Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

zavirovany pocitac

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

zavirovany pocitac

#1 Příspěvek od Rhonwyn »

Dobry den, prosim o pomoc s maminym notebookem. Pry ji nefungovala mozila, tak jsem ji odinstalovala, znovu nainstalovat nejde, pise to nejaky problem s certifikatem. Vsimla jsem si ze jako hlavni vyhledavac tam ma Bing... Nefunguje pry ani Skype a notebook je celkove zpomaleny. Procistila jsem ji pc a registry s ccleanerem a projela MBAM ale MBAM nic nenasel, tak se obracim pro pomoc zde. Dekuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by Katerina Rod at 2015-03-17 12:33:54
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 88 GB (19%) free of 462 GB
Total RAM: 3986 MB (31% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:34:00 PM, on 17/03/2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\WinFLTray.exe
C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe
C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServ.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Windows\UMStor\Res.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\KATERI~1\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Katerina Rod.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\windows\UMStor\Res.EXE
O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files (x86)\Multimedia Keyboard Driver\StartAutorun.exe PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [WinFLTray] C:\windows\SysWow64\WinFLTray.exe
O4 - HKCU\..\Run: [FLBackup] C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLService - New Softwares.net - C:\windows\SysWow64\WinFLService.exe
O23 - Service: GFNEX Service (GFNEXSrv) - Unknown owner - C:\Windows\System32\GFNEXSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10655 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\GFNEXSrv.exe
C:\windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\SysWow64\WinFLService.exe
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\windows\SysWOW64\PnkBstrA.exe
C:\windows\system32\svchost.exe -k regsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\windows\system32\TODDSrv.exe
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
ngservice.exe pipeserver
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\TOSHIBA\PeakShift\TPSCMain.exe"
C:\windows\System32\svchost.exe -k swprv
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\SysWOW64\WinFLTray.exe"
"C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe"
"C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServ.exe" -Embedding
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Windows\UMStor\Res.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Katerina Rod\AppData\Local\Steam\htmlcache" -steampid 5548 -buildid 1424305157 -steamid "0" --blacklist-accelerated-compositing --process-per-tab --disable-accelerated-video-decode --enable-direct-write
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-accelerated-compositing --disable-gpu-compositing --channel="2488.0.2063942700\1985873982" /prefetch:673131151
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-accelerated-compositing --disable-gpu-compositing --channel="2488.3.1281561101\1714507656" /prefetch:673131151
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\vssvc.exe

"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Users\KATERI~1\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"c:\users\kateri~1\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:9800 CREDAT:275457 /prefetch:2
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1638243991-162663850-1552511273-100036_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1638243991-162663850-1552511273-100036 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Katerina Rod\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\AdobeAAMUpdater-1.0-KaterinaRod-PC-Katerina Rod.job - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe -mode=scheduled
C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller winlogon-impersonate
C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller scheduler-impersonate

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-04 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2011-11-03 700800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-17 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-04 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-17 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2011-11-03 534400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-02-01 12446824]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2011-11-24 1548208]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2011-12-14 712096]
"TPSCMain"=C:\Program Files\TOSHIBA\PeakShift\TPSCMain.exe [2011-12-21 740792]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2011-11-26 710560]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2011-06-28 38824]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2012-05-10 170264]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2012-05-10 398616]
"Persistence"=C:\windows\system32\igfxpers.exe [2012-05-10 440088]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-02-03 557768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WinFLTray"=C:\windows\SysWow64\WinFLTray.exe [2012-10-19 321736]
"FLBackup"=C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe [2012-10-19 275656]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-01-23 31087200]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]
"CCleaner"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-01-05 291608]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2011-07-12 1298816]
"USB Storage Toolbox"=C:\windows\UMStor\Res.EXE [2005-09-14 65536]
"WireLessKeyboard"=C:\Program Files (x86)\Multimedia Keyboard Driver\StartAutorun.exe [2005-11-30 94208]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2015-02-15 2694320]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-27 5227112]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2012-05-10 436224]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinFLAdrv.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-17 12:33:54 ----D---- C:\rsit
2015-03-13 12:08:54 ----A---- C:\windows\SYSWOW64\atmfd.dll
2015-03-13 12:08:54 ----A---- C:\windows\system32\lpk.dll
2015-03-13 12:08:54 ----A---- C:\windows\system32\atmlib.dll
2015-03-13 12:08:54 ----A---- C:\windows\system32\atmfd.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\lpk.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\fontsub.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\dciman32.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\atmlib.dll
2015-03-13 12:08:53 ----A---- C:\windows\system32\fontsub.dll
2015-03-13 12:08:53 ----A---- C:\windows\system32\dciman32.dll
2015-03-13 12:08:29 ----A---- C:\windows\SYSWOW64\mf.dll
2015-03-13 12:08:28 ----A---- C:\windows\SYSWOW64\wmp.dll
2015-03-13 12:08:28 ----A---- C:\windows\system32\ntoskrnl.exe
2015-03-13 12:08:25 ----A---- C:\windows\system32\crypt32.dll
2015-03-13 12:08:24 ----A---- C:\windows\SYSWOW64\crypt32.dll
2015-03-13 12:08:22 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-03-13 12:08:22 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-03-13 12:08:17 ----A---- C:\windows\system32\drivers\mountmgr.sys
2015-03-13 12:08:15 ----A---- C:\windows\system32\mf.dll
2015-03-13 12:08:14 ----A---- C:\windows\system32\wmp.dll
2015-03-13 12:08:10 ----A---- C:\windows\system32\drmv2clt.dll
2015-03-13 12:08:09 ----A---- C:\windows\SYSWOW64\quartz.dll
2015-03-13 12:08:09 ----A---- C:\windows\system32\quartz.dll
2015-03-13 12:08:06 ----A---- C:\windows\SYSWOW64\drmv2clt.dll
2015-03-13 12:08:06 ----A---- C:\windows\system32\winload.exe
2015-03-13 12:08:06 ----A---- C:\windows\system32\msscp.dll
2015-03-13 12:08:05 ----A---- C:\windows\SYSWOW64\qdvd.dll
2015-03-13 12:08:05 ----A---- C:\windows\system32\cryptui.dll
2015-03-13 12:08:04 ----A---- C:\windows\SYSWOW64\cryptui.dll
2015-03-13 12:08:04 ----A---- C:\windows\SYSWOW64\blackbox.dll
2015-03-13 12:08:04 ----A---- C:\windows\system32\wmdrmsdk.dll
2015-03-13 12:08:04 ----A---- C:\windows\system32\cryptnet.dll
2015-03-13 12:08:03 ----A---- C:\windows\SYSWOW64\wintrust.dll
2015-03-13 12:08:03 ----A---- C:\windows\system32\wintrust.dll
2015-03-13 12:08:03 ----A---- C:\windows\system32\pcasvc.dll
2015-03-13 12:08:03 ----A---- C:\windows\system32\audiosrv.dll
2015-03-13 12:08:02 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2015-03-13 12:08:02 ----A---- C:\windows\system32\srcore.dll
2015-03-13 12:08:02 ----A---- C:\windows\system32\blackbox.dll
2015-03-13 12:08:01 ----A---- C:\windows\system32\rstrui.exe
2015-03-13 12:07:59 ----A---- C:\windows\SYSWOW64\wmdrmsdk.dll
2015-03-13 12:07:58 ----A---- C:\windows\system32\drmmgrtn.dll
2015-03-13 12:07:54 ----A---- C:\windows\SYSWOW64\mfplat.dll
2015-03-13 12:07:54 ----A---- C:\windows\SYSWOW64\evr.dll
2015-03-13 12:07:54 ----A---- C:\windows\system32\mfplat.dll
2015-03-13 12:07:54 ----A---- C:\windows\system32\AUDIOKSE.dll
2015-03-13 12:07:53 ----A---- C:\windows\SYSWOW64\drmmgrtn.dll
2015-03-13 12:07:53 ----A---- C:\windows\system32\evr.dll
2015-03-13 12:07:52 ----A---- C:\windows\SYSWOW64\msscp.dll
2015-03-13 12:07:52 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2015-03-13 12:07:51 ----A---- C:\windows\system32\AudioSes.dll
2015-03-13 12:07:50 ----A---- C:\windows\system32\qdvd.dll
2015-03-13 12:07:48 ----A---- C:\windows\system32\audiodg.exe
2015-03-13 12:07:45 ----A---- C:\windows\system32\msnetobj.dll
2015-03-13 12:07:45 ----A---- C:\windows\system32\cryptsvc.dll
2015-03-13 12:07:42 ----A---- C:\windows\SYSWOW64\msnetobj.dll
2015-03-13 12:07:42 ----A---- C:\windows\system32\pcadm.dll
2015-03-13 12:07:42 ----A---- C:\windows\system32\AudioEng.dll
2015-03-13 12:07:40 ----A---- C:\windows\SYSWOW64\AudioEng.dll
2015-03-13 12:07:40 ----A---- C:\windows\system32\rrinstaller.exe
2015-03-13 12:07:38 ----A---- C:\windows\SYSWOW64\rrinstaller.exe
2015-03-13 12:07:37 ----A---- C:\windows\SYSWOW64\AUDIOKSE.dll
2015-03-13 12:07:37 ----A---- C:\windows\system32\smss.exe
2015-03-13 12:07:36 ----A---- C:\windows\system32\mfps.dll
2015-03-13 12:07:34 ----A---- C:\windows\SYSWOW64\mfps.dll
2015-03-13 12:07:34 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-03-13 12:07:33 ----A---- C:\windows\system32\msmmsp.dll
2015-03-13 12:07:33 ----A---- C:\windows\system32\drivers\PEAuth.sys
2015-03-13 12:07:33 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-03-13 12:07:32 ----A---- C:\windows\SYSWOW64\AudioSes.dll
2015-03-13 12:07:32 ----A---- C:\windows\system32\pcawrk.exe
2015-03-13 12:07:32 ----A---- C:\windows\system32\appidsvc.dll
2015-03-13 12:07:32 ----A---- C:\windows\system32\appidapi.dll
2015-03-13 12:07:31 ----A---- C:\windows\SYSWOW64\cryptsp.dll
2015-03-13 12:07:31 ----A---- C:\windows\system32\srclient.dll
2015-03-13 12:07:31 ----A---- C:\windows\system32\pcalua.exe
2015-03-13 12:07:31 ----A---- C:\windows\system32\mfpmp.exe
2015-03-13 12:07:31 ----A---- C:\windows\system32\cryptsp.dll
2015-03-13 12:07:30 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-03-13 12:07:30 ----A---- C:\windows\SYSWOW64\mfpmp.exe
2015-03-13 12:07:30 ----A---- C:\windows\system32\EncDump.dll
2015-03-13 12:07:30 ----A---- C:\windows\system32\csrsrv.dll
2015-03-13 12:07:29 ----A---- C:\windows\system32\setbcdlocale.dll
2015-03-13 12:07:28 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-03-13 12:07:26 ----A---- C:\windows\system32\drivers\appid.sys
2015-03-13 12:07:19 ----A---- C:\windows\system32\spwmp.dll
2015-03-13 12:07:15 ----A---- C:\windows\SYSWOW64\spwmp.dll
2015-03-13 12:07:15 ----A---- C:\windows\SYSWOW64\dxmasf.dll
2015-03-13 12:07:15 ----A---- C:\windows\system32\dxmasf.dll
2015-03-13 12:07:14 ----A---- C:\windows\system32\pcaevts.dll
2015-03-13 12:07:13 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-03-13 12:07:13 ----A---- C:\windows\system32\apisetschema.dll
2015-03-13 12:07:10 ----A---- C:\windows\SYSWOW64\wmploc.DLL
2015-03-13 12:07:10 ----A---- C:\windows\system32\wmploc.DLL
2015-03-13 12:06:52 ----A---- C:\windows\SYSWOW64\mferror.dll
2015-03-13 12:06:51 ----A---- C:\windows\system32\mferror.dll
2015-03-13 12:05:19 ----A---- C:\windows\system32\rdpudd.dll
2015-03-13 12:05:19 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2015-03-13 12:05:19 ----A---- C:\windows\system32\rdpcorets.dll
2015-03-13 12:03:12 ----A---- C:\windows\SYSWOW64\ubpm.dll
2015-03-13 12:03:12 ----A---- C:\windows\system32\ubpm.dll
2015-03-13 12:03:05 ----A---- C:\windows\system32\shell32.dll
2015-03-13 12:03:02 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-03-13 12:02:30 ----A---- C:\windows\system32\schannel.dll
2015-03-13 12:02:30 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-03-13 12:02:30 ----A---- C:\windows\system32\drivers\cng.sys
2015-03-13 12:02:28 ----A---- C:\windows\system32\lsasrv.dll
2015-03-13 12:02:27 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-03-13 12:02:27 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-03-13 12:02:26 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-03-13 12:02:25 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-03-13 12:02:25 ----A---- C:\windows\system32\wdigest.dll
2015-03-13 12:02:25 ----A---- C:\windows\system32\msv1_0.dll
2015-03-13 12:02:25 ----A---- C:\windows\system32\kerberos.dll
2015-03-13 12:02:24 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-03-13 12:02:24 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-03-13 12:02:24 ----A---- C:\windows\system32\TSpkg.dll
2015-03-13 12:02:24 ----A---- C:\windows\system32\sspicli.dll
2015-03-13 12:02:24 ----A---- C:\windows\system32\ncrypt.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-03-13 12:02:23 ----A---- C:\windows\system32\sspisrv.dll
2015-03-13 12:02:23 ----A---- C:\windows\system32\secur32.dll
2015-03-13 12:02:23 ----A---- C:\windows\system32\lsass.exe
2015-03-13 12:02:23 ----A---- C:\windows\system32\credssp.dll
2015-03-13 12:02:23 ----A---- C:\windows\system32\auditpol.exe
2015-03-13 12:02:22 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-03-13 12:02:21 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-03-13 12:02:21 ----A---- C:\windows\system32\adtschema.dll
2015-03-13 12:02:20 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-03-13 12:02:20 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-03-13 12:02:20 ----A---- C:\windows\system32\msaudite.dll
2015-03-13 12:02:19 ----A---- C:\windows\system32\msobjs.dll
2015-03-13 12:02:09 ----A---- C:\windows\SYSWOW64\msctf.dll
2015-03-13 12:02:09 ----A---- C:\windows\system32\msctf.dll
2015-03-13 12:02:08 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2015-03-13 12:02:08 ----A---- C:\windows\system32\WindowsCodecs.dll
2015-03-13 12:02:05 ----A---- C:\windows\system32\win32k.sys
2015-03-13 12:01:56 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-03-13 12:01:55 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-03-13 12:01:55 ----A---- C:\windows\system32\ieetwcollector.exe
2015-03-13 12:01:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-03-13 12:01:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-03-13 12:01:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-03-13 12:01:50 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-03-13 12:01:50 ----A---- C:\windows\system32\iernonce.dll
2015-03-13 12:01:50 ----A---- C:\windows\system32\ie4uinit.exe
2015-03-13 12:01:49 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-03-13 12:01:49 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-13 12:01:48 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-03-13 12:01:48 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-03-13 12:01:48 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-03-13 12:01:47 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-03-13 12:01:46 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-03-13 12:01:46 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-03-13 12:01:45 ----A---- C:\windows\system32\iedkcs32.dll
2015-03-13 12:01:44 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-03-13 12:01:44 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-03-13 12:01:44 ----A---- C:\windows\system32\urlmon.dll
2015-03-13 12:01:44 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-03-13 12:01:43 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-03-13 12:01:43 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-03-13 12:01:42 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-03-13 12:01:42 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-03-13 12:01:42 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-03-13 12:01:42 ----A---- C:\windows\system32\msfeeds.dll
2015-03-13 12:01:42 ----A---- C:\windows\system32\dxtrans.dll
2015-03-13 12:01:41 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-03-13 12:01:41 ----A---- C:\windows\system32\iesetup.dll
2015-03-13 12:01:40 ----A---- C:\windows\system32\ieapfltr.dll
2015-03-13 12:01:39 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-03-13 12:01:39 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-03-13 12:01:39 ----A---- C:\windows\system32\iertutil.dll
2015-03-13 12:01:38 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-03-13 12:01:38 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-03-13 12:01:37 ----A---- C:\windows\system32\jsproxy.dll
2015-03-13 12:01:36 ----A---- C:\windows\system32\ieUnatt.exe
2015-03-13 12:01:34 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-03-13 12:01:32 ----A---- C:\windows\system32\ieui.dll
2015-03-13 12:01:32 ----A---- C:\windows\system32\dxtmsft.dll
2015-03-13 12:01:31 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-03-13 12:01:31 ----A---- C:\windows\system32\mshtmled.dll
2015-03-13 12:01:31 ----A---- C:\windows\system32\ieframe.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\wininet.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\vbscript.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\jscript9diag.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\jscript9.dll
2015-03-13 12:01:29 ----A---- C:\windows\system32\msrating.dll
2015-03-13 12:01:29 ----A---- C:\windows\system32\MshtmlDac.dll
2015-03-13 12:01:28 ----A---- C:\windows\system32\mshtml.dll
2015-03-13 12:01:08 ----A---- C:\windows\system32\WMPhoto.dll
2015-03-13 12:01:07 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2015-03-08 20:17:57 ----D---- C:\Users\Katerina Rod\AppData\Roaming\11bitstudios
2015-03-07 18:12:29 ----D---- C:\Program Files\7-Zip
2015-02-26 12:24:37 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-02-18 21:29:31 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 month======

2015-03-17 12:33:57 ----D---- C:\windows\Temp
2015-03-17 12:33:57 ----D---- C:\Program Files\trend micro
2015-03-17 12:07:22 ----AD---- C:\windows\System32
2015-03-17 12:06:54 ----D---- C:\windows\twain_32
2015-03-17 12:06:54 ----D---- C:\windows\SysWOW64
2015-03-17 12:06:53 ----D---- C:\windows\system32\DriverStore
2015-03-17 12:06:53 ----D---- C:\windows\inf
2015-03-17 12:06:40 ----HD---- C:\ProgramData
2015-03-17 12:05:11 ----D---- C:\windows\system32\LogFiles
2015-03-17 12:05:11 ----D---- C:\windows\SoftwareDistribution
2015-03-17 12:05:11 ----D---- C:\Program Files (x86)\Steam
2015-03-17 12:05:11 ----AD---- C:\Windows
2015-03-17 12:04:04 ----D---- C:\Program Files\CCleaner
2015-03-17 12:01:13 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-17 11:45:45 ----D---- C:\Users\Katerina Rod\AppData\Roaming\Skype
2015-03-17 00:25:54 ----D---- C:\windows\system32\config
2015-03-16 20:26:00 ----A---- C:\IFRToolLog.txt
2015-03-16 14:55:33 ----SHD---- C:\System Volume Information
2015-03-16 11:19:28 ----A---- C:\windows\SYSWOW64\log.txt
2015-03-16 08:40:12 ----D---- C:\windows\Tasks
2015-03-15 17:42:51 ----D---- C:\Users\Katerina Rod\AppData\Roaming\TS3Client
2015-03-15 11:57:49 ----D---- C:\windows\winsxs
2015-03-14 12:32:26 ----D---- C:\windows\debug
2015-03-14 12:06:14 ----D---- C:\Program Files\Windows Media Player
2015-03-14 12:06:13 ----D---- C:\windows\SYSWOW64\en-US
2015-03-14 12:06:13 ----D---- C:\windows\SYSWOW64\Dism
2015-03-14 12:06:13 ----D---- C:\windows\system32\en-US
2015-03-14 12:06:13 ----D---- C:\windows\system32\drivers
2015-03-14 12:06:13 ----D---- C:\windows\system32\Dism
2015-03-14 12:06:13 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-14 12:06:12 ----D---- C:\windows\system32\Boot
2015-03-14 12:06:10 ----D---- C:\Program Files\Internet Explorer
2015-03-14 12:06:08 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-14 11:53:11 ----D---- C:\windows\system32\MRT
2015-03-14 11:45:28 ----A---- C:\windows\system32\MRT.exe
2015-03-13 12:00:31 ----D---- C:\windows\system32\catroot2
2015-03-13 11:43:10 ----D---- C:\windows\Prefetch
2015-03-08 20:17:38 ----SHD---- C:\windows\Installer
2015-03-07 18:12:29 ----RD---- C:\Program Files
2015-03-07 14:52:18 ----D---- C:\Users\Katerina Rod\AppData\Roaming\.technic
2015-03-06 19:09:24 ----D---- C:\Program Files (x86)
2015-03-01 14:21:35 ----D---- C:\ProgramData\Skype
2015-03-01 14:21:32 ----RD---- C:\Program Files (x86)\Skype
2015-02-26 15:56:32 ----D---- C:\windows\rescache
2015-02-24 03:17:24 ----N---- C:\windows\system32\MpSigStub.exe
2015-02-20 20:51:00 ----D---- C:\windows\system32\Tasks
2015-02-19 21:25:42 ----D---- C:\ProgramData\Package Cache
2015-02-18 21:38:35 ----D---- C:\Users\Katerina Rod\AppData\Roaming\Adobe
2015-02-18 21:37:32 ----D---- C:\Program Files\Common Files\Adobe
2015-02-18 21:36:30 ----D---- C:\Program Files (x86)\Adobe
2015-02-18 21:21:13 ----D---- C:\ProgramData\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-12-04 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-12-04 267632]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-11-30 568600]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\DRIVERS\iusb3hcs.sys [2012-01-05 16152]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 tos_sps64;TOSHIBA tos_sps64 Service; C:\windows\system32\DRIVERS\tos_sps64.sys [2009-06-24 482384]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-12-04 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-12-04 1050432]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-12-04 436624]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2009-12-31 360712]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R1 WinFLAdrv;WinFLAdrv; C:\windows\SysWOW64\WinFLAdrv.sys [2012-10-19 34816]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-12-04 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-12-04 83280]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-12-04 116728]
R2 NEWDRIVER;NEWDRIVER; \??\C:\windows\SysWow64\WinVDEdrv6.sys [2012-10-19 197648]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 14472]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-12-04 271752]
R2 WinVDEDrv;WinVDEDrv; \??\C:\windows\SysWow64\WinVDEdrv.sys [2012-10-19 225680]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-05-10 14759136]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2012-02-01 4739304]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\iusb3hub.sys [2012-01-05 355096]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\DRIVERS\iusb3xhc.sys [2012-01-05 786200]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 PGEffect;Pangu effect driver; C:\windows\system32\DRIVERS\pgeffect.sys [2011-02-09 38096]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2011-08-17 251496]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtwlane.sys [2012-01-17 1082472]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\windows\system32\DRIVERS\tdcmdpst.sys [2009-07-31 27784]
R3 tosrfec;Bluetooth ACPI; C:\windows\system32\DRIVERS\tosrfec.sys [2010-06-19 18872]
R3 vpcbus;Virtual PC Host Bus Service; C:\windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;USB Virtualization Connector Service; C:\windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dc3d;MS Hardware Device Detection Driver (USB); C:\windows\system32\DRIVERS\dc3d.sys [2011-05-17 47616]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\windows\system32\DRIVERS\ewusbnet.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\windows\system32\DRIVERS\ewusbdev.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TDEIO;TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys []
S3 tosrfbd;Bluetooth RFBUS; C:\windows\system32\DRIVERS\tosrfbd.sys [2012-01-30 304696]
S3 Tosrfcom;Tosrfcom; C:\windows\system32\drivers\Tosrfcom.sys []
S3 Tosrfusb;Bluetooth USB Controller; C:\windows\system32\DRIVERS\tosrfusb.sys [2011-12-17 79040]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;USB Scanner Driver; C:\windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-12-04 50344]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2011-06-07 250296]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2011-06-07 47032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2011-03-01 27648]
R2 FLService;FLService; C:\windows\SysWow64\WinFLService.exe [2012-10-19 91336]
R2 GFNEXSrv;GFNEX Service; C:\Windows\System32\GFNEXSrv.exe [2010-09-10 162824]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-01-11 627936]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-01-20 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-01-20 161560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-01-21 277784]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2015-02-13 76888]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-14 3467768]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\windows\system32\TODDSrv.exe [2010-10-20 138656]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2011-11-24 294848]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-01-21 363800]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-12-04 4012248]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-11-26 138152]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2011-12-14 833976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2011-03-01 27648]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2012-05-10 276248]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EasyAntiCheat;EasyAntiCheat; C:\windows\syswow64\EasyAntiCheat.exe [2014-11-05 174112]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2011-03-01 27648]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-02-19 835776]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2011-03-01 27648]
S3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2011-04-02 198064]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2011-03-01 27648]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-07-17 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: zavirovany pocitac

#2 Příspěvek od Roli »

Zdravím, máš v PC nastaven aktuální datum a čas ?


Stáhni a ulož na plochu AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#3 Příspěvek od Rhonwyn »

# AdwCleaner v4.112 - Logfile created 17/03/2015 at 18:53:01
# Updated 09/03/2015 by Xplode
# Database : 2015-03-15.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Katerina Rod - KATERINAROD-PC
# Running from : C:\Users\Katerina Rod\Downloads\adwcleaner_4.112.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v


-\\ Google Chrome v


-\\ Chromium v


*************************

AdwCleaner[R0].txt - [55157 bytes] - [04/11/2014 21:09:10]
AdwCleaner[R1].txt - [1690 bytes] - [17/12/2014 11:37:15]
AdwCleaner[R2].txt - [1040 bytes] - [04/01/2015 12:13:58]
AdwCleaner[R3].txt - [1101 bytes] - [04/01/2015 12:19:16]
AdwCleaner[R4].txt - [1304 bytes] - [30/01/2015 16:23:25]
AdwCleaner[R5].txt - [1340 bytes] - [17/03/2015 18:50:38]
AdwCleaner[S0].txt - [53162 bytes] - [04/11/2014 21:10:31]
AdwCleaner[S1].txt - [1767 bytes] - [17/12/2014 11:39:30]
AdwCleaner[S2].txt - [1271 bytes] - [04/01/2015 12:20:34]
AdwCleaner[S3].txt - [1368 bytes] - [30/01/2015 16:38:57]
AdwCleaner[S4].txt - [1268 bytes] - [17/03/2015 18:53:01]

########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [1327 bytes] ##########

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#4 Příspěvek od Rhonwyn »

ComboFix 15-03-14.03 - Katerina Rod 17/03/2015 19:06:47.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.3986.2133 [GMT 1:00]
Running from: c:\users\Katerina Rod\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\programdata\86998342-aefb-4bdb-96ce-74be1e808b51
c:\windows\msdownld.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NEWDRIVER
-------\Service_NEWDRIVER
.
.
((((((((((((((((((((((((( Files Created from 2015-02-17 to 2015-03-17 )))))))))))))))))))))))))))))))
.
.
2015-03-17 12:01 . 2015-03-17 12:01 -------- d-----w- c:\users\Katerina Rod\Tracing
2015-03-17 11:33 . 2015-03-17 11:34 -------- d-----w- C:\rsit
2015-03-13 11:07 . 2015-02-03 03:12 617984 ----a-w- c:\windows\SysWow64\wmdrmsdk.dll
2015-03-13 11:06 . 2015-02-03 03:09 2048 ----a-w- c:\windows\SysWow64\mferror.dll
2015-03-13 11:06 . 2015-02-03 03:28 2048 ----a-w- c:\windows\system32\mferror.dll
2015-03-13 11:05 . 2015-01-31 03:48 3179520 ----a-w- c:\windows\system32\rdpcorets.dll
2015-03-13 11:05 . 2015-01-31 03:48 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2015-03-13 11:05 . 2015-01-30 23:56 243200 ----a-w- c:\windows\system32\rdpudd.dll
2015-03-13 11:03 . 2015-02-03 03:31 215552 ----a-w- c:\windows\system32\ubpm.dll
2015-03-13 11:03 . 2015-02-03 03:12 171520 ----a-w- c:\windows\SysWow64\ubpm.dll
2015-03-13 11:03 . 2015-02-13 05:22 14177280 ----a-w- c:\windows\system32\shell32.dll
2015-03-13 11:01 . 2015-02-20 02:08 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2015-03-08 19:17 . 2015-03-08 19:17 -------- d-----w- c:\users\Katerina Rod\AppData\Roaming\11bitstudios
2015-03-07 17:12 . 2015-03-07 17:12 -------- d-----w- c:\program files\7-Zip
2015-02-19 17:55 . 2015-02-19 17:55 -------- d-----w- c:\users\Katerina Rod\AppData\Local\Steam
2015-02-18 20:29 . 2015-02-18 20:34 -------- d-----w- c:\program files\Adobe
2015-02-18 20:13 . 2015-02-18 20:13 -------- d-----r- c:\users\Katerina Rod\Creative Cloud Files
2015-02-18 19:57 . 2015-02-18 19:57 -------- d-----r- c:\users\Katerina Rod\Creative Cloud Files (unknown)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-17 11:08 . 2014-11-05 20:57 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-03-14 10:45 . 2012-07-26 10:52 122905848 ----a-w- c:\windows\system32\MRT.exe
2015-02-24 02:17 . 2010-11-21 03:27 295552 ------w- c:\windows\system32\MpSigStub.exe
2015-02-13 15:33 . 2015-02-13 15:33 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2015-02-13 15:33 . 2015-02-13 15:33 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2015-02-13 15:33 . 2015-02-13 15:33 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2015-02-06 20:27 . 2012-04-24 23:44 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-02-06 20:27 . 2012-04-24 23:44 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-02-04 03:16 . 2015-02-13 17:37 609280 ----a-w- c:\windows\system32\generaltel.dll
2015-02-04 03:16 . 2015-02-13 17:37 762368 ----a-w- c:\windows\system32\invagent.dll
2015-02-04 03:16 . 2015-02-13 17:37 414720 ----a-w- c:\windows\system32\devinv.dll
2015-02-04 03:16 . 2015-02-13 17:37 894976 ----a-w- c:\windows\system32\appraiser.dll
2015-02-04 03:16 . 2015-02-13 17:37 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-02-04 03:16 . 2015-02-13 17:37 192000 ----a-w- c:\windows\system32\aepic.dll
2015-02-04 03:13 . 2015-02-13 17:37 1098752 ----a-w- c:\windows\system32\aeinv.dll
2015-01-29 09:07 . 2015-03-17 17:50 11910896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{567E77FB-A2CB-45C7-B278-B95FBDD9580C}\mpengine.dll
2015-01-27 23:36 . 2015-02-13 17:37 1239720 ----a-w- c:\windows\system32\aitstatic.exe
2015-01-09 03:14 . 2015-02-13 17:39 91136 ----a-w- c:\windows\system32\wdi.dll
2015-01-09 03:14 . 2015-02-13 17:39 29696 ----a-w- c:\windows\system32\powertracker.dll
2015-01-09 03:14 . 2015-02-13 17:39 950272 ----a-w- c:\windows\system32\perftrack.dll
2015-01-09 02:48 . 2015-02-13 17:39 76800 ----a-w- c:\windows\SysWow64\wdi.dll
2014-12-19 03:06 . 2015-01-19 13:31 210432 ----a-w- c:\windows\system32\profsvc.dll
2014-12-19 01:46 . 2015-01-19 13:31 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinFLTray"="c:\windows\SysWow64\WinFLTray.exe" [2012-10-19 321736]
"FLBackup"="c:\program files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe" [2012-10-19 275656]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-02-26 31344744]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2015-02-19 7416088]
"CCleaner"="c:\program files\CCleaner\CCleaner64.exe" [2015-02-19 7416088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-05 291608]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"USB Storage Toolbox"="c:\windows\UMStor\Res.EXE" [2005-09-14 65536]
"WireLessKeyboard"="c:\program files (x86)\Multimedia Keyboard Driver\StartAutorun.exe" [2005-11-30 94208]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2015-02-15 2694320]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-10-07 507776]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe;c:\program files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [x]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbdev.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TDEIO;TDEIO;c:\windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys;c:\windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys;c:\windows\SYSNATIVE\DRIVERS\tos_sps64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 WinFLAdrv;WinFLAdrv;SysWOW64\WinFLAdrv.sys;SysWOW64\WinFLAdrv.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 FLService;FLService;c:\windows\SysWow64\WinFLService.exe;c:\windows\SysWow64\WinFLService.exe [x]
S2 GFNEXSrv;GFNEX Service;c:\windows\System32\GFNEXSrv.exe;c:\windows\SYSNATIVE\GFNEXSrv.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
S2 WinVDEDrv;WinVDEDrv;c:\windows\SysWow64\WinVDEdrv.sys;c:\windows\SysWow64\WinVDEdrv.sys [x]
S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2015-03-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-24 20:27]
.
2015-03-03 c:\windows\Tasks\AdobeAAMUpdater-1.0-KaterinaRod-PC-Katerina Rod.job
- c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2015-02-03 09:03]
.
2015-03-17 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
2015-03-16 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2015-02-11 14:13 997536 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2015-02-11 14:13 997536 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2015-02-11 14:13 997536 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-12-04 10:34 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-01 12446824]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-11-26 710560]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-05-10 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-05-10 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-05-10 440088]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-02-03 557768]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: google.cz\www
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{D16F0E93-BF6B-49B4-B425-BACA0E2DE301}: DhcpNameServer = 192.168.0.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Toolbar-Locked - (no file)
SafeBoot-WinFLAdrv.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-10 - (no file)
Toolbar-Locked - (no file)
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
HKLM-Run-TPSCMain - c:\program files (x86)\TOSHIBA\PeakShift\TPSCMain.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
AddRemove-UnityWebPlayer - c:\users\Katerina Rod\AppData\Local\Unity\WebPlayer\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Component Based Servicing\ApplicabilityEvaluationCache\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514]
@DACL=(02 0000)
"ApplicabilityState"=dword:00000070
"CurrentState"=dword:00000070
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files (x86)\NewSoftware's\Folder Lock\FLComServ.exe
c:\program files (x86)\Multimedia Keyboard Driver\PS2USBKbdDrv.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
c:\program files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
c:\program files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
c:\users\KATERI~1\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
.
**************************************************************************
.
Completion time: 2015-03-17 19:29:44 - machine was rebooted
ComboFix-quarantined-files.txt 2015-03-17 18:29
.
Pre-Run: 92,943,847,424 bytes free
Post-Run: 92,598,935,552 bytes free
.
- - End Of File - - 8123A07D80A897E8FB8648654E1CB7B6

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: zavirovany pocitac

#5 Příspěvek od Roli »

Roli píše:Zdravím, máš v PC nastaven aktuální datum a čas ?

Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Pak dej vědět jak se PC chová.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#6 Příspěvek od Rhonwyn »

Dobry den, aktualni datum a cas tam je, combofix je odinstalovan podle navodu, jdeme na ten t-cleaner, a protoze to delam mame pres teamviewer, tak dam vedet az rekne jak se pc chova:)

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: zavirovany pocitac

#7 Příspěvek od Roli »

Rhonwyn píše:....... a protoze to delam mame pres teamviewer, tak dam vedet az rekne jak se pc chova:)
V pohodě času dost :)
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#8 Příspěvek od Rhonwyn »

Tak konecne jsme se k tomu zase dostaly, a vypada to, ze je to ok. Mozila uz funguje i ten skype. Akorat pry pocitac nesel zapnout jeden den, ale to uz je asi spis hardwarovy problem. A ze pry je porad trochu zpomaleny. Tak jestli uz mi nemuzete vic pomoct diky za pomoc, jestli jeste enco budeme delat, tak na tom jeste zapracujeme.

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#9 Příspěvek od Rhonwyn »

Jo a ted jsme si vsimla, ze v te mozile neni videt krizek, minimalizace a maximalizace ty tlacitka...:(

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: zavirovany pocitac

#10 Příspěvek od Roli »

Rhonwyn píše:Jo a ted jsme si vsimla, ze v te mozile neni videt krizek, minimalizace a maximalizace ty tlacitka...:(
To je divné, nemáš okno posunuté nebo jiné rozlišení monitoru na obou PC ?


Dej mi sem tedy ještě aktuální log z Rsit a mrknem i na ten hardware.


Stáhni HD Tune a otestuj HDD.

Benchmark - Test disku Klikni na tlačítko Start a vyčkej dokud se nezaplní celý graf. Poté se dozvíš přenosovou rychlost a přístupový čas pevného disku.

Info Přesná kapacita, souborový systém, podporované funkce, verze firmware, sériové číslo a typ zapojení disků.

Health - Kondice Seznam důležitých parametrů a jejich hodnoty. Ideální je mít všude OK.

Když je nějaká položka žlutá pravděpodobně brzy změní status na failed. Když je červená má status failed, to by znamenalo výměnu disku.

Error Scan - Hledání chyb Klikni na tlačítko Start a program prozkoumá disk zda na něm nejsou vadné bloky.

Pokud na konci testu jsou všechny zelené, je vše v pořádku. Když je byť jeden z nich červený, doporučuji zazálohovat data a počítat s výměnou disku.

Teplota Teploměr nahoře a číslo vedle něj znázorňují teplotu disku. Normální hodnota je pod 50°C. Teplota ale nesmí přesáhnout 60°C, program upozorní když dosáhne hranice 55°C.


Stáhni MEMTEST

soubor rozbal a spusť exe soubor.

Připoj flashdisk pozor vše co na něm je bude smazáno !,

v okénku Select your USB Flash Drive vyber tento disk a dej Create.

Během chvilky se Memtest nainstaluje.

Flashdisk nech v USB, restartuj PC a nabootuj z něj.

Před tím samozřemě musíš v Bios Setup do kterého se dostaneš při restartu mačkáním klávesy :

* DEL
* F2
* F1
* F10

záleží na PC, ale vždy je to na monitoru napsáno,

otevři nabídku ADVANCED BIOS FEATURES a vyhledej Boot Devices 0 až 4 nebo Boot Sequence.

Na první místo nastav Flashdisk,

na druhé pevný disk HDD, u obou položek bývá napsán i výrobce.

Stisknutím Save většinou je to F10 a potvrzením Entrem uložíš nastavení,

pak ještě stisknutím Save and Exit se dostaneš z Biosu.

Test nech projet minimálně jednou, ideálně však několikrát třeba přes noc a s každým RAM modulem zvlášť.


Pak dej vědět jak to vše dopadlo.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#11 Příspěvek od Rhonwyn »

No ta horni lista, oni ji tam vidi taky tak bez tech tlacitek,. takze to rozlisenim nebude a vim ze se to stalo uz pred par mesicama, a to jsem jim projela jen MBAM a adwcleaner a pak to zmizlo... ale je divny ze to tam maji zase kdyz jsem jim tu mozilu pred chvili nainstalovala cerstvou. Tady je log jdu na zbytek.


Logfile of random's system information tool 1.10 (written by random/random)
Run by Katerina Rod at 2015-03-22 11:45:46
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 313 GB (68%) free of 462 GB
Total RAM: 3986 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:45:52 AM, on 22/03/2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\WinFLTray.exe
C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe
C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServ.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Windows\UMStor\Res.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
C:\Users\KATERI~1\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\trend micro\Katerina Rod.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\windows\UMStor\Res.EXE
O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files (x86)\Multimedia Keyboard Driver\StartAutorun.exe PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [WinFLTray] C:\windows\SysWow64\WinFLTray.exe
O4 - HKCU\..\Run: [FLBackup] C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLService - New Softwares.net - C:\windows\SysWow64\WinFLService.exe
O23 - Service: GFNEX Service (GFNEXSrv) - Unknown owner - C:\Windows\System32\GFNEXSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10156 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
winlogon.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\GFNEXSrv.exe
C:\windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\SysWow64\WinFLService.exe
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\windows\SysWOW64\PnkBstrA.exe
C:\windows\system32\svchost.exe -k regsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\windows\system32\TODDSrv.exe
C:\windows\System32\svchost.exe -k secsvcs
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
ngservice.exe pipeserver
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\TOSHIBA\PeakShift\TPSCMain.exe"
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Windows\System32\hkcmd.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\SysWOW64\WinFLTray.exe"
"C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe"
"C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServ.exe" -Embedding
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Windows\UMStor\Res.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Katerina Rod\AppData\Local\Steam\htmlcache" -steampid 9592 -buildid 1424305157 -steamid "0" --blacklist-accelerated-compositing --process-per-tab --disable-accelerated-video-decode --enable-direct-write
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-accelerated-compositing --disable-gpu-compositing --channel="9684.0.102838736\1833626512" /prefetch:673131151
C:\windows\system32\vssvc.exe
C:\windows\System32\svchost.exe -k swprv
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\System32\alg.exe

"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=26688.2c6d5040.507233163 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 26688 "\\.\pipe\gecko-crash-server-pipe.26688" plugin
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe" --proxy-stub-channel=Flash28572.6100E7D8.16722 --host-broker-channel=Flash28572.6100E7D8.21949 --host-pid=28572 --host-npapi-version=28 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll"
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe" --channel=8148.002AF7A0.714736174 --proxy-stub-channel=Flash28572.6100E7D8.16722 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll" --host-npapi-version=28 --type=renderer
"C:\Users\KATERI~1\AppData\Local\Temp\TeamViewer\Version8\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"c:\users\kateri~1\appdata\local\temp\teamviewer\version8\TeamViewer_Desktop.exe" --IPCport 5939
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe26_ Global\UsGthrCtrlFltPipeMssGthrPipe26 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Katerina Rod\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\AdobeAAMUpdater-1.0-KaterinaRod-PC-Katerina Rod.job - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe -mode=scheduled
C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller winlogon-impersonate
C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller scheduler-impersonate
C:\windows\tasks\User_Feed_Synchronization-{D54004C2-4C96-4D9A-82EF-D02B44B640F8}.job - C:\windows\system32\msfeedssync.exe sync

=========Mozilla firefox=========

ProfilePath - C:\Users\Katerina Rod\AppData\Roaming\Mozilla\Firefox\Profiles\fe7ucfuu.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "keyword.URL" - ""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
nppluginrichmediaplayer.dll

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-04 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2011-11-03 700800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-17 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-04 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-17 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2011-11-03 534400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-02-01 12446824]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2011-11-24 1548208]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2011-12-14 712096]
"TPSCMain"=C:\Program Files\TOSHIBA\PeakShift\TPSCMain.exe [2011-12-21 740792]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2011-11-26 710560]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2011-06-28 38824]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2012-05-10 170264]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2012-05-10 398616]
"Persistence"=C:\windows\system32\igfxpers.exe [2012-05-10 440088]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-02-03 557768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WinFLTray"=C:\windows\SysWow64\WinFLTray.exe [2012-10-19 321736]
"FLBackup"=C:\Program Files (x86)\NewSoftware's\Folder Lock\FLComServCtrl.exe [2012-10-19 275656]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-02-26 31344744]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]
"CCleaner"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-01-05 291608]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2011-07-12 1298816]
"USB Storage Toolbox"=C:\windows\UMStor\Res.EXE [2005-09-14 65536]
"WireLessKeyboard"=C:\Program Files (x86)\Multimedia Keyboard Driver\StartAutorun.exe [2005-11-30 94208]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2015-02-15 2694320]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-27 5227112]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2012-05-10 436224]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2015-03-22 11:45:46 ----D---- C:\rsit
2015-03-22 11:15:36 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-20 16:53:29 ----SHD---- C:\$RECYCLE.BIN
2015-03-19 14:27:45 ----SD---- C:\ComboFix
2015-03-17 12:55:35 ----D---- C:\Config.Msi
2015-03-13 12:08:54 ----A---- C:\windows\SYSWOW64\atmfd.dll
2015-03-13 12:08:54 ----A---- C:\windows\system32\lpk.dll
2015-03-13 12:08:54 ----A---- C:\windows\system32\atmlib.dll
2015-03-13 12:08:54 ----A---- C:\windows\system32\atmfd.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\lpk.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\fontsub.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\dciman32.dll
2015-03-13 12:08:53 ----A---- C:\windows\SYSWOW64\atmlib.dll
2015-03-13 12:08:53 ----A---- C:\windows\system32\fontsub.dll
2015-03-13 12:08:53 ----A---- C:\windows\system32\dciman32.dll
2015-03-13 12:08:29 ----A---- C:\windows\SYSWOW64\mf.dll
2015-03-13 12:08:28 ----A---- C:\windows\SYSWOW64\wmp.dll
2015-03-13 12:08:28 ----A---- C:\windows\system32\ntoskrnl.exe
2015-03-13 12:08:25 ----A---- C:\windows\system32\crypt32.dll
2015-03-13 12:08:24 ----A---- C:\windows\SYSWOW64\crypt32.dll
2015-03-13 12:08:22 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-03-13 12:08:22 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-03-13 12:08:17 ----A---- C:\windows\system32\drivers\mountmgr.sys
2015-03-13 12:08:15 ----A---- C:\windows\system32\mf.dll
2015-03-13 12:08:14 ----A---- C:\windows\system32\wmp.dll
2015-03-13 12:08:10 ----A---- C:\windows\system32\drmv2clt.dll
2015-03-13 12:08:09 ----A---- C:\windows\SYSWOW64\quartz.dll
2015-03-13 12:08:09 ----A---- C:\windows\system32\quartz.dll
2015-03-13 12:08:06 ----A---- C:\windows\SYSWOW64\drmv2clt.dll
2015-03-13 12:08:06 ----A---- C:\windows\system32\winload.exe
2015-03-13 12:08:06 ----A---- C:\windows\system32\msscp.dll
2015-03-13 12:08:05 ----A---- C:\windows\SYSWOW64\qdvd.dll
2015-03-13 12:08:05 ----A---- C:\windows\system32\cryptui.dll
2015-03-13 12:08:04 ----A---- C:\windows\SYSWOW64\cryptui.dll
2015-03-13 12:08:04 ----A---- C:\windows\SYSWOW64\blackbox.dll
2015-03-13 12:08:04 ----A---- C:\windows\system32\wmdrmsdk.dll
2015-03-13 12:08:04 ----A---- C:\windows\system32\cryptnet.dll
2015-03-13 12:08:03 ----A---- C:\windows\SYSWOW64\wintrust.dll
2015-03-13 12:08:03 ----A---- C:\windows\system32\wintrust.dll
2015-03-13 12:08:03 ----A---- C:\windows\system32\pcasvc.dll
2015-03-13 12:08:03 ----A---- C:\windows\system32\audiosrv.dll
2015-03-13 12:08:02 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2015-03-13 12:08:02 ----A---- C:\windows\system32\srcore.dll
2015-03-13 12:08:02 ----A---- C:\windows\system32\blackbox.dll
2015-03-13 12:08:01 ----A---- C:\windows\system32\rstrui.exe
2015-03-13 12:07:59 ----A---- C:\windows\SYSWOW64\wmdrmsdk.dll
2015-03-13 12:07:58 ----A---- C:\windows\system32\drmmgrtn.dll
2015-03-13 12:07:54 ----A---- C:\windows\SYSWOW64\mfplat.dll
2015-03-13 12:07:54 ----A---- C:\windows\SYSWOW64\evr.dll
2015-03-13 12:07:54 ----A---- C:\windows\system32\mfplat.dll
2015-03-13 12:07:54 ----A---- C:\windows\system32\AUDIOKSE.dll
2015-03-13 12:07:53 ----A---- C:\windows\SYSWOW64\drmmgrtn.dll
2015-03-13 12:07:53 ----A---- C:\windows\system32\evr.dll
2015-03-13 12:07:52 ----A---- C:\windows\SYSWOW64\msscp.dll
2015-03-13 12:07:52 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2015-03-13 12:07:51 ----A---- C:\windows\system32\AudioSes.dll
2015-03-13 12:07:50 ----A---- C:\windows\system32\qdvd.dll
2015-03-13 12:07:48 ----A---- C:\windows\system32\audiodg.exe
2015-03-13 12:07:45 ----A---- C:\windows\system32\msnetobj.dll
2015-03-13 12:07:45 ----A---- C:\windows\system32\cryptsvc.dll
2015-03-13 12:07:42 ----A---- C:\windows\SYSWOW64\msnetobj.dll
2015-03-13 12:07:42 ----A---- C:\windows\system32\pcadm.dll
2015-03-13 12:07:42 ----A---- C:\windows\system32\AudioEng.dll
2015-03-13 12:07:40 ----A---- C:\windows\SYSWOW64\AudioEng.dll
2015-03-13 12:07:40 ----A---- C:\windows\system32\rrinstaller.exe
2015-03-13 12:07:38 ----A---- C:\windows\SYSWOW64\rrinstaller.exe
2015-03-13 12:07:37 ----A---- C:\windows\SYSWOW64\AUDIOKSE.dll
2015-03-13 12:07:37 ----A---- C:\windows\system32\smss.exe
2015-03-13 12:07:36 ----A---- C:\windows\system32\mfps.dll
2015-03-13 12:07:34 ----A---- C:\windows\SYSWOW64\mfps.dll
2015-03-13 12:07:34 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-03-13 12:07:33 ----A---- C:\windows\system32\msmmsp.dll
2015-03-13 12:07:33 ----A---- C:\windows\system32\drivers\PEAuth.sys
2015-03-13 12:07:33 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-03-13 12:07:32 ----A---- C:\windows\SYSWOW64\AudioSes.dll
2015-03-13 12:07:32 ----A---- C:\windows\system32\pcawrk.exe
2015-03-13 12:07:32 ----A---- C:\windows\system32\appidsvc.dll
2015-03-13 12:07:32 ----A---- C:\windows\system32\appidapi.dll
2015-03-13 12:07:31 ----A---- C:\windows\SYSWOW64\cryptsp.dll
2015-03-13 12:07:31 ----A---- C:\windows\system32\srclient.dll
2015-03-13 12:07:31 ----A---- C:\windows\system32\pcalua.exe
2015-03-13 12:07:31 ----A---- C:\windows\system32\mfpmp.exe
2015-03-13 12:07:31 ----A---- C:\windows\system32\cryptsp.dll
2015-03-13 12:07:30 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-03-13 12:07:30 ----A---- C:\windows\SYSWOW64\mfpmp.exe
2015-03-13 12:07:30 ----A---- C:\windows\system32\EncDump.dll
2015-03-13 12:07:30 ----A---- C:\windows\system32\csrsrv.dll
2015-03-13 12:07:29 ----A---- C:\windows\system32\setbcdlocale.dll
2015-03-13 12:07:28 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-03-13 12:07:26 ----A---- C:\windows\system32\drivers\appid.sys
2015-03-13 12:07:19 ----A---- C:\windows\system32\spwmp.dll
2015-03-13 12:07:15 ----A---- C:\windows\SYSWOW64\spwmp.dll
2015-03-13 12:07:15 ----A---- C:\windows\SYSWOW64\dxmasf.dll
2015-03-13 12:07:15 ----A---- C:\windows\system32\dxmasf.dll
2015-03-13 12:07:14 ----A---- C:\windows\system32\pcaevts.dll
2015-03-13 12:07:13 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-03-13 12:07:13 ----A---- C:\windows\system32\apisetschema.dll
2015-03-13 12:07:10 ----A---- C:\windows\SYSWOW64\wmploc.DLL
2015-03-13 12:07:10 ----A---- C:\windows\system32\wmploc.DLL
2015-03-13 12:06:52 ----A---- C:\windows\SYSWOW64\mferror.dll
2015-03-13 12:06:51 ----A---- C:\windows\system32\mferror.dll
2015-03-13 12:05:19 ----A---- C:\windows\system32\rdpudd.dll
2015-03-13 12:05:19 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2015-03-13 12:05:19 ----A---- C:\windows\system32\rdpcorets.dll
2015-03-13 12:03:12 ----A---- C:\windows\SYSWOW64\ubpm.dll
2015-03-13 12:03:12 ----A---- C:\windows\system32\ubpm.dll
2015-03-13 12:03:05 ----A---- C:\windows\system32\shell32.dll
2015-03-13 12:03:02 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-03-13 12:02:30 ----A---- C:\windows\system32\schannel.dll
2015-03-13 12:02:30 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-03-13 12:02:30 ----A---- C:\windows\system32\drivers\cng.sys
2015-03-13 12:02:28 ----A---- C:\windows\system32\lsasrv.dll
2015-03-13 12:02:27 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-03-13 12:02:27 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-03-13 12:02:26 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-03-13 12:02:25 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-03-13 12:02:25 ----A---- C:\windows\system32\wdigest.dll
2015-03-13 12:02:25 ----A---- C:\windows\system32\msv1_0.dll
2015-03-13 12:02:25 ----A---- C:\windows\system32\kerberos.dll
2015-03-13 12:02:24 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-03-13 12:02:24 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-03-13 12:02:24 ----A---- C:\windows\system32\TSpkg.dll
2015-03-13 12:02:24 ----A---- C:\windows\system32\sspicli.dll
2015-03-13 12:02:24 ----A---- C:\windows\system32\ncrypt.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-03-13 12:02:23 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-03-13 12:02:23 ----A---- C:\windows\system32\sspisrv.dll
2015-03-13 12:02:23 ----A---- C:\windows\system32\secur32.dll
2015-03-13 12:02:23 ----A---- C:\windows\system32\lsass.exe
2015-03-13 12:02:23 ----A---- C:\windows\system32\credssp.dll
2015-03-13 12:02:23 ----A---- C:\windows\system32\auditpol.exe
2015-03-13 12:02:22 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-03-13 12:02:21 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-03-13 12:02:21 ----A---- C:\windows\system32\adtschema.dll
2015-03-13 12:02:20 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-03-13 12:02:20 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-03-13 12:02:20 ----A---- C:\windows\system32\msaudite.dll
2015-03-13 12:02:19 ----A---- C:\windows\system32\msobjs.dll
2015-03-13 12:02:09 ----A---- C:\windows\SYSWOW64\msctf.dll
2015-03-13 12:02:09 ----A---- C:\windows\system32\msctf.dll
2015-03-13 12:02:08 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2015-03-13 12:02:08 ----A---- C:\windows\system32\WindowsCodecs.dll
2015-03-13 12:02:05 ----A---- C:\windows\system32\win32k.sys
2015-03-13 12:01:56 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-03-13 12:01:55 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-03-13 12:01:55 ----A---- C:\windows\system32\ieetwcollector.exe
2015-03-13 12:01:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-03-13 12:01:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-03-13 12:01:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-03-13 12:01:50 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-03-13 12:01:50 ----A---- C:\windows\system32\iernonce.dll
2015-03-13 12:01:50 ----A---- C:\windows\system32\ie4uinit.exe
2015-03-13 12:01:49 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-03-13 12:01:49 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-13 12:01:48 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-03-13 12:01:48 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-03-13 12:01:48 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-03-13 12:01:47 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-03-13 12:01:46 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-03-13 12:01:46 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-03-13 12:01:45 ----A---- C:\windows\system32\iedkcs32.dll
2015-03-13 12:01:44 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-03-13 12:01:44 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-03-13 12:01:44 ----A---- C:\windows\system32\urlmon.dll
2015-03-13 12:01:44 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-03-13 12:01:43 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-03-13 12:01:43 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-03-13 12:01:42 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-03-13 12:01:42 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-03-13 12:01:42 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-03-13 12:01:42 ----A---- C:\windows\system32\msfeeds.dll
2015-03-13 12:01:42 ----A---- C:\windows\system32\dxtrans.dll
2015-03-13 12:01:41 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-03-13 12:01:41 ----A---- C:\windows\system32\iesetup.dll
2015-03-13 12:01:40 ----A---- C:\windows\system32\ieapfltr.dll
2015-03-13 12:01:39 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-03-13 12:01:39 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-03-13 12:01:39 ----A---- C:\windows\system32\iertutil.dll
2015-03-13 12:01:38 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-03-13 12:01:38 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-03-13 12:01:37 ----A---- C:\windows\system32\jsproxy.dll
2015-03-13 12:01:36 ----A---- C:\windows\system32\ieUnatt.exe
2015-03-13 12:01:34 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-03-13 12:01:32 ----A---- C:\windows\system32\ieui.dll
2015-03-13 12:01:32 ----A---- C:\windows\system32\dxtmsft.dll
2015-03-13 12:01:31 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-03-13 12:01:31 ----A---- C:\windows\system32\mshtmled.dll
2015-03-13 12:01:31 ----A---- C:\windows\system32\ieframe.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\wininet.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\vbscript.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\jscript9diag.dll
2015-03-13 12:01:30 ----A---- C:\windows\system32\jscript9.dll
2015-03-13 12:01:29 ----A---- C:\windows\system32\msrating.dll
2015-03-13 12:01:29 ----A---- C:\windows\system32\MshtmlDac.dll
2015-03-13 12:01:28 ----A---- C:\windows\system32\mshtml.dll
2015-03-13 12:01:08 ----A---- C:\windows\system32\WMPhoto.dll
2015-03-13 12:01:07 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2015-03-08 20:17:57 ----D---- C:\Users\Katerina Rod\AppData\Roaming\11bitstudios
2015-03-07 18:12:29 ----D---- C:\Program Files\7-Zip
2015-02-26 12:24:37 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2015-03-22 11:45:49 ----D---- C:\Program Files\trend micro
2015-03-22 11:45:45 ----D---- C:\windows\Temp
2015-03-22 11:15:37 ----D---- C:\windows\Prefetch
2015-03-22 11:15:36 ----D---- C:\Program Files (x86)
2015-03-22 05:54:35 ----D---- C:\windows\inf
2015-03-21 21:23:49 ----D---- C:\Program Files (x86)\Steam
2015-03-21 21:00:01 ----D---- C:\windows\system32\LogFiles
2015-03-21 19:09:54 ----D---- C:\Users\Katerina Rod\AppData\Roaming\TS3Client
2015-03-21 18:13:29 ----A---- C:\IFRToolLog.txt
2015-03-21 17:29:00 ----D---- C:\windows\Tasks
2015-03-21 13:40:02 ----D---- C:\windows\system32\config
2015-03-21 10:36:04 ----AD---- C:\Windows
2015-03-21 10:20:48 ----AD---- C:\windows\System32
2015-03-21 10:02:04 ----D---- C:\windows\SoftwareDistribution
2015-03-21 10:01:42 ----D---- C:\Users\Katerina Rod\AppData\Roaming\Skype
2015-03-21 09:58:29 ----A---- C:\windows\SYSWOW64\log.txt
2015-03-20 17:04:36 ----SHD---- C:\System Volume Information
2015-03-17 19:29:53 ----D---- C:\windows\system32\drivers
2015-03-17 19:20:40 ----A---- C:\windows\system.ini
2015-03-17 19:20:28 ----D---- C:\windows\system32\drivers\etc
2015-03-17 19:16:04 ----D---- C:\ProgramData
2015-03-17 19:12:35 ----D---- C:\windows\SYSWOW64\drivers
2015-03-17 19:12:35 ----D---- C:\windows\SysWOW64
2015-03-17 19:12:35 ----D---- C:\windows\AppPatch
2015-03-17 19:12:33 ----D---- C:\Program Files (x86)\Common Files
2015-03-17 12:56:45 ----SHD---- C:\windows\Installer
2015-03-17 12:56:42 ----RD---- C:\Program Files (x86)\Skype
2015-03-17 12:55:35 ----D---- C:\ProgramData\Skype
2015-03-17 12:06:54 ----D---- C:\windows\twain_32
2015-03-17 12:06:53 ----D---- C:\windows\system32\DriverStore
2015-03-17 12:04:04 ----D---- C:\Program Files\CCleaner
2015-03-15 11:57:49 ----D---- C:\windows\winsxs
2015-03-14 12:32:26 ----D---- C:\windows\debug
2015-03-14 12:06:14 ----D---- C:\Program Files\Windows Media Player
2015-03-14 12:06:13 ----D---- C:\windows\SYSWOW64\en-US
2015-03-14 12:06:13 ----D---- C:\windows\SYSWOW64\Dism
2015-03-14 12:06:13 ----D---- C:\windows\system32\en-US
2015-03-14 12:06:13 ----D---- C:\windows\system32\Dism
2015-03-14 12:06:13 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-14 12:06:12 ----D---- C:\windows\system32\Boot
2015-03-14 12:06:10 ----D---- C:\Program Files\Internet Explorer
2015-03-14 12:06:08 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-14 11:53:11 ----D---- C:\windows\system32\MRT
2015-03-14 11:45:28 ----A---- C:\windows\system32\MRT.exe
2015-03-13 12:00:31 ----D---- C:\windows\system32\catroot2
2015-03-07 18:12:29 ----RD---- C:\Program Files
2015-03-07 14:52:18 ----D---- C:\Users\Katerina Rod\AppData\Roaming\.technic
2015-02-26 15:56:32 ----D---- C:\windows\rescache
2015-02-24 03:17:24 ----N---- C:\windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-12-04 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-12-04 267632]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-11-30 568600]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\DRIVERS\iusb3hcs.sys [2012-01-05 16152]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 tos_sps64;TOSHIBA tos_sps64 Service; C:\windows\system32\DRIVERS\tos_sps64.sys [2009-06-24 482384]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-12-04 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-12-04 1050432]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-12-04 436624]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2009-12-31 360712]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R1 WinFLAdrv;WinFLAdrv; C:\windows\SysWOW64\WinFLAdrv.sys [2012-10-19 34816]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-12-04 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-12-04 83280]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-12-04 116728]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 14472]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-12-04 271752]
R2 WinVDEDrv;WinVDEDrv; \??\C:\windows\SysWow64\WinVDEdrv.sys [2012-10-19 225680]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-05-10 14759136]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2012-02-01 4739304]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\iusb3hub.sys [2012-01-05 355096]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\DRIVERS\iusb3xhc.sys [2012-01-05 786200]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 PGEffect;Pangu effect driver; C:\windows\system32\DRIVERS\pgeffect.sys [2011-02-09 38096]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2011-08-17 251496]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtwlane.sys [2012-01-17 1082472]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\windows\system32\DRIVERS\tdcmdpst.sys [2009-07-31 27784]
R3 tosrfec;Bluetooth ACPI; C:\windows\system32\DRIVERS\tosrfec.sys [2010-06-19 18872]
R3 vpcbus;Virtual PC Host Bus Service; C:\windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;USB Virtualization Connector Service; C:\windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dc3d;MS Hardware Device Detection Driver (USB); C:\windows\system32\DRIVERS\dc3d.sys [2011-05-17 47616]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\windows\system32\DRIVERS\ewusbnet.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\windows\system32\DRIVERS\ewusbdev.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TDEIO;TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys []
S3 tosrfbd;Bluetooth RFBUS; C:\windows\system32\DRIVERS\tosrfbd.sys [2012-01-30 304696]
S3 Tosrfcom;Tosrfcom; C:\windows\system32\drivers\Tosrfcom.sys []
S3 Tosrfusb;Bluetooth USB Controller; C:\windows\system32\DRIVERS\tosrfusb.sys [2011-12-17 79040]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;USB Scanner Driver; C:\windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-12-04 50344]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2011-06-07 250296]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2011-06-07 47032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2011-03-01 27648]
R2 FLService;FLService; C:\windows\SysWow64\WinFLService.exe [2012-10-19 91336]
R2 GFNEXSrv;GFNEX Service; C:\Windows\System32\GFNEXSrv.exe [2010-09-10 162824]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-01-11 627936]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-01-20 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-01-20 161560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-01-21 277784]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2015-02-13 76888]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2012-12-14 3467768]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\windows\system32\TODDSrv.exe [2010-10-20 138656]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2011-11-24 294848]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-01-21 363800]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-12-04 4012248]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-11-26 138152]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2011-12-14 833976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2011-03-01 27648]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2012-05-10 276248]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EasyAntiCheat;EasyAntiCheat; C:\windows\syswow64\EasyAntiCheat.exe [2014-11-05 174112]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-21 148080]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2011-03-01 27648]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-02-19 835776]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2011-03-01 27648]
S3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2011-04-02 198064]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2011-03-01 27648]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-07-17 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#12 Příspěvek od Rhonwyn »

Tady je obrazek toho hd tune, a v tom health nebylo napsany vubec nic, proste prazdny. Ted delame ty harddiskovy sektory. A uz se tesim jak jim budu bez TV diktovat po telefonu co maji delat s tim biosem:D to bude sranda... no snad to zvladnou...:)
Přílohy
fhs.png
fhs.png (50.85 KiB) Zobrazeno 3534 x

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#13 Příspěvek od Rhonwyn »

Jak jsem cekala, do toho biosu sami rypat nechcou, takze jim to zitra zajedu udelat osobne. Muzete mi kdyztak udelat preventivku mojeho pocitace prosim? mam zalozit novy tema, at se to neplete nebo muzem pokracovat tady?

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#14 Příspěvek od Rhonwyn »

Tak naslo to jeden vadny sektor. Zbytek teda udelam zitra az notas budu mit realne v ruce. :)

Rhonwyn
Návštěvník
Návštěvník
Příspěvky: 207
Registrován: 05 črc 2012 08:33
Bydliště: Brno

Re: zavirovany pocitac

#15 Příspěvek od Rhonwyn »

Tak udelali jsme to s tou flashkou a biosem podle navodu, ale nic to neudelalo... zadny test se nespustil.

Odpovědět