Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Bari
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 20 kvě 2011 09:06

Prosím o kontrolu logu

#1 Příspěvek od Bari »

Dobrý den.

Prosím o kontrolu logu. Na počítači byl problém s psaním diakritiky (zdvojování znaků mimo písmeno, pravděpodobně nějaký keylogger), což ale nějak odstranil nejspíš integrovaný MSE, ale nefungují Windows Update. Když chci dát vyhledat aktualizace, vyhodí to chybu, že nemůže vyhledat aktualizace, protože služba není spuštěna.

Notebook DELL Latitude E6420, Windows 7 Professional 64bit SP1, Microsoft Security Essentials.

Zkoušel jsem udělat rychlou kontrolu v Malwarebytes, ale nic to nenašlo.


RSIT log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by admin at 2013-04-02 10:24:15
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 35 GB (14%) free of 244 GB
Total RAM: 3977 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:24:20, on 2.4.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16521)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Microsoft Lync\communicator.exe
C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
C:\Program Files (x86)\Microsoft Lync\UcMapi.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Lync add-on BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Kooperativa - PDF Server.lnk = C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Canon LBP2900 Status Window.lnk = C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
O4 - Global Startup: Dell System Manager.lnk = C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra 'Tools' menuitem: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73888E2B-FF04-416C-8847-984D7FC4507F} (RtspVaPgCtrlNew2 Class) - http://192.168.30.2:5002/RtspVaPgDecNew2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0410B595-9815-4BBB-87D8-13D3C269B729}: NameServer = 192.168.1.1 192.168.1.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{911668B1-E281-494F-98F9-434E70F9A5D7}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1ED4646-9B86-4E99-ABAB-B966B236DA7A}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAED5936-BA1C-42FA-9A0C-3B8BF00AACE6}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CS1\Services\Tcpip\..\{0410B595-9815-4BBB-87D8-13D3C269B729}: NameServer = 192.168.1.1 192.168.1.201
O17 - HKLM\System\CS2\Services\Tcpip\..\{0410B595-9815-4BBB-87D8-13D3C269B729}: NameServer = 192.168.1.1 192.168.1.201
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Dell System Manager Service (dcpsysmgrsvc) - Dell Inc. - C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: O2SDIOAssist - Unknown owner - C:\Windows\SysWOW64\srvany.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: NTRU TSS v1.2.1.36 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Connect Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: Wave Authentication Manager Service - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: WV5Communication - LaCrosse Technology - C:\Program Files (x86)\HeavyWeatherWV5\HeavyWeatherService.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 15104 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
winlogon.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe 30035552
\??\C:\Windows\system32\conhost.exe "-16077734701567734343868355633-1559577673-1037233675-1177325971-1643657855104937923
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe"
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe"
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files\Common Files\SPBA\upeksvr.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE"
C:\Windows\system32\DRIVERS\o2flash.exe
C:\Windows\SysWOW64\srvany.exe
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\sysWOW64\SDIOAssist.exe
C:\Windows\system32\svchost.exe -k imgsvc
MSOIDSvcm.exe 2208
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\HeavyWeatherWV5\HeavyWeatherService.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe"
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe"
C:\Windows\system32\CNAB4RPD.EXE
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a192e0fc-11b0-4d8a-8433-358ed7330286 -SystemEventPortName:HostProcess-3820b512-5577-45b0-887e-fada69989ef9 -IoCancelEventPortName:HostProcess-5ed383a1-8753-4ac0-934a-4f7143a396b5 -NonStateChangingEventPortName:HostProcess-24ff83c2-1143-4ff2-8dd1-0d6e70bfeb5a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:cf35a95a-e524-458d-9bca-feb33e250795 -DeviceGroupId:
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler64.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe"
"C:\Program Files\DellTPad\Apoint.exe"
"C:\Program Files\DellTPad\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files\DellTPad\HidFind.exe"
"Apntex.exe"
"C:\Windows\System32\igfxpers.exe"
\??\C:\Windows\system32\conhost.exe "15735692861778237190363915499719755668-709009392-20435211592422435368959962
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe"
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
"C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Microsoft Lync\UcMapi.exe" -Embedding
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3708 CREDAT:209921 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3708 CREDAT:996427 /prefetch:2
"C:\Windows\System32\MsSpellCheckingFacility.exe" -Embedding
"C:\Users\admin\Desktop\RSITx64.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 6670496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-19 551840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-19 209824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll [2010-11-03 211720]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-19 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-19 170912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-25 525312]
"FreeFallProtection"=C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [2011-07-25 686704]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2011-07-20 611192]
"TdmNotify"=C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [2011-05-27 257392]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 1281512]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-01-08 172016]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-01-08 399856]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-01-08 441840]
"IntelPROSet"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2012-12-03 4790576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2005-02-16 221184]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe []
"Google Update"=C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-09 116648]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-11-06 283160]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Print2PDF Print Monitor"=C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [2011-10-04 220992]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
"MobileBroadband"=C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2011-07-14 279552]
"Communicator"=C:\Program Files (x86)\Microsoft Lync\communicator.exe [2012-09-28 12105344]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2012-12-14 512360]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Canon LBP2900 Status Window.lnk - C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
Dell System Manager.lnk - C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe

C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Kooperativa - PDF Server.lnk - C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-12-12 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\spba]
C:\Program Files\Common Files\SPBA\homefus2.dll [2010-09-15 2305872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 6670496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
wvauth

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\SysWOW64\msiexec.exe"="C:\Windows\SysWOW64\msiexec.exe:*:Generic Host Process"
"C:\Windows\SysWOW64\svchost.exe"="C:\Windows\SysWOW64\svchost.exe:*:Generic Host Process"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-04-02 10:24:15 ----D---- C:\rsit
2013-04-02 10:24:15 ----D---- C:\Program Files\trend micro
2013-04-02 10:12:14 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2013-04-02 10:11:54 ----D---- C:\ProgramData\Malwarebytes
2013-04-02 10:11:52 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-02 10:11:52 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-03-25 19:17:33 ----D---- C:\Users\admin\AppData\Roaming\Kyilca
2013-03-25 19:17:33 ----D---- C:\Users\admin\AppData\Roaming\Esy
2013-03-19 20:33:57 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-03-19 20:33:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-03-19 20:33:57 ----A---- C:\Windows\system32\elshyph.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\url.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\wininet.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\webcheck.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\urlmon.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\url.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-03-19 20:33:55 ----A---- C:\Windows\system32\msrating.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\msls31.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\jsproxy.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iesetup.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iertutil.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iernonce.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iedkcs32.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ieapfltr.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ieapfltr.dat
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ie4uinit.exe
2013-03-19 20:33:55 ----A---- C:\Windows\system32\icardie.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\dxtrans.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\dxtmsft.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\wextract.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\vbscript.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\pngfilt.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\occache.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtmler.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtmled.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtml.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshta.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeedssync.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeeds.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\licmgr10.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\jscript9.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\jscript.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\inseng.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\imgutil.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iexpress.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieUnatt.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieui.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iesysprep.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iepeers.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieframe.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-03-19 20:33:26 ----A---- C:\Windows\system32\ZLhp2600.DLL
2013-03-19 20:27:55 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-03-19 20:15:02 ----D---- C:\Program Files (x86)\Cisco
2013-03-19 20:14:59 ----D---- C:\ProgramData\Intel.sav
2013-03-19 20:13:45 ----D---- C:\ProgramData\Package Cache
2013-03-19 20:10:13 ----A---- C:\Windows\system32\javaws.exe
2013-03-19 20:10:11 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2013-03-19 20:10:11 ----A---- C:\Windows\system32\javaw.exe
2013-03-19 20:10:11 ----A---- C:\Windows\system32\java.exe
2013-03-19 20:09:45 ----D---- C:\Program Files\Java
2013-03-19 20:08:42 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\java.exe
2013-03-19 20:08:11 ----D---- C:\Program Files (x86)\Java
2013-03-19 17:35:25 ----D---- C:\Users\admin\AppData\Roaming\Mikrotik
2013-03-06 17:26:45 ----A---- C:\Windows\Uninstall_tkexe.exe
2013-03-06 17:26:44 ----D---- C:\Program Files (x86)\TKexe

======List of files/folders modified in the last 1 month======

2013-04-02 10:24:15 ----RD---- C:\Program Files
2013-04-02 10:20:45 ----D---- C:\Windows\Temp
2013-04-02 10:11:54 ----HD---- C:\ProgramData
2013-04-02 10:11:52 ----RD---- C:\Program Files (x86)
2013-04-02 10:11:52 ----AD---- C:\Windows\system32\drivers
2013-04-02 10:11:39 ----D---- C:\Windows\system32\config
2013-04-02 10:05:45 ----D---- C:\Windows\System32
2013-04-02 10:05:45 ----D---- C:\Windows\inf
2013-04-02 10:05:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-04-02 10:03:41 ----A---- C:\Windows\SYSWOW64\log.txt
2013-04-01 20:28:03 ----HD---- C:\Windows\system32\WLANProfiles
2013-03-25 19:17:37 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2013-03-25 10:24:06 ----D---- C:\Windows\system32\FxsTmp
2013-03-23 15:09:42 ----SHD---- C:\System Volume Information
2013-03-23 09:10:01 ----D---- C:\Windows
2013-03-22 10:49:34 ----D---- C:\Program Files (x86)\CDBurnerXP
2013-03-21 19:05:51 ----D---- C:\Users\admin\AppData\Roaming\Nokia
2013-03-21 19:03:48 ----D---- C:\Windows\system32\DriverStore
2013-03-21 19:03:48 ----D---- C:\Windows\system32\catroot2
2013-03-21 19:03:48 ----D---- C:\Windows\system32\catroot
2013-03-19 21:41:13 ----D---- C:\Windows\rescache
2013-03-19 21:16:22 ----D---- C:\Windows\winsxs
2013-03-19 21:15:59 ----D---- C:\Windows\SysWOW64
2013-03-19 21:15:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-03-19 21:15:16 ----D---- C:\Windows\system32\cs-CZ
2013-03-19 21:15:16 ----D---- C:\Program Files\Internet Explorer
2013-03-19 21:15:16 ----D---- C:\Program Files (x86)\Internet Explorer
2013-03-19 21:15:15 ----D---- C:\Windows\SYSWOW64\migration
2013-03-19 21:15:15 ----D---- C:\Windows\SYSWOW64\en-US
2013-03-19 21:15:15 ----D---- C:\Windows\system32\migration
2013-03-19 21:15:15 ----D---- C:\Windows\system32\en-US
2013-03-19 21:15:15 ----D---- C:\Windows\PolicyDefinitions
2013-03-19 20:36:33 ----D---- C:\Windows\Logs
2013-03-19 20:15:50 ----SHD---- C:\Windows\Installer
2013-03-19 20:15:45 ----D---- C:\Program Files\Intel
2013-03-19 20:12:15 ----D---- C:\Program Files (x86)\Intel
2013-03-19 20:10:07 ----A---- C:\Windows\system32\npdeployJava1.dll
2013-03-19 20:10:06 ----A---- C:\Windows\system32\deployJava1.dll
2013-03-19 20:08:50 ----D---- C:\Program Files (x86)\Common Files
2013-03-19 20:08:34 ----A---- C:\Windows\SYSWOW64\npdeployJava1.dll
2013-03-19 20:08:34 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-03-19 19:53:56 ----D---- C:\Users\admin\AppData\Roaming\vlc
2013-03-19 19:48:08 ----D---- C:\Windows\Downloaded Program Files
2013-03-19 19:48:08 ----D---- C:\Program Files\SystemRequirementsLab
2013-03-15 17:49:02 ----D---- C:\AgnisWork
2013-03-13 21:21:23 ----D---- C:\Program Files\Microsoft Silverlight
2013-03-13 21:21:23 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-03-13 21:20:52 ----D---- C:\Windows\AppPatch
2013-03-13 21:05:43 ----D---- C:\ProgramData\Microsoft Help
2013-03-13 21:02:37 ----A---- C:\Windows\system32\MRT.exe
2013-03-13 21:02:34 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel RAID Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-06 438808]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-01-20 230320]
R0 PBADRV;PBADRV; C:\Windows\system32\DRIVERS\PBADRV.sys [2010-07-21 32240]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer; C:\Windows\system32\DRIVERS\stdcfltn.sys [2011-07-15 22128]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 Acceler;Accelerometer Service; C:\Windows\system32\DRIVERS\accelern.sys [2011-07-22 27760]
R3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® + High Speed; C:\Windows\system32\DRIVERS\AMPPAL.sys [2012-12-08 163368]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x64; C:\Windows\system32\DRIVERS\Apfiltr.sys [2011-05-26 368464]
R3 cvusbdrv;Dell ControlVault; C:\Windows\System32\Drivers\cvusbdrv.sys [2011-05-10 38504]
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C; C:\Windows\system32\DRIVERS\e1c62x64.sys [2012-08-11 482128]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2011-07-12 86016]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-12-12 5353888]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2012-12-06 11518976]
R3 O2MDFRDR;O2MDFRDR; C:\Windows\system32\DRIVERS\O2MDFw7x64.sys [2011-01-03 72808]
R3 O2SDJRDR;O2SDJRDR; C:\Windows\system32\DRIVERS\o2sdjw7x64.sys [2011-03-23 83560]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2011-01-25 520192]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\Windows\system32\DRIVERS\adusbser.sys [2009-11-06 154112]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2012-03-23 507392]
S3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® + High Speed; C:\Windows\system32\DRIVERS\amppal.sys [2012-12-08 163368]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2012-02-24 348712]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2012-02-24 106536]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2012-02-24 138280]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2012-02-24 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2012-02-24 21416]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2011-07-12 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-07-12 13952]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\Windows\system32\DRIVERS\ewusbnet.sys [2009-07-23 132608]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2011-07-12 98816]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2011-07-12 28672]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2011-07-12 213504]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-07-23 116992]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2009-07-23 113792]
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-11-16 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-11-16 27136]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\drivers\nusb3hub.sys [2010-09-30 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\nusb3xhc.sys [2010-09-30 180736]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-11-16 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-11-16 9216]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-12-08 753704]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-09-12 135984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-10-15 953632]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2011-05-13 1043872]
R2 Credential Vault Host Storage;Credential Vault Host Storage; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2011-05-13 36768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 dcpsysmgrsvc;Dell System Manager Service; C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe [2011-07-28 519536]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2012-12-03 620848]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2012-09-06 170824]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-08-08 325912]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 22056]
R2 msoidsvc;Microsoft Online Services Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2012-05-17 2079520]
R2 O2FLASH;O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [2010-02-10 72296]
R2 O2SDIOAssist;O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [2003-04-18 8192]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2012-12-03 149296]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-25 296448]
R2 TdmService;TdmService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe [2011-05-27 3792240]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-08-08 2656536]
R2 VmbService;Vodafone Mobile Connect Service; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2011-07-14 9216]
R2 Wave Authentication Manager Service;Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2011-07-01 1600000]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S2 tcsd_win32.exe;NTRU TSS v1.2.1.36 TCS; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [2011-02-17 1633280]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-13 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-01-08 277488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SecureStorageService;SecureStorageService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe [2011-05-24 2154888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-02-24 1255736]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#2 Příspěvek od Rudy »

Zdravím!
1. Startmenu>přík. řádek>(napsat) servces.msc>Enter. Službu najděte a pokud opravdu není spuštěna, spusťte, nastavte na >automaticky<, uložte a restartujte PC.
2. Spusťte tuto utilitu:
Stáhněte AdwCleaner http://www.stahuj.centrum.cz/utility_a_ ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte na Search
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bari
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 20 kvě 2011 09:06

Re: Prosím o kontrolu logu

#3 Příspěvek od Bari »

Windows Update jsem opravil pomocí nástroje FixIt od Microsoftu.

Zde je log z adwcleaner

# AdwCleaner v2.200 - Log vytvooen 03/04/2013 v 08:24:24
# Aktualizováno 02/04/2013 Xplode
# Operaení systém : Windows 7 Professional Service Pack 1 (64 bits)
# Uživatel : admin - DELL
# Spuštin systém : Normální
# Spuštino z : C:\Users\admin\Desktop\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Nalezeno : C:\ProgramData\Ask

***** [Registry] *****

Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16521

[OK] Registry jsou eisté.

-\\ Google Chrome v26.0.1410.43

Soubor : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [1190 octets] - [03/04/2013 08:24:24]

########## EOF - C:\AdwCleaner[R1].txt - [1250 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#4 Příspěvek od Rudy »

Spusťte znovu ADWCleaner a klikněte na >Delete<. Vložte nový log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bari
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 20 kvě 2011 09:06

Re: Prosím o kontrolu logu

#5 Příspěvek od Bari »

Vyčištěno. Tento log se objevil po restartu počítače.


# AdwCleaner v2.200 - Log vytvooen 04/04/2013 v 19:26:32
# Aktualizováno 02/04/2013 Xplode
# Operaení systém : Windows 7 Professional Service Pack 1 (64 bits)
# Uživatel : admin - DELL
# Spuštin systém : Normální
# Spuštino z : C:\Users\admin\Desktop\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Vymazáno : C:\ProgramData\Ask

***** [Registry] *****

Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16521

[OK] Registry jsou eisté.

-\\ Google Chrome v26.0.1410.43

Soubor : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [1315 octets] - [03/04/2013 08:24:24]
AdwCleaner[R2].txt - [1375 octets] - [04/04/2013 19:26:08]
AdwCleaner[S1].txt - [1308 octets] - [04/04/2013 19:26:32]

########## EOF - C:\AdwCleaner[S1].txt - [1368 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#6 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bari
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 20 kvě 2011 09:06

Re: Prosím o kontrolu logu

#7 Příspěvek od Bari »

Logfile of random's system information tool 1.09 (written by random/random)
Run by admin at 2013-04-05 16:35:57
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 48 GB (20%) free of 244 GB
Total RAM: 3977 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:35:59, on 5.4.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16521)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Microsoft Lync\communicator.exe
C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
C:\Program Files (x86)\Microsoft Lync\UcMapi.exe
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Lync add-on BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Smart Settings.lnk = C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (User 'Default user')
O4 - Startup: Kooperativa - PDF Server.lnk = C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
O4 - Startup: Smart Settings.lnk = C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Canon LBP2900 Status Window.lnk = C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra 'Tools' menuitem: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73888E2B-FF04-416C-8847-984D7FC4507F} (RtspVaPgCtrlNew2 Class) - http://192.168.30.2:5002/RtspVaPgDecNew2.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.co ... 5.13.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0410B595-9815-4BBB-87D8-13D3C269B729}: NameServer = 192.168.1.1 192.168.1.201
O17 - HKLM\System\CCS\Services\Tcpip\..\{911668B1-E281-494F-98F9-434E70F9A5D7}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1ED4646-9B86-4E99-ABAB-B966B236DA7A}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAED5936-BA1C-42FA-9A0C-3B8BF00AACE6}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CS1\Services\Tcpip\..\{0410B595-9815-4BBB-87D8-13D3C269B729}: NameServer = 192.168.1.1 192.168.1.201
O17 - HKLM\System\CS2\Services\Tcpip\..\{0410B595-9815-4BBB-87D8-13D3C269B729}: NameServer = 192.168.1.1 192.168.1.201
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Dell Feature Enhancement Pack Service (DFEPService) - Dell Inc. - C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: O2SDIOAssist - Unknown owner - C:\Windows\SysWOW64\srvany.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: NTRU TSS v1.2.1.37 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Connect Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: WV5Communication - LaCrosse Technology - C:\Program Files (x86)\HeavyWeatherWV5\HeavyWeatherService.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 14572 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe 27188048
\??\C:\Windows\system32\conhost.exe "12572271813453635771394557667-1071799406-53291456711903799442119809041178888719
"C:\Program Files\Common Files\SPBA\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe"
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE"
C:\Windows\system32\DRIVERS\o2flash.exe
C:\Windows\SysWOW64\srvany.exe
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\sysWOW64\SDIOAssist.exe
C:\Windows\system32\svchost.exe -k imgsvc
MSOIDSvcm.exe 2144
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\HeavyWeatherWV5\HeavyWeatherService.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe"
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe"
C:\Windows\system32\CNAB4RPD.EXE
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ae93a953-7e7b-4f48-b247-0fc3d500e82f -SystemEventPortName:HostProcess-c899d5d3-4366-4dea-891d-b9bf3f1b3ba1 -IoCancelEventPortName:HostProcess-b9ecd49d-c0ce-4a0d-bff8-7dbc8add3308 -NonStateChangingEventPortName:HostProcess-6ffbd70f-ef7d-4b89-8b8d-96fd4e095027 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:83221d45-0835-4c1c-9fd6-89d3f4687803 -DeviceGroupId:
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler64.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe"
"C:\Program Files\DellTPad\Apoint.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\DellTPad\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe"
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "18387126811453727421-1543290960-19731369191825801631-948092835-3697897702013490571
"C:\Program Files\DellTPad\HidFind.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
"C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe"
"C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Microsoft Lync\UcMapi.exe" -Embedding
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Users\admin\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe109_ Global\UsGthrCtrlFltPipeMssGthrPipe109 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 6670496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-19 551840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-19 209824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll [2010-11-03 211720]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-19 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-19 170912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-25 525312]
"FreeFallProtection"=C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [2011-07-25 686704]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2011-07-20 611192]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 1281512]
"IntelPROSet"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2012-12-03 4790576]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-03-22 172016]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-03-22 399856]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-03-22 442352]
"DFEPApplication"=C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [2012-05-08 7078424]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2005-02-16 221184]
"Google Update"=C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-09 116648]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-11-06 283160]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Print2PDF Print Monitor"=C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [2011-10-04 220992]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
"MobileBroadband"=C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2011-07-14 279552]
"Communicator"=C:\Program Files (x86)\Microsoft Lync\communicator.exe [2012-09-28 12105344]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Canon LBP2900 Status Window.lnk - C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE

C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Kooperativa - PDF Server.lnk - C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
Smart Settings.lnk - C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-03-08 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\spba]
C:\Program Files\Common Files\SPBA\homefus2.dll [2010-09-15 2305872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 6670496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\SysWOW64\msiexec.exe"="C:\Windows\SysWOW64\msiexec.exe:*:Generic Host Process"
"C:\Windows\SysWOW64\svchost.exe"="C:\Windows\SysWOW64\svchost.exe:*:Generic Host Process"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-04-04 19:26:32 ----A---- C:\AdwCleaner[S1].txt
2013-04-04 19:26:08 ----A---- C:\AdwCleaner[R2].txt
2013-04-03 08:24:24 ----A---- C:\AdwCleaner[R1].txt
2013-04-02 14:07:04 ----A---- C:\Windows\system32\drivers\HECIx64.sys
2013-04-02 14:06:49 ----D---- C:\apps
2013-04-02 14:06:45 ----D---- C:\ProgramData\NTRU Cryptosystems
2013-04-02 14:06:45 ----D---- C:\Program Files\NTRU Cryptosystems
2013-04-02 14:06:45 ----D---- C:\Program Files (x86)\NTRU Cryptosystems
2013-04-02 14:06:01 ----A---- C:\Windows\SYSWOW64\pbadrvdll.dll
2013-04-02 14:06:01 ----A---- C:\Windows\system32\pbadrvdll.dll
2013-04-02 14:06:01 ----A---- C:\Windows\system32\drivers\PBADRV.SYS
2013-04-02 14:05:59 ----D---- C:\Program Files (x86)\Gemalto
2013-04-02 14:05:10 ----A---- C:\Windows\system32\brcmbsp.dll
2013-04-02 14:05:10 ----A---- C:\Windows\system32\bipbsp.dll
2013-04-02 14:05:00 ----D---- C:\Program Files\Broadcom Corporation
2013-04-02 14:02:29 ----SHD---- C:\Config.Msi
2013-04-02 13:42:12 ----D---- C:\Windows\{69093D49-3DD1-4FB5-A378-0D4DB4CF86EA}
2013-04-02 13:29:02 ----A---- C:\Windows\invcol.tmp
2013-04-02 11:58:59 ----RD---- C:\Program Files (x86)\Skype
2013-04-02 11:48:12 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2013-04-02 11:43:42 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2013-04-02 10:24:15 ----D---- C:\rsit
2013-04-02 10:24:15 ----D---- C:\Program Files\trend micro
2013-04-02 10:12:14 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2013-04-02 10:11:54 ----D---- C:\ProgramData\Malwarebytes
2013-04-02 10:11:52 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-02 10:11:52 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-03-25 19:17:33 ----D---- C:\Users\admin\AppData\Roaming\Kyilca
2013-03-25 19:17:33 ----D---- C:\Users\admin\AppData\Roaming\Esy
2013-03-22 10:14:30 ----A---- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxtray.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxsrvc.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxpers.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxext.exe
2013-03-22 10:14:26 ----A---- C:\Windows\system32\hkcmd.exe
2013-03-22 10:14:26 ----A---- C:\Windows\system32\GfxUI.exe
2013-03-22 10:14:26 ----A---- C:\Windows\system32\difx64.exe
2013-03-19 20:33:57 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-03-19 20:33:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-03-19 20:33:57 ----A---- C:\Windows\system32\elshyph.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\url.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\wininet.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\webcheck.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\urlmon.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\url.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-03-19 20:33:55 ----A---- C:\Windows\system32\msrating.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\msls31.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\jsproxy.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iesetup.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iertutil.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iernonce.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iedkcs32.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ieapfltr.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ieapfltr.dat
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ie4uinit.exe
2013-03-19 20:33:55 ----A---- C:\Windows\system32\icardie.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\dxtrans.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\dxtmsft.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\wextract.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\vbscript.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\pngfilt.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\occache.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtmler.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtmled.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtml.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshta.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeedssync.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeeds.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\licmgr10.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\jscript9.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\jscript.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\inseng.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\imgutil.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iexpress.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieUnatt.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieui.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iesysprep.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iepeers.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieframe.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-03-19 20:33:26 ----A---- C:\Windows\system32\ZLhp2600.DLL
2013-03-19 20:27:55 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-03-19 20:15:02 ----D---- C:\Program Files (x86)\Cisco
2013-03-19 20:14:59 ----D---- C:\ProgramData\Intel.sav
2013-03-19 20:13:45 ----D---- C:\ProgramData\Package Cache
2013-03-19 20:10:13 ----A---- C:\Windows\system32\javaws.exe
2013-03-19 20:10:11 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2013-03-19 20:10:11 ----A---- C:\Windows\system32\javaw.exe
2013-03-19 20:10:11 ----A---- C:\Windows\system32\java.exe
2013-03-19 20:09:45 ----D---- C:\Program Files\Java
2013-03-19 20:08:42 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\java.exe
2013-03-19 20:08:11 ----D---- C:\Program Files (x86)\Java
2013-03-19 17:35:25 ----D---- C:\Users\admin\AppData\Roaming\Mikrotik
2013-03-12 15:10:24 ----A---- C:\Windows\system32\igfxCoIn_v3062.dll
2013-03-08 19:12:10 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll
2013-03-08 19:10:18 ----A---- C:\Windows\system32\igdumd64.dll
2013-03-08 19:10:18 ----A---- C:\Windows\system32\igdde64.dll
2013-03-08 19:10:18 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2013-03-08 19:10:10 ----A---- C:\Windows\SYSWOW64\igdde32.dll
2013-03-08 19:09:50 ----A---- C:\Windows\system32\igfxress.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxTMM.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxpph.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxdo.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\IGFXDEVLib.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxdev.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\gfxSrvc.dll
2013-03-08 19:09:46 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll
2013-03-08 19:09:44 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2013-03-08 19:09:36 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll
2013-03-08 19:08:50 ----A---- C:\Windows\system32\ig4icd64.dll
2013-03-08 19:06:48 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2013-03-08 19:06:48 ----A---- C:\Windows\SYSWOW64\igfxcmjit32.dll
2013-03-08 19:06:48 ----A---- C:\Windows\SYSWOW64\igfx11cmrt32.dll
2013-03-08 19:06:48 ----A---- C:\Windows\system32\igfxcmrt64.dll
2013-03-08 19:06:48 ----A---- C:\Windows\system32\igfxcmjit64.dll
2013-03-08 19:06:48 ----A---- C:\Windows\system32\igfx11cmrt64.dll
2013-03-06 17:26:45 ----A---- C:\Windows\Uninstall_tkexe.exe
2013-03-06 17:26:44 ----D---- C:\Program Files (x86)\TKexe

======List of files/folders modified in the last 1 month======

2013-04-05 16:26:50 ----D---- C:\Windows\Temp
2013-04-05 01:54:56 ----D---- C:\Windows\system32\config
2013-04-04 19:32:09 ----D---- C:\Windows\System32
2013-04-04 19:32:09 ----D---- C:\Windows\inf
2013-04-04 19:32:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-04-04 19:30:02 ----A---- C:\Windows\SYSWOW64\log.txt
2013-04-04 19:26:39 ----HD---- C:\ProgramData
2013-04-03 08:30:12 ----SHD---- C:\System Volume Information
2013-04-02 14:32:16 ----D---- C:\Windows\winsxs
2013-04-02 14:13:45 ----D---- C:\ProgramData\Intel
2013-04-02 14:12:13 ----D---- C:\Windows
2013-04-02 14:11:57 ----D---- C:\Windows\system32\drivers\UMDF
2013-04-02 14:11:34 ----D---- C:\Windows\system32\catroot
2013-04-02 14:11:33 ----D---- C:\Windows\system32\DriverStore
2013-04-02 14:11:33 ----AD---- C:\Windows\system32\drivers
2013-04-02 14:07:19 ----D---- C:\Program Files (x86)\Intel
2013-04-02 14:06:46 ----SHD---- C:\Windows\Installer
2013-04-02 14:06:45 ----RD---- C:\Program Files (x86)
2013-04-02 14:06:45 ----RD---- C:\Program Files
2013-04-02 14:06:39 ----D---- C:\Program Files\Dell
2013-04-02 14:06:07 ----D---- C:\Program Files\Common Files\SPBA
2013-04-02 14:06:06 ----D---- C:\Program Files (x86)\Common Files
2013-04-02 14:06:01 ----DC---- C:\Windows\system32\DRVSTORE
2013-04-02 14:06:01 ----D---- C:\Windows\SysWOW64
2013-04-02 14:05:22 ----D---- C:\Windows\system32\wbem
2013-04-02 14:05:21 ----RSD---- C:\Windows\assembly
2013-04-02 14:05:10 ----A---- C:\Windows\system32\brcmbsp_log.txt
2013-04-02 14:05:03 ----D---- C:\Windows\system32\catroot2
2013-04-02 14:04:58 ----D---- C:\Windows\Downloaded Installations
2013-04-02 14:04:45 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-04-02 14:02:58 ----D---- C:\ProgramData\Wave Systems Corp
2013-04-02 14:00:36 ----A---- C:\Windows\system32\bioapi100.dll
2013-04-02 14:00:36 ----A---- C:\Windows\system32\bioapi_mds300.dll
2013-04-02 14:00:22 ----D---- C:\ProgramData\Dell
2013-04-02 13:42:18 ----D---- C:\Program Files (x86)\Dell
2013-04-02 13:21:45 ----D---- C:\Windows\SoftwareDistribution
2013-04-02 12:34:28 ----N---- C:\Windows\system32\MpSigStub.exe
2013-04-02 12:01:02 ----D---- C:\Users\admin\AppData\Roaming\Winamp
2013-04-02 12:01:01 ----D---- C:\Windows\Panther
2013-04-02 12:01:01 ----D---- C:\Windows\ModemLogs
2013-04-02 12:01:00 ----D---- C:\Windows\Logs
2013-04-02 12:01:00 ----D---- C:\Windows\debug
2013-04-02 11:59:41 ----D---- C:\Users\admin\AppData\Roaming\Skype
2013-04-02 11:59:05 ----D---- C:\ProgramData\Skype
2013-04-02 11:58:20 ----D---- C:\Windows\system32\Tasks
2013-04-02 11:47:49 ----D---- C:\Program Files (x86)\Nokia
2013-04-02 11:43:43 ----D---- C:\Windows\Downloaded Program Files
2013-04-02 11:41:45 ----D---- C:\Program Files\CCleaner
2013-04-01 20:28:03 ----HD---- C:\Windows\system32\WLANProfiles
2013-03-25 19:17:37 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2013-03-25 10:24:06 ----D---- C:\Windows\system32\FxsTmp
2013-03-22 10:49:34 ----D---- C:\Program Files (x86)\CDBurnerXP
2013-03-21 19:05:51 ----D---- C:\Users\admin\AppData\Roaming\Nokia
2013-03-19 21:41:13 ----D---- C:\Windows\rescache
2013-03-19 21:15:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-03-19 21:15:16 ----D---- C:\Windows\system32\cs-CZ
2013-03-19 21:15:16 ----D---- C:\Program Files\Internet Explorer
2013-03-19 21:15:16 ----D---- C:\Program Files (x86)\Internet Explorer
2013-03-19 21:15:15 ----D---- C:\Windows\SYSWOW64\migration
2013-03-19 21:15:15 ----D---- C:\Windows\SYSWOW64\en-US
2013-03-19 21:15:15 ----D---- C:\Windows\system32\migration
2013-03-19 21:15:15 ----D---- C:\Windows\system32\en-US
2013-03-19 21:15:15 ----D---- C:\Windows\PolicyDefinitions
2013-03-19 20:15:45 ----D---- C:\Program Files\Intel
2013-03-19 20:10:07 ----A---- C:\Windows\system32\npdeployJava1.dll
2013-03-19 20:10:06 ----A---- C:\Windows\system32\deployJava1.dll
2013-03-19 20:08:34 ----A---- C:\Windows\SYSWOW64\npdeployJava1.dll
2013-03-19 20:08:34 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-03-19 19:53:56 ----D---- C:\Users\admin\AppData\Roaming\vlc
2013-03-19 19:48:08 ----D---- C:\Program Files\SystemRequirementsLab
2013-03-15 17:49:02 ----D---- C:\AgnisWork
2013-03-13 21:21:23 ----D---- C:\Program Files\Microsoft Silverlight
2013-03-13 21:21:23 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-03-13 21:20:52 ----D---- C:\Windows\AppPatch
2013-03-13 21:05:43 ----D---- C:\ProgramData\Microsoft Help
2013-03-13 21:02:37 ----A---- C:\Windows\system32\MRT.exe
2013-03-13 21:02:34 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-03-08 19:13:20 ----A---- C:\Windows\system32\igd10umd64.dll
2013-03-08 19:10:12 ----A---- C:\Windows\SYSWOW64\igdumd32.dll
2013-03-08 19:09:50 ----A---- C:\Windows\system32\igfxsrvc.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxexps.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\hccutils.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel RAID Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-06 438808]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-01-20 230320]
R0 PBADRV;PBADRV; C:\Windows\system32\DRIVERS\PBADRV.sys [2013-04-02 32240]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer; C:\Windows\system32\DRIVERS\stdcfltn.sys [2011-07-15 22128]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 Acceler;Accelerometer Service; C:\Windows\system32\DRIVERS\accelern.sys [2011-07-22 27760]
R3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® + High Speed; C:\Windows\system32\DRIVERS\AMPPAL.sys [2012-12-08 163368]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x64; C:\Windows\system32\DRIVERS\Apfiltr.sys [2011-05-26 368464]
R3 cvusbdrv;Dell ControlVault; C:\Windows\System32\Drivers\cvusbdrv.sys [2012-03-19 45672]
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C; C:\Windows\system32\DRIVERS\e1c62x64.sys [2012-08-11 482128]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2011-07-12 86016]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-03-08 5358016]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2011-09-22 56600]
R3 NETwNs64;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2012-12-06 11518976]
R3 O2MDFRDR;O2MDFRDR; C:\Windows\system32\DRIVERS\O2MDFw7x64.sys [2011-01-03 72808]
R3 O2SDJRDR;O2SDJRDR; C:\Windows\system32\DRIVERS\o2sdjw7x64.sys [2011-03-23 83560]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2011-01-25 520192]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
R3 WinUsb;Ovladač WinUSB; C:\Windows\system32\drivers\WinUSB.sys [2010-11-21 41984]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\Windows\system32\DRIVERS\adusbser.sys [2009-11-06 154112]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2012-03-23 507392]
S3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® + High Speed; C:\Windows\system32\DRIVERS\amppal.sys [2012-12-08 163368]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2012-02-24 348712]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2012-02-24 106536]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2012-02-24 138280]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2012-02-24 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2012-02-24 21416]
S3 cpudrv64;cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-06-02 17864]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2011-07-12 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-07-12 13952]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\Windows\system32\DRIVERS\ewusbnet.sys [2009-07-23 132608]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2011-07-12 98816]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2011-07-12 28672]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2011-07-12 213504]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-07-23 116992]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2009-07-23 113792]
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\drivers\nusb3hub.sys [2010-09-30 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\nusb3xhc.sys [2010-09-30 180736]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-12-08 753704]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-09-12 135984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-10-15 953632]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2012-03-19 1043872]
R2 Credential Vault Host Storage;Credential Vault Host Storage; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2012-03-19 36768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DFEPService;Dell Feature Enhancement Pack Service; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2012-05-08 2279960]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2012-12-03 620848]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2012-09-06 170824]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-01-19 325912]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 22056]
R2 msoidsvc;Microsoft Online Services Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2012-05-17 2079520]
R2 O2FLASH;O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [2010-02-10 72296]
R2 O2SDIOAssist;O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [2003-04-18 8192]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2012-12-03 149296]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-25 296448]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-01-19 2594584]
R2 VmbService;Vodafone Mobile Connect Service; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2011-07-14 9216]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
S2 tcsd_win32.exe;NTRU TSS v1.2.1.37 TCS; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [2011-10-08 1637888]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-13 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-03-22 279024]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-12-19 732648]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-02-24 1255736]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#8 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000UA.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bari
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 20 kvě 2011 09:06

Re: Prosím o kontrolu logu

#9 Příspěvek od Bari »

RSIT log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by admin at 2013-04-07 11:14:12
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 49 GB (20%) free of 244 GB
Total RAM: 3977 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:14:15, on 7.4.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16521)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Microsoft Lync\communicator.exe
C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
C:\Program Files (x86)\Microsoft Lync\UcMapi.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Lync add-on BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Smart Settings.lnk = C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (User 'Default user')
O4 - Startup: Kooperativa - PDF Server.lnk = C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
O4 - Startup: Smart Settings.lnk = C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Canon LBP2900 Status Window.lnk = C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra 'Tools' menuitem: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {73888E2B-FF04-416C-8847-984D7FC4507F} (RtspVaPgCtrlNew2 Class) - http://192.168.30.2:5002/RtspVaPgDecNew2.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.co ... 5.13.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{911668B1-E281-494F-98F9-434E70F9A5D7}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1ED4646-9B86-4E99-ABAB-B966B236DA7A}: NameServer = 217.77.165.81 217.77.161.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAED5936-BA1C-42FA-9A0C-3B8BF00AACE6}: NameServer = 217.77.165.81 217.77.161.131
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Dell Feature Enhancement Pack Service (DFEPService) - Dell Inc. - C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: O2SDIOAssist - Unknown owner - C:\Windows\SysWOW64\srvany.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: NTRU TSS v1.2.1.37 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Connect Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: WV5Communication - LaCrosse Technology - C:\Program Files (x86)\HeavyWeatherWV5\HeavyWeatherService.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 14328 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe 28988896
\??\C:\Windows\system32\conhost.exe "-1713280928819127414-600337583-9522356381431460370-716078504283595059221684824
"C:\Program Files\Common Files\SPBA\upeksvr.exe"
taskeng.exe {77CF3656-9A04-4888-8B39-0FA463035B7B}
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe"
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE"
C:\Windows\system32\DRIVERS\o2flash.exe
C:\Windows\SysWOW64\srvany.exe
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\sysWOW64\SDIOAssist.exe
C:\Windows\system32\svchost.exe -k imgsvc
MSOIDSvcm.exe 2132
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\HeavyWeatherWV5\HeavyWeatherService.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe"
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe"
C:\Windows\system32\CNAB4RPD.EXE
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f451bf92-294a-446d-b4ee-88296a553bbe -SystemEventPortName:HostProcess-f26e1ef6-93c3-4adb-ba46-b456cc0caebd -IoCancelEventPortName:HostProcess-6f9913b7-9880-45cc-aa91-6fb4b788f177 -NonStateChangingEventPortName:HostProcess-195b4a69-0ae3-4e8d-8005-1d5e1349c575 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c64536da-6268-4ca6-80e5-b4dcef9d9a1a -DeviceGroupId:
C:\Windows\servicing\TrustedInstaller.exe
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler64.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe"
"C:\Program Files\DellTPad\Apoint.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\DellTPad\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe"
"Apntex.exe"
"C:\Program Files\DellTPad\HidFind.exe"
\??\C:\Windows\system32\conhost.exe "1036551566-1102500776375388280-1572422631807280856-1321560727-1639132969-1070101691
"C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe"
"C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Microsoft Lync\UcMapi.exe" -Embedding
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5004 CREDAT:209921 /prefetch:2
"C:\Windows\System32\MsSpellCheckingFacility.exe" -Embedding
"C:\Users\admin\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 6670496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-19 551840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-19 209824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll [2010-11-03 211720]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-19 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-19 170912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-25 525312]
"FreeFallProtection"=C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [2011-07-25 686704]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2011-07-20 611192]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 1281512]
"IntelPROSet"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2012-12-03 4790576]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-03-22 172016]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-03-22 399856]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-03-22 442352]
"DFEPApplication"=C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [2012-05-08 7078424]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2005-02-16 221184]
"Google Update"=C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-09 116648]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-11-06 283160]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Print2PDF Print Monitor"=C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [2011-10-04 220992]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
"MobileBroadband"=C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2011-07-14 279552]
"Communicator"=C:\Program Files (x86)\Microsoft Lync\communicator.exe [2012-09-28 12105344]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Canon LBP2900 Status Window.lnk - C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE

C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Kooperativa - PDF Server.lnk - C:\Aplikace\KoopP7BNZFP\KoopP7BNZFP\KoopP7BNZFP\KoopPDFServerSA.exe
Smart Settings.lnk - C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-03-08 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\spba]
C:\Program Files\Common Files\SPBA\homefus2.dll [2010-09-15 2305872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 6670496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\SysWOW64\msiexec.exe"="C:\Windows\SysWOW64\msiexec.exe:*:Generic Host Process"
"C:\Windows\SysWOW64\svchost.exe"="C:\Windows\SysWOW64\svchost.exe:*:Generic Host Process"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-04-07 11:06:41 ----D---- C:\_OTM
2013-04-04 19:26:32 ----A---- C:\AdwCleaner[S1].txt
2013-04-04 19:26:08 ----A---- C:\AdwCleaner[R2].txt
2013-04-03 08:24:24 ----A---- C:\AdwCleaner[R1].txt
2013-04-02 14:07:04 ----A---- C:\Windows\system32\drivers\HECIx64.sys
2013-04-02 14:06:49 ----D---- C:\apps
2013-04-02 14:06:45 ----D---- C:\ProgramData\NTRU Cryptosystems
2013-04-02 14:06:45 ----D---- C:\Program Files\NTRU Cryptosystems
2013-04-02 14:06:45 ----D---- C:\Program Files (x86)\NTRU Cryptosystems
2013-04-02 14:06:01 ----A---- C:\Windows\SYSWOW64\pbadrvdll.dll
2013-04-02 14:06:01 ----A---- C:\Windows\system32\pbadrvdll.dll
2013-04-02 14:06:01 ----A---- C:\Windows\system32\drivers\PBADRV.SYS
2013-04-02 14:05:59 ----D---- C:\Program Files (x86)\Gemalto
2013-04-02 14:05:10 ----A---- C:\Windows\system32\brcmbsp.dll
2013-04-02 14:05:10 ----A---- C:\Windows\system32\bipbsp.dll
2013-04-02 14:05:00 ----D---- C:\Program Files\Broadcom Corporation
2013-04-02 14:02:29 ----SHD---- C:\Config.Msi
2013-04-02 13:42:12 ----D---- C:\Windows\{69093D49-3DD1-4FB5-A378-0D4DB4CF86EA}
2013-04-02 11:58:59 ----RD---- C:\Program Files (x86)\Skype
2013-04-02 11:48:12 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2013-04-02 11:43:42 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2013-04-02 10:24:15 ----D---- C:\rsit
2013-04-02 10:24:15 ----D---- C:\Program Files\trend micro
2013-04-02 10:12:14 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2013-04-02 10:11:54 ----D---- C:\ProgramData\Malwarebytes
2013-04-02 10:11:52 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-02 10:11:52 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-03-25 19:17:33 ----D---- C:\Users\admin\AppData\Roaming\Kyilca
2013-03-25 19:17:33 ----D---- C:\Users\admin\AppData\Roaming\Esy
2013-03-22 10:14:30 ----A---- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxtray.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxsrvc.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxpers.exe
2013-03-22 10:14:28 ----A---- C:\Windows\system32\igfxext.exe
2013-03-22 10:14:26 ----A---- C:\Windows\system32\hkcmd.exe
2013-03-22 10:14:26 ----A---- C:\Windows\system32\GfxUI.exe
2013-03-22 10:14:26 ----A---- C:\Windows\system32\difx64.exe
2013-03-19 20:33:57 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-03-19 20:33:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-03-19 20:33:57 ----A---- C:\Windows\system32\elshyph.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-03-19 20:33:56 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\url.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-03-19 20:33:55 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\wininet.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\webcheck.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\urlmon.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\url.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-03-19 20:33:55 ----A---- C:\Windows\system32\msrating.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\msls31.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\jsproxy.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iesetup.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iertutil.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iernonce.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\iedkcs32.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ieapfltr.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ieapfltr.dat
2013-03-19 20:33:55 ----A---- C:\Windows\system32\ie4uinit.exe
2013-03-19 20:33:55 ----A---- C:\Windows\system32\icardie.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\dxtrans.dll
2013-03-19 20:33:55 ----A---- C:\Windows\system32\dxtmsft.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\wextract.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\vbscript.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\pngfilt.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\occache.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtmler.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtmled.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshtml.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\mshta.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeedssync.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\msfeeds.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\licmgr10.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\jscript9.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\jscript.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\inseng.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\imgutil.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iexpress.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieUnatt.exe
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieui.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iesysprep.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\iepeers.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\ieframe.dll
2013-03-19 20:33:54 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-03-19 20:33:26 ----A---- C:\Windows\system32\ZLhp2600.DLL
2013-03-19 20:27:55 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-03-19 20:15:02 ----D---- C:\Program Files (x86)\Cisco
2013-03-19 20:14:59 ----D---- C:\ProgramData\Intel.sav
2013-03-19 20:13:45 ----D---- C:\ProgramData\Package Cache
2013-03-19 20:10:13 ----A---- C:\Windows\system32\javaws.exe
2013-03-19 20:10:11 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2013-03-19 20:10:11 ----A---- C:\Windows\system32\javaw.exe
2013-03-19 20:10:11 ----A---- C:\Windows\system32\java.exe
2013-03-19 20:09:45 ----D---- C:\Program Files\Java
2013-03-19 20:08:42 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-03-19 20:08:39 ----A---- C:\Windows\SYSWOW64\java.exe
2013-03-19 20:08:11 ----D---- C:\Program Files (x86)\Java
2013-03-19 17:35:25 ----D---- C:\Users\admin\AppData\Roaming\Mikrotik
2013-03-12 15:10:24 ----A---- C:\Windows\system32\igfxCoIn_v3062.dll
2013-03-08 19:12:10 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll
2013-03-08 19:10:18 ----A---- C:\Windows\system32\igdumd64.dll
2013-03-08 19:10:18 ----A---- C:\Windows\system32\igdde64.dll
2013-03-08 19:10:18 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2013-03-08 19:10:10 ----A---- C:\Windows\SYSWOW64\igdde32.dll
2013-03-08 19:09:50 ----A---- C:\Windows\system32\igfxress.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxTMM.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxpph.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxdo.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\IGFXDEVLib.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxdev.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\gfxSrvc.dll
2013-03-08 19:09:46 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll
2013-03-08 19:09:44 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2013-03-08 19:09:36 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll
2013-03-08 19:08:50 ----A---- C:\Windows\system32\ig4icd64.dll
2013-03-08 19:06:48 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2013-03-08 19:06:48 ----A---- C:\Windows\SYSWOW64\igfxcmjit32.dll
2013-03-08 19:06:48 ----A---- C:\Windows\SYSWOW64\igfx11cmrt32.dll
2013-03-08 19:06:48 ----A---- C:\Windows\system32\igfxcmrt64.dll
2013-03-08 19:06:48 ----A---- C:\Windows\system32\igfxcmjit64.dll
2013-03-08 19:06:48 ----A---- C:\Windows\system32\igfx11cmrt64.dll

======List of files/folders modified in the last 1 month======

2013-04-07 11:12:56 ----D---- C:\Windows\System32
2013-04-07 11:12:56 ----D---- C:\Windows\inf
2013-04-07 11:12:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-04-07 11:10:49 ----A---- C:\Windows\SYSWOW64\log.txt
2013-04-07 11:09:44 ----D---- C:\Windows\Temp
2013-04-07 11:08:48 ----D---- C:\Windows\system32\config
2013-04-07 11:07:30 ----D---- C:\Windows
2013-04-07 11:06:41 ----D---- C:\Windows\Tasks
2013-04-06 08:03:59 ----D---- C:\Windows\system32\FxsTmp
2013-04-05 19:38:49 ----SHD---- C:\System Volume Information
2013-04-04 19:26:39 ----HD---- C:\ProgramData
2013-04-02 14:32:16 ----D---- C:\Windows\winsxs
2013-04-02 14:13:45 ----D---- C:\ProgramData\Intel
2013-04-02 14:11:57 ----D---- C:\Windows\system32\drivers\UMDF
2013-04-02 14:11:34 ----D---- C:\Windows\system32\catroot
2013-04-02 14:11:33 ----D---- C:\Windows\system32\DriverStore
2013-04-02 14:11:33 ----AD---- C:\Windows\system32\drivers
2013-04-02 14:07:19 ----D---- C:\Program Files (x86)\Intel
2013-04-02 14:06:46 ----SHD---- C:\Windows\Installer
2013-04-02 14:06:45 ----RD---- C:\Program Files (x86)
2013-04-02 14:06:45 ----RD---- C:\Program Files
2013-04-02 14:06:39 ----D---- C:\Program Files\Dell
2013-04-02 14:06:07 ----D---- C:\Program Files\Common Files\SPBA
2013-04-02 14:06:06 ----D---- C:\Program Files (x86)\Common Files
2013-04-02 14:06:01 ----DC---- C:\Windows\system32\DRVSTORE
2013-04-02 14:06:01 ----D---- C:\Windows\SysWOW64
2013-04-02 14:05:22 ----D---- C:\Windows\system32\wbem
2013-04-02 14:05:21 ----RSD---- C:\Windows\assembly
2013-04-02 14:05:10 ----A---- C:\Windows\system32\brcmbsp_log.txt
2013-04-02 14:05:03 ----D---- C:\Windows\system32\catroot2
2013-04-02 14:04:58 ----D---- C:\Windows\Downloaded Installations
2013-04-02 14:04:45 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-04-02 14:02:58 ----D---- C:\ProgramData\Wave Systems Corp
2013-04-02 14:00:36 ----A---- C:\Windows\system32\bioapi100.dll
2013-04-02 14:00:36 ----A---- C:\Windows\system32\bioapi_mds300.dll
2013-04-02 14:00:22 ----D---- C:\ProgramData\Dell
2013-04-02 13:42:18 ----D---- C:\Program Files (x86)\Dell
2013-04-02 13:21:45 ----D---- C:\Windows\SoftwareDistribution
2013-04-02 12:34:28 ----N---- C:\Windows\system32\MpSigStub.exe
2013-04-02 12:01:02 ----D---- C:\Users\admin\AppData\Roaming\Winamp
2013-04-02 12:01:01 ----D---- C:\Windows\Panther
2013-04-02 12:01:01 ----D---- C:\Windows\ModemLogs
2013-04-02 12:01:00 ----D---- C:\Windows\Logs
2013-04-02 12:01:00 ----D---- C:\Windows\debug
2013-04-02 11:59:41 ----D---- C:\Users\admin\AppData\Roaming\Skype
2013-04-02 11:59:05 ----D---- C:\ProgramData\Skype
2013-04-02 11:58:20 ----D---- C:\Windows\system32\Tasks
2013-04-02 11:47:49 ----D---- C:\Program Files (x86)\Nokia
2013-04-02 11:43:43 ----D---- C:\Windows\Downloaded Program Files
2013-04-02 11:41:45 ----D---- C:\Program Files\CCleaner
2013-04-01 20:28:03 ----HD---- C:\Windows\system32\WLANProfiles
2013-03-25 19:17:37 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2013-03-22 10:49:34 ----D---- C:\Program Files (x86)\CDBurnerXP
2013-03-21 19:05:51 ----D---- C:\Users\admin\AppData\Roaming\Nokia
2013-03-19 21:41:13 ----D---- C:\Windows\rescache
2013-03-19 21:15:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-03-19 21:15:16 ----D---- C:\Windows\system32\cs-CZ
2013-03-19 21:15:16 ----D---- C:\Program Files\Internet Explorer
2013-03-19 21:15:16 ----D---- C:\Program Files (x86)\Internet Explorer
2013-03-19 21:15:15 ----D---- C:\Windows\SYSWOW64\migration
2013-03-19 21:15:15 ----D---- C:\Windows\SYSWOW64\en-US
2013-03-19 21:15:15 ----D---- C:\Windows\system32\migration
2013-03-19 21:15:15 ----D---- C:\Windows\system32\en-US
2013-03-19 21:15:15 ----D---- C:\Windows\PolicyDefinitions
2013-03-19 20:15:45 ----D---- C:\Program Files\Intel
2013-03-19 20:10:07 ----A---- C:\Windows\system32\npdeployJava1.dll
2013-03-19 20:10:06 ----A---- C:\Windows\system32\deployJava1.dll
2013-03-19 20:08:34 ----A---- C:\Windows\SYSWOW64\npdeployJava1.dll
2013-03-19 20:08:34 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-03-19 19:53:56 ----D---- C:\Users\admin\AppData\Roaming\vlc
2013-03-19 19:48:08 ----D---- C:\Program Files\SystemRequirementsLab
2013-03-15 17:49:02 ----D---- C:\AgnisWork
2013-03-13 21:21:23 ----D---- C:\Program Files\Microsoft Silverlight
2013-03-13 21:21:23 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-03-13 21:20:52 ----D---- C:\Windows\AppPatch
2013-03-13 21:05:43 ----D---- C:\ProgramData\Microsoft Help
2013-03-13 21:02:37 ----A---- C:\Windows\system32\MRT.exe
2013-03-13 21:02:34 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-03-08 19:13:20 ----A---- C:\Windows\system32\igd10umd64.dll
2013-03-08 19:10:12 ----A---- C:\Windows\SYSWOW64\igdumd32.dll
2013-03-08 19:09:50 ----A---- C:\Windows\system32\igfxsrvc.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\igfxexps.dll
2013-03-08 19:09:48 ----A---- C:\Windows\system32\hccutils.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel RAID Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-06 438808]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-01-20 230320]
R0 PBADRV;PBADRV; C:\Windows\system32\DRIVERS\PBADRV.sys [2013-04-02 32240]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer; C:\Windows\system32\DRIVERS\stdcfltn.sys [2011-07-15 22128]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 Acceler;Accelerometer Service; C:\Windows\system32\DRIVERS\accelern.sys [2011-07-22 27760]
R3 AMPPAL;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® + High Speed; C:\Windows\system32\DRIVERS\AMPPAL.sys [2012-12-08 163368]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x64; C:\Windows\system32\DRIVERS\Apfiltr.sys [2011-05-26 368464]
R3 cvusbdrv;Dell ControlVault; C:\Windows\System32\Drivers\cvusbdrv.sys [2012-03-19 45672]
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C; C:\Windows\system32\DRIVERS\e1c62x64.sys [2012-08-11 482128]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2011-07-12 86016]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-03-08 5358016]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2011-09-22 56600]
R3 NETwNs64;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2012-12-06 11518976]
R3 O2MDFRDR;O2MDFRDR; C:\Windows\system32\DRIVERS\O2MDFw7x64.sys [2011-01-03 72808]
R3 O2SDJRDR;O2SDJRDR; C:\Windows\system32\DRIVERS\o2sdjw7x64.sys [2011-03-23 83560]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2011-01-25 520192]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
R3 WinUsb;Ovladač WinUSB; C:\Windows\system32\drivers\WinUSB.sys [2010-11-21 41984]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\Windows\system32\DRIVERS\adusbser.sys [2009-11-06 154112]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2012-03-23 507392]
S3 AMPPALP;Protokol Intel® Centrino® Wireless Bluetooth® + High Speed; C:\Windows\system32\DRIVERS\amppal.sys [2012-12-08 163368]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2012-02-24 348712]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2012-02-24 106536]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2012-02-24 138280]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2012-02-24 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2012-02-24 21416]
S3 cpudrv64;cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-06-02 17864]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2011-07-12 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-07-12 13952]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\Windows\system32\DRIVERS\ewusbnet.sys [2009-07-23 132608]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2011-07-12 98816]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2011-07-12 28672]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2011-07-12 213504]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-07-23 116992]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2009-07-23 113792]
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\drivers\nusb3hub.sys [2010-09-30 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\nusb3xhc.sys [2010-09-30 180736]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-12-08 753704]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-09-12 135984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-10-15 953632]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2012-03-19 1043872]
R2 Credential Vault Host Storage;Credential Vault Host Storage; C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2012-03-19 36768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DFEPService;Dell Feature Enhancement Pack Service; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2012-05-08 2279960]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2012-12-03 620848]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2012-09-06 170824]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-01-19 325912]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 22056]
R2 msoidsvc;Microsoft Online Services Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2012-05-17 2079520]
R2 O2FLASH;O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [2010-02-10 72296]
R2 O2SDIOAssist;O2SDIOAssist; C:\Windows\SysWOW64\srvany.exe [2003-04-18 8192]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2012-12-03 149296]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-25 296448]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-01-19 2594584]
R2 VmbService;Vodafone Mobile Connect Service; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2011-07-14 9216]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
S2 tcsd_win32.exe;NTRU TSS v1.2.1.37 TCS; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [2011-10-08 1637888]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-13 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-03-22 279024]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-05 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-12-19 732648]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-02-24 1255736]

-----------------EOF-----------------



Pro jistotu přikládám do code i log z OTM, který vyskočil po restartu:

Kód: Vybrat vše

All processes killed
========== FILES ==========
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000Core.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-449368200-3802964555-3164789258-1000UA.job moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: admin
->Temp folder emptied: 364976896 bytes
->Temporary Internet Files folder emptied: 166872117 bytes
->Java cache emptied: 3795671 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1821 bytes
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 317513396 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 562 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36028672 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 556 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 848,00 mb
 
 
[EMPTYFLASH]
 
User: admin
->Flash cache emptied: 0 bytes
 
User: All Users
 
User: Default
 
User: Default User
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
OTM by OldTimer - Version 3.1.21.0 log created on 04072013_110641

Files moved on Reboot...
C:\Users\admin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\7A7E08C8-3FF5-45F2-873D-A84D669DC82F.dat moved successfully.
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YS4IU68C\viewtopic[1].htm moved successfully.
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#10 Příspěvek od Rudy »

Log je již OK. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bari
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 20 kvě 2011 09:06

Re: Prosím o kontrolu logu

#11 Příspěvek od Bari »

Díky moc!

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#12 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno