
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventivni kontrola logu
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Preventivni kontrola logu
Ahoj,
rad bych poprosil o preventivni kontrolu logu. Delsi dobu jsem mel problem, ze mi zustavali vyset nejake procesy pri nahlem zavreni aplikace (chvilku po startu). Ovsem prisuzuju to tomu, ze jsem mel muj Avast v tichem modu, takze se me nezeptal, zda chci spousteci soubor analyzovat a proste nechal proces jen tak vyset. Kdyz sem vypnul tichej mod, tak se me Avast zeptal, a poptvrzeni me aplikace bezproblemu nabehla a nepada, ale radsi si to necham potvrdit konrolou logu, ze v tom nema ruce (software) nekdo jiny.
Dekuju moc.
Pupupaj
Logfile of random's system information tool 1.09 (written by random/random)
Run by pupupaj at 2013-12-03 20:19:41
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 36 GB (36%) free of 100 GB
Total RAM: 3951 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:19:45, on 3.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\pupupaj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe /check
O4 - HKCU\..\Run: [Google Update] "C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: T-Mobile Con App Svc (CATmobile) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: T-Mobile RcApp Svc (TMobileRcAppSvc) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11709 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
KHALMNPR.EXE /API
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE"
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4956.0.489684447\1852947920" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --gpu-vendor-id=0x1002 --gpu-device-id=0x9555 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.3000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4956.1.1358371659\1693596593" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="4956.2.137651475\1543633921" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4956.4.533218632\2076021777" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4956.5.1434072810\348541308" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderDisabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="4956.8.1078143265\1577620691" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"D:\Download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2013-11-13 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-20 553384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2013-11-13 878808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2013-11-13 2328776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-20 210856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2013-11-13 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-22 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL [2013-11-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-13 1725640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-22 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-29 136176]
""= []
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
"SkyDrive"=C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2013-10-24 257136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-22 3567800]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"20131121"=C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe [2013-11-23 180184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-13 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-11-13 20:38:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-13 20:35:03 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-13 20:35:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ie4uinit.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\elshyph.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-13 20:33:10 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 20:33:02 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-11-13 20:33:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\wksprt.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\mstsc.exe
2013-11-13 20:32:59 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\mstscax.dll
2013-11-13 20:25:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-11-13 20:25:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-11-13 20:13:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-13 20:13:58 ----A---- C:\Windows\system32\crypt32.dll
2013-11-13 20:13:55 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-13 20:13:54 ----A---- C:\Windows\system32\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\credui.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsass.exe
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-13 20:13:48 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-13 20:13:48 ----A---- C:\Windows\system32\gdi32.dll
2013-11-13 20:13:47 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-13 20:13:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 20:13:46 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-07 21:27:58 ----D---- C:\Program Files\iPod
2013-11-07 21:27:57 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-07 21:27:57 ----D---- C:\Program Files\iTunes
2013-11-07 21:27:57 ----D---- C:\Program Files (x86)\iTunes
======List of files/folders modified in the last 1 month======
2013-12-03 20:19:45 ----D---- C:\Windows\Prefetch
2013-12-03 20:19:44 ----D---- C:\Windows\temp
2013-12-03 20:19:44 ----D---- C:\Program Files\trend micro
2013-12-03 20:10:29 ----D---- C:\Users\pupupaj\AppData\Roaming\Skype
2013-12-03 20:00:34 ----SHD---- C:\Windows\Installer
2013-12-03 19:53:58 ----D---- C:\Windows\system32\config
2013-12-03 19:43:22 ----SHD---- C:\System Volume Information
2013-11-26 22:43:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-26 21:40:06 ----D---- C:\Program Files\CCleaner
2013-11-26 21:28:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-15 16:49:43 ----D---- C:\Windows\System32
2013-11-15 16:49:43 ----D---- C:\Windows\inf
2013-11-15 16:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-14 20:30:57 ----D---- C:\Windows\rescache
2013-11-14 20:11:59 ----D---- C:\Windows\Microsoft.NET
2013-11-14 20:11:58 ----RSD---- C:\Windows\assembly
2013-11-14 19:26:28 ----D---- C:\Windows\winsxs
2013-11-14 19:25:39 ----D---- C:\Windows\Panther
2013-11-13 21:24:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-11-13 21:24:30 ----D---- C:\Program Files\Internet Explorer
2013-11-13 21:24:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-11-13 21:24:29 ----D---- C:\Windows\system32\cs-CZ
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\migration
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2013-11-13 21:24:28 ----D---- C:\Windows\SysWOW64
2013-11-13 21:24:27 ----D---- C:\Windows\system32\migration
2013-11-13 21:24:27 ----D---- C:\Windows\system32\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\PolicyDefinitions
2013-11-13 21:24:26 ----D---- C:\Windows\SYSWOW64\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers\en-US
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers
2013-11-13 21:24:23 ----D---- C:\Windows\system32\DriverStore
2013-11-13 21:20:38 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2013-11-13 21:18:55 ----D---- C:\Program Files\Microsoft Office 15
2013-11-13 20:39:26 ----D---- C:\Windows\system32\catroot
2013-11-13 20:39:25 ----D---- C:\Windows\system32\catroot2
2013-11-13 20:38:44 ----D---- C:\Windows\Logs
2013-11-13 20:33:46 ----D---- C:\Windows
2013-11-13 20:32:27 ----D---- C:\Windows\system32\MRT
2013-11-13 20:26:34 ----D---- C:\Windows\debug
2013-11-13 20:26:30 ----A---- C:\Windows\system32\MRT.exe
2013-11-13 19:58:41 ----D---- C:\Windows\system32\Tasks
2013-11-11 05:50:16 ----N---- C:\Windows\system32\MpSigStub.exe
2013-11-07 21:27:58 ----RD---- C:\Program Files
2013-11-07 21:27:57 ----RD---- C:\Program Files (x86)
2013-11-07 21:27:57 ----D---- C:\ProgramData
2013-11-05 19:19:17 ----D---- C:\ProgramData\Skype
2013-11-05 19:19:14 ----RD---- C:\Program Files (x86)\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-22 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-10-22 205320]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2013-10-22 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2013-10-22 447888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-22 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-10-22 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-10 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-10-22 65264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-10-22 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-10-22 84328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 86016]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
R3 tmobile_mf691_dc_enum;tmobile_mf691_dc_enum; C:\Windows\system32\DRIVERS\tmobile_mf691_dc_enum.sys [2010-04-09 75776]
S3 ALSysIO;ALSysIO; \??\C:\Users\pupupaj\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver; \??\C:\Windows\syswow64\PCTINDIS5X64.SYS []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-10-22 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-10-22 179088]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-21 227896]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 OfficeSvc;Služba Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17 1907896]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-07-08 4153184]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S3 CATmobile;T-Mobile Con App Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe [2010-12-22 118784]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-21 988728]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-13 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-06-13 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-06-13 5132888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe [2010-12-22 114688]
S3 VisualSVNServer;VisualSVN Server; C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe [2011-10-24 24424]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-29 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service; C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 306400]
-----------------EOF-----------------
rad bych poprosil o preventivni kontrolu logu. Delsi dobu jsem mel problem, ze mi zustavali vyset nejake procesy pri nahlem zavreni aplikace (chvilku po startu). Ovsem prisuzuju to tomu, ze jsem mel muj Avast v tichem modu, takze se me nezeptal, zda chci spousteci soubor analyzovat a proste nechal proces jen tak vyset. Kdyz sem vypnul tichej mod, tak se me Avast zeptal, a poptvrzeni me aplikace bezproblemu nabehla a nepada, ale radsi si to necham potvrdit konrolou logu, ze v tom nema ruce (software) nekdo jiny.
Dekuju moc.
Pupupaj
Logfile of random's system information tool 1.09 (written by random/random)
Run by pupupaj at 2013-12-03 20:19:41
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 36 GB (36%) free of 100 GB
Total RAM: 3951 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:19:45, on 3.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\pupupaj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe /check
O4 - HKCU\..\Run: [Google Update] "C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: T-Mobile Con App Svc (CATmobile) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: T-Mobile RcApp Svc (TMobileRcAppSvc) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11709 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
KHALMNPR.EXE /API
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE"
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4956.0.489684447\1852947920" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --gpu-vendor-id=0x1002 --gpu-device-id=0x9555 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.3000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4956.1.1358371659\1693596593" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="4956.2.137651475\1543633921" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4956.4.533218632\2076021777" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="4956.5.1434072810\348541308" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderDisabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="4956.8.1078143265\1577620691" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"D:\Download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2013-11-13 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-20 553384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2013-11-13 878808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2013-11-13 2328776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-20 210856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2013-11-13 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-22 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL [2013-11-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-13 1725640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-22 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-29 136176]
""= []
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
"SkyDrive"=C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2013-10-24 257136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-22 3567800]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"20131121"=C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe [2013-11-23 180184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-13 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-11-13 20:38:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-13 20:35:03 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-13 20:35:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ie4uinit.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\elshyph.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-13 20:33:10 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 20:33:02 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-11-13 20:33:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\wksprt.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\mstsc.exe
2013-11-13 20:32:59 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\mstscax.dll
2013-11-13 20:25:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-11-13 20:25:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-11-13 20:13:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-13 20:13:58 ----A---- C:\Windows\system32\crypt32.dll
2013-11-13 20:13:55 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-13 20:13:54 ----A---- C:\Windows\system32\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\credui.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsass.exe
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-13 20:13:48 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-13 20:13:48 ----A---- C:\Windows\system32\gdi32.dll
2013-11-13 20:13:47 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-13 20:13:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 20:13:46 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-07 21:27:58 ----D---- C:\Program Files\iPod
2013-11-07 21:27:57 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-11-07 21:27:57 ----D---- C:\Program Files\iTunes
2013-11-07 21:27:57 ----D---- C:\Program Files (x86)\iTunes
======List of files/folders modified in the last 1 month======
2013-12-03 20:19:45 ----D---- C:\Windows\Prefetch
2013-12-03 20:19:44 ----D---- C:\Windows\temp
2013-12-03 20:19:44 ----D---- C:\Program Files\trend micro
2013-12-03 20:10:29 ----D---- C:\Users\pupupaj\AppData\Roaming\Skype
2013-12-03 20:00:34 ----SHD---- C:\Windows\Installer
2013-12-03 19:53:58 ----D---- C:\Windows\system32\config
2013-12-03 19:43:22 ----SHD---- C:\System Volume Information
2013-11-26 22:43:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-26 21:40:06 ----D---- C:\Program Files\CCleaner
2013-11-26 21:28:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-15 16:49:43 ----D---- C:\Windows\System32
2013-11-15 16:49:43 ----D---- C:\Windows\inf
2013-11-15 16:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-14 20:30:57 ----D---- C:\Windows\rescache
2013-11-14 20:11:59 ----D---- C:\Windows\Microsoft.NET
2013-11-14 20:11:58 ----RSD---- C:\Windows\assembly
2013-11-14 19:26:28 ----D---- C:\Windows\winsxs
2013-11-14 19:25:39 ----D---- C:\Windows\Panther
2013-11-13 21:24:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-11-13 21:24:30 ----D---- C:\Program Files\Internet Explorer
2013-11-13 21:24:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-11-13 21:24:29 ----D---- C:\Windows\system32\cs-CZ
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\migration
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2013-11-13 21:24:28 ----D---- C:\Windows\SysWOW64
2013-11-13 21:24:27 ----D---- C:\Windows\system32\migration
2013-11-13 21:24:27 ----D---- C:\Windows\system32\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\PolicyDefinitions
2013-11-13 21:24:26 ----D---- C:\Windows\SYSWOW64\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers\en-US
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers
2013-11-13 21:24:23 ----D---- C:\Windows\system32\DriverStore
2013-11-13 21:20:38 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2013-11-13 21:18:55 ----D---- C:\Program Files\Microsoft Office 15
2013-11-13 20:39:26 ----D---- C:\Windows\system32\catroot
2013-11-13 20:39:25 ----D---- C:\Windows\system32\catroot2
2013-11-13 20:38:44 ----D---- C:\Windows\Logs
2013-11-13 20:33:46 ----D---- C:\Windows
2013-11-13 20:32:27 ----D---- C:\Windows\system32\MRT
2013-11-13 20:26:34 ----D---- C:\Windows\debug
2013-11-13 20:26:30 ----A---- C:\Windows\system32\MRT.exe
2013-11-13 19:58:41 ----D---- C:\Windows\system32\Tasks
2013-11-11 05:50:16 ----N---- C:\Windows\system32\MpSigStub.exe
2013-11-07 21:27:58 ----RD---- C:\Program Files
2013-11-07 21:27:57 ----RD---- C:\Program Files (x86)
2013-11-07 21:27:57 ----D---- C:\ProgramData
2013-11-05 19:19:17 ----D---- C:\ProgramData\Skype
2013-11-05 19:19:14 ----RD---- C:\Program Files (x86)\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-22 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-10-22 205320]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2013-10-22 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2013-10-22 447888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-22 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-10-22 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-10 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-10-22 65264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-10-22 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-10-22 84328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 86016]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
R3 tmobile_mf691_dc_enum;tmobile_mf691_dc_enum; C:\Windows\system32\DRIVERS\tmobile_mf691_dc_enum.sys [2010-04-09 75776]
S3 ALSysIO;ALSysIO; \??\C:\Users\pupupaj\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver; \??\C:\Windows\syswow64\PCTINDIS5X64.SYS []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-10-22 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-10-22 179088]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-21 227896]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 OfficeSvc;Služba Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17 1907896]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-07-08 4153184]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S3 CATmobile;T-Mobile Con App Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe [2010-12-22 118784]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-21 988728]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-13 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-06-13 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-06-13 5132888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe [2010-12-22 114688]
S3 VisualSVNServer;VisualSVN Server; C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe [2011-10-24 24424]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-29 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service; C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 306400]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Preventivni kontrola logu
Zdravím!
Spusťte nejprve tuto utilitu:
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Preventivni kontrola logu
Ahoj Rudy,
dle instrukci prikladam log a omlouvam se za pozdejsi odezvu:)
Pupupaj
# AdwCleaner v3.014 - Report created 05/12/2013 at 08:15:43
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : pupupaj - PUPIKOV
# Running from : C:\Users\pupupaj\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\acaoakiamfeidcmgooclgeleejkbaecf
Key Deleted : HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D9B1B31-D034-4738-8F6E-40F0AFCC742C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\PIP
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Google Chrome v
[ File : C:\Users\pupupaj\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2314 octets] - [05/12/2013 08:14:09]
AdwCleaner[S0].txt - [2122 octets] - [05/12/2013 08:15:43]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2182 octets] ##########
dle instrukci prikladam log a omlouvam se za pozdejsi odezvu:)
Pupupaj
# AdwCleaner v3.014 - Report created 05/12/2013 at 08:15:43
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : pupupaj - PUPIKOV
# Running from : C:\Users\pupupaj\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\acaoakiamfeidcmgooclgeleejkbaecf
Key Deleted : HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D9B1B31-D034-4738-8F6E-40F0AFCC742C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{78CE34FD-F6D4-4866-B79C-A37268D06A04}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{80904944-C726-4C7D-A452-3FFF2A882095}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\PIP
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Google Chrome v
[ File : C:\Users\pupupaj\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2314 octets] - [05/12/2013 08:14:09]
AdwCleaner[S0].txt - [2122 octets] - [05/12/2013 08:15:43]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2182 octets] ##########
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Preventivni kontrola logu
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Preventivni kontrola logu
Ahoj,
zde je:
Logfile of random's system information tool 1.09 (written by random/random)
Run by pupupaj at 2013-12-08 20:00:20
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 35 GB (35%) free of 100 GB
Total RAM: 3951 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:00:24, on 8.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\trend micro\pupupaj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe /check
O4 - HKCU\..\Run: [Google Update] "C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: T-Mobile Con App Svc (CATmobile) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: T-Mobile RcApp Svc (TMobileRcAppSvc) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11226 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
KHALMNPR.EXE /API
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\system32\msiexec.exe /V
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe {0613B0B4-80E5-4A08-9608-871EDA2D11E4}
taskeng.exe {017FC2F8-5FFE-4390-B889-1A058C018A97}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\pupupaj\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2013-11-13 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-20 553384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2013-11-13 878808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2013-11-13 2328776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-20 210856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2013-11-13 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-22 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL [2013-11-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-13 1725640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-22 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-29 136176]
""= []
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
"SkyDrive"=C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2013-10-24 257136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-22 3567800]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"20131121"=C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe [2013-11-23 180184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-13 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-12-05 08:13:59 ----D---- C:\AdwCleaner
2013-11-13 20:38:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-13 20:35:03 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-13 20:35:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ie4uinit.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\elshyph.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-13 20:33:10 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 20:33:02 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-11-13 20:33:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\wksprt.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\mstsc.exe
2013-11-13 20:32:59 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\mstscax.dll
2013-11-13 20:25:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-11-13 20:25:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-11-13 20:13:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-13 20:13:58 ----A---- C:\Windows\system32\crypt32.dll
2013-11-13 20:13:55 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-13 20:13:54 ----A---- C:\Windows\system32\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\credui.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsass.exe
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-13 20:13:48 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-13 20:13:48 ----A---- C:\Windows\system32\gdi32.dll
2013-11-13 20:13:47 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-13 20:13:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 20:13:46 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
======List of files/folders modified in the last 1 month======
2013-12-08 20:00:24 ----D---- C:\Windows\temp
2013-12-08 20:00:23 ----D---- C:\Program Files\trend micro
2013-12-08 19:57:42 ----D---- C:\Windows\Prefetch
2013-12-08 19:57:37 ----SHD---- C:\Windows\Installer
2013-12-08 19:51:37 ----SHD---- C:\System Volume Information
2013-12-08 19:50:38 ----D---- C:\Users\pupupaj\AppData\Roaming\Skype
2013-12-08 19:49:58 ----D---- C:\Windows\system32\config
2013-12-08 19:49:35 ----D---- C:\ProgramData\Skype
2013-12-08 19:49:31 ----RD---- C:\Program Files (x86)\Skype
2013-11-26 22:43:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-26 21:40:06 ----D---- C:\Program Files\CCleaner
2013-11-26 21:28:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-15 16:49:43 ----D---- C:\Windows\System32
2013-11-15 16:49:43 ----D---- C:\Windows\inf
2013-11-15 16:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-14 20:30:57 ----D---- C:\Windows\rescache
2013-11-14 20:11:59 ----D---- C:\Windows\Microsoft.NET
2013-11-14 20:11:58 ----RSD---- C:\Windows\assembly
2013-11-14 19:26:28 ----D---- C:\Windows\winsxs
2013-11-14 19:25:39 ----D---- C:\Windows\Panther
2013-11-13 21:24:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-11-13 21:24:30 ----D---- C:\Program Files\Internet Explorer
2013-11-13 21:24:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-11-13 21:24:29 ----D---- C:\Windows\system32\cs-CZ
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\migration
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2013-11-13 21:24:28 ----D---- C:\Windows\SysWOW64
2013-11-13 21:24:27 ----D---- C:\Windows\system32\migration
2013-11-13 21:24:27 ----D---- C:\Windows\system32\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\PolicyDefinitions
2013-11-13 21:24:26 ----D---- C:\Windows\SYSWOW64\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers\en-US
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers
2013-11-13 21:24:23 ----D---- C:\Windows\system32\DriverStore
2013-11-13 21:20:38 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2013-11-13 21:18:55 ----D---- C:\Program Files\Microsoft Office 15
2013-11-13 20:39:26 ----D---- C:\Windows\system32\catroot
2013-11-13 20:39:25 ----D---- C:\Windows\system32\catroot2
2013-11-13 20:38:44 ----D---- C:\Windows\Logs
2013-11-13 20:33:46 ----D---- C:\Windows
2013-11-13 20:32:27 ----D---- C:\Windows\system32\MRT
2013-11-13 20:26:34 ----D---- C:\Windows\debug
2013-11-13 20:26:30 ----A---- C:\Windows\system32\MRT.exe
2013-11-13 19:58:41 ----D---- C:\Windows\system32\Tasks
2013-11-11 05:50:16 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-22 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-10-22 205320]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2013-10-22 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2013-10-22 447888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-22 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-10-22 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-10 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-10-22 65264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-10-22 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-10-22 84328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 86016]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
R3 tmobile_mf691_dc_enum;tmobile_mf691_dc_enum; C:\Windows\system32\DRIVERS\tmobile_mf691_dc_enum.sys [2010-04-09 75776]
S3 ALSysIO;ALSysIO; \??\C:\Users\pupupaj\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver; \??\C:\Windows\syswow64\PCTINDIS5X64.SYS []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-10-22 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-10-22 179088]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-21 227896]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 OfficeSvc;Služba Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17 1907896]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-07-08 4153184]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S3 CATmobile;T-Mobile Con App Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe [2010-12-22 118784]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-21 988728]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-13 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-06-13 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-06-13 5132888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe [2010-12-22 114688]
S3 VisualSVNServer;VisualSVN Server; C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe [2011-10-24 24424]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-29 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service; C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 306400]
-----------------EOF-----------------
zde je:
Logfile of random's system information tool 1.09 (written by random/random)
Run by pupupaj at 2013-12-08 20:00:20
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 35 GB (35%) free of 100 GB
Total RAM: 3951 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:00:24, on 8.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\trend micro\pupupaj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe /check
O4 - HKCU\..\Run: [Google Update] "C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: T-Mobile Con App Svc (CATmobile) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: T-Mobile RcApp Svc (TMobileRcAppSvc) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11226 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
KHALMNPR.EXE /API
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\system32\msiexec.exe /V
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe {0613B0B4-80E5-4A08-9608-871EDA2D11E4}
taskeng.exe {017FC2F8-5FFE-4390-B889-1A058C018A97}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\pupupaj\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2013-11-13 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-20 553384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2013-11-13 878808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2013-11-13 2328776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-20 210856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2013-11-13 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-22 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL [2013-11-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-13 1725640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-22 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-29 136176]
""= []
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
"SkyDrive"=C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2013-10-24 257136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-22 3567800]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"20131121"=C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe [2013-11-23 180184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-13 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-12-05 08:13:59 ----D---- C:\AdwCleaner
2013-11-13 20:38:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-13 20:35:03 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-13 20:35:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ie4uinit.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\elshyph.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-13 20:33:10 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 20:33:02 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-11-13 20:33:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\wksprt.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\mstsc.exe
2013-11-13 20:32:59 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\mstscax.dll
2013-11-13 20:25:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-11-13 20:25:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-11-13 20:13:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-13 20:13:58 ----A---- C:\Windows\system32\crypt32.dll
2013-11-13 20:13:55 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-13 20:13:54 ----A---- C:\Windows\system32\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\credui.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsass.exe
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-13 20:13:48 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-13 20:13:48 ----A---- C:\Windows\system32\gdi32.dll
2013-11-13 20:13:47 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-13 20:13:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 20:13:46 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
======List of files/folders modified in the last 1 month======
2013-12-08 20:00:24 ----D---- C:\Windows\temp
2013-12-08 20:00:23 ----D---- C:\Program Files\trend micro
2013-12-08 19:57:42 ----D---- C:\Windows\Prefetch
2013-12-08 19:57:37 ----SHD---- C:\Windows\Installer
2013-12-08 19:51:37 ----SHD---- C:\System Volume Information
2013-12-08 19:50:38 ----D---- C:\Users\pupupaj\AppData\Roaming\Skype
2013-12-08 19:49:58 ----D---- C:\Windows\system32\config
2013-12-08 19:49:35 ----D---- C:\ProgramData\Skype
2013-12-08 19:49:31 ----RD---- C:\Program Files (x86)\Skype
2013-11-26 22:43:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-26 21:40:06 ----D---- C:\Program Files\CCleaner
2013-11-26 21:28:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-15 16:49:43 ----D---- C:\Windows\System32
2013-11-15 16:49:43 ----D---- C:\Windows\inf
2013-11-15 16:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-14 20:30:57 ----D---- C:\Windows\rescache
2013-11-14 20:11:59 ----D---- C:\Windows\Microsoft.NET
2013-11-14 20:11:58 ----RSD---- C:\Windows\assembly
2013-11-14 19:26:28 ----D---- C:\Windows\winsxs
2013-11-14 19:25:39 ----D---- C:\Windows\Panther
2013-11-13 21:24:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-11-13 21:24:30 ----D---- C:\Program Files\Internet Explorer
2013-11-13 21:24:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-11-13 21:24:29 ----D---- C:\Windows\system32\cs-CZ
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\migration
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2013-11-13 21:24:28 ----D---- C:\Windows\SysWOW64
2013-11-13 21:24:27 ----D---- C:\Windows\system32\migration
2013-11-13 21:24:27 ----D---- C:\Windows\system32\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\PolicyDefinitions
2013-11-13 21:24:26 ----D---- C:\Windows\SYSWOW64\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers\en-US
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers
2013-11-13 21:24:23 ----D---- C:\Windows\system32\DriverStore
2013-11-13 21:20:38 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2013-11-13 21:18:55 ----D---- C:\Program Files\Microsoft Office 15
2013-11-13 20:39:26 ----D---- C:\Windows\system32\catroot
2013-11-13 20:39:25 ----D---- C:\Windows\system32\catroot2
2013-11-13 20:38:44 ----D---- C:\Windows\Logs
2013-11-13 20:33:46 ----D---- C:\Windows
2013-11-13 20:32:27 ----D---- C:\Windows\system32\MRT
2013-11-13 20:26:34 ----D---- C:\Windows\debug
2013-11-13 20:26:30 ----A---- C:\Windows\system32\MRT.exe
2013-11-13 19:58:41 ----D---- C:\Windows\system32\Tasks
2013-11-11 05:50:16 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-22 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-10-22 205320]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2013-10-22 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2013-10-22 447888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-22 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-10-22 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-10 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-10-22 65264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-10-22 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-10-22 84328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 86016]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
R3 tmobile_mf691_dc_enum;tmobile_mf691_dc_enum; C:\Windows\system32\DRIVERS\tmobile_mf691_dc_enum.sys [2010-04-09 75776]
S3 ALSysIO;ALSysIO; \??\C:\Users\pupupaj\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver; \??\C:\Windows\syswow64\PCTINDIS5X64.SYS []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-10-22 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-10-22 179088]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-21 227896]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 OfficeSvc;Služba Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17 1907896]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-07-08 4153184]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S3 CATmobile;T-Mobile Con App Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe [2010-12-22 118784]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-21 988728]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-13 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-06-13 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-06-13 5132888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe [2010-12-22 114688]
S3 VisualSVNServer;VisualSVN Server; C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe [2011-10-24 24424]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-29 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service; C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 306400]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Preventivni kontrola logu
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.:files
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2549713440-40261444-2675400-1001UA.job
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Preventivni kontrola logu
Logfile of random's system information tool 1.09 (written by random/random)
Run by pupupaj at 2013-12-08 20:44:49
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 36 GB (36%) free of 100 GB
Total RAM: 3951 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:44:53, on 8.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\trend micro\pupupaj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe /check
O4 - HKCU\..\Run: [Google Update] "C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: T-Mobile Con App Svc (CATmobile) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: T-Mobile RcApp Svc (TMobileRcAppSvc) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11772 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
atieclxx
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
taskeng.exe {C79DAF62-C918-498C-B200-BACD6A3BF2CB}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\system32\msiexec.exe /V
KHALMNPR.EXE /API
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\sppsvc.exe
taskeng.exe {CC235F4C-39A1-4ABF-B84E-563A10C9B237}
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3912.0.1167101386\1922144653" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --gpu-vendor-id=0x1002 --gpu-device-id=0x9555 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.3000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="3912.1.112450037\1860129896" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="3912.2.2109678097\1505032692" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="3912.3.1396451810\1189663940" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="3912.4.286875244\1305587608" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="3912.5.1142625084\645805831" /prefetch:673131151
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
"C:\Users\pupupaj\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2013-11-13 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-20 553384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2013-11-13 878808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2013-11-13 2328776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-20 210856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2013-11-13 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-22 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL [2013-11-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-13 1725640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-22 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-29 136176]
""= []
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
"SkyDrive"=C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2013-10-24 257136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-22 3567800]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"20131121"=C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe [2013-11-23 180184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-13 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-12-08 20:31:32 ----D---- C:\_OTM
2013-12-05 08:13:59 ----D---- C:\AdwCleaner
2013-11-13 20:38:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-13 20:35:03 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-13 20:35:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ie4uinit.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\elshyph.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-13 20:33:10 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 20:33:02 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-11-13 20:33:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\wksprt.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\mstsc.exe
2013-11-13 20:32:59 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\mstscax.dll
2013-11-13 20:25:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-11-13 20:25:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-11-13 20:13:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-13 20:13:58 ----A---- C:\Windows\system32\crypt32.dll
2013-11-13 20:13:55 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-13 20:13:54 ----A---- C:\Windows\system32\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\credui.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsass.exe
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-13 20:13:48 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-13 20:13:48 ----A---- C:\Windows\system32\gdi32.dll
2013-11-13 20:13:47 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-13 20:13:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 20:13:46 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
======List of files/folders modified in the last 1 month======
2013-12-08 20:44:52 ----D---- C:\Windows\temp
2013-12-08 20:44:52 ----D---- C:\Program Files\trend micro
2013-12-08 20:44:47 ----D---- C:\Users\pupupaj\AppData\Roaming\Skype
2013-12-08 20:42:38 ----D---- C:\Windows\system32\config
2013-12-08 20:41:01 ----SHD---- C:\Windows\Installer
2013-12-08 20:36:56 ----D---- C:\Windows\Prefetch
2013-12-08 20:32:45 ----D---- C:\Windows\SysWOW64
2013-12-08 20:31:33 ----D---- C:\Windows\Tasks
2013-12-08 19:51:37 ----SHD---- C:\System Volume Information
2013-12-08 19:49:35 ----D---- C:\ProgramData\Skype
2013-12-08 19:49:31 ----RD---- C:\Program Files (x86)\Skype
2013-11-26 22:43:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-26 21:40:06 ----D---- C:\Program Files\CCleaner
2013-11-26 21:28:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-15 16:49:43 ----D---- C:\Windows\System32
2013-11-15 16:49:43 ----D---- C:\Windows\inf
2013-11-15 16:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-14 20:30:57 ----D---- C:\Windows\rescache
2013-11-14 20:11:59 ----D---- C:\Windows\Microsoft.NET
2013-11-14 20:11:58 ----RSD---- C:\Windows\assembly
2013-11-14 19:26:28 ----D---- C:\Windows\winsxs
2013-11-14 19:25:39 ----D---- C:\Windows\Panther
2013-11-13 21:24:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-11-13 21:24:30 ----D---- C:\Program Files\Internet Explorer
2013-11-13 21:24:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-11-13 21:24:29 ----D---- C:\Windows\system32\cs-CZ
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\migration
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\system32\migration
2013-11-13 21:24:27 ----D---- C:\Windows\system32\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\PolicyDefinitions
2013-11-13 21:24:26 ----D---- C:\Windows\SYSWOW64\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers\en-US
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers
2013-11-13 21:24:23 ----D---- C:\Windows\system32\DriverStore
2013-11-13 21:20:38 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2013-11-13 21:18:55 ----D---- C:\Program Files\Microsoft Office 15
2013-11-13 20:39:26 ----D---- C:\Windows\system32\catroot
2013-11-13 20:39:25 ----D---- C:\Windows\system32\catroot2
2013-11-13 20:38:44 ----D---- C:\Windows\Logs
2013-11-13 20:33:46 ----D---- C:\Windows
2013-11-13 20:32:27 ----D---- C:\Windows\system32\MRT
2013-11-13 20:26:34 ----D---- C:\Windows\debug
2013-11-13 20:26:30 ----A---- C:\Windows\system32\MRT.exe
2013-11-13 19:58:41 ----D---- C:\Windows\system32\Tasks
2013-11-11 05:50:16 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-22 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-10-22 205320]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2013-10-22 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2013-10-22 447888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-22 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-10-22 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-10 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-10-22 65264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-10-22 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-10-22 84328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 86016]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
R3 tmobile_mf691_dc_enum;tmobile_mf691_dc_enum; C:\Windows\system32\DRIVERS\tmobile_mf691_dc_enum.sys [2010-04-09 75776]
S3 ALSysIO;ALSysIO; \??\C:\Users\pupupaj\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver; \??\C:\Windows\syswow64\PCTINDIS5X64.SYS []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-10-22 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-10-22 179088]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-21 227896]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 OfficeSvc;Služba Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17 1907896]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-07-08 4153184]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S3 CATmobile;T-Mobile Con App Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe [2010-12-22 118784]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-21 988728]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-13 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-06-13 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-06-13 5132888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe [2010-12-22 114688]
S3 VisualSVNServer;VisualSVN Server; C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe [2011-10-24 24424]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-29 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service; C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 306400]
-----------------EOF-----------------
Run by pupupaj at 2013-12-08 20:44:49
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 36 GB (36%) free of 100 GB
Total RAM: 3951 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:44:53, on 8.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\trend micro\pupupaj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe /check
O4 - HKCU\..\Run: [Google Update] "C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: T-Mobile Con App Svc (CATmobile) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: T-Mobile RcApp Svc (TMobileRcAppSvc) - SmithMicro Inc. - C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11772 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
atieclxx
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
taskeng.exe {C79DAF62-C918-498C-B200-BACD6A3BF2CB}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\system32\msiexec.exe /V
KHALMNPR.EXE /API
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\sppsvc.exe
taskeng.exe {CC235F4C-39A1-4ABF-B84E-563A10C9B237}
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3912.0.1167101386\1922144653" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --gpu-vendor-id=0x1002 --gpu-device-id=0x9555 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.3000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="3912.1.112450037\1860129896" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="3912.2.2109678097\1505032692" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="3912.3.1396451810\1189663940" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="3912.4.286875244\1305587608" /prefetch:673131151
"C:\Users\pupupaj\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Group7 pct:10f stable:pp1 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="3912.5.1142625084\645805831" /prefetch:673131151
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
"C:\Users\pupupaj\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2013-11-13 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-20 553384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2013-11-13 878808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2013-11-13 2328776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-20 210856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll [2013-11-13 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-22 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL [2013-11-13 705240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-13 1725640]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-22 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-10-14 245592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-10-22 606544]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2011-10-07 1744152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\pupupaj\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-29 136176]
""= []
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
"SkyDrive"=C:\Users\pupupaj\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2013-10-24 257136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-03 284696]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-22 3567800]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-11-02 152392]
"20131121"=C:\Program Files\AVAST Software\Avast\setup\emupdate\bc6f6662-9aa6-4ae0-8ee0-32e7f3975ccb.exe [2013-11-23 180184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-13 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-12-08 20:31:32 ----D---- C:\_OTM
2013-12-05 08:13:59 ----D---- C:\AdwCleaner
2013-11-13 20:38:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-13 20:35:03 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-13 20:35:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wininet.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\wextract.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\webcheck.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\vbscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\urlmon.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\url.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\occache.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msrating.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msls31.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshtml.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\mshta.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9diag.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript9.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\jscript.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\inseng.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\imgutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iexpress.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieUnatt.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieui.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iesetup.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iertutil.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iernonce.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iepeers.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieframe.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-13 20:34:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\ie4uinit.exe
2013-11-13 20:34:59 ----A---- C:\Windows\system32\icardie.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\elshyph.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-13 20:34:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-13 20:33:10 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 20:33:02 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 20:33:02 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\wksprtPS.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-11-13 20:33:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-11-13 20:33:01 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-11-13 20:33:00 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\wksprt.exe
2013-11-13 20:33:00 ----A---- C:\Windows\system32\mstsc.exe
2013-11-13 20:32:59 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\rdvidcrl.dll
2013-11-13 20:32:59 ----A---- C:\Windows\system32\mstscax.dll
2013-11-13 20:25:56 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2013-11-13 20:25:56 ----A---- C:\Windows\system32\TSWorkspace.dll
2013-11-13 20:13:58 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-13 20:13:58 ----A---- C:\Windows\system32\crypt32.dll
2013-11-13 20:13:55 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-13 20:13:54 ----A---- C:\Windows\system32\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 20:13:53 ----A---- C:\Windows\system32\credui.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\sspicli.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\schannel.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\secur32.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsass.exe
2013-11-13 20:13:50 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-13 20:13:50 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-13 20:13:48 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-13 20:13:48 ----A---- C:\Windows\system32\gdi32.dll
2013-11-13 20:13:47 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-13 20:13:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-13 20:13:47 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 20:13:46 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
======List of files/folders modified in the last 1 month======
2013-12-08 20:44:52 ----D---- C:\Windows\temp
2013-12-08 20:44:52 ----D---- C:\Program Files\trend micro
2013-12-08 20:44:47 ----D---- C:\Users\pupupaj\AppData\Roaming\Skype
2013-12-08 20:42:38 ----D---- C:\Windows\system32\config
2013-12-08 20:41:01 ----SHD---- C:\Windows\Installer
2013-12-08 20:36:56 ----D---- C:\Windows\Prefetch
2013-12-08 20:32:45 ----D---- C:\Windows\SysWOW64
2013-12-08 20:31:33 ----D---- C:\Windows\Tasks
2013-12-08 19:51:37 ----SHD---- C:\System Volume Information
2013-12-08 19:49:35 ----D---- C:\ProgramData\Skype
2013-12-08 19:49:31 ----RD---- C:\Program Files (x86)\Skype
2013-11-26 22:43:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-11-26 21:40:06 ----D---- C:\Program Files\CCleaner
2013-11-26 21:28:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-15 16:49:43 ----D---- C:\Windows\System32
2013-11-15 16:49:43 ----D---- C:\Windows\inf
2013-11-15 16:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-14 20:30:57 ----D---- C:\Windows\rescache
2013-11-14 20:11:59 ----D---- C:\Windows\Microsoft.NET
2013-11-14 20:11:58 ----RSD---- C:\Windows\assembly
2013-11-14 19:26:28 ----D---- C:\Windows\winsxs
2013-11-14 19:25:39 ----D---- C:\Windows\Panther
2013-11-13 21:24:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-11-13 21:24:30 ----D---- C:\Program Files\Internet Explorer
2013-11-13 21:24:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-11-13 21:24:29 ----D---- C:\Windows\system32\cs-CZ
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\migration
2013-11-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\system32\migration
2013-11-13 21:24:27 ----D---- C:\Windows\system32\en-US
2013-11-13 21:24:27 ----D---- C:\Windows\PolicyDefinitions
2013-11-13 21:24:26 ----D---- C:\Windows\SYSWOW64\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\wbem
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers\en-US
2013-11-13 21:24:26 ----D---- C:\Windows\system32\drivers
2013-11-13 21:24:23 ----D---- C:\Windows\system32\DriverStore
2013-11-13 21:20:38 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2013-11-13 21:18:55 ----D---- C:\Program Files\Microsoft Office 15
2013-11-13 20:39:26 ----D---- C:\Windows\system32\catroot
2013-11-13 20:39:25 ----D---- C:\Windows\system32\catroot2
2013-11-13 20:38:44 ----D---- C:\Windows\Logs
2013-11-13 20:33:46 ----D---- C:\Windows
2013-11-13 20:32:27 ----D---- C:\Windows\system32\MRT
2013-11-13 20:26:34 ----D---- C:\Windows\debug
2013-11-13 20:26:30 ----A---- C:\Windows\system32\MRT.exe
2013-11-13 19:58:41 ----D---- C:\Windows\system32\Tasks
2013-11-11 05:50:16 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-22 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-10-22 205320]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2013-10-22 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2013-10-22 447888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-22 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-10-22 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-10 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-10-22 65264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-10-22 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-10-22 84328]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-04 359936]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-07-27 86016]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
R3 tmobile_mf691_dc_enum;tmobile_mf691_dc_enum; C:\Windows\system32\DRIVERS\tmobile_mf691_dc_enum.sys [2010-04-09 75776]
S3 ALSysIO;ALSysIO; \??\C:\Users\pupupaj\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-04 11922944]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2010-01-18 32768]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-08-07 121600]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver; \??\C:\Windows\syswow64\PCTINDIS5X64.SYS []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-04 238080]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-10-22 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-10-22 179088]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-21 227896]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-03 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 OfficeSvc;Služba Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17 1907896]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-07-08 4153184]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-11-02 641352]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-26 257416]
S3 CATmobile;T-Mobile Con App Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\conappssvc.exe [2010-12-22 118784]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-21 988728]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-13 111616]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-06-13 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-06-13 5132888]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-10-03 725400]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc; C:\Program Files (x86)\T-Mobile\webConnect Manager\RcAppSvc.exe [2010-12-22 114688]
S3 VisualSVNServer;VisualSVN Server; C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe [2011-10-24 24424]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-29 1255736]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service; C:\Program Files\Zune\WMZuneComm.exe [2011-08-05 306400]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Preventivni kontrola logu
Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Preventivni kontrola logu
Dekuju,
zatim vse slape jak ma, tak uvidim za delsi dobu. Bylo tam neco skaredeho nebo to bylo jen preventivni procisteni?
zatim vse slape jak ma, tak uvidim za delsi dobu. Bylo tam neco skaredeho nebo to bylo jen preventivni procisteni?
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Preventivni kontrola logu
Jen AdWary a zbytečnosti. Vir žádný.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.