Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

PC pořád něco "chroustá"

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
petrsedlak
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 13 úno 2009 15:46

PC pořád něco "chroustá"

#1 Příspěvek od petrsedlak »

Zdar borci,

po dlouhé době mám na vás opět dotaz.

Moje PC mi dneska po instalaci několika prográmků kvůli GPSce (GIS) začalo nějako více chroustat, je vytížený procesor a disk pořád něco dělá. Nevím, možná se mi to zdá ale přece jen Vás prosím o preventivní kontrolu zda sem si sem nedotáhl nějakýho pazgřivce :).

Zda je log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by xpetrsedlak at 2014-12-29 20:06:07
Microsoft Windows 8.1
System drive C: has 225 GB (88%) free of 256 GB
Total RAM: 8092 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:06:10 PM, on 12/29/2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe
C:\Windows\jmesoft\hotkey.exe
C:\Users\xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Launchy\Launchy.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\windows\SysWOW64\notepad.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\xpetrsedlak.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN228353SW05V3:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1
O4 - Startup: Dropbox.lnk = xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Launchy.lnk = C:\Program Files (x86)\Launchy\Launchy.exe
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7422 bytes

======Listing Processes======





wininit.exe


C:\windows\system32\lsass.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"C:\windows\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\nvvsvc.exe -session
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 912615595024
\??\C:\windows\system32\conhost.exe 0x4
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe"
"C:\Program Files (x86)\Lenovo\EducationPortal\Services\IdeaTouch.LocalDataServer.Education.exe"
dashost.exe {cb72f815-3ce3-4e7d-ae7eafd85d43edab}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k iissvcs

"C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\windows\System32\svchost.exe -k LocalServicePeerNet
taskhostex.exe
C:\windows\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Dolby Digital Plus\ddp.exe" -autostart
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\System32\igfxtray.exe"
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Windows\WindowsMobile\wmdcBase.exe"
C:\windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe"
"C:\Windows\jmesoft\hotkey.exe"
"C:\Users\xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Windows\jmesoft\JME_LOAD.exe"
"C:\Program Files (x86)\Launchy\Launchy.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16384_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\WWAHost.exe" -ServerName:Windows.Store
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
C:\windows\explorer.exe
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
notepad "C:\Users\XPETRS~1\AppData\Local\Temp\JRT.txt"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"

"C:\windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568
C:\windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\xpetrsedlak\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\WpsNotifyTask_xpetrsedlak.job - C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsnotify.exe -from=task
C:\windows\tasks\WpsUpdateTask_xpetrsedlak.job - C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe -from=task

=========Mozilla firefox=========

ProfilePath - C:\Users\xpetrsedlak\AppData\Roaming\Mozilla\Firefox\Profiles\bik8q31b.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2014-02-20 391152]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2014-02-20 771568]
"Persistence"=C:\windows\system32\igfxpers.exe [2014-02-20 770544]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-10-24 13662936]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-11-13 1368792]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-11-13 1368792]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-04 36352]
"Windows Mobile-based device management"=C:\windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-12-12 7394584]
"HP Photosmart 5510 series (NET)"=C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2013-07-24 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-08-17 28672]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe

C:\Users\xpetrsedlak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe
Launchy.lnk - C:\Program Files (x86)\Launchy\Launchy.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2014-02-20 624640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-12-29 20:06:08 ----D---- C:\Program Files\trend micro
2014-12-29 20:06:07 ----D---- C:\rsit
2014-12-29 20:00:49 ----D---- C:\windows\ERUNT
2014-12-29 19:47:13 ----D---- C:\Program Files (x86)\Reference Assemblies
2014-12-29 19:47:13 ----D---- C:\Program Files (x86)\MSBuild
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\XPSViewer
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\BestPractices
2014-12-29 19:47:04 ----D---- C:\windows\system32\BestPractices
2014-12-29 19:47:04 ----D---- C:\Program Files\MSBuild
2014-12-29 19:47:04 ----D---- C:\inetpub
2014-12-29 19:18:07 ----D---- C:\windows\WindowsMobile
2014-12-28 19:51:11 ----D---- C:\Program Files (x86)\IrfanView
2014-12-28 19:39:20 ----D---- C:\Program Files (x86)\Mendeley Desktop
2014-12-28 19:16:16 ----D---- C:\Program Files (x86)\Chromas
2014-12-28 17:56:10 ----N---- C:\windows\system32\HPDiscoPMa111.dll
2014-12-28 17:55:41 ----D---- C:\ProgramData\HP
2014-12-28 17:55:40 ----D---- C:\Program Files (x86)\HP
2014-12-28 17:55:39 ----D---- C:\Program Files\HP
2014-12-28 17:55:28 ----A---- C:\ProgramData\Ament.ini
2014-12-28 17:34:42 ----D---- C:\windows\system32\MRT
2014-12-28 17:34:39 ----A---- C:\windows\system32\MRT.exe
2014-12-28 17:27:49 ----A---- C:\windows\system32\poqexec.exe
2014-12-28 17:27:48 ----A---- C:\windows\SYSWOW64\poqexec.exe
2014-12-28 17:26:31 ----A---- C:\windows\system32\mshtml.dll
2014-12-28 17:26:30 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-12-28 17:26:25 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-12-28 17:26:25 ----A---- C:\windows\system32\mshtmled.dll
2014-12-28 17:25:50 ----A---- C:\windows\SYSWOW64\shell32.dll
2014-12-28 17:25:50 ----A---- C:\windows\system32\shell32.dll
2014-12-28 17:23:48 ----A---- C:\windows\system32\sppsvc.exe
2014-12-28 17:23:47 ----A---- C:\windows\system32\mfcore.dll
2014-12-28 17:23:47 ----A---- C:\windows\system32\drivers\tcpip.sys
2014-12-28 17:23:46 ----A---- C:\windows\system32\combase.dll
2014-12-28 17:23:45 ----A---- C:\windows\SYSWOW64\mfcore.dll
2014-12-28 17:23:44 ----A---- C:\windows\SYSWOW64\combase.dll
2014-12-28 17:23:44 ----A---- C:\windows\system32\mfmpeg2srcsnk.dll
2014-12-28 17:23:43 ----A---- C:\windows\system32\mstscax.dll
2014-12-28 17:23:42 ----A---- C:\windows\SYSWOW64\mfmpeg2srcsnk.dll
2014-12-28 17:23:41 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-12-28 17:23:40 ----A---- C:\windows\system32\dbghelp.dll
2014-12-28 17:23:40 ----A---- C:\windows\system32\dbgeng.dll
2014-12-28 17:23:38 ----A---- C:\windows\SYSWOW64\dbgeng.dll
2014-12-28 17:23:38 ----A---- C:\windows\system32\swprv.dll
2014-12-28 17:23:38 ----A---- C:\windows\system32\Faultrep.dll
2014-12-28 17:23:37 ----A---- C:\windows\SYSWOW64\Faultrep.dll
2014-12-28 17:23:37 ----A---- C:\windows\SYSWOW64\dbghelp.dll
2014-12-28 17:23:37 ----A---- C:\windows\system32\WerFault.exe
2014-12-28 17:23:36 ----A---- C:\windows\system32\mfps.dll
2014-12-28 17:23:35 ----A---- C:\windows\SYSWOW64\WerFault.exe
2014-12-28 17:23:35 ----A---- C:\windows\system32\drivers\volsnap.sys
2014-12-28 17:23:34 ----A---- C:\windows\SYSWOW64\rdpencom.dll
2014-12-28 17:23:34 ----A---- C:\windows\system32\rdvidcrl.dll
2014-12-28 17:23:34 ----A---- C:\windows\system32\rdpencom.dll
2014-12-28 17:23:34 ----A---- C:\windows\system32\DWWIN.EXE
2014-12-28 17:23:33 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2014-12-28 17:23:33 ----A---- C:\windows\SYSWOW64\DWWIN.EXE
2014-12-28 17:23:33 ----A---- C:\windows\system32\tsgqec.dll
2014-12-28 17:23:32 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2014-12-28 17:23:32 ----A---- C:\windows\system32\sppcomapi.dll
2014-12-28 17:22:31 ----A---- C:\windows\system32\drivers\ntfs.sys
2014-12-28 17:22:31 ----A---- C:\windows\system32\drivers\clfs.sys
2014-12-28 17:22:20 ----A---- C:\windows\system32\KernelBase.dll
2014-12-28 17:22:19 ----A---- C:\windows\system32\kernel32.dll
2014-12-28 17:22:18 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2014-12-28 17:22:18 ----A---- C:\windows\SYSWOW64\kernel32.dll
2014-12-28 17:21:59 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-12-28 17:21:59 ----A---- C:\windows\system32\iertutil.dll
2014-12-28 17:21:58 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-12-28 17:21:58 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-12-28 17:21:57 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-12-28 17:21:56 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-12-28 17:21:56 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-12-28 17:21:56 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-12-28 17:21:52 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-12-28 17:21:52 ----A---- C:\windows\system32\iernonce.dll
2014-12-28 17:21:51 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-12-28 17:21:51 ----A---- C:\windows\system32\urlmon.dll
2014-12-28 17:21:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-12-28 17:21:50 ----A---- C:\windows\system32\ieetwcollector.exe
2014-12-28 17:21:49 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-12-28 17:21:49 ----A---- C:\windows\system32\msfeeds.dll
2014-12-28 17:21:48 ----A---- C:\windows\system32\iesetup.dll
2014-12-28 17:21:46 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-12-28 17:21:46 ----A---- C:\windows\system32\ie4uinit.exe
2014-12-28 17:21:45 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-12-28 17:21:44 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-12-28 17:21:44 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-12-28 17:21:44 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-12-28 17:21:42 ----A---- C:\windows\system32\ieframe.dll
2014-12-28 17:21:41 ----A---- C:\windows\system32\jscript9diag.dll
2014-12-28 17:21:41 ----A---- C:\windows\system32\jscript9.dll
2014-12-28 17:21:41 ----A---- C:\windows\system32\ieUnatt.exe
2014-12-28 17:21:40 ----A---- C:\windows\system32\ieapfltr.dll
2014-12-28 17:21:39 ----A---- C:\windows\system32\wininet.dll
2014-12-28 17:21:39 ----A---- C:\windows\system32\msrating.dll
2014-12-28 17:21:39 ----A---- C:\windows\system32\jsproxy.dll
2014-12-28 17:19:24 ----A---- C:\windows\system32\win32k.sys
2014-12-28 17:19:16 ----A---- C:\windows\SYSWOW64\qedit.dll
2014-12-28 17:19:16 ----A---- C:\windows\system32\qedit.dll
2014-12-28 17:19:05 ----A---- C:\windows\system32\Windows.UI.Xaml.dll
2014-12-28 17:19:04 ----A---- C:\windows\SYSWOW64\Windows.UI.Xaml.dll
2014-12-28 17:19:01 ----A---- C:\windows\SYSWOW64\twinui.dll
2014-12-28 17:19:01 ----A---- C:\windows\system32\twinui.dll
2014-12-28 17:19:00 ----A---- C:\windows\system32\SearchFolder.dll
2014-12-28 17:19:00 ----A---- C:\windows\system32\schedsvc.dll
2014-12-28 17:18:59 ----A---- C:\windows\SYSWOW64\SearchFolder.dll
2014-12-28 17:18:59 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2014-12-28 17:18:58 ----A---- C:\windows\system32\SettingSyncHost.exe
2014-12-28 17:18:58 ----A---- C:\windows\system32\mfsvr.dll
2014-12-28 17:18:58 ----A---- C:\windows\system32\MFMediaEngine.dll
2014-12-28 17:18:57 ----A---- C:\windows\SYSWOW64\SettingSyncHost.exe
2014-12-28 17:18:57 ----A---- C:\windows\SYSWOW64\mfsvr.dll
2014-12-28 17:18:57 ----A---- C:\windows\SYSWOW64\MFMediaEngine.dll
2014-12-28 17:18:57 ----A---- C:\windows\system32\SettingSyncCore.dll
2014-12-28 17:18:56 ----A---- C:\windows\SYSWOW64\SettingSyncCore.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\XpsGdiConverter.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\ReAgent.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\pnrpsvc.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\MsSpellCheckingFacility.dll
2014-12-28 17:18:55 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2014-12-28 17:18:55 ----A---- C:\windows\SYSWOW64\WSClient.dll
2014-12-28 17:18:55 ----A---- C:\windows\SYSWOW64\ReAgent.dll
2014-12-28 17:18:55 ----A---- C:\windows\system32\WSClient.dll
2014-12-28 17:18:55 ----A---- C:\windows\system32\hal.dll
2014-12-28 17:18:55 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2014-12-28 17:18:54 ----A---- C:\windows\SYSWOW64\ntdll.dll
2014-12-28 17:18:54 ----A---- C:\windows\SYSWOW64\MsSpellCheckingFacility.dll
2014-12-28 17:18:54 ----A---- C:\windows\system32\reseteng.dll
2014-12-28 17:18:53 ----A---- C:\windows\system32\sti.dll
2014-12-28 17:18:53 ----A---- C:\windows\system32\ntdll.dll
2014-12-28 17:18:53 ----A---- C:\windows\system32\easinvoker.exe
2014-12-28 17:18:53 ----A---- C:\windows\system32\drivers\rdbss.sys
2014-12-28 17:18:52 ----A---- C:\windows\SYSWOW64\OEMLicense.dll
2014-12-28 17:18:52 ----A---- C:\windows\SYSWOW64\easwrt.dll
2014-12-28 17:18:52 ----A---- C:\windows\system32\OEMLicense.dll
2014-12-28 17:18:52 ----A---- C:\windows\system32\easwrt.dll
2014-12-28 17:18:52 ----A---- C:\windows\system32\drivers\USBXHCI.SYS
2014-12-28 17:18:51 ----A---- C:\windows\SYSWOW64\sti.dll
2014-12-28 17:18:50 ----A---- C:\windows\system32\drivers\USBAUDIO.sys
2014-12-28 17:17:04 ----A---- C:\windows\system32\winload.exe
2014-12-28 17:16:50 ----A---- C:\windows\system32\drivers\WdFilter.sys
2014-12-28 17:16:48 ----A---- C:\windows\system32\drivers\WdBoot.sys
2014-12-28 17:16:46 ----A---- C:\windows\system32\drivers\WdNisDrv.sys
2014-12-28 17:10:04 ----D---- C:\Program Files (x86)\FreeCommander XE
2014-12-28 17:08:46 ----A---- C:\windows\SYSWOW64\msxml3.dll
2014-12-28 17:08:46 ----A---- C:\windows\system32\msxml3.dll
2014-12-28 17:08:40 ----A---- C:\windows\system32\d2d1.dll
2014-12-28 17:08:39 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2014-12-28 17:08:39 ----A---- C:\windows\SYSWOW64\d2d1.dll
2014-12-28 17:08:39 ----A---- C:\windows\system32\d3d10warp.dll
2014-12-28 17:06:02 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\AIMP3
2014-12-28 17:05:56 ----D---- C:\Program Files (x86)\AIMP3
2014-12-28 17:05:23 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-12-28 17:05:23 ----A---- C:\windows\system32\vbscript.dll
2014-12-28 16:51:23 ----D---- C:\Program Files (x86)\Kingsoft
2014-12-28 16:47:01 ----D---- C:\ProgramData\Kingsoft
2014-12-28 16:46:35 ----D---- C:\Program Files (x86)\Microsoft Office
2014-12-28 16:44:34 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\kingsoft
2014-12-28 16:43:57 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Launchy
2014-12-28 16:43:52 ----D---- C:\Program Files (x86)\Launchy
2014-12-28 16:43:22 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Dropbox
2014-12-28 16:36:15 ----N---- C:\windows\system32\pwdspio.sys
2014-12-28 16:36:15 ----N---- C:\windows\system32\pwdrvio.sys
2014-12-28 16:36:15 ----A---- C:\windows\system32\pwNative.exe
2014-12-28 16:35:24 ----D---- C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.1.1
2014-12-28 16:20:17 ----D---- C:\Program Files (x86)\EaseUS
2014-12-28 16:15:24 ----D---- C:\Program Files (x86)\VideoLAN
2014-12-28 16:04:40 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Nitro
2014-12-28 15:51:24 ----D---- C:\Program Files\CCleaner
2014-12-28 15:48:07 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Mozilla
2014-12-28 15:48:01 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Nitro PDF
2014-12-28 15:47:59 ----D---- C:\ProgramData\Mozilla
2014-12-28 15:47:58 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-28 15:47:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-12-28 15:47:18 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\LSC
2014-12-28 15:42:34 ----A---- C:\windows\SYSWOW64\taskSchedularLog.txt
2014-12-28 15:39:55 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Intel Corporation
2014-12-28 15:39:35 ----A---- C:\windows\system32\WudfUpdate_01011.dll
2014-12-28 15:38:06 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Adobe
2014-12-28 15:38:03 ----SD---- C:\Users\xpetrsedlak\AppData\Roaming\Microsoft
2014-12-28 15:38:03 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Macromedia

======List of files/folders modified in the last 1 month======

2014-12-29 20:06:08 ----RD---- C:\Program Files
2014-12-29 20:04:18 ----D---- C:\windows\Prefetch
2014-12-29 20:00:49 ----AD---- C:\Windows
2014-12-29 20:00:00 ----D---- C:\windows\system32\sru
2014-12-29 19:58:46 ----D---- C:\windows\SoftwareDistribution
2014-12-29 19:58:46 ----D---- C:\windows\Inf
2014-12-29 19:58:46 ----D---- C:\windows\debug
2014-12-29 19:58:24 ----D---- C:\windows\Temp
2014-12-29 19:57:38 ----AD---- C:\windows\System32
2014-12-29 19:57:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-12-29 19:52:43 ----RD---- C:\Program Files (x86)
2014-12-29 19:52:43 ----D---- C:\ProgramData\McAfee
2014-12-29 19:52:43 ----D---- C:\Program Files\Common Files
2014-12-29 19:52:42 ----D---- C:\Program Files (x86)\Common Files
2014-12-29 19:50:54 ----D---- C:\windows\system32\drivers
2014-12-29 19:50:52 ----HD---- C:\windows\ELAMBKUP
2014-12-29 19:50:15 ----D---- C:\windows\AppReadiness
2014-12-29 19:48:36 ----D---- C:\windows\WinSxS
2014-12-29 19:48:36 ----D---- C:\windows\Microsoft.NET
2014-12-29 19:48:18 ----D---- C:\windows\SysWOW64
2014-12-29 19:48:18 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\MUI
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\migration
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\inetsrv
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\en-US
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-12-29 19:47:06 ----D---- C:\windows\system32\migration
2014-12-29 19:47:06 ----D---- C:\windows\system32\inetsrv
2014-12-29 19:47:06 ----D---- C:\windows\system32\cs-CZ
2014-12-29 19:47:05 ----D---- C:\windows\system32\MUI
2014-12-29 19:47:05 ----D---- C:\windows\system32\en-US
2014-12-29 19:47:04 ----RSD---- C:\windows\Fonts
2014-12-29 19:43:20 ----D---- C:\windows\system32\config
2014-12-29 19:41:06 ----D---- C:\windows\system32\catroot2
2014-12-29 19:40:19 ----SHD---- C:\windows\Installer
2014-12-29 19:39:30 ----D---- C:\windows\system32\DriverStore
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\wamregps.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\iisRtl.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\iisrstap.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\iisreset.exe
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\ahadmin.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\admwprox.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\wamregps.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\iisRtl.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\iisrstap.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\iisreset.exe
2014-12-29 19:34:10 ----A---- C:\windows\system32\ahadmin.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\admwprox.dll
2014-12-29 19:30:07 ----D---- C:\windows\CbsTemp
2014-12-29 19:27:06 ----SD---- C:\ProgramData\Microsoft
2014-12-29 19:26:36 ----D---- C:\windows\system32\wdi
2014-12-29 19:25:59 ----HD---- C:\Program Files\WindowsApps
2014-12-29 19:23:55 ----D---- C:\windows\system32\catroot
2014-12-29 19:18:25 ----D---- C:\windows\system32\LogFiles
2014-12-29 19:18:03 ----SHD---- C:\System Volume Information
2014-12-29 18:34:18 ----RSD---- C:\windows\assembly
2014-12-29 06:34:41 ----D---- C:\windows\rescache
2014-12-28 21:56:10 ----D---- C:\windows\Panther
2014-12-28 21:56:09 ----D---- C:\windows\Logs
2014-12-28 21:55:29 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-12-28 21:54:26 ----D---- C:\Program Files (x86)\Cyberlink
2014-12-28 21:54:21 ----D---- C:\ProgramData\CyberLink
2014-12-28 21:50:33 ----D---- C:\Program Files (x86)\Lenovo
2014-12-28 18:58:04 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-28 18:58:03 ----D---- C:\Program Files\Internet Explorer
2014-12-28 18:57:54 ----RD---- C:\windows\ToastData
2014-12-28 18:57:41 ----D---- C:\windows\system32\Boot
2014-12-28 18:57:36 ----D---- C:\Program Files\Windows Defender
2014-12-28 18:57:34 ----D---- C:\Program Files (x86)\Windows Defender
2014-12-28 18:57:26 ----D---- C:\windows\system32\SecureBootUpdates
2014-12-28 18:02:32 ----D---- C:\Program Files\Lenovo
2014-12-28 17:58:37 ----D---- C:\windows\system32\Tasks
2014-12-28 17:57:36 ----D---- C:\ProgramData\Lenovo
2014-12-28 17:57:33 ----D---- C:\windows\system32\drivers\UMDF
2014-12-28 17:55:41 ----HD---- C:\ProgramData
2014-12-28 17:55:40 ----D---- C:\windows\twain_32
2014-12-28 17:04:34 ----D---- C:\windows\Tasks
2014-12-28 17:04:29 ----D---- C:\windows\ShellNew
2014-12-28 16:02:37 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-12-28 15:54:58 ----D---- C:\windows\system32\restore
2014-12-28 15:41:39 ----SHD---- C:\$Recycle.Bin
2014-12-28 15:38:00 ----AD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2013-11-04 632168]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 AVerPola;@oem7.inf,%ServiceDescription%;AVerMedia USB Polaris Series Capture Service; C:\windows\system32\DRIVERS\AVerPola.sys [2013-06-28 845824]
R3 AVPolDIR;@oem6.inf,%ServiceDescription%;AVerMedia USB Polaris Series DIR Service; C:\windows\System32\drivers\AVPolDIR.sys [2013-06-28 7168]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2014-02-20 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-11-15 3718488]
R3 iwdbus;@oem4.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\windows\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem22.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-12 99288]
R3 nvlddmkm;nvlddmkm; C:\windows\system32\DRIVERS\nvlddmkm.sys [2014-03-27 12691232]
R3 RSP2STOR;@oem18.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\windows\system32\DRIVERS\RtsP2Stor.sys [2013-07-05 290008]
R3 RTL8168;@oem20.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2013-07-26 827096]
R3 RTWlanE;@oem19.inf,%RTWlanE.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\windows\system32\DRIVERS\rtwlane.sys [2013-08-21 2944216]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Still Serial Digital Camera Driver; C:\windows\system32\DRIVERS\serscan.sys [2013-08-22 11776]
R3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\windows\system32\drivers\usbaudio.sys [2013-12-13 121088]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vmuacflt;@oem21.inf,%vmuacflt.SrvDesc%;Vimicro USB Audio Filter; C:\windows\System32\Drivers\vmuacflt.sys [2013-04-23 15872]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem3.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\windows\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 IntcDAud;@oem1.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2014-02-20 450520]
S3 NETwNe64;@netwew00.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\windows\system32\DRIVERS\NETwew00.sys [2013-07-08 3344352]
S3 pwdrvio;pwdrvio; \??\C:\windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\windows\syswow64\pwdspio.sys []
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;USB RNDIS Adapter; C:\windows\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\windows\system32\svchost.exe [2013-08-22 37768]
R2 AVerRemote;AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2013-06-26 368640]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2013-08-16 772096]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-04 15720]
R2 IdeaTouch.LocalDataServer.Education;IdeaTouch.LocalDataServer.Education; C:\Program Files (x86)\Lenovo\EducationPortal\Services\IdeaTouch.LocalDataServer.Education.exe [2012-05-17 7680]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-12 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-12 390616]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2013-08-31 117400]
R2 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-08-10 139856]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2014-03-27 925128]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2014-03-27 1365448]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2013-08-22 37768]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2013-05-14 390632]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\windows\system32\svchost.exe [2013-08-22 37768]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2013-08-22 37768]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\windows\system32\svchost.exe [2013-08-22 37768]
S2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-08-17 32768]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-28 267440]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-08-10 50784]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2014-02-20 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-22 43696]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-11-26 114800]
S3 w3logsvc;@%windir%\system32\inetsrv\iisres.dll,-30014; C:\windows\system32\svchost.exe [2013-08-22 37768]
S4 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2013-08-31 117400]

-----------------EOF-----------------


Díky moc!

Čud

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119557
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PC pořád něco "chroustá"

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

petrsedlak
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 13 úno 2009 15:46

Re: PC pořád něco "chroustá"

#3 Příspěvek od petrsedlak »

Tohle je asi vse co mi to vyhodilo:

# AdwCleaner v4.106 - Report created 29/12/2014 at 23:50:47
# Updated 21/12/2014 by Xplode
# Database : 2014-12-28.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : xpetrsedlak - CUD
# Running from : C:\Users\xpetrsedlak\Desktop\adwcleaner_4.106.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Mozilla Firefox v34.0.5 (x86 en-US)


*************************

AdwCleaner[R0].txt - [740 octets] - [29/12/2014 23:47:44]
AdwCleaner[S0].txt - [662 octets] - [29/12/2014 23:50:47]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [721 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119557
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PC pořád něco "chroustá"

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

petrsedlak
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 13 úno 2009 15:46

Re: PC pořád něco "chroustá"

#5 Příspěvek od petrsedlak »

RSIT:

Logfile of random's system information tool 1.10 (written by random/random)
Run by xpetrsedlak at 2014-12-30 18:48:13
Microsoft Windows 8.1
System drive C: has 223 GB (87%) free of 256 GB
Total RAM: 8092 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:48:14 PM, on 12/30/2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe
C:\Windows\jmesoft\hotkey.exe
C:\Users\xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Launchy\Launchy.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\xpetrsedlak.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN228353SW05V3:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1
O4 - Startup: Dropbox.lnk = xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Launchy.lnk = C:\Program Files (x86)\Launchy\Launchy.exe
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Foxit Cloud Safe Update Service (FoxitCloudUpdateService) - Foxit Software Inc. - C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7570 bytes

======Listing Processes======





wininit.exe


C:\windows\system32\lsass.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"C:\windows\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\nvvsvc.exe -session
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 113814320096
\??\C:\windows\system32\conhost.exe 0x4
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe"
"C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe"
dashost.exe {db537b16-557e-4d61-8e6d539989c58609}
"C:\Program Files (x86)\Lenovo\EducationPortal\Services\IdeaTouch.LocalDataServer.Education.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\jmesoft\Service.exe
C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k iissvcs

"C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k LocalServicePeerNet

C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\windows\system32\svchost.exe -k WindowsMobile
C:\windows\system32\SearchIndexer.exe /Embedding
taskhostex.exe
C:\windows\Explorer.EXE
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\windows\notepad.exe" C:\_OTM\MovedFiles\12302014_183829.log
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Dolby Digital Plus\ddp.exe" -autostart
"C:\Windows\System32\igfxtray.exe"
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16384_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
"C:\Windows\System32\hkcmd.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe"
"C:\Windows\jmesoft\hotkey.exe"
"C:\Users\xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Windows\jmesoft\JME_LOAD.exe"
"C:\Program Files (x86)\Launchy\Launchy.exe"
"C:\Windows\System32\WWAHost.exe" -ServerName:Windows.Store

taskeng.exe {663826E7-D9F0-48AC-A2AD-3E9245BCCF98}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey B5F24519-79AF-40B7-7D9E-F25702FF760C -Reinvoke
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
C:\windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\xpetrsedlak\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\WpsNotifyTask_xpetrsedlak.job - C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsnotify.exe -from=task
C:\windows\tasks\WpsUpdateTask_xpetrsedlak.job - C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe -from=task

=========Mozilla firefox=========

ProfilePath - C:\Users\xpetrsedlak\AppData\Roaming\Mozilla\Firefox\Profiles\bik8q31b.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2014-02-20 391152]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2014-02-20 771568]
"Persistence"=C:\windows\system32\igfxpers.exe [2014-02-20 770544]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-10-24 13662936]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-11-13 1368792]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-11-13 1368792]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-04 36352]
"Windows Mobile-based device management"=C:\windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-12-12 7394584]
"HP Photosmart 5510 series (NET)"=C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2013-07-24 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-08-17 28672]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerHIDReceiver\AVerHIDReceiver.exe

C:\Users\xpetrsedlak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\xpetrsedlak\AppData\Roaming\Dropbox\bin\Dropbox.exe
Launchy.lnk - C:\Program Files (x86)\Launchy\Launchy.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2014-02-20 624640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-12-30 18:38:29 ----D---- C:\_OTM
2014-12-30 18:32:45 ----D---- C:\Program Files (x86)\7-Zip
2014-12-30 18:24:47 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Foxit Software
2014-12-30 18:21:14 ----D---- C:\Program Files (x86)\Foxit Software
2014-12-30 15:31:42 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\gtk-2.0
2014-12-30 10:41:23 ----N---- C:\windows\system32\MpSigStub.exe
2014-12-29 23:55:52 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\vlc
2014-12-29 23:47:24 ----D---- C:\AdwCleaner
2014-12-29 20:06:08 ----D---- C:\Program Files\trend micro
2014-12-29 20:06:07 ----D---- C:\rsit
2014-12-29 20:00:49 ----D---- C:\windows\ERUNT
2014-12-29 19:47:13 ----D---- C:\Program Files (x86)\Reference Assemblies
2014-12-29 19:47:13 ----D---- C:\Program Files (x86)\MSBuild
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\XPSViewer
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\BestPractices
2014-12-29 19:47:04 ----D---- C:\windows\system32\BestPractices
2014-12-29 19:47:04 ----D---- C:\Program Files\MSBuild
2014-12-29 19:47:04 ----D---- C:\inetpub
2014-12-29 19:18:07 ----D---- C:\windows\WindowsMobile
2014-12-28 19:51:11 ----D---- C:\Program Files (x86)\IrfanView
2014-12-28 19:39:20 ----D---- C:\Program Files (x86)\Mendeley Desktop
2014-12-28 19:16:16 ----D---- C:\Program Files (x86)\Chromas
2014-12-28 17:56:10 ----N---- C:\windows\system32\HPDiscoPMa111.dll
2014-12-28 17:55:41 ----D---- C:\ProgramData\HP
2014-12-28 17:55:40 ----D---- C:\Program Files (x86)\HP
2014-12-28 17:55:39 ----D---- C:\Program Files\HP
2014-12-28 17:55:28 ----A---- C:\ProgramData\Ament.ini
2014-12-28 17:34:42 ----D---- C:\windows\system32\MRT
2014-12-28 17:34:39 ----A---- C:\windows\system32\MRT.exe
2014-12-28 17:27:49 ----A---- C:\windows\system32\poqexec.exe
2014-12-28 17:27:48 ----A---- C:\windows\SYSWOW64\poqexec.exe
2014-12-28 17:26:31 ----A---- C:\windows\system32\mshtml.dll
2014-12-28 17:26:30 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-12-28 17:26:25 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-12-28 17:26:25 ----A---- C:\windows\system32\mshtmled.dll
2014-12-28 17:25:50 ----A---- C:\windows\SYSWOW64\shell32.dll
2014-12-28 17:25:50 ----A---- C:\windows\system32\shell32.dll
2014-12-28 17:23:48 ----A---- C:\windows\system32\sppsvc.exe
2014-12-28 17:23:47 ----A---- C:\windows\system32\mfcore.dll
2014-12-28 17:23:47 ----A---- C:\windows\system32\drivers\tcpip.sys
2014-12-28 17:23:46 ----A---- C:\windows\system32\combase.dll
2014-12-28 17:23:45 ----A---- C:\windows\SYSWOW64\mfcore.dll
2014-12-28 17:23:44 ----A---- C:\windows\SYSWOW64\combase.dll
2014-12-28 17:23:44 ----A---- C:\windows\system32\mfmpeg2srcsnk.dll
2014-12-28 17:23:43 ----A---- C:\windows\system32\mstscax.dll
2014-12-28 17:23:42 ----A---- C:\windows\SYSWOW64\mfmpeg2srcsnk.dll
2014-12-28 17:23:41 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-12-28 17:23:40 ----A---- C:\windows\system32\dbghelp.dll
2014-12-28 17:23:40 ----A---- C:\windows\system32\dbgeng.dll
2014-12-28 17:23:38 ----A---- C:\windows\SYSWOW64\dbgeng.dll
2014-12-28 17:23:38 ----A---- C:\windows\system32\swprv.dll
2014-12-28 17:23:38 ----A---- C:\windows\system32\Faultrep.dll
2014-12-28 17:23:37 ----A---- C:\windows\SYSWOW64\Faultrep.dll
2014-12-28 17:23:37 ----A---- C:\windows\SYSWOW64\dbghelp.dll
2014-12-28 17:23:37 ----A---- C:\windows\system32\WerFault.exe
2014-12-28 17:23:36 ----A---- C:\windows\system32\mfps.dll
2014-12-28 17:23:35 ----A---- C:\windows\SYSWOW64\WerFault.exe
2014-12-28 17:23:35 ----A---- C:\windows\system32\drivers\volsnap.sys
2014-12-28 17:23:34 ----A---- C:\windows\SYSWOW64\rdpencom.dll
2014-12-28 17:23:34 ----A---- C:\windows\system32\rdvidcrl.dll
2014-12-28 17:23:34 ----A---- C:\windows\system32\rdpencom.dll
2014-12-28 17:23:34 ----A---- C:\windows\system32\DWWIN.EXE
2014-12-28 17:23:33 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2014-12-28 17:23:33 ----A---- C:\windows\SYSWOW64\DWWIN.EXE
2014-12-28 17:23:33 ----A---- C:\windows\system32\tsgqec.dll
2014-12-28 17:23:32 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll
2014-12-28 17:23:32 ----A---- C:\windows\system32\sppcomapi.dll
2014-12-28 17:22:31 ----A---- C:\windows\system32\drivers\ntfs.sys
2014-12-28 17:22:31 ----A---- C:\windows\system32\drivers\clfs.sys
2014-12-28 17:22:20 ----A---- C:\windows\system32\KernelBase.dll
2014-12-28 17:22:19 ----A---- C:\windows\system32\kernel32.dll
2014-12-28 17:22:18 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2014-12-28 17:22:18 ----A---- C:\windows\SYSWOW64\kernel32.dll
2014-12-28 17:21:59 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-12-28 17:21:59 ----A---- C:\windows\system32\iertutil.dll
2014-12-28 17:21:58 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-12-28 17:21:58 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-12-28 17:21:57 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-12-28 17:21:56 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-12-28 17:21:56 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-12-28 17:21:56 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-12-28 17:21:52 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-12-28 17:21:52 ----A---- C:\windows\system32\iernonce.dll
2014-12-28 17:21:51 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-12-28 17:21:51 ----A---- C:\windows\system32\urlmon.dll
2014-12-28 17:21:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-12-28 17:21:50 ----A---- C:\windows\system32\ieetwcollector.exe
2014-12-28 17:21:49 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-12-28 17:21:49 ----A---- C:\windows\system32\msfeeds.dll
2014-12-28 17:21:48 ----A---- C:\windows\system32\iesetup.dll
2014-12-28 17:21:46 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-12-28 17:21:46 ----A---- C:\windows\system32\ie4uinit.exe
2014-12-28 17:21:45 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-12-28 17:21:44 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-12-28 17:21:44 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-12-28 17:21:44 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-12-28 17:21:42 ----A---- C:\windows\system32\ieframe.dll
2014-12-28 17:21:41 ----A---- C:\windows\system32\jscript9diag.dll
2014-12-28 17:21:41 ----A---- C:\windows\system32\jscript9.dll
2014-12-28 17:21:41 ----A---- C:\windows\system32\ieUnatt.exe
2014-12-28 17:21:40 ----A---- C:\windows\system32\ieapfltr.dll
2014-12-28 17:21:39 ----A---- C:\windows\system32\wininet.dll
2014-12-28 17:21:39 ----A---- C:\windows\system32\msrating.dll
2014-12-28 17:21:39 ----A---- C:\windows\system32\jsproxy.dll
2014-12-28 17:19:24 ----A---- C:\windows\system32\win32k.sys
2014-12-28 17:19:16 ----A---- C:\windows\SYSWOW64\qedit.dll
2014-12-28 17:19:16 ----A---- C:\windows\system32\qedit.dll
2014-12-28 17:19:05 ----A---- C:\windows\system32\Windows.UI.Xaml.dll
2014-12-28 17:19:04 ----A---- C:\windows\SYSWOW64\Windows.UI.Xaml.dll
2014-12-28 17:19:01 ----A---- C:\windows\SYSWOW64\twinui.dll
2014-12-28 17:19:01 ----A---- C:\windows\system32\twinui.dll
2014-12-28 17:19:00 ----A---- C:\windows\system32\SearchFolder.dll
2014-12-28 17:19:00 ----A---- C:\windows\system32\schedsvc.dll
2014-12-28 17:18:59 ----A---- C:\windows\SYSWOW64\SearchFolder.dll
2014-12-28 17:18:59 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2014-12-28 17:18:58 ----A---- C:\windows\system32\SettingSyncHost.exe
2014-12-28 17:18:58 ----A---- C:\windows\system32\mfsvr.dll
2014-12-28 17:18:58 ----A---- C:\windows\system32\MFMediaEngine.dll
2014-12-28 17:18:57 ----A---- C:\windows\SYSWOW64\SettingSyncHost.exe
2014-12-28 17:18:57 ----A---- C:\windows\SYSWOW64\mfsvr.dll
2014-12-28 17:18:57 ----A---- C:\windows\SYSWOW64\MFMediaEngine.dll
2014-12-28 17:18:57 ----A---- C:\windows\system32\SettingSyncCore.dll
2014-12-28 17:18:56 ----A---- C:\windows\SYSWOW64\SettingSyncCore.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\XpsGdiConverter.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\ReAgent.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\pnrpsvc.dll
2014-12-28 17:18:56 ----A---- C:\windows\system32\MsSpellCheckingFacility.dll
2014-12-28 17:18:55 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2014-12-28 17:18:55 ----A---- C:\windows\SYSWOW64\WSClient.dll
2014-12-28 17:18:55 ----A---- C:\windows\SYSWOW64\ReAgent.dll
2014-12-28 17:18:55 ----A---- C:\windows\system32\WSClient.dll
2014-12-28 17:18:55 ----A---- C:\windows\system32\hal.dll
2014-12-28 17:18:55 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2014-12-28 17:18:54 ----A---- C:\windows\SYSWOW64\ntdll.dll
2014-12-28 17:18:54 ----A---- C:\windows\SYSWOW64\MsSpellCheckingFacility.dll
2014-12-28 17:18:54 ----A---- C:\windows\system32\reseteng.dll
2014-12-28 17:18:53 ----A---- C:\windows\system32\sti.dll
2014-12-28 17:18:53 ----A---- C:\windows\system32\ntdll.dll
2014-12-28 17:18:53 ----A---- C:\windows\system32\easinvoker.exe
2014-12-28 17:18:53 ----A---- C:\windows\system32\drivers\rdbss.sys
2014-12-28 17:18:52 ----A---- C:\windows\SYSWOW64\OEMLicense.dll
2014-12-28 17:18:52 ----A---- C:\windows\SYSWOW64\easwrt.dll
2014-12-28 17:18:52 ----A---- C:\windows\system32\OEMLicense.dll
2014-12-28 17:18:52 ----A---- C:\windows\system32\easwrt.dll
2014-12-28 17:18:52 ----A---- C:\windows\system32\drivers\USBXHCI.SYS
2014-12-28 17:18:51 ----A---- C:\windows\SYSWOW64\sti.dll
2014-12-28 17:18:50 ----A---- C:\windows\system32\drivers\USBAUDIO.sys
2014-12-28 17:17:04 ----A---- C:\windows\system32\winload.exe
2014-12-28 17:16:50 ----A---- C:\windows\system32\drivers\WdFilter.sys
2014-12-28 17:16:48 ----A---- C:\windows\system32\drivers\WdBoot.sys
2014-12-28 17:16:46 ----A---- C:\windows\system32\drivers\WdNisDrv.sys
2014-12-28 17:10:04 ----D---- C:\Program Files (x86)\FreeCommander XE
2014-12-28 17:08:46 ----A---- C:\windows\SYSWOW64\msxml3.dll
2014-12-28 17:08:46 ----A---- C:\windows\system32\msxml3.dll
2014-12-28 17:08:40 ----A---- C:\windows\system32\d2d1.dll
2014-12-28 17:08:39 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2014-12-28 17:08:39 ----A---- C:\windows\SYSWOW64\d2d1.dll
2014-12-28 17:08:39 ----A---- C:\windows\system32\d3d10warp.dll
2014-12-28 17:06:02 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\AIMP3
2014-12-28 17:05:56 ----D---- C:\Program Files (x86)\AIMP3
2014-12-28 17:05:23 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-12-28 17:05:23 ----A---- C:\windows\system32\vbscript.dll
2014-12-28 16:51:23 ----D---- C:\Program Files (x86)\Kingsoft
2014-12-28 16:47:01 ----D---- C:\ProgramData\Kingsoft
2014-12-28 16:46:35 ----D---- C:\Program Files (x86)\Microsoft Office
2014-12-28 16:44:34 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\kingsoft
2014-12-28 16:43:57 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Launchy
2014-12-28 16:43:52 ----D---- C:\Program Files (x86)\Launchy
2014-12-28 16:43:22 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Dropbox
2014-12-28 16:36:15 ----N---- C:\windows\system32\pwdspio.sys
2014-12-28 16:36:15 ----N---- C:\windows\system32\pwdrvio.sys
2014-12-28 16:36:15 ----A---- C:\windows\system32\pwNative.exe
2014-12-28 16:35:24 ----D---- C:\Program Files (x86)\MiniTool Partition Wizard Home Edition 8.1.1
2014-12-28 16:20:17 ----D---- C:\Program Files (x86)\EaseUS
2014-12-28 16:15:24 ----D---- C:\Program Files (x86)\VideoLAN
2014-12-28 16:04:40 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Nitro
2014-12-28 15:51:24 ----D---- C:\Program Files\CCleaner
2014-12-28 15:48:07 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Mozilla
2014-12-28 15:48:01 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Nitro PDF
2014-12-28 15:47:59 ----D---- C:\ProgramData\Mozilla
2014-12-28 15:47:58 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-28 15:47:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-12-28 15:47:18 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\LSC
2014-12-28 15:42:34 ----A---- C:\windows\SYSWOW64\taskSchedularLog.txt
2014-12-28 15:39:55 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Intel Corporation
2014-12-28 15:39:35 ----A---- C:\windows\system32\WudfUpdate_01011.dll
2014-12-28 15:38:06 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Adobe
2014-12-28 15:38:03 ----SD---- C:\Users\xpetrsedlak\AppData\Roaming\Microsoft
2014-12-28 15:38:03 ----D---- C:\Users\xpetrsedlak\AppData\Roaming\Macromedia

======List of files/folders modified in the last 1 month======

2014-12-30 18:47:50 ----D---- C:\windows\Prefetch
2014-12-30 18:47:42 ----D---- C:\windows\Temp
2014-12-30 18:44:45 ----D---- C:\windows\Inf
2014-12-30 18:44:45 ----AD---- C:\windows\System32
2014-12-30 18:44:45 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-12-30 18:36:13 ----AD---- C:\Users
2014-12-30 18:32:45 ----RD---- C:\Program Files (x86)
2014-12-30 18:00:00 ----D---- C:\windows\system32\sru
2014-12-30 15:47:28 ----D---- C:\windows\system32\config
2014-12-30 15:45:28 ----SHD---- C:\windows\Installer
2014-12-30 15:29:40 ----D---- C:\windows\WinSxS
2014-12-30 10:58:10 ----HD---- C:\Program Files\WindowsApps
2014-12-30 10:42:06 ----D---- C:\windows\AppReadiness
2014-12-30 09:39:00 ----D---- C:\windows\SoftwareDistribution
2014-12-30 09:39:00 ----AD---- C:\Windows
2014-12-30 09:37:06 ----D---- C:\windows\system32\wdi
2014-12-29 20:17:19 ----D---- C:\windows\Microsoft.NET
2014-12-29 20:06:08 ----RD---- C:\Program Files
2014-12-29 19:58:46 ----D---- C:\windows\debug
2014-12-29 19:52:43 ----D---- C:\ProgramData\McAfee
2014-12-29 19:52:43 ----D---- C:\Program Files\Common Files
2014-12-29 19:52:42 ----D---- C:\Program Files (x86)\Common Files
2014-12-29 19:50:54 ----D---- C:\windows\system32\drivers
2014-12-29 19:50:52 ----HD---- C:\windows\ELAMBKUP
2014-12-29 19:48:39 ----D---- C:\windows\CbsTemp
2014-12-29 19:48:18 ----D---- C:\windows\SysWOW64
2014-12-29 19:48:18 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\MUI
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\migration
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\inetsrv
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\en-US
2014-12-29 19:47:06 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-12-29 19:47:06 ----D---- C:\windows\system32\migration
2014-12-29 19:47:06 ----D---- C:\windows\system32\inetsrv
2014-12-29 19:47:06 ----D---- C:\windows\system32\cs-CZ
2014-12-29 19:47:05 ----D---- C:\windows\system32\MUI
2014-12-29 19:47:05 ----D---- C:\windows\system32\en-US
2014-12-29 19:47:04 ----RSD---- C:\windows\Fonts
2014-12-29 19:41:06 ----D---- C:\windows\system32\catroot2
2014-12-29 19:39:30 ----D---- C:\windows\system32\DriverStore
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\wamregps.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\iisRtl.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\iisrstap.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\iisreset.exe
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\ahadmin.dll
2014-12-29 19:34:19 ----A---- C:\windows\SYSWOW64\admwprox.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\wamregps.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\iisRtl.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\iisrstap.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\iisreset.exe
2014-12-29 19:34:10 ----A---- C:\windows\system32\ahadmin.dll
2014-12-29 19:34:10 ----A---- C:\windows\system32\admwprox.dll
2014-12-29 19:27:06 ----SD---- C:\ProgramData\Microsoft
2014-12-29 19:23:55 ----D---- C:\windows\system32\catroot
2014-12-29 19:18:25 ----D---- C:\windows\system32\LogFiles
2014-12-29 19:18:03 ----SHD---- C:\System Volume Information
2014-12-29 18:34:18 ----RSD---- C:\windows\assembly
2014-12-29 06:34:41 ----D---- C:\windows\rescache
2014-12-28 21:56:10 ----D---- C:\windows\Panther
2014-12-28 21:56:09 ----D---- C:\windows\Logs
2014-12-28 21:55:29 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-12-28 21:54:26 ----D---- C:\Program Files (x86)\Cyberlink
2014-12-28 21:54:21 ----D---- C:\ProgramData\CyberLink
2014-12-28 21:50:33 ----D---- C:\Program Files (x86)\Lenovo
2014-12-28 18:58:04 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-28 18:58:03 ----D---- C:\Program Files\Internet Explorer
2014-12-28 18:57:54 ----RD---- C:\windows\ToastData
2014-12-28 18:57:41 ----D---- C:\windows\system32\Boot
2014-12-28 18:57:36 ----D---- C:\Program Files\Windows Defender
2014-12-28 18:57:34 ----D---- C:\Program Files (x86)\Windows Defender
2014-12-28 18:57:26 ----D---- C:\windows\system32\SecureBootUpdates
2014-12-28 18:02:32 ----D---- C:\Program Files\Lenovo
2014-12-28 17:58:37 ----D---- C:\windows\system32\Tasks
2014-12-28 17:57:36 ----D---- C:\ProgramData\Lenovo
2014-12-28 17:57:33 ----D---- C:\windows\system32\drivers\UMDF
2014-12-28 17:55:41 ----HD---- C:\ProgramData
2014-12-28 17:55:40 ----D---- C:\windows\twain_32
2014-12-28 17:04:34 ----D---- C:\windows\Tasks
2014-12-28 17:04:29 ----D---- C:\windows\ShellNew
2014-12-28 16:02:37 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-12-28 15:54:58 ----D---- C:\windows\system32\restore
2014-12-28 15:41:39 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2013-11-04 632168]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 AVerPola;@oem7.inf,%ServiceDescription%;AVerMedia USB Polaris Series Capture Service; C:\windows\system32\DRIVERS\AVerPola.sys [2013-06-28 845824]
R3 AVPolDIR;@oem6.inf,%ServiceDescription%;AVerMedia USB Polaris Series DIR Service; C:\windows\System32\drivers\AVPolDIR.sys [2013-06-28 7168]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2014-02-20 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-11-15 3718488]
R3 iwdbus;@oem4.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\windows\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 MEIx64;@oem22.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-12 99288]
R3 nvlddmkm;nvlddmkm; C:\windows\system32\DRIVERS\nvlddmkm.sys [2014-03-27 12691232]
R3 RSP2STOR;@oem18.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\windows\system32\DRIVERS\RtsP2Stor.sys [2013-07-05 290008]
R3 RTL8168;@oem20.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2013-07-26 827096]
R3 RTWlanE;@oem19.inf,%RTWlanE.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\windows\system32\DRIVERS\rtwlane.sys [2013-08-21 2944216]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Still Serial Digital Camera Driver; C:\windows\system32\DRIVERS\serscan.sys [2013-08-22 11776]
R3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\windows\system32\drivers\usbaudio.sys [2013-12-13 121088]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vmuacflt;@oem21.inf,%vmuacflt.SrvDesc%;Vimicro USB Audio Filter; C:\windows\System32\Drivers\vmuacflt.sys [2013-04-23 15872]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem3.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\windows\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 IntcDAud;@oem1.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2014-02-20 450520]
S3 NETwNe64;@netwew00.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\windows\system32\DRIVERS\NETwew00.sys [2013-07-08 3344352]
S3 pwdrvio;pwdrvio; \??\C:\windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\windows\syswow64\pwdspio.sys []
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;USB RNDIS Adapter; C:\windows\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\windows\system32\svchost.exe [2013-08-22 37768]
R2 AVerRemote;AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2013-06-26 368640]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2013-08-16 772096]
R2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [2014-10-28 244448]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-04 15720]
R2 IdeaTouch.LocalDataServer.Education;IdeaTouch.LocalDataServer.Education; C:\Program Files (x86)\Lenovo\EducationPortal\Services\IdeaTouch.LocalDataServer.Education.exe [2012-05-17 7680]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-12 169432]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-08-17 32768]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-12 390616]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2013-08-31 117400]
R2 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-08-10 139856]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2014-03-27 925128]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2014-03-27 1365448]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2013-08-22 37768]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2013-05-14 390632]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\windows\system32\svchost.exe [2013-08-22 37768]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2013-08-22 37768]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\windows\system32\svchost.exe [2013-08-22 37768]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-28 267440]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-08-10 50784]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2014-02-20 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-22 43696]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-11-26 114800]
S3 w3logsvc;@%windir%\system32\inetsrv\iisres.dll,-30014; C:\windows\system32\svchost.exe [2013-08-22 37768]
S4 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe [2013-08-31 117400]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119557
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PC pořád něco "chroustá"

#6 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

petrsedlak
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 13 úno 2009 15:46

Re: PC pořád něco "chroustá"

#7 Příspěvek od petrsedlak »

Vypadá to vskutku o dost lépe!

Díky, určitě něco pošlu, jako vždy.

Ještě malá otázka:

Program OTM se dá čas od času pouštět pro vyčištění PC?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119557
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: PC pořád něco "chroustá"

#8 Příspěvek od Rudy »

My děkujeme za příspěvek.
petrsedlak píše:Program OTM se dá čas od času pouštět pro vyčištění PC?
Jistě, musíte ale napsat skript. OTM maže jen to, co mu přikážete. Pro laiky je vhodnější ADW. Vykydá toolbary, zbytečnosti a některé AdWary.

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět