windows\system32\win32k.sys
2017-09-13 12:55:22 ----A---- C:\Windows\system32\DXPTaskRingtone.dll
2017-09-13 12:55:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-09-13 12:55:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2017-09-13 12:55:21 ----A---- C:\Windows\SYSWOW64\DXPTaskRingtone.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\urlmon.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\shell32.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\mmcndmgr.dll
2017-09-13 12:55:21 ----A---- C:\Windows\system32\mmc.exe
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-09-13 12:55:20 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-09-13 12:55:20 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-09-13 12:55:20 ----A---- C:\Windows\system32\msfeeds.dll
2017-09-13 12:55:20 ----A---- C:\Windows\system32\localspl.dll
2017-09-13 12:55:19 ----A---- C:\Windows\SYSWOW64\mmcndmgr.dll
2017-09-13 12:55:19 ----A---- C:\Windows\SYSWOW64\mmc.exe
2017-09-13 12:55:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-09-13 12:55:19 ----A---- C:\Windows\system32\win32spl.dll
2017-09-13 12:55:19 ----A---- C:\Windows\system32\iedkcs32.dll
2017-09-13 12:55:18 ----A---- C:\Windows\SYSWOW64\Wldap32.dll
2017-09-13 12:55:18 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2017-09-13 12:55:18 ----A---- C:\Windows\SYSWOW64\usp10.dll
2017-09-13 12:55:18 ----A---- C:\Windows\system32\Wldap32.dll
2017-09-13 12:55:18 ----A---- C:\Windows\system32\usp10.dll
2017-09-13 12:55:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-09-13 12:55:18 ----A---- C:\Windows\system32\ie4uinit.exe
2017-09-13 12:55:18 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-09-13 12:55:18 ----A---- C:\Windows\system32\cic.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\ntprint.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\mmcshext.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\mmcbase.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\cic.dll
2017-09-13 12:55:17 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\winnsi.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\webcheck.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\shdocvw.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\ntprint.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\ntdll.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\nsisvc.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\msrating.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\mshtmled.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\mmcshext.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\mmcbase.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\dxtrans.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\dxtmsft.dll
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\nsiproxy.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\netbt.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-09-13 12:55:17 ----A---- C:\Windows\system32\certcli.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\winnsi.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ole32.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\nsi.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-09-13 12:55:16 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\vbscript.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\smss.exe
2017-09-13 12:55:16 ----A---- C:\Windows\system32\rpcss.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\rpcrt4.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ole32.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\occache.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\nsi.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\lsasrv.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\kerberos.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\jsproxy.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\jscript9diag.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\jscript.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\inseng.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieUnatt.exe
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieui.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\iesetup.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\iernonce.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-09-13 12:55:16 ----A---- C:\Windows\system32\ieapfltr.dll
2017-09-13 12:55:16 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-09-13 12:55:16 ----A---- C:\Windows\system32\drivers\srv.sys
2017-09-13 12:55:16 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 12:55:15 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ntprint.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\netbtugc.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\comcat.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-09-13 12:55:15 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wpnpinst.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wow64win.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wow64cpu.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wow64.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\winsrv.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\wdigest.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\TSpkg.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\sspisrv.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\sspicli.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\srcore.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\srclient.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\schannel.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\secur32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\rstrui.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\rpchttp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ntvdm64.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ntprint.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\netbtugc.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ncrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\msv1_0.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\lsass.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\KernelBase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\kernel32.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\inetppui.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\inetpp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-09-13 12:55:15 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-09-13 12:55:15 ----A---- C:\Windows\system32\drivers\appid.sys
2017-09-13 12:55:15 ----A---- C:\Windows\system32\csrsrv.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\cryptbase.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\credssp.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\conhost.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\comcat.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\bcrypt.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\auditpol.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidsvc.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-09-13 12:55:15 ----A---- C:\Windows\system32\appidapi.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\apisetschema.dll
2017-09-13 12:55:15 ----A---- C:\Windows\system32\advapi32.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\user.exe
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\oleres.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-09-13 12:55:14 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\PrintBrmUi.exe
2017-09-13 12:55:14 ----A---- C:\Windows\system32\oleres.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\msobjs.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\msaudite.dll
2017-09-13 12:55:14 ----A---- C:\Windows\system32\adtschema.dll
2017-09-09 10:21:00 ----D---- C:\Users\Othala\AppData\Roaming\Avira
2017-09-08 12:25:46 ----D---- C:\Program Files (x86)\Spyware Terminator
2017-09-08 12:12:59 ----A---- C:\Windows\system32\WavesGUILib.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tosade.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tepeqapo64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo264.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\tadefxapo.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSWOW64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSX64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSTSH64.dll
2017-09-08 12:12:58 ----A---- C:\Windows\system32\SRSHP64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFSS_APO.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFNHK64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFCOM64.dll
2017-09-08 12:12:55 ----A---- C:\Windows\system32\SFAPO64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtPgEx64.dll
2017-09-08 12:12:54 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2017-09-08 12:12:53 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2017-09-08 12:12:52 ----A---- C:\Windows\system32\RtkCfg64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkAPO64.dll
2017-09-08 12:12:51 ----A---- C:\Windows\system32\RtkApi64.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEP64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEL64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEEG64A.dll
2017-09-08 12:12:50 ----A---- C:\Windows\system32\RTEED64A.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RTCOM64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DHT64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\RP3DAA64.dll
2017-09-08 12:12:49 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoRes64.dat
2017-09-08 12:12:47 ----A---- C:\Windows\system32\RCoInstII64.dll
2017-09-08 12:12:46 ----A---- C:\Windows\system32\R4EEP64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEL64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEG64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EED64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\R4EEA64A.dll
2017-09-08 12:12:45 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2017-09-08 12:12:44 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2017-09-08 12:12:43 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2017-09-08 12:12:41 ----A---- C:\Windows\system32\KAAPORT64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\FMAPO64.dll
2017-09-08 12:12:33 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2017-09-08 12:12:32 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2017-09-08 12:12:30 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2017-09-08 12:12:27 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-09-08 12:12:25 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2017-09-08 12:12:24 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2017-09-08 12:12:23 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-09-08 12:12:19 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2017-09-08 12:12:17 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAR64.dll
2017-09-08 12:12:11 ----A---- C:\Windows\system32\AERTAC64.dll
2017-09-08 11:56:07 ----D---- C:\Program Files\Realtek
2017-09-08 11:56:06 ----D---- C:\Windows\SYSWOW64\RTCOM
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE3.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE2.dll
2017-09-08 11:55:15 ----A---- C:\Windows\system32\YamahaAE.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\WavesGUILib64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tossaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\toseaeapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tosasfapo64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\tbb_waves.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRRPTR64.dll
2017-09-08 11:55:14 ----A---- C:\Windows\system32\SRCOM64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRCOM.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\SRAPO64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sltech64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slprp64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\slcnt64.dll
2017-09-08 11:55:13 ----A---- C:\Windows\system32\sl3apo64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SEHDHF32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\SYSWOW64\SECOMN32.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDRA64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEHDHF64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SECOMN64.dll
2017-09-08 11:55:12 ----A---- C:\Windows\system32\SEAPO64.dll
2017-09-08 11:55:11 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2017-09-08 11:55:10 ----A---- C:\Windows\system32\drivers\rtkSSTsetting.dat
2017-09-08 11:55:08 ----A---- C:\Windows\system32\RtDataProc64.dll
2017-09-08 11:55:07 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2017-09-08 11:55:07 ----A---- C:\Windows\system32\RltkAPO64.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2017-09-08 11:55:04 ----A---- C:\Windows\system32\MISS_APO.dll
2017-09-08 11:55:03 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2017-09-08 11:55:02 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2017-09-08 11:55:01 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2017-09-08 11:55:00 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2017-09-08 11:54:55 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2017-09-08 11:54:54 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2017-09-08 11:54:53 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2017-09-08 11:54:52 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2017-09-08 11:54:51 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMUI.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMLimiter.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMHVS.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMEQ.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMClariFi.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HMAPO.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2APIPCLL.dll
2017-09-08 11:54:50 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2017-09-08 11:54:44 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2017-09-08 11:54:43 ----A---- C:\Windows\system32\DolbyDAX2APOvlldp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPP64A.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64AF3.dll
2017-09-08 11:54:42 ----A---- C:\Windows\system32\DDPO64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64AF3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPD64A.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64F3.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DDPA64.dll
2017-09-08 11:54:41 ----A---- C:\Windows\system32\DAX3APOv251.dll
2017-09-08 11:54:40 ----A---- C:\Windows\system32\DAX3APOProp.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64Proxy.dll
2017-09-08 11:54:37 ----A---- C:\Windows\system32\CX64APO.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\CAF64APO2.dll
2017-09-08 11:54:35 ----A---- C:\Windows\system32\Caf64api.dll
2017-09-08 11:54:33 ----A---- C:\Windows\system32\AudysseyEfx.dll
2017-09-08 11:54:31 ----A---- C:\Windows\system32\audioLibVc.dll
2017-09-08 11:54:30 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2017-09-08 11:11:17 ----D---- C:\ProgramData\Simply Super Software
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avipbb.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2017-09-08 10:58:25 ----A---- C:\Windows\system32\drivers\avdevprot.sys
2017-09-08 10:55:42 ----D---- C:\Program Files (x86)\Avira
2017-09-08 10:55:41 ----D---- C:\ProgramData\Avira
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RtNicProp64.dll
2017-09-08 10:42:25 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2017-09-02 19:22:55 ----D---- C:\Program Files (x86)\Steam
2017-08-24 10:49:59 ----D---- C:\Users\Othala\AppData\Roaming\R-Link 2 Toolbox

======List of files/folders modified in the last 1 month======

2017-09-15 08:43:39 ----D---- C:\Windows\Temp
2017-09-15 08:43:39 ----D---- C:\Program Files\trend micro
2017-09-15 08:40:16 ----D---- C:\Windows\System32
2017-09-15 08:40:16 ----D---- C:\Windows
2017-09-15 08:36:57 ----D---- C:\Windows\system32\config
2017-09-14 17:49:13 ----SHD---- C:\Windows\Installer
2017-09-14 17:49:04 ----D---- C:\ProgramData\Microsoft Help
2017-09-14 17:45:06 ----D---- C:\Windows\system32\MRT
2017-09-14 17:40:34 ----D---- C:\Windows\debug
2017-09-14 17:40:22 ----AC---- C:\Windows\system32\MRT.exe
2017-09-14 17:39:17 ----RSD---- C:\Windows\Fonts
2017-09-14 17:33:31 ----D---- C:\Windows\inf
2017-09-14 17:33:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-14 17:33:01 ----SHD---- C:\System Volume Information
2017-09-14 17:28:00 ----D---- C:\Windows\winsxs
2017-09-14 17:24:54 ----D---- C:\Windows\SYSWOW64\en-US
2017-09-14 17:24:54 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-09-14 17:24:54 ----D---- C:\Program Files\Internet Explorer
2017-09-14 17:24:54 ----D---- C:\Program Files (x86)\Internet Explorer
2017-09-14 17:24:53 ----D---- C:\Windows\SysWOW64
2017-09-14 17:24:52 ----D---- C:\Windows\system32\en-US
2017-09-14 17:24:52 ----D---- C:\Windows\system32\drivers
2017-09-14 17:24:52 ----D---- C:\Windows\system32\cs-CZ
2017-09-14 17:24:49 ----D---- C:\Windows\AppPatch
2017-09-14 17:24:48 ----D---- C:\Windows\system32\Boot
2017-09-13 20:10:43 ----RSD---- C:\Windows\assembly
2017-09-13 20:07:44 ----D---- C:\Windows\Microsoft.NET
2017-09-13 20:02:32 ----A---- C:\Windows\win.ini
2017-09-13 20:02:03 ----D---- C:\Windows\system32\catroot2
2017-09-13 20:00:26 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-09-13 19:59:58 ----D---- C:\Windows\Prefetch
2017-09-13 19:46:28 ----D---- C:\Users\Othala\AppData\Roaming\uTorrent
2017-09-13 18:19:24 ----RD---- C:\## Torrent
2017-09-13 12:38:46 ----D---- C:\ProgramData\IObit
2017-09-13 12:37:54 ----D---- C:\AdwCleaner
2017-09-09 10:15:32 ----AHD---- C:\ProgramData
2017-09-09 10:15:15 ----RD---- C:\Program Files (x86)
2017-09-08 19:36:19 ----D---- C:\Users\Othala\AppData\Roaming\MPC-HC
2017-09-08 12:14:53 ----HD---- C:\Program Files (x86)\Temp
2017-09-08 12:13:25 ----D---- C:\Windows\system32\DriverStore
2017-09-08 12:12:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-09-08 12:07:31 ----D---- C:\Program Files (x86)\Common Files
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX3
2017-09-08 11:56:14 ----D---- C:\Windows\system32\DAX2
2017-09-08 11:56:14 ----D---- C:\ProgramData\Audyssey Labs
2017-09-08 11:56:07 ----RD---- C:\Program Files
2017-09-08 11:51:40 ----D---- C:\Windows\system32\catroot
2017-09-08 11:49:00 ----D---- C:\Program Files (x86)\Realtek
2017-09-08 11:06:37 ----D---- C:\Windows\system32\Tasks
2017-09-08 10:55:16 ----D---- C:\ProgramData\Package Cache
2017-09-08 10:52:57 ----D---- C:\ProgramData\MFAData
2017-09-08 10:42:25 ----A---- C:\Windows\system32\RTNUninst64.dll
2017-09-08 10:22:23 ----D---- C:\Users\Othala\AppData\Roaming\IObit
2017-09-08 10:18:39 ----D---- C:\Windows\Logs
2017-09-08 10:18:07 ----RD---- C:\##FOTKY
2017-09-08 10:18:03 ----D---- C:\##RŮZNÉ
2017-09-07 16:18:37 ----D---- C:\ProgramData\CanonIJPLM
2017-09-02 12:06:53 ----D---- C:\Program Files (x86)\OSCAR Editor X7
2017-08-23 17:53:04 ----D---- C:\##POHÁDKY
2017-08-23 10:17:03 ----RD---- C:\##HUDBA
2017-08-19 15:30:29 ----D---- C:\Windows\rescache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2016-06-13 85704]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2016-06-13 43720]
R0 avdevprot;avdevprot; C:\Windows\system32\DRIVERS\avdevprot.sys [2017-08-17 64504]
R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2017-08-17 34128]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2017-08-17 151128]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2017-08-17 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-06-13 26528]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2017-08-17 194912]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2017-08-17 78600]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2017-09-08 1049056]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
S1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys []
S3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 AtiDCM;AtiDCM; \??\C:\AMD\AMD-Catalyst-15.7.1-Without-DOTNet45-Win7-64bit\Bin64\atdcm64a.sys [2015-08-04 33992]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_usbccgpfilter;HwHandSet_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbccgpfilter.sys [2017-04-11 18944]
S3 GeneStor;Genesys Logic Storage Driver; C:\Windows\system32\DRIVERS\GeneStor.sys [2016-09-03 60928]
S3 MSICDSetup;MSICDSetup; \??\E:\CDriver64.sys []
S3 MWAC;MWAC; \??\C:\Windows\system32\drivers\ []
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys []
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2017-08-17 490968]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2017-08-17 490968]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-08-30 402768]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [2017-04-11 192200]
R2 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2017-08-17 1128432]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2017-08-17 1525240]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-08-13 116224]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-09-07 1610016]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-06-15 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-11 272384]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-13 154440]
S4 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
S4 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2016-07-29 3046688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118199
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o preventivku, děkuji

#11 Příspěvek od Rudy »

Teď je to OK. Log je již čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Hanss1982
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 17 zář 2013 11:16
Bydliště: Brno

Re: Prosím o preventivku, děkuji

#12 Příspěvek od Hanss1982 »

Děkuji za pomoc mohu Vám poslat nějaký dar?
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118199
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o preventivku, děkuji

#13 Příspěvek od Rudy »

Nemáte zač! :) Vše o přispění na naše fórum najdete zde: https://forum.viry.cz/viewtopic.php?f=7&t=78175 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno