
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu - několik virů, nejspíše od YT Downloader
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu - několik virů, nejspíše od YT Downloader
Pospuštění PC a při pokusech o odinstalaci YT Downloaderu hlásí Avast několik virů včetně samotného YTuninstaller.exe, takže není možné ani tento downloader odinstalovat. Děkuji předem moc za radu.
Logfile of random's system information tool 1.10 (written by random/random)
Run by martin at 2014-09-22 18:59:38
Microsoft Windows 8.1
System drive C: has 377 GB (82%) free of 461 GB
Total RAM: 3950 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:59:57, on 22. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files (x86)\YTDownloader\YTDownloader.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE
O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: @oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem12.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update WebSpades - Unknown owner - C:\Program Files (x86)\WebSpades\updateWebSpades.exe
O23 - Service: Util WebSpades - Unknown owner - C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11853 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\WINDOWS\System32\spoolsv.exe
taskhostex.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
dashost.exe {03b4caa8-b25a-4cbc-87ab0ab63a8ec7e4}
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files (x86)\WebSpades\updateWebSpades.exe"
"C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-5ed60afe-4f19-4098-9462-4f11535da771 -SystemEventPortName:HostProcess-97af60c7-fd34-4f54-a472-2ad8255a5a91 -IoCancelEventPortName:HostProcess-fd441861-0465-4e3e-b214-0612323082b0 -NonStateChangingEventPortName:HostProcess-84da16be-3d91-4227-9439-4cb999d8c1a4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0a2038e9-270d-4b7b-bb8e-0350970a8912 -DeviceGroupId:
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-1c110397-9af2-404c-b609-52f4b11656e8 -SystemEventPortName:HostProcess-3288e334-6e92-4440-8612-8d808763f01a -IoCancelEventPortName:HostProcess-c2843b93-1fe7-4d1c-8934-dc4a36a819c6 -NonStateChangingEventPortName:HostProcess-3cb7d72a-d8ad-437e-9318-c336d647f1dd -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b31d06fb-e1b4-4bc4-b1d6-1e01571c7414 -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-db41ff15-705c-4fc3-af17-d6c040d12240 -SystemEventPortName:HostProcess-d75050cf-dc84-41da-bd64-01106e17ac2d -IoCancelEventPortName:HostProcess-69ee79da-06e6-4f61-be85-bb27e46d09cd -NonStateChangingEventPortName:HostProcess-ee070795-0cdb-4bef-92fa-0befd83c5229 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b4136b31-e04e-4e42-986d-bfd3d1b471d9 -DeviceGroupId:
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Windows\System32\igfxtray.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
"C:\Windows\System32\igfxpers.exe"
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Lenovo\HOTKEY\extapsup.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\Lenovo\Communications Utility\cammute.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe"
wmiadap.exe /F /T /R
"C:\Program Files (x86)\YTDownloader\YTDownloader.exe"
taskeng.exe {EDC7E508-668C-4349-9CA8-562FBC0FF9EB}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Users\martin\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\searchplugins\
buenosearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-08-12 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-19 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-08-12 2334416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-08-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-19 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-08-12 1729232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-20 13192848]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2013-06-20 255480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-03-04 74288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2014-08-25 1988968]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2012-08-30 548864]
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2013-09-23 738032]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-19 4085896]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-31 571392]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-28 207424]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2014-08-25 1988968]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-22 18:59:38 ----D---- C:\rsit
2014-09-22 18:59:38 ----D---- C:\Program Files\trend micro
2014-09-20 19:09:07 ----D---- C:\Program Files\CCleaner
2014-09-20 17:48:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 17:47:02 ----A---- C:\autoexec.bat
2014-09-20 17:46:31 ----D---- C:\Program Files\Enigma Software Group
2014-09-20 17:44:39 ----D---- C:\WINDOWS\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-09-20 17:34:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 20:23:12 ----D---- C:\ProgramData\TEMP
2014-09-15 05:37:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 05:37:50 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 05:37:50 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 05:37:49 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 05:37:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 05:37:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 05:37:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 05:36:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 05:36:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 05:36:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 05:36:55 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 05:36:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 05:36:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 05:36:53 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 05:36:52 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 05:36:43 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 05:36:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 05:36:41 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 05:36:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 05:36:36 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 05:36:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 05:36:33 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 05:36:31 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 05:36:30 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 05:36:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 05:36:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 05:36:15 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 05:36:11 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 05:36:04 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 05:36:03 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 05:35:54 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 05:35:53 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 05:35:50 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 05:35:49 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 05:35:49 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 05:35:44 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 05:35:38 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 05:35:32 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 05:35:30 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 05:35:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 05:35:24 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 05:35:23 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 05:27:44 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 13:09:37 ----D---- C:\Users\martin\AppData\Roaming\Ashampoo
2014-09-14 13:09:29 ----D---- C:\ProgramData\Ashampoo
2014-09-14 13:06:47 ----D---- C:\Program Files (x86)\YTDownloader
2014-09-14 13:03:52 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-14 13:03:21 ----D---- C:\Users\martin\AppData\Roaming\Opera Software
2014-09-14 13:03:07 ----D---- C:\Program Files (x86)\Opera
2014-09-14 13:01:33 ----D---- C:\ProgramData\WindowsMangerProtect
2014-09-14 13:01:25 ----D---- C:\Users\martin\AppData\Roaming\webssearches
2014-09-10 08:12:08 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-10 08:12:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 08:12:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 08:11:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-10 08:11:49 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-10 08:11:48 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 23:40:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-08-27 19:59:30 ----A---- C:\WINDOWS\system32\win32k.sys
2014-08-23 16:12:04 ----D---- C:\WINDOWS\Minidump
======List of files/folders modified in the last 1 month======
2014-09-22 18:59:42 ----RD---- C:\WINDOWS\System32
2014-09-22 18:59:42 ----D---- C:\WINDOWS\Inf
2014-09-22 18:59:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-22 18:59:38 ----D---- C:\Program Files
2014-09-22 18:59:37 ----D---- C:\WINDOWS\Prefetch
2014-09-22 18:57:57 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-22 18:57:56 ----D---- C:\Windows
2014-09-22 18:57:38 ----D---- C:\Users\martin\AppData\Roaming\Skype
2014-09-22 18:54:48 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-09-22 18:52:53 ----D---- C:\WINDOWS\Temp
2014-09-22 18:48:54 ----SHD---- C:\WINDOWS\Installer
2014-09-22 18:48:54 ----RD---- C:\Program Files (x86)
2014-09-22 18:48:54 ----HD---- C:\ProgramData
2014-09-22 18:40:02 ----D---- C:\ProgramData\ArcSoft
2014-09-22 18:39:48 ----D---- C:\Users\martin\AppData\Roaming\ArcSoft
2014-09-22 18:09:39 ----D---- C:\WINDOWS\system32\Tasks
2014-09-22 18:09:38 ----D---- C:\WINDOWS\Tasks
2014-09-22 18:02:54 ----D---- C:\WINDOWS\system32\sru
2014-09-22 16:46:51 ----D---- C:\WINDOWS\system32\config
2014-09-22 16:18:22 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 21:45:20 ----SHD---- C:\System Volume Information
2014-09-21 19:48:16 ----AD---- C:\ProgramData\Lenovo
2014-09-21 16:56:07 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-20 19:26:32 ----D---- C:\WINDOWS\WinSxS
2014-09-20 19:22:24 ----RD---- C:\WINDOWS\ToastData
2014-09-20 19:22:24 ----D---- C:\WINDOWS\SysWOW64
2014-09-20 19:22:22 ----D---- C:\WINDOWS\WinStore
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-20 19:22:22 ----D---- C:\Program Files\Windows Journal
2014-09-20 19:22:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\setup
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 19:22:20 ----RSD---- C:\WINDOWS\Fonts
2014-09-20 19:22:20 ----D---- C:\WINDOWS\apppatch
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 19:22:19 ----D---- C:\WINDOWS\system32\migration
2014-09-20 19:22:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-20 19:13:14 ----D---- C:\Program Files (x86)\Linkey
2014-09-20 19:11:59 ----D---- C:\Users\martin\AppData\Roaming\uTorrent
2014-09-20 19:10:43 ----DC---- C:\WINDOWS\Panther
2014-09-20 19:10:42 ----D---- C:\WINDOWS\debug
2014-09-20 19:05:52 ----D---- C:\Program Files (x86)\TornTV.com
2014-09-20 17:44:36 ----D---- C:\Program Files (x86)\Common Files
2014-09-20 17:37:40 ----D---- C:\Program Files (x86)\Google
2014-09-19 00:34:09 ----D---- C:\WINDOWS\AppReadiness
2014-09-19 00:34:08 ----HD---- C:\Program Files\WindowsApps
2014-09-16 08:10:16 ----RSD---- C:\WINDOWS\assembly
2014-09-16 08:03:53 ----D---- C:\WINDOWS\CbsTemp
2014-09-16 07:59:37 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 13:06:50 ----D---- C:\Program Files\Common Files\System
2014-09-13 22:56:53 ----D---- C:\WINDOWS\rescache
2014-09-13 09:18:01 ----D---- C:\WINDOWS\system32\MRT
2014-09-13 09:11:31 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-12 17:06:56 ----D---- C:\Program Files\Internet Explorer
2014-09-12 17:06:56 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-10 08:12:39 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-10 08:12:38 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-10 08:12:23 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-10 08:12:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-02 22:06:15 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-02 17:40:28 ----D---- C:\WINDOWS\tracing
2014-09-01 21:34:28 ----D---- C:\WINDOWS\system32\NDF
2014-08-24 19:16:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-19 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-19 224896]
R0 Fastboot;Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [2013-09-23 66288]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-19 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-19 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-19 427360]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwr64v.sys [2014-03-07 20736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-19 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-19 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-19 92008]
R2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [2014-08-25 58728]
R3 AmUStor;@oem20.inf,%AmUStor.SvcDesc%;AM USB Stroage Driver; C:\WINDOWS\system32\drivers\AmUStor.SYS [2012-07-20 100992]
R3 bcbtums;@oem29.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-05 170712]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btwampfl;@oem29.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem3.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2012-09-19 186648]
R3 btwavdt;@oem4.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\system32\DRIVERS\btwavdt.sys [2012-09-16 224568]
R3 btwl2cap;@oem6.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2012-09-16 22328]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2013-04-17 44800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-21 4106256]
R3 IntcDAud;@oem13.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem21.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem23.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vm331avs;@oem10.inf,%USBCamera.DeviceDesc2%;Digital Camera 1; C:\WINDOWS\System32\Drivers\vm331avs.sys [2012-09-05 981112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem16.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-19 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2012-09-26 957304]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2013-09-23 140016]
R2 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R2 IBMPMSVC;@oem12.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2013-04-17 61224]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-07-17 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-03-10 2085184]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2012-08-11 136288]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 LocationTaskManager;LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-12-12 468288]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-20 142960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2014-06-10 124400]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R2 Update WebSpades;Update WebSpades; C:\Program Files (x86)\WebSpades\updateWebSpades.exe [2014-05-20 317728]
R2 Util WebSpades;Util WebSpades; C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe [2014-05-20 317728]
R3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-03-04 573488]
R3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-03-04 512048]
R3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-03-04 527920]
R3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-03-04 702512]
R3 Power Manager DBC Service;Lenovo Settings Power Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2014-03-07 1669976]
S2 BcmBtRSupport;@oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-05 2252504]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-09 178760]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2014-02-21 24120]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2014-04-07 110128]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by martin at 2014-09-22 18:59:38
Microsoft Windows 8.1
System drive C: has 377 GB (82%) free of 461 GB
Total RAM: 3950 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:59:57, on 22. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files (x86)\YTDownloader\YTDownloader.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE
O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: @oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem12.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update WebSpades - Unknown owner - C:\Program Files (x86)\WebSpades\updateWebSpades.exe
O23 - Service: Util WebSpades - Unknown owner - C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11853 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\WINDOWS\System32\spoolsv.exe
taskhostex.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
dashost.exe {03b4caa8-b25a-4cbc-87ab0ab63a8ec7e4}
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files (x86)\WebSpades\updateWebSpades.exe"
"C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-5ed60afe-4f19-4098-9462-4f11535da771 -SystemEventPortName:HostProcess-97af60c7-fd34-4f54-a472-2ad8255a5a91 -IoCancelEventPortName:HostProcess-fd441861-0465-4e3e-b214-0612323082b0 -NonStateChangingEventPortName:HostProcess-84da16be-3d91-4227-9439-4cb999d8c1a4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0a2038e9-270d-4b7b-bb8e-0350970a8912 -DeviceGroupId:
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-1c110397-9af2-404c-b609-52f4b11656e8 -SystemEventPortName:HostProcess-3288e334-6e92-4440-8612-8d808763f01a -IoCancelEventPortName:HostProcess-c2843b93-1fe7-4d1c-8934-dc4a36a819c6 -NonStateChangingEventPortName:HostProcess-3cb7d72a-d8ad-437e-9318-c336d647f1dd -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b31d06fb-e1b4-4bc4-b1d6-1e01571c7414 -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-db41ff15-705c-4fc3-af17-d6c040d12240 -SystemEventPortName:HostProcess-d75050cf-dc84-41da-bd64-01106e17ac2d -IoCancelEventPortName:HostProcess-69ee79da-06e6-4f61-be85-bb27e46d09cd -NonStateChangingEventPortName:HostProcess-ee070795-0cdb-4bef-92fa-0befd83c5229 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b4136b31-e04e-4e42-986d-bfd3d1b471d9 -DeviceGroupId:
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Windows\System32\igfxtray.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
"C:\Windows\System32\igfxpers.exe"
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Lenovo\HOTKEY\extapsup.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\Lenovo\Communications Utility\cammute.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe"
wmiadap.exe /F /T /R
"C:\Program Files (x86)\YTDownloader\YTDownloader.exe"
taskeng.exe {EDC7E508-668C-4349-9CA8-562FBC0FF9EB}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Users\martin\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\searchplugins\
buenosearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-08-12 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-19 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-08-12 2334416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-08-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-19 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-08-12 1729232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-20 13192848]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2013-06-20 255480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-03-04 74288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2014-08-25 1988968]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2012-08-30 548864]
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2013-09-23 738032]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-19 4085896]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-31 571392]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-28 207424]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2014-08-25 1988968]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-22 18:59:38 ----D---- C:\rsit
2014-09-22 18:59:38 ----D---- C:\Program Files\trend micro
2014-09-20 19:09:07 ----D---- C:\Program Files\CCleaner
2014-09-20 17:48:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 17:47:02 ----A---- C:\autoexec.bat
2014-09-20 17:46:31 ----D---- C:\Program Files\Enigma Software Group
2014-09-20 17:44:39 ----D---- C:\WINDOWS\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-09-20 17:34:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 20:23:12 ----D---- C:\ProgramData\TEMP
2014-09-15 05:37:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 05:37:50 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 05:37:50 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 05:37:49 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 05:37:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 05:37:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 05:37:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 05:36:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 05:36:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 05:36:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 05:36:55 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 05:36:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 05:36:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 05:36:53 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 05:36:52 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 05:36:43 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 05:36:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 05:36:41 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 05:36:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 05:36:36 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 05:36:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 05:36:33 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 05:36:31 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 05:36:30 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 05:36:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 05:36:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 05:36:15 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 05:36:11 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 05:36:04 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 05:36:03 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 05:35:54 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 05:35:53 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 05:35:50 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 05:35:49 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 05:35:49 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 05:35:44 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 05:35:38 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 05:35:32 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 05:35:30 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 05:35:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 05:35:24 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 05:35:23 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 05:27:44 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 13:09:37 ----D---- C:\Users\martin\AppData\Roaming\Ashampoo
2014-09-14 13:09:29 ----D---- C:\ProgramData\Ashampoo
2014-09-14 13:06:47 ----D---- C:\Program Files (x86)\YTDownloader
2014-09-14 13:03:52 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-14 13:03:21 ----D---- C:\Users\martin\AppData\Roaming\Opera Software
2014-09-14 13:03:07 ----D---- C:\Program Files (x86)\Opera
2014-09-14 13:01:33 ----D---- C:\ProgramData\WindowsMangerProtect
2014-09-14 13:01:25 ----D---- C:\Users\martin\AppData\Roaming\webssearches
2014-09-10 08:12:08 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-10 08:12:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 08:12:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 08:11:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-10 08:11:49 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-10 08:11:48 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 23:40:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-08-27 19:59:30 ----A---- C:\WINDOWS\system32\win32k.sys
2014-08-23 16:12:04 ----D---- C:\WINDOWS\Minidump
======List of files/folders modified in the last 1 month======
2014-09-22 18:59:42 ----RD---- C:\WINDOWS\System32
2014-09-22 18:59:42 ----D---- C:\WINDOWS\Inf
2014-09-22 18:59:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-22 18:59:38 ----D---- C:\Program Files
2014-09-22 18:59:37 ----D---- C:\WINDOWS\Prefetch
2014-09-22 18:57:57 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-22 18:57:56 ----D---- C:\Windows
2014-09-22 18:57:38 ----D---- C:\Users\martin\AppData\Roaming\Skype
2014-09-22 18:54:48 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-09-22 18:52:53 ----D---- C:\WINDOWS\Temp
2014-09-22 18:48:54 ----SHD---- C:\WINDOWS\Installer
2014-09-22 18:48:54 ----RD---- C:\Program Files (x86)
2014-09-22 18:48:54 ----HD---- C:\ProgramData
2014-09-22 18:40:02 ----D---- C:\ProgramData\ArcSoft
2014-09-22 18:39:48 ----D---- C:\Users\martin\AppData\Roaming\ArcSoft
2014-09-22 18:09:39 ----D---- C:\WINDOWS\system32\Tasks
2014-09-22 18:09:38 ----D---- C:\WINDOWS\Tasks
2014-09-22 18:02:54 ----D---- C:\WINDOWS\system32\sru
2014-09-22 16:46:51 ----D---- C:\WINDOWS\system32\config
2014-09-22 16:18:22 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 21:45:20 ----SHD---- C:\System Volume Information
2014-09-21 19:48:16 ----AD---- C:\ProgramData\Lenovo
2014-09-21 16:56:07 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-20 19:26:32 ----D---- C:\WINDOWS\WinSxS
2014-09-20 19:22:24 ----RD---- C:\WINDOWS\ToastData
2014-09-20 19:22:24 ----D---- C:\WINDOWS\SysWOW64
2014-09-20 19:22:22 ----D---- C:\WINDOWS\WinStore
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-20 19:22:22 ----D---- C:\Program Files\Windows Journal
2014-09-20 19:22:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\setup
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 19:22:20 ----RSD---- C:\WINDOWS\Fonts
2014-09-20 19:22:20 ----D---- C:\WINDOWS\apppatch
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 19:22:19 ----D---- C:\WINDOWS\system32\migration
2014-09-20 19:22:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-20 19:13:14 ----D---- C:\Program Files (x86)\Linkey
2014-09-20 19:11:59 ----D---- C:\Users\martin\AppData\Roaming\uTorrent
2014-09-20 19:10:43 ----DC---- C:\WINDOWS\Panther
2014-09-20 19:10:42 ----D---- C:\WINDOWS\debug
2014-09-20 19:05:52 ----D---- C:\Program Files (x86)\TornTV.com
2014-09-20 17:44:36 ----D---- C:\Program Files (x86)\Common Files
2014-09-20 17:37:40 ----D---- C:\Program Files (x86)\Google
2014-09-19 00:34:09 ----D---- C:\WINDOWS\AppReadiness
2014-09-19 00:34:08 ----HD---- C:\Program Files\WindowsApps
2014-09-16 08:10:16 ----RSD---- C:\WINDOWS\assembly
2014-09-16 08:03:53 ----D---- C:\WINDOWS\CbsTemp
2014-09-16 07:59:37 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 13:06:50 ----D---- C:\Program Files\Common Files\System
2014-09-13 22:56:53 ----D---- C:\WINDOWS\rescache
2014-09-13 09:18:01 ----D---- C:\WINDOWS\system32\MRT
2014-09-13 09:11:31 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-12 17:06:56 ----D---- C:\Program Files\Internet Explorer
2014-09-12 17:06:56 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-10 08:12:39 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-10 08:12:38 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-10 08:12:23 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-10 08:12:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-02 22:06:15 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-02 17:40:28 ----D---- C:\WINDOWS\tracing
2014-09-01 21:34:28 ----D---- C:\WINDOWS\system32\NDF
2014-08-24 19:16:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-19 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-19 224896]
R0 Fastboot;Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [2013-09-23 66288]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-19 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-19 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-19 427360]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwr64v.sys [2014-03-07 20736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-19 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-19 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-19 92008]
R2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [2014-08-25 58728]
R3 AmUStor;@oem20.inf,%AmUStor.SvcDesc%;AM USB Stroage Driver; C:\WINDOWS\system32\drivers\AmUStor.SYS [2012-07-20 100992]
R3 bcbtums;@oem29.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-05 170712]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btwampfl;@oem29.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem3.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2012-09-19 186648]
R3 btwavdt;@oem4.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\system32\DRIVERS\btwavdt.sys [2012-09-16 224568]
R3 btwl2cap;@oem6.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2012-09-16 22328]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2013-04-17 44800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-21 4106256]
R3 IntcDAud;@oem13.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem21.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem23.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vm331avs;@oem10.inf,%USBCamera.DeviceDesc2%;Digital Camera 1; C:\WINDOWS\System32\Drivers\vm331avs.sys [2012-09-05 981112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem16.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-19 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2012-09-26 957304]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2013-09-23 140016]
R2 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R2 IBMPMSVC;@oem12.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2013-04-17 61224]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-07-17 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-03-10 2085184]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2012-08-11 136288]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 LocationTaskManager;LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-12-12 468288]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-20 142960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2014-06-10 124400]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R2 Update WebSpades;Update WebSpades; C:\Program Files (x86)\WebSpades\updateWebSpades.exe [2014-05-20 317728]
R2 Util WebSpades;Util WebSpades; C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe [2014-05-20 317728]
R3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-03-04 573488]
R3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-03-04 512048]
R3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-03-04 527920]
R3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-03-04 702512]
R3 Power Manager DBC Service;Lenovo Settings Power Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2014-03-07 1669976]
S2 BcmBtRSupport;@oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-05 2252504]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-09 178760]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2014-02-21 24120]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2014-04-07 110128]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119547
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Zdravím!
Spusťte nejprve tuto utilitu:
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Výpis z logu:
# AdwCleaner v3.310 - Report created 22/09/2014 at 19:25:51
# Updated 12/09/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : martin - LENOVO-PC
# Running from : C:\Users\martin\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : sbmntr
[#] Service Deleted : Update WebSpades
[#] Service Deleted : Util WebSpades
Service Deleted : WindowsMangerProtect
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
[#] Folder Deleted : C:\ProgramData\BitGuard
[#] Folder Deleted : C:\ProgramData\Browser Manager
[#] Folder Deleted : C:\ProgramData\BrowserProtect
Folder Deleted : C:\ProgramData\wincert
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Linkey
Folder Deleted : C:\Program Files (x86)\TornTV.com
Folder Deleted : C:\Program Files (x86)\WebSpades
Folder Deleted : C:\Program Files (x86)\WinZip Registry Optimizer
Folder Deleted : C:\Program Files (x86)\YTDownloader
Folder Deleted : C:\Users\martin\AppData\Local\globalUpdate
Folder Deleted : C:\Users\martin\AppData\Local\Temp\WebSpades
Folder Deleted : C:\Users\martin\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\martin\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\martin\AppData\Roaming\playnowradio
Folder Deleted : C:\Users\martin\AppData\Roaming\webssearches
Folder Deleted : C:\Users\martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Folder Deleted : C:\Users\martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\Users\martin\Desktop\TornTV.lnk
File Deleted : C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\invalidprefs.js
File Deleted : C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\searchplugins\buenosearch.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml
***** [ Scheduled Tasks ] *****
Task Deleted : SMupdate1
Task Deleted : YTDownloader
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebSpades_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebSpades_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateWebSpades_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateWebSpades_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilWebSpades_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilWebSpades_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update WebSpades
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util WebSpades
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\WebSpades
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\SystemK
Key Deleted : HKLM\SOFTWARE\WebSpades
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17278
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v32.0.2 (x86 cs)
[ File : C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\prefs.js ]
Line Deleted : user_pref("extensions.BTR-V7.apn-domain", "\"www.search.ask.com\"");
Line Deleted : user_pref("extensions.buenosearch.admin", false);
Line Deleted : user_pref("extensions.buenosearch.aflt", "babsst");
Line Deleted : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
Line Deleted : user_pref("extensions.buenosearch.autoRvrt", "false");
Line Deleted : user_pref("extensions.buenosearch.bbDpng", "20");
Line Deleted : user_pref("extensions.buenosearch.cntry", "CZ");
Line Deleted : user_pref("extensions.buenosearch.dfltLng", "cs");
Line Deleted : user_pref("extensions.buenosearch.excTlbr", false);
Line Deleted : user_pref("extensions.buenosearch.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.buenosearch.hdrMd5", "A5BD93975599DC1CAC1B9A09CBFCB1C1");
Line Deleted : user_pref("extensions.buenosearch.id", "e67bca37000000000000fa2fa8fb9a03");
Line Deleted : user_pref("extensions.buenosearch.instlDay", "16208");
Line Deleted : user_pref("extensions.buenosearch.instlRef", "sst");
Line Deleted : user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5251");
Line Deleted : user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.715:01:04");
Line Deleted : user_pref("extensions.buenosearch.newTab", false);
Line Deleted : user_pref("extensions.buenosearch.prdct", "buenosearch");
Line Deleted : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
Line Deleted : user_pref("extensions.buenosearch.rvrt", "false");
Line Deleted : user_pref("extensions.buenosearch.sg", "azb");
Line Deleted : user_pref("extensions.buenosearch.smplGrp", "none");
Line Deleted : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5251");
Line Deleted : user_pref("extensions.buenosearch.tlbrId", "base");
Line Deleted : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5251");
Line Deleted : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
Line Deleted : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.715:01:04");
Line Deleted : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
Line Deleted : user_pref("extensions.crossrider.bic", "14893b31ed893f67db46a6f70a71ca16");
Line Deleted : user_pref("extensions.toolbar_BTR-V7@apn.ask.com.install-event-fired", true);
-\\ Google Chrome v
[ File : C:\Users\martin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [18096 octets] - [22/09/2014 19:24:01]
AdwCleaner[S0].txt - [14798 octets] - [22/09/2014 19:25:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14859 octets] ##########
# AdwCleaner v3.310 - Report created 22/09/2014 at 19:25:51
# Updated 12/09/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : martin - LENOVO-PC
# Running from : C:\Users\martin\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : sbmntr
[#] Service Deleted : Update WebSpades
[#] Service Deleted : Util WebSpades
Service Deleted : WindowsMangerProtect
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
[#] Folder Deleted : C:\ProgramData\BitGuard
[#] Folder Deleted : C:\ProgramData\Browser Manager
[#] Folder Deleted : C:\ProgramData\BrowserProtect
Folder Deleted : C:\ProgramData\wincert
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Linkey
Folder Deleted : C:\Program Files (x86)\TornTV.com
Folder Deleted : C:\Program Files (x86)\WebSpades
Folder Deleted : C:\Program Files (x86)\WinZip Registry Optimizer
Folder Deleted : C:\Program Files (x86)\YTDownloader
Folder Deleted : C:\Users\martin\AppData\Local\globalUpdate
Folder Deleted : C:\Users\martin\AppData\Local\Temp\WebSpades
Folder Deleted : C:\Users\martin\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\martin\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\martin\AppData\Roaming\playnowradio
Folder Deleted : C:\Users\martin\AppData\Roaming\webssearches
Folder Deleted : C:\Users\martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Folder Deleted : C:\Users\martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\Users\martin\Desktop\TornTV.lnk
File Deleted : C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\invalidprefs.js
File Deleted : C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\searchplugins\buenosearch.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml
***** [ Scheduled Tasks ] *****
Task Deleted : SMupdate1
Task Deleted : YTDownloader
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebSpades_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebSpades_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateWebSpades_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updateWebSpades_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilWebSpades_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilWebSpades_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update WebSpades
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util WebSpades
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\WebSpades
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\SystemK
Key Deleted : HKLM\SOFTWARE\WebSpades
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17278
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v32.0.2 (x86 cs)
[ File : C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default\prefs.js ]
Line Deleted : user_pref("extensions.BTR-V7.apn-domain", "\"www.search.ask.com\"");
Line Deleted : user_pref("extensions.buenosearch.admin", false);
Line Deleted : user_pref("extensions.buenosearch.aflt", "babsst");
Line Deleted : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
Line Deleted : user_pref("extensions.buenosearch.autoRvrt", "false");
Line Deleted : user_pref("extensions.buenosearch.bbDpng", "20");
Line Deleted : user_pref("extensions.buenosearch.cntry", "CZ");
Line Deleted : user_pref("extensions.buenosearch.dfltLng", "cs");
Line Deleted : user_pref("extensions.buenosearch.excTlbr", false);
Line Deleted : user_pref("extensions.buenosearch.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.buenosearch.hdrMd5", "A5BD93975599DC1CAC1B9A09CBFCB1C1");
Line Deleted : user_pref("extensions.buenosearch.id", "e67bca37000000000000fa2fa8fb9a03");
Line Deleted : user_pref("extensions.buenosearch.instlDay", "16208");
Line Deleted : user_pref("extensions.buenosearch.instlRef", "sst");
Line Deleted : user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5251");
Line Deleted : user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.715:01:04");
Line Deleted : user_pref("extensions.buenosearch.newTab", false);
Line Deleted : user_pref("extensions.buenosearch.prdct", "buenosearch");
Line Deleted : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
Line Deleted : user_pref("extensions.buenosearch.rvrt", "false");
Line Deleted : user_pref("extensions.buenosearch.sg", "azb");
Line Deleted : user_pref("extensions.buenosearch.smplGrp", "none");
Line Deleted : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5251");
Line Deleted : user_pref("extensions.buenosearch.tlbrId", "base");
Line Deleted : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5251");
Line Deleted : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
Line Deleted : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.715:01:04");
Line Deleted : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
Line Deleted : user_pref("extensions.crossrider.bic", "14893b31ed893f67db46a6f70a71ca16");
Line Deleted : user_pref("extensions.toolbar_BTR-V7@apn.ask.com.install-event-fired", true);
-\\ Google Chrome v
[ File : C:\Users\martin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [18096 octets] - [22/09/2014 19:24:01]
AdwCleaner[S0].txt - [14798 octets] - [22/09/2014 19:25:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14859 octets] ##########
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
A po odeslání výpisu přišly opět 3 upozornění od Avastu, poslední toto:
URL
hxxp://s3.amazonaws.com/shopper-pro/ShopperProJSFull.exe
Infekce
FileRepMetagen [DRP]
URL
hxxp://s3.amazonaws.com/shopper-pro/ShopperProJSFull.exe
Infekce
FileRepMetagen [DRP]
- Rudy
- Site Admin
- Příspěvky: 119547
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
PC se snaží stáhnout šmejda, přístup byl zablokován. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Logfile of random's system information tool 1.10 (written by random/random)
Run by martin at 2014-09-22 20:07:57
Microsoft Windows 8.1
System drive C: has 377 GB (82%) free of 461 GB
Total RAM: 3950 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:08:00, on 22. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE
O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: @oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem12.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10935 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\ibmpmsvc.exe
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
dashost.exe {9b7af6c2-0cda-464a-af527042b09483a5}
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ab179fd3-b591-4883-92d3-c2d63452a465 -SystemEventPortName:HostProcess-9e0f229a-1ad5-45f7-ab1f-0fdb4fe963fa -IoCancelEventPortName:HostProcess-9ae4e857-23aa-46cf-8f2b-447969cc928b -NonStateChangingEventPortName:HostProcess-51c68536-57a0-44cb-b45e-07ef84ad1a6b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0afa07f3-886c-468c-ac44-68af79a9009d -DeviceGroupId:
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-1ce54694-f81b-443b-93eb-5a075c777e41 -SystemEventPortName:HostProcess-41ca345d-80bf-44a3-9328-583d9483d1ae -IoCancelEventPortName:HostProcess-3d7c1b15-4e81-4596-ad8e-238ea440261e -NonStateChangingEventPortName:HostProcess-a7a97550-91f7-4585-a938-9f598470ecc8 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:fc28bacf-7737-4552-a47b-af678e475c2c -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8e3b680f-c0f7-46eb-8d7b-7e98df57b472 -SystemEventPortName:HostProcess-da1d9fb1-2c84-482a-b761-4dc9966ff536 -IoCancelEventPortName:HostProcess-19b42841-c1f5-4fe4-94a3-7fad93b6a2ac -NonStateChangingEventPortName:HostProcess-15de8b96-1c43-4cca-8f43-1ed780e0f92f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7edace5e-2a22-4fb0-a5d4-2198607c5caf -DeviceGroupId:
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\igfxpers.exe"
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Lenovo\HOTKEY\extapsup.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\AdwCleaner\AdwCleaner[S0].txt
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\Lenovo\Communications Utility\cammute.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\martin\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-08-12 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-19 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-08-12 2334416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-08-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-19 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-08-12 1729232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-20 13192848]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2013-06-20 255480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-03-04 74288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2012-08-30 548864]
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2013-09-23 738032]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-19 4085896]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-31 571392]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-28 207424]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)\Skype
2014-09-22 19:25:10 ----A---- C:\WINDOWS\SYSWOW64\sqlite3.dll
2014-09-22 19:23:58 ----D---- C:\AdwCleaner
2014-09-22 18:59:38 ----D---- C:\rsit
2014-09-22 18:59:38 ----D---- C:\Program Files\trend micro
2014-09-20 19:09:07 ----D---- C:\Program Files\CCleaner
2014-09-20 17:48:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 17:47:02 ----A---- C:\autoexec.bat
2014-09-20 17:46:31 ----D---- C:\Program Files\Enigma Software Group
2014-09-20 17:44:39 ----D---- C:\WINDOWS\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-09-20 17:34:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 20:23:12 ----D---- C:\ProgramData\TEMP
2014-09-15 05:37:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 05:37:50 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 05:37:50 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 05:37:49 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 05:37:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 05:37:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 05:37:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 05:36:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 05:36:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 05:36:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 05:36:55 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 05:36:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 05:36:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 05:36:53 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 05:36:52 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 05:36:43 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 05:36:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 05:36:41 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 05:36:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 05:36:36 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 05:36:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 05:36:33 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 05:36:31 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 05:36:30 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 05:36:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 05:36:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 05:36:15 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 05:36:11 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 05:36:04 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 05:36:03 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 05:35:54 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 05:35:53 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 05:35:50 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 05:35:49 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 05:35:49 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 05:35:44 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 05:35:38 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 05:35:32 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 05:35:30 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 05:35:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 05:35:24 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 05:35:23 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 05:27:44 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 13:09:37 ----D---- C:\Users\martin\AppData\Roaming\Ashampoo
2014-09-14 13:09:29 ----D---- C:\ProgramData\Ashampoo
2014-09-14 13:03:21 ----D---- C:\Users\martin\AppData\Roaming\Opera Software
2014-09-14 13:03:07 ----D---- C:\Program Files (x86)\Opera
2014-09-10 08:12:08 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-10 08:12:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 08:12:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 08:11:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-10 08:11:49 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-10 08:11:48 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 23:40:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-08-27 19:59:30 ----A---- C:\WINDOWS\system32\win32k.sys
2014-08-23 16:12:04 ----D---- C:\WINDOWS\Minidump
======List of files/folders modified in the last 1 month======
2014-09-22 20:02:02 ----D---- C:\WINDOWS\system32\sru
2014-09-22 19:41:02 ----D---- C:\WINDOWS\Temp
2014-09-22 19:35:03 ----RD---- C:\WINDOWS\System32
2014-09-22 19:35:03 ----D---- C:\WINDOWS\Inf
2014-09-22 19:35:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-22 19:30:36 ----D---- C:\Users\martin\AppData\Roaming\Skype
2014-09-22 19:29:59 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-09-22 19:29:25 ----SHD---- C:\WINDOWS\Installer
2014-09-22 19:29:23 ----D---- C:\WINDOWS\Prefetch
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)
2014-09-22 19:29:20 ----D---- C:\Program Files (x86)\Common Files
2014-09-22 19:29:19 ----D---- C:\ProgramData\Skype
2014-09-22 19:25:52 ----HD---- C:\ProgramData
2014-09-22 19:25:52 ----D---- C:\WINDOWS\system32\Tasks
2014-09-22 19:25:10 ----D---- C:\WINDOWS\SysWOW64
2014-09-22 18:59:38 ----D---- C:\Program Files
2014-09-22 18:57:57 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-22 18:57:56 ----D---- C:\Windows
2014-09-22 18:40:02 ----D---- C:\ProgramData\ArcSoft
2014-09-22 18:39:48 ----D---- C:\Users\martin\AppData\Roaming\ArcSoft
2014-09-22 18:09:38 ----D---- C:\WINDOWS\Tasks
2014-09-22 16:46:51 ----D---- C:\WINDOWS\system32\config
2014-09-22 16:18:22 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 21:45:20 ----SHD---- C:\System Volume Information
2014-09-21 19:48:16 ----AD---- C:\ProgramData\Lenovo
2014-09-21 16:56:07 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-20 19:26:32 ----D---- C:\WINDOWS\WinSxS
2014-09-20 19:22:24 ----RD---- C:\WINDOWS\ToastData
2014-09-20 19:22:22 ----D---- C:\WINDOWS\WinStore
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-20 19:22:22 ----D---- C:\Program Files\Windows Journal
2014-09-20 19:22:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\setup
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 19:22:20 ----RSD---- C:\WINDOWS\Fonts
2014-09-20 19:22:20 ----D---- C:\WINDOWS\apppatch
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 19:22:19 ----D---- C:\WINDOWS\system32\migration
2014-09-20 19:22:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-20 19:11:59 ----D---- C:\Users\martin\AppData\Roaming\uTorrent
2014-09-20 19:10:43 ----DC---- C:\WINDOWS\Panther
2014-09-20 19:10:42 ----D---- C:\WINDOWS\debug
2014-09-20 17:37:40 ----D---- C:\Program Files (x86)\Google
2014-09-19 00:34:09 ----D---- C:\WINDOWS\AppReadiness
2014-09-19 00:34:08 ----HD---- C:\Program Files\WindowsApps
2014-09-16 08:10:16 ----RSD---- C:\WINDOWS\assembly
2014-09-16 08:03:53 ----D---- C:\WINDOWS\CbsTemp
2014-09-16 07:59:37 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 13:06:50 ----D---- C:\Program Files\Common Files\System
2014-09-13 22:56:53 ----D---- C:\WINDOWS\rescache
2014-09-13 09:18:01 ----D---- C:\WINDOWS\system32\MRT
2014-09-13 09:11:31 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-12 17:06:56 ----D---- C:\Program Files\Internet Explorer
2014-09-12 17:06:56 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-10 08:12:39 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-10 08:12:38 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-10 08:12:23 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-10 08:12:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-02 22:06:15 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-02 17:40:28 ----D---- C:\WINDOWS\tracing
2014-09-01 21:34:28 ----D---- C:\WINDOWS\system32\NDF
2014-08-24 19:16:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-19 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-19 224896]
R0 Fastboot;Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [2013-09-23 66288]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-19 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-19 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-19 427360]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwr64v.sys [2014-03-07 20736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-19 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-19 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-19 92008]
R3 AmUStor;@oem20.inf,%AmUStor.SvcDesc%;AM USB Stroage Driver; C:\WINDOWS\system32\drivers\AmUStor.SYS [2012-07-20 100992]
R3 bcbtums;@oem29.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-05 170712]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btwampfl;@oem29.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem3.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2012-09-19 186648]
R3 btwavdt;@oem4.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\system32\DRIVERS\btwavdt.sys [2012-09-16 224568]
R3 btwl2cap;@oem6.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2012-09-16 22328]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2013-04-17 44800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-21 4106256]
R3 IntcDAud;@oem13.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem21.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem23.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vm331avs;@oem10.inf,%USBCamera.DeviceDesc2%;Digital Camera 1; C:\WINDOWS\System32\Drivers\vm331avs.sys [2012-09-05 981112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem16.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-19 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2012-09-26 957304]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2013-09-23 140016]
R2 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R2 IBMPMSVC;@oem12.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2013-04-17 61224]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-07-17 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-03-10 2085184]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2012-08-11 136288]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 LocationTaskManager;LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-12-12 468288]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-20 142960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2014-06-10 124400]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-03-04 573488]
R3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-03-04 512048]
R3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-03-04 527920]
R3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-03-04 702512]
R3 Power Manager DBC Service;Lenovo Settings Power Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2014-03-07 1669976]
S2 BcmBtRSupport;@oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-05 2252504]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-09 178760]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2014-02-21 24120]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2014-04-07 110128]
-----------------EOF-----------------
Run by martin at 2014-09-22 20:07:57
Microsoft Windows 8.1
System drive C: has 377 GB (82%) free of 461 GB
Total RAM: 3950 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:08:00, on 22. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE
O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: @oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem12.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10935 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\ibmpmsvc.exe
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
dashost.exe {9b7af6c2-0cda-464a-af527042b09483a5}
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ab179fd3-b591-4883-92d3-c2d63452a465 -SystemEventPortName:HostProcess-9e0f229a-1ad5-45f7-ab1f-0fdb4fe963fa -IoCancelEventPortName:HostProcess-9ae4e857-23aa-46cf-8f2b-447969cc928b -NonStateChangingEventPortName:HostProcess-51c68536-57a0-44cb-b45e-07ef84ad1a6b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0afa07f3-886c-468c-ac44-68af79a9009d -DeviceGroupId:
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-1ce54694-f81b-443b-93eb-5a075c777e41 -SystemEventPortName:HostProcess-41ca345d-80bf-44a3-9328-583d9483d1ae -IoCancelEventPortName:HostProcess-3d7c1b15-4e81-4596-ad8e-238ea440261e -NonStateChangingEventPortName:HostProcess-a7a97550-91f7-4585-a938-9f598470ecc8 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:fc28bacf-7737-4552-a47b-af678e475c2c -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8e3b680f-c0f7-46eb-8d7b-7e98df57b472 -SystemEventPortName:HostProcess-da1d9fb1-2c84-482a-b761-4dc9966ff536 -IoCancelEventPortName:HostProcess-19b42841-c1f5-4fe4-94a3-7fad93b6a2ac -NonStateChangingEventPortName:HostProcess-15de8b96-1c43-4cca-8f43-1ed780e0f92f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7edace5e-2a22-4fb0-a5d4-2198607c5caf -DeviceGroupId:
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\igfxpers.exe"
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Lenovo\HOTKEY\extapsup.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\AdwCleaner\AdwCleaner[S0].txt
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\Lenovo\Communications Utility\cammute.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\martin\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-08-12 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-19 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-08-12 2334416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-08-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-19 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-08-12 1729232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-20 13192848]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2013-06-20 255480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-03-04 74288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2012-08-30 548864]
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2013-09-23 738032]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-19 4085896]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-31 571392]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-28 207424]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)\Skype
2014-09-22 19:25:10 ----A---- C:\WINDOWS\SYSWOW64\sqlite3.dll
2014-09-22 19:23:58 ----D---- C:\AdwCleaner
2014-09-22 18:59:38 ----D---- C:\rsit
2014-09-22 18:59:38 ----D---- C:\Program Files\trend micro
2014-09-20 19:09:07 ----D---- C:\Program Files\CCleaner
2014-09-20 17:48:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 17:47:02 ----A---- C:\autoexec.bat
2014-09-20 17:46:31 ----D---- C:\Program Files\Enigma Software Group
2014-09-20 17:44:39 ----D---- C:\WINDOWS\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-09-20 17:34:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 20:23:12 ----D---- C:\ProgramData\TEMP
2014-09-15 05:37:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 05:37:50 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 05:37:50 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 05:37:49 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 05:37:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 05:37:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 05:37:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 05:36:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 05:36:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 05:36:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 05:36:55 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 05:36:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 05:36:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 05:36:53 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 05:36:52 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 05:36:43 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 05:36:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 05:36:41 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 05:36:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 05:36:36 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 05:36:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 05:36:33 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 05:36:31 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 05:36:30 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 05:36:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 05:36:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 05:36:15 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 05:36:11 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 05:36:04 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 05:36:03 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 05:35:54 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 05:35:53 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 05:35:50 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 05:35:49 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 05:35:49 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 05:35:44 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 05:35:38 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 05:35:32 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 05:35:30 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 05:35:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 05:35:24 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 05:35:23 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 05:27:44 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 13:09:37 ----D---- C:\Users\martin\AppData\Roaming\Ashampoo
2014-09-14 13:09:29 ----D---- C:\ProgramData\Ashampoo
2014-09-14 13:03:21 ----D---- C:\Users\martin\AppData\Roaming\Opera Software
2014-09-14 13:03:07 ----D---- C:\Program Files (x86)\Opera
2014-09-10 08:12:08 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-10 08:12:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 08:12:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 08:11:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-10 08:11:49 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-10 08:11:48 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 23:40:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-08-27 19:59:30 ----A---- C:\WINDOWS\system32\win32k.sys
2014-08-23 16:12:04 ----D---- C:\WINDOWS\Minidump
======List of files/folders modified in the last 1 month======
2014-09-22 20:02:02 ----D---- C:\WINDOWS\system32\sru
2014-09-22 19:41:02 ----D---- C:\WINDOWS\Temp
2014-09-22 19:35:03 ----RD---- C:\WINDOWS\System32
2014-09-22 19:35:03 ----D---- C:\WINDOWS\Inf
2014-09-22 19:35:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-22 19:30:36 ----D---- C:\Users\martin\AppData\Roaming\Skype
2014-09-22 19:29:59 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-09-22 19:29:25 ----SHD---- C:\WINDOWS\Installer
2014-09-22 19:29:23 ----D---- C:\WINDOWS\Prefetch
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)
2014-09-22 19:29:20 ----D---- C:\Program Files (x86)\Common Files
2014-09-22 19:29:19 ----D---- C:\ProgramData\Skype
2014-09-22 19:25:52 ----HD---- C:\ProgramData
2014-09-22 19:25:52 ----D---- C:\WINDOWS\system32\Tasks
2014-09-22 19:25:10 ----D---- C:\WINDOWS\SysWOW64
2014-09-22 18:59:38 ----D---- C:\Program Files
2014-09-22 18:57:57 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-22 18:57:56 ----D---- C:\Windows
2014-09-22 18:40:02 ----D---- C:\ProgramData\ArcSoft
2014-09-22 18:39:48 ----D---- C:\Users\martin\AppData\Roaming\ArcSoft
2014-09-22 18:09:38 ----D---- C:\WINDOWS\Tasks
2014-09-22 16:46:51 ----D---- C:\WINDOWS\system32\config
2014-09-22 16:18:22 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 21:45:20 ----SHD---- C:\System Volume Information
2014-09-21 19:48:16 ----AD---- C:\ProgramData\Lenovo
2014-09-21 16:56:07 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-20 19:26:32 ----D---- C:\WINDOWS\WinSxS
2014-09-20 19:22:24 ----RD---- C:\WINDOWS\ToastData
2014-09-20 19:22:22 ----D---- C:\WINDOWS\WinStore
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-20 19:22:22 ----D---- C:\Program Files\Windows Journal
2014-09-20 19:22:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\setup
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 19:22:20 ----RSD---- C:\WINDOWS\Fonts
2014-09-20 19:22:20 ----D---- C:\WINDOWS\apppatch
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 19:22:19 ----D---- C:\WINDOWS\system32\migration
2014-09-20 19:22:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-20 19:11:59 ----D---- C:\Users\martin\AppData\Roaming\uTorrent
2014-09-20 19:10:43 ----DC---- C:\WINDOWS\Panther
2014-09-20 19:10:42 ----D---- C:\WINDOWS\debug
2014-09-20 17:37:40 ----D---- C:\Program Files (x86)\Google
2014-09-19 00:34:09 ----D---- C:\WINDOWS\AppReadiness
2014-09-19 00:34:08 ----HD---- C:\Program Files\WindowsApps
2014-09-16 08:10:16 ----RSD---- C:\WINDOWS\assembly
2014-09-16 08:03:53 ----D---- C:\WINDOWS\CbsTemp
2014-09-16 07:59:37 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 13:06:50 ----D---- C:\Program Files\Common Files\System
2014-09-13 22:56:53 ----D---- C:\WINDOWS\rescache
2014-09-13 09:18:01 ----D---- C:\WINDOWS\system32\MRT
2014-09-13 09:11:31 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-12 17:06:56 ----D---- C:\Program Files\Internet Explorer
2014-09-12 17:06:56 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-10 08:12:39 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-10 08:12:38 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-10 08:12:23 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-10 08:12:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-02 22:06:15 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-02 17:40:28 ----D---- C:\WINDOWS\tracing
2014-09-01 21:34:28 ----D---- C:\WINDOWS\system32\NDF
2014-08-24 19:16:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-19 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-19 224896]
R0 Fastboot;Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [2013-09-23 66288]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-19 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-19 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-19 427360]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwr64v.sys [2014-03-07 20736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-19 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-19 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-19 92008]
R3 AmUStor;@oem20.inf,%AmUStor.SvcDesc%;AM USB Stroage Driver; C:\WINDOWS\system32\drivers\AmUStor.SYS [2012-07-20 100992]
R3 bcbtums;@oem29.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-05 170712]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btwampfl;@oem29.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem3.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2012-09-19 186648]
R3 btwavdt;@oem4.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\system32\DRIVERS\btwavdt.sys [2012-09-16 224568]
R3 btwl2cap;@oem6.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2012-09-16 22328]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2013-04-17 44800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-21 4106256]
R3 IntcDAud;@oem13.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem21.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem23.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vm331avs;@oem10.inf,%USBCamera.DeviceDesc2%;Digital Camera 1; C:\WINDOWS\System32\Drivers\vm331avs.sys [2012-09-05 981112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem16.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-19 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2012-09-26 957304]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2013-09-23 140016]
R2 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R2 IBMPMSVC;@oem12.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2013-04-17 61224]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-07-17 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-03-10 2085184]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2012-08-11 136288]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 LocationTaskManager;LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-12-12 468288]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-20 142960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2014-06-10 124400]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-03-04 573488]
R3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-03-04 512048]
R3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-03-04 527920]
R3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-03-04 702512]
R3 Power Manager DBC Service;Lenovo Settings Power Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2014-03-07 1669976]
S2 BcmBtRSupport;@oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-05 2252504]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-09 178760]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2014-02-21 24120]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2014-04-07 110128]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119547
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.:files
C:\Program Files (x86)\YTDownloader
C:\WINDOWS\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YTDownloader"=-
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Tak jak to vypadá teď? Vypadá to lépe, ale spouštění PC je stále poměrně pomalé.
Logfile of random's system information tool 1.10 (written by random/random)
Run by martin at 2014-09-23 18:41:40
Microsoft Windows 8.1
System drive C: has 376 GB (82%) free of 461 GB
Total RAM: 3950 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:41:43, on 23. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE
O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: @oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem12.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10745 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
dashost.exe {ed15a8f5-3285-4db3-ac76b14ae804aa53}
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ce8801a5-a252-4d63-9046-ec60b075f899 -SystemEventPortName:HostProcess-102ae29c-152d-4c69-bd92-74da858fab30 -IoCancelEventPortName:HostProcess-ebf83ad4-84e9-4479-9b74-a583f9a2f783 -NonStateChangingEventPortName:HostProcess-693e211e-f46e-41bd-9852-76f70895899b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:419e9034-cd95-46e1-a68b-110c2f65cc43 -DeviceGroupId:
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f0c0f103-260e-4fae-8365-529fdfd7b236 -SystemEventPortName:HostProcess-92b25ea3-3632-4069-b167-4cd4c6462bcd -IoCancelEventPortName:HostProcess-87920f4e-c70c-4955-978c-bb6be8f64d18 -NonStateChangingEventPortName:HostProcess-c8256a5a-6586-49d0-a8f9-d022def127dd -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a270412d-d17a-4f07-8922-9eeba1acffbd -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0fd34f48-4d62-46a2-a517-75dce5e401f1 -SystemEventPortName:HostProcess-65bcb276-393f-4406-80cb-20951af13c14 -IoCancelEventPortName:HostProcess-52529066-c75f-4cfa-80ec-0c672948d589 -NonStateChangingEventPortName:HostProcess-8278c85d-c7b9-4a8c-b33b-abdbf9f60d5c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:da30dce9-73ed-4069-a209-7a292e6e17cc -DeviceGroupId:
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\System32\igfxtray.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Lenovo\HOTKEY\extapsup.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
taskeng.exe {5209C498-BECC-495E-8E8B-D62438E9D12D}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\Lenovo\Communications Utility\cammute.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
C:\WINDOWS\WinStore\WSHost.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\martin\Desktop\RSITx64.exe"
wmiadap.exe /F /T /R
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-08-12 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-19 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-08-12 2334416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-08-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-19 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-08-12 1729232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-20 13192848]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2013-06-20 255480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-03-04 74288]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2012-08-30 548864]
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2013-09-23 738032]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-19 4085896]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-31 571392]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-28 207424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-23 18:33:50 ----D---- C:\_OTM
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)\Skype
2014-09-22 19:25:10 ----A---- C:\WINDOWS\SYSWOW64\sqlite3.dll
2014-09-22 19:23:58 ----D---- C:\AdwCleaner
2014-09-22 18:59:38 ----D---- C:\rsit
2014-09-22 18:59:38 ----D---- C:\Program Files\trend micro
2014-09-20 19:09:07 ----D---- C:\Program Files\CCleaner
2014-09-20 17:48:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 17:47:02 ----A---- C:\autoexec.bat
2014-09-20 17:46:31 ----D---- C:\Program Files\Enigma Software Group
2014-09-20 17:34:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 20:23:12 ----D---- C:\ProgramData\TEMP
2014-09-15 05:37:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 05:37:50 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 05:37:50 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 05:37:49 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 05:37:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 05:37:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 05:37:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 05:36:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 05:36:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 05:36:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 05:36:55 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 05:36:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 05:36:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 05:36:53 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 05:36:52 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 05:36:43 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 05:36:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 05:36:41 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 05:36:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 05:36:36 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 05:36:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 05:36:33 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 05:36:31 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 05:36:30 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 05:36:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 05:36:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 05:36:15 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 05:36:11 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 05:36:04 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 05:36:03 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 05:35:54 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 05:35:53 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 05:35:50 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 05:35:49 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 05:35:49 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 05:35:44 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 05:35:38 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 05:35:32 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 05:35:30 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 05:35:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 05:35:24 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 05:35:23 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 05:27:44 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 13:09:37 ----D---- C:\Users\martin\AppData\Roaming\Ashampoo
2014-09-14 13:09:29 ----D---- C:\ProgramData\Ashampoo
2014-09-14 13:03:21 ----D---- C:\Users\martin\AppData\Roaming\Opera Software
2014-09-14 13:03:07 ----D---- C:\Program Files (x86)\Opera
2014-09-10 08:12:08 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-10 08:12:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 08:12:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 08:11:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-10 08:11:49 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-10 08:11:48 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 23:40:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-08-27 19:59:30 ----A---- C:\WINDOWS\system32\win32k.sys
======List of files/folders modified in the last 1 month======
2014-09-23 18:41:28 ----D---- C:\WINDOWS\Prefetch
2014-09-23 18:39:52 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-09-23 18:38:04 ----D---- C:\WINDOWS\Temp
2014-09-23 18:33:50 ----D---- C:\Windows
2014-09-23 18:30:26 ----D---- C:\Users\martin\AppData\Roaming\Skype
2014-09-23 18:00:00 ----D---- C:\WINDOWS\system32\sru
2014-09-23 17:47:36 ----RD---- C:\WINDOWS\System32
2014-09-23 17:47:36 ----D---- C:\WINDOWS\Inf
2014-09-23 17:47:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-23 14:51:26 ----D---- C:\WINDOWS\system32\config
2014-09-22 22:34:46 ----D---- C:\WINDOWS\rescache
2014-09-22 22:14:52 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-22 19:29:25 ----SHD---- C:\WINDOWS\Installer
2014-09-22 19:29:24 ----D---- C:\ProgramData\Skype
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)
2014-09-22 19:29:20 ----D---- C:\Program Files (x86)\Common Files
2014-09-22 19:25:52 ----HD---- C:\ProgramData
2014-09-22 19:25:52 ----D---- C:\WINDOWS\system32\Tasks
2014-09-22 19:25:10 ----D---- C:\WINDOWS\SysWOW64
2014-09-22 18:59:38 ----D---- C:\Program Files
2014-09-22 18:57:57 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-22 18:40:02 ----D---- C:\ProgramData\ArcSoft
2014-09-22 18:39:48 ----D---- C:\Users\martin\AppData\Roaming\ArcSoft
2014-09-22 18:09:38 ----D---- C:\WINDOWS\Tasks
2014-09-22 16:18:22 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 21:45:20 ----SHD---- C:\System Volume Information
2014-09-21 19:48:16 ----AD---- C:\ProgramData\Lenovo
2014-09-20 19:26:32 ----D---- C:\WINDOWS\WinSxS
2014-09-20 19:22:24 ----RD---- C:\WINDOWS\ToastData
2014-09-20 19:22:22 ----D---- C:\WINDOWS\WinStore
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-20 19:22:22 ----D---- C:\Program Files\Windows Journal
2014-09-20 19:22:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\setup
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 19:22:20 ----RSD---- C:\WINDOWS\Fonts
2014-09-20 19:22:20 ----D---- C:\WINDOWS\apppatch
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 19:22:19 ----D---- C:\WINDOWS\system32\migration
2014-09-20 19:22:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-20 19:11:59 ----D---- C:\Users\martin\AppData\Roaming\uTorrent
2014-09-20 19:10:43 ----DC---- C:\WINDOWS\Panther
2014-09-20 19:10:42 ----D---- C:\WINDOWS\Minidump
2014-09-20 19:10:42 ----D---- C:\WINDOWS\debug
2014-09-20 17:37:40 ----D---- C:\Program Files (x86)\Google
2014-09-19 00:34:09 ----D---- C:\WINDOWS\AppReadiness
2014-09-19 00:34:08 ----HD---- C:\Program Files\WindowsApps
2014-09-16 08:10:16 ----RSD---- C:\WINDOWS\assembly
2014-09-16 08:03:53 ----D---- C:\WINDOWS\CbsTemp
2014-09-16 07:59:37 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 13:06:50 ----D---- C:\Program Files\Common Files\System
2014-09-13 09:18:01 ----D---- C:\WINDOWS\system32\MRT
2014-09-13 09:11:31 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-12 17:06:56 ----D---- C:\Program Files\Internet Explorer
2014-09-12 17:06:56 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-10 08:12:39 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-10 08:12:38 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-10 08:12:23 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-10 08:12:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-02 22:06:15 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-02 17:40:28 ----D---- C:\WINDOWS\tracing
2014-09-01 21:34:28 ----D---- C:\WINDOWS\system32\NDF
2014-08-24 19:16:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-19 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-19 224896]
R0 Fastboot;Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [2013-09-23 66288]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-19 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-19 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-19 427360]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwr64v.sys [2014-03-07 20736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-19 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-19 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-19 92008]
R3 AmUStor;@oem20.inf,%AmUStor.SvcDesc%;AM USB Stroage Driver; C:\WINDOWS\system32\drivers\AmUStor.SYS [2012-07-20 100992]
R3 bcbtums;@oem29.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-05 170712]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btwampfl;@oem29.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem3.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2012-09-19 186648]
R3 btwavdt;@oem4.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\system32\DRIVERS\btwavdt.sys [2012-09-16 224568]
R3 btwl2cap;@oem6.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2012-09-16 22328]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2013-04-17 44800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-21 4106256]
R3 IntcDAud;@oem13.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem21.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem23.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vm331avs;@oem10.inf,%USBCamera.DeviceDesc2%;Digital Camera 1; C:\WINDOWS\System32\Drivers\vm331avs.sys [2012-09-05 981112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem16.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-19 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2012-09-26 957304]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2013-09-23 140016]
R2 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R2 IBMPMSVC;@oem12.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2013-04-17 61224]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-07-17 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-03-10 2085184]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2012-08-11 136288]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 LocationTaskManager;LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-12-12 468288]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-20 142960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2014-06-10 124400]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-03-04 573488]
R3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-03-04 512048]
R3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-03-04 527920]
R3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-03-04 702512]
R3 Power Manager DBC Service;Lenovo Settings Power Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2014-03-07 1669976]
S2 BcmBtRSupport;@oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-05 2252504]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-09 178760]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2014-02-21 24120]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2014-04-07 110128]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by martin at 2014-09-23 18:41:40
Microsoft Windows 8.1
System drive C: has 376 GB (82%) free of 461 GB
Total RAM: 3950 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:41:43, on 23. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE
O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: @oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem12.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Stardock Start8 (Start8) - Stardock Software, Inc - C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10745 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe"
"C:\Program Files (x86)\Stardock\Start8\Start8_64.exe" START
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
dashost.exe {ed15a8f5-3285-4db3-ac76b14ae804aa53}
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ce8801a5-a252-4d63-9046-ec60b075f899 -SystemEventPortName:HostProcess-102ae29c-152d-4c69-bd92-74da858fab30 -IoCancelEventPortName:HostProcess-ebf83ad4-84e9-4479-9b74-a583f9a2f783 -NonStateChangingEventPortName:HostProcess-693e211e-f46e-41bd-9852-76f70895899b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:419e9034-cd95-46e1-a68b-110c2f65cc43 -DeviceGroupId:
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f0c0f103-260e-4fae-8365-529fdfd7b236 -SystemEventPortName:HostProcess-92b25ea3-3632-4069-b167-4cd4c6462bcd -IoCancelEventPortName:HostProcess-87920f4e-c70c-4955-978c-bb6be8f64d18 -NonStateChangingEventPortName:HostProcess-c8256a5a-6586-49d0-a8f9-d022def127dd -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a270412d-d17a-4f07-8922-9eeba1acffbd -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0fd34f48-4d62-46a2-a517-75dce5e401f1 -SystemEventPortName:HostProcess-65bcb276-393f-4406-80cb-20951af13c14 -IoCancelEventPortName:HostProcess-52529066-c75f-4cfa-80ec-0c672948d589 -NonStateChangingEventPortName:HostProcess-8278c85d-c7b9-4a8c-b33b-abdbf9f60d5c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:da30dce9-73ed-4069-a209-7a292e6e17cc -DeviceGroupId:
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\System32\igfxtray.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Lenovo\HOTKEY\extapsup.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"c:\program files (x86)\teamviewer\version9\TeamViewer_Desktop.exe" --IPCport 5939
taskeng.exe {5209C498-BECC-495E-8E8B-D62438E9D12D}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\Lenovo\Communications Utility\cammute.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe"
"C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
C:\WINDOWS\WinStore\WSHost.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\martin\Desktop\RSITx64.exe"
wmiadap.exe /F /T /R
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\martin\AppData\Roaming\Mozilla\Firefox\Profiles\kkfayzju.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-08-12 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-19 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-08-12 2334416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-08-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-19 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-08-12 1729232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-20 13192848]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2013-06-20 255480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-03-04 74288]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2012-08-30 548864]
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2013-09-23 738032]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-19 4085896]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2011-10-31 571392]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-28 207424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-23 18:33:50 ----D---- C:\_OTM
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)\Skype
2014-09-22 19:25:10 ----A---- C:\WINDOWS\SYSWOW64\sqlite3.dll
2014-09-22 19:23:58 ----D---- C:\AdwCleaner
2014-09-22 18:59:38 ----D---- C:\rsit
2014-09-22 18:59:38 ----D---- C:\Program Files\trend micro
2014-09-20 19:09:07 ----D---- C:\Program Files\CCleaner
2014-09-20 17:48:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 17:47:02 ----A---- C:\autoexec.bat
2014-09-20 17:46:31 ----D---- C:\Program Files\Enigma Software Group
2014-09-20 17:34:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 20:23:12 ----D---- C:\ProgramData\TEMP
2014-09-15 05:37:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 05:37:50 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 05:37:50 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 05:37:49 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 05:37:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 05:37:45 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 05:37:44 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 05:37:40 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 05:37:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 05:37:02 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 05:37:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 05:36:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 05:36:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 05:36:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 05:36:55 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 05:36:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 05:36:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 05:36:53 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 05:36:52 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 05:36:43 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 05:36:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 05:36:41 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 05:36:40 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 05:36:39 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 05:36:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 05:36:36 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 05:36:35 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 05:36:34 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 05:36:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 05:36:33 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 05:36:32 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 05:36:31 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 05:36:31 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 05:36:30 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 05:36:29 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 05:36:27 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 05:36:26 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 05:36:25 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 05:36:24 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 05:36:23 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 05:36:22 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 05:36:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 05:36:21 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 05:36:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 05:36:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 05:36:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 05:36:17 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 05:36:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 05:36:15 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 05:36:14 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 05:36:13 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 05:36:12 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 05:36:11 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 05:36:11 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 05:36:10 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 05:36:09 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 05:36:08 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 05:36:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 05:36:06 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 05:36:05 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 05:36:04 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 05:36:04 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 05:36:03 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 05:36:02 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 05:36:01 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 05:36:00 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 05:35:59 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 05:35:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 05:35:57 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 05:35:57 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 05:35:56 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 05:35:54 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 05:35:53 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 05:35:53 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 05:35:52 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 05:35:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 05:35:50 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 05:35:50 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 05:35:49 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 05:35:49 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 05:35:48 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 05:35:47 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 05:35:46 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 05:35:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 05:35:44 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 05:35:43 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 05:35:42 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 05:35:41 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 05:35:40 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 05:35:39 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 05:35:38 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-15 05:35:33 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 05:35:32 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 05:35:31 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 05:35:30 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 05:35:29 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 05:35:27 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:26 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 05:35:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 05:35:24 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 05:35:23 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 05:27:44 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 13:09:37 ----D---- C:\Users\martin\AppData\Roaming\Ashampoo
2014-09-14 13:09:29 ----D---- C:\ProgramData\Ashampoo
2014-09-14 13:03:21 ----D---- C:\Users\martin\AppData\Roaming\Opera Software
2014-09-14 13:03:07 ----D---- C:\Program Files (x86)\Opera
2014-09-10 08:12:08 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-10 08:12:08 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-10 08:12:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 08:12:05 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 08:12:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-10 08:12:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 08:12:00 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-10 08:11:59 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-10 08:11:57 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 08:11:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-10 08:11:52 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-10 08:11:51 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-10 08:11:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-10 08:11:49 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-10 08:11:48 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-10 08:11:47 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-09 23:43:36 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 23:40:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-08-27 19:59:30 ----A---- C:\WINDOWS\system32\win32k.sys
======List of files/folders modified in the last 1 month======
2014-09-23 18:41:28 ----D---- C:\WINDOWS\Prefetch
2014-09-23 18:39:52 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-09-23 18:38:04 ----D---- C:\WINDOWS\Temp
2014-09-23 18:33:50 ----D---- C:\Windows
2014-09-23 18:30:26 ----D---- C:\Users\martin\AppData\Roaming\Skype
2014-09-23 18:00:00 ----D---- C:\WINDOWS\system32\sru
2014-09-23 17:47:36 ----RD---- C:\WINDOWS\System32
2014-09-23 17:47:36 ----D---- C:\WINDOWS\Inf
2014-09-23 17:47:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-23 14:51:26 ----D---- C:\WINDOWS\system32\config
2014-09-22 22:34:46 ----D---- C:\WINDOWS\rescache
2014-09-22 22:14:52 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-22 19:29:25 ----SHD---- C:\WINDOWS\Installer
2014-09-22 19:29:24 ----D---- C:\ProgramData\Skype
2014-09-22 19:29:20 ----RD---- C:\Program Files (x86)
2014-09-22 19:29:20 ----D---- C:\Program Files (x86)\Common Files
2014-09-22 19:25:52 ----HD---- C:\ProgramData
2014-09-22 19:25:52 ----D---- C:\WINDOWS\system32\Tasks
2014-09-22 19:25:10 ----D---- C:\WINDOWS\SysWOW64
2014-09-22 18:59:38 ----D---- C:\Program Files
2014-09-22 18:57:57 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-22 18:40:02 ----D---- C:\ProgramData\ArcSoft
2014-09-22 18:39:48 ----D---- C:\Users\martin\AppData\Roaming\ArcSoft
2014-09-22 18:09:38 ----D---- C:\WINDOWS\Tasks
2014-09-22 16:18:22 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 21:45:20 ----SHD---- C:\System Volume Information
2014-09-21 19:48:16 ----AD---- C:\ProgramData\Lenovo
2014-09-20 19:26:32 ----D---- C:\WINDOWS\WinSxS
2014-09-20 19:22:24 ----RD---- C:\WINDOWS\ToastData
2014-09-20 19:22:22 ----D---- C:\WINDOWS\WinStore
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 19:22:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-20 19:22:22 ----D---- C:\Program Files\Windows Journal
2014-09-20 19:22:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\setup
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\drivers
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-20 19:22:21 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 19:22:20 ----RSD---- C:\WINDOWS\Fonts
2014-09-20 19:22:20 ----D---- C:\WINDOWS\apppatch
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 19:22:19 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 19:22:19 ----D---- C:\WINDOWS\system32\migration
2014-09-20 19:22:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-20 19:11:59 ----D---- C:\Users\martin\AppData\Roaming\uTorrent
2014-09-20 19:10:43 ----DC---- C:\WINDOWS\Panther
2014-09-20 19:10:42 ----D---- C:\WINDOWS\Minidump
2014-09-20 19:10:42 ----D---- C:\WINDOWS\debug
2014-09-20 17:37:40 ----D---- C:\Program Files (x86)\Google
2014-09-19 00:34:09 ----D---- C:\WINDOWS\AppReadiness
2014-09-19 00:34:08 ----HD---- C:\Program Files\WindowsApps
2014-09-16 08:10:16 ----RSD---- C:\WINDOWS\assembly
2014-09-16 08:03:53 ----D---- C:\WINDOWS\CbsTemp
2014-09-16 07:59:37 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 13:06:50 ----D---- C:\Program Files\Common Files\System
2014-09-13 09:18:01 ----D---- C:\WINDOWS\system32\MRT
2014-09-13 09:11:31 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-12 17:06:56 ----D---- C:\Program Files\Internet Explorer
2014-09-12 17:06:56 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-10 08:12:39 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-10 08:12:38 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 08:12:28 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-10 08:12:27 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-10 08:12:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-10 08:12:23 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-10 08:12:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-02 22:06:15 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-02 17:40:28 ----D---- C:\WINDOWS\tracing
2014-09-01 21:34:28 ----D---- C:\WINDOWS\system32\NDF
2014-08-24 19:16:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-19 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-19 224896]
R0 Fastboot;Fastboot; C:\WINDOWS\System32\DRIVERS\fastboot.sys [2013-09-23 66288]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-11-19 652344]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-19 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-19 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-19 427360]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwr64v.sys [2014-03-07 20736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-19 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-19 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-19 92008]
R3 AmUStor;@oem20.inf,%AmUStor.SvcDesc%;AM USB Stroage Driver; C:\WINDOWS\system32\drivers\AmUStor.SYS [2012-07-20 100992]
R3 bcbtums;@oem29.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-05 170712]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 btwampfl;@oem29.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem3.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2012-09-19 186648]
R3 btwavdt;@oem4.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\system32\DRIVERS\btwavdt.sys [2012-09-16 224568]
R3 btwl2cap;@oem6.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2012-09-16 22328]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2013-04-17 44800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-21 4106256]
R3 IntcDAud;@oem13.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem21.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem23.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vm331avs;@oem10.inf,%USBCamera.DeviceDesc2%;Digital Camera 1; C:\WINDOWS\System32\Drivers\vm331avs.sys [2012-09-05 981112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem16.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-19 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2012-09-26 957304]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2013-09-23 140016]
R2 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R2 IBMPMSVC;@oem12.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2013-04-17 61224]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-07-17 128896]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-03-10 2085184]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2012-08-11 136288]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 LocationTaskManager;LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [2013-12-12 468288]
R2 Start8;Stardock Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [2013-03-20 142960]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2014-06-10 124400]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-03-04 573488]
R3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-03-04 512048]
R3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-03-04 527920]
R3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-03-04 702512]
R3 Power Manager DBC Service;Lenovo Settings Power Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2014-03-07 1669976]
S2 BcmBtRSupport;@oem29.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-05 2252504]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-09 178760]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2014-02-21 24120]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2014-04-07 110128]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119547
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Smazáno, log je již OK. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Děkuji moc za pomoc. Nyní vše vypadá OK. Takto jsem si činnost mého PC představoval. 

- Rudy
- Site Admin
- Příspěvky: 119547
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - několik virů, nejspíše od YT Downloa
Rádo se stalo! 

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.