Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Dlouhý start noťasu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
malina
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 15 bře 2007 22:17

Dlouhý start noťasu

#1 Příspěvek od malina »

Dobrý den, poslední dobou mi noťas nabíhá nějak dlouho a divně. Po zadání přihlašovacího hesla do W7 mám dlouhou dobu (několik desítek sekund) pouze černou obrazovku s kurzorem a jinak nic. Pak se začne objevovat pozadí a jednotlivé ikony, ale než se to uvede do provozuschopného stavu, tak je to zase všechno na dlouhý lokte. Prosím o pomoc - předem díky.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Linda at 2015-03-20 15:22:04
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 354 GB (75%) free of 473 GB
Total RAM: 3912 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:22:43, on 20.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Linda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.default-search.net?sid=498&a ... 55&src=hmp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://www.samsungsetup.com
O20 - AppInit_DLLs: , C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - Unknown owner - C:\Program Files\AVAST Software\Avast\afwServ.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8759 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 26067040
\??\C:\Windows\system32\conhost.exe "-1344534419-96641595-14479102261868583981751767973-11947291051313522171110231421
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 150b85fc-c378-4d54-aa65-c60e9c0d5003 1
\??\C:\Windows\system32\conhost.exe "-1529557964-1915865635-13603537916866468071043499019-5037067-8389564191546466268
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-867061195169288944180387391350816577728187169251794466015427993791692981929
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=gpu-process --channel="3268.0.2128426986\1367432578" --no-sandbox --lang=en-US --log-file="C:\Users\Linda\AppData\Roaming\AVAST Software\Avast\log\avastium.log" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Avastium (10.2.2214)" --proxy-auto-detect --disable-gpu --disable-software-rasterizer --no-sandbox --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.3347 --lang=en-US --log-file="C:\Users\Linda\AppData\Roaming\AVAST Software\Avast\log\avastium.log" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Avastium (10.2.2214)" --proxy-auto-detect --disable-gpu --disable-software-rasterizer --no-sandbox /prefetch:822062411
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"taskhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"

C:\Windows\system32\sppsvc.exe
"C:\Users\Linda\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\3znkgufj.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "keyword.URL" - "http://www.default-search.net/search?si ... &src=ds&p="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\3znkgufj.default\searchplugins\
default-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09 551848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-19 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09 212904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-19 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05 194504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05 194504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-10-23 7138816]
"CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2010-12-17 438784]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-12-27 12343400]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-02-14 2868496]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-11-07 442328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]
""= []
"ShowBatteryBar"=C:\Program Files\BatteryBar\ShowBatteryBar.exe [2014-09-19 89600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2015-02-24 311616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2014-11-19 1092448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-03-19 5511352]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-02-29 56088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-07 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2015-03-20 15:22:04 ----D---- C:\rsit
2015-03-20 15:22:04 ----D---- C:\Program Files\trend micro
2015-03-19 22:48:56 ----D---- C:\ProgramData\Auslogics
2015-03-19 22:48:49 ----D---- C:\Program Files (x86)\Auslogics
2015-03-19 22:20:33 ----N---- C:\bootsqm.dat
2015-03-19 21:32:12 ----D---- C:\Users\Linda\AppData\Roaming\AVG
2015-03-19 21:30:27 ----HD---- C:\ProgramData\Common Files
2015-03-19 21:30:23 ----D---- C:\ProgramData\AVG
2015-03-19 21:15:22 ----D---- C:\Windows\pss
2015-03-19 17:46:04 ----A---- C:\Windows\system32\aswBoot.exe
2015-03-19 17:45:47 ----A---- C:\Windows\avastSS.scr
2015-03-18 17:55:11 ----D---- C:\ProgramData\smdmf
2015-03-18 17:55:11 ----D---- C:\Program Files (x86)\Assets Manager
2015-03-18 17:54:09 ----D---- C:\Users\Linda\AppData\Roaming\ZIP RAR ACE Password Recovery
2015-03-13 20:48:30 ----D---- C:\Users\Linda\AppData\Roaming\Kingosoft
2015-03-13 18:41:35 ----A---- C:\Windows\system32\pwNative.exe
2015-03-13 18:41:34 ----N---- C:\Windows\system32\pwdspio.sys
2015-03-13 18:41:34 ----N---- C:\Windows\system32\pwdrvio.sys
2015-03-13 17:40:48 ----D---- C:\Program Files (x86)\MiniTool Partition Wizard Free 9.0
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 18:38:08 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 18:38:08 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 18:38:01 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 18:38:01 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 18:38:01 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 18:37:59 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 18:37:57 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 18:37:55 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 18:37:55 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 18:37:55 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 18:37:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 18:37:53 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 18:37:52 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 18:37:51 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 18:37:51 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 18:37:51 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 18:37:49 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 18:37:49 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 18:37:48 ----A---- C:\Windows\system32\evr.dll
2015-03-11 18:37:47 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 18:37:46 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 18:37:44 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 18:37:43 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 18:37:42 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 18:37:42 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 18:37:42 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 18:37:41 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 18:37:41 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 18:37:41 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 18:37:40 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 18:37:40 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 18:37:40 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 18:37:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 18:37:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 18:37:36 ----A---- C:\Windows\system32\winload.exe
2015-03-11 18:37:35 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 18:37:35 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 18:37:34 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\ci.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 18:37:33 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 18:37:33 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 18:37:33 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 18:37:32 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 18:37:32 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 18:37:31 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 18:37:31 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 18:37:31 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 18:37:31 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 18:37:30 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 18:37:30 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 18:37:30 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 18:37:29 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 18:37:28 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 18:37:27 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 18:37:27 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 18:37:27 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 18:37:26 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 18:37:26 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 18:37:26 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 18:37:25 ----A---- C:\Windows\system32\smss.exe
2015-03-11 18:37:25 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 18:37:24 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 18:37:24 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 18:37:24 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 18:37:24 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 18:37:24 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 18:37:23 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 18:37:23 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 18:37:23 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 18:37:23 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 18:37:22 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 18:37:22 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 18:37:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 18:37:21 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 18:37:20 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 18:37:20 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 18:37:20 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 18:37:17 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 18:37:14 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 18:37:14 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 18:37:09 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 18:37:09 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 18:37:01 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 18:37:01 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 18:36:53 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 18:36:52 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 18:36:52 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 18:36:19 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 18:36:19 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 18:36:16 ----A---- C:\Windows\system32\shell32.dll
2015-03-11 18:36:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 18:36:06 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 18:36:06 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 18:36:06 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 18:36:05 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 18:36:05 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 18:36:05 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 18:36:04 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 18:36:04 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 18:36:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 18:36:02 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 18:36:01 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 18:36:01 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 18:36:01 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 18:36:00 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 18:35:58 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 18:35:58 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 18:35:58 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 18:35:58 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 18:35:57 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 18:35:57 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 18:35:51 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 18:35:50 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 18:35:49 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 18:35:48 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 18:35:45 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 18:35:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 18:35:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 18:35:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 18:35:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 18:35:41 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 18:35:41 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 18:35:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 18:35:39 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 18:35:39 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 18:35:39 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 18:35:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 18:35:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 18:35:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 18:35:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 18:35:35 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 18:35:34 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 18:35:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 18:35:33 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 18:35:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 18:35:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 18:35:32 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 18:35:32 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 18:35:32 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 18:35:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 18:35:31 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 18:35:30 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 18:35:29 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 18:35:28 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 18:35:28 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 18:35:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 18:35:27 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 18:35:26 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 18:35:26 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 18:35:26 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 18:35:24 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 18:35:24 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 18:35:24 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 18:35:22 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 18:35:22 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 18:35:21 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 18:35:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 18:35:20 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 18:35:19 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 18:35:16 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-11 18:35:15 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\WinUSBCoInstaller.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\drivers\ssudmdm.sys
2015-03-09 22:21:00 ----A---- C:\Windows\system32\drivers\ssudbus.sys
2015-03-09 22:19:32 ----A---- C:\Windows\SYSWOW64\secman.dll
2015-03-09 22:19:28 ----A---- C:\Windows\SYSWOW64\Redemption.dll
2015-03-06 20:05:03 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2015-03-20 15:22:06 ----D---- C:\Windows\Temp
2015-03-20 15:22:04 ----D---- C:\Program Files
2015-03-20 15:01:07 ----D---- C:\Windows\Microsoft.NET
2015-03-20 15:01:04 ----RSD---- C:\Windows\assembly
2015-03-20 14:51:41 ----D---- C:\Windows\inf
2015-03-20 14:46:27 ----D---- C:\Windows\SoftwareDistribution
2015-03-20 14:46:14 ----D---- C:\Windows
2015-03-20 14:42:37 ----D---- C:\Windows\system32\config
2015-03-20 14:18:42 ----D---- C:\Windows\System32
2015-03-20 14:10:29 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-20 14:09:31 ----SHD---- C:\System Volume Information
2015-03-20 13:44:18 ----SHD---- C:\Windows\Installer
2015-03-20 13:43:23 ----D---- C:\Windows\SysWOW64
2015-03-20 13:42:56 ----D---- C:\Windows\Prefetch
2015-03-20 13:39:36 ----D---- C:\Program Files (x86)
2015-03-20 13:37:38 ----D---- C:\Windows\system32\Tasks
2015-03-20 12:44:40 ----D---- C:\ProgramData\Microsoft Help
2015-03-20 12:43:41 ----SD---- C:\ProgramData\Microsoft
2015-03-20 12:43:41 ----D---- C:\Program Files\Microsoft Office
2015-03-20 12:43:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-03-20 12:43:41 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-03-20 12:42:49 ----RSD---- C:\Windows\Fonts
2015-03-20 12:42:34 ----D---- C:\Windows\ShellNew
2015-03-20 12:42:32 ----D---- C:\Program Files (x86)\MSBuild
2015-03-20 12:42:24 ----D---- C:\Program Files\Common Files
2015-03-20 12:41:05 ----D---- C:\Program Files\Common Files\System
2015-03-20 12:41:04 ----A---- C:\Windows\win.ini
2015-03-20 12:23:24 ----D---- C:\Users\Linda\AppData\Roaming\PDF Architect
2015-03-20 12:21:22 ----D---- C:\Program Files (x86)\Common Files
2015-03-20 00:08:09 ----D---- C:\Windows\system32\LogFiles
2015-03-20 00:08:09 ----D---- C:\Windows\debug
2015-03-19 22:48:56 ----HD---- C:\ProgramData
2015-03-19 21:50:52 ----D---- C:\Windows\system32\sysprep
2015-03-19 21:50:51 ----D---- C:\Windows\Tasks
2015-03-19 17:52:30 ----D---- C:\Windows\system32\drivers
2015-03-16 17:59:48 ----D---- C:\Windows\rescache
2015-03-13 22:37:59 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-11 19:03:26 ----D---- C:\Windows\winsxs
2015-03-11 19:03:25 ----SHD---- C:\Boot
2015-03-11 18:59:18 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-11 18:59:18 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-11 18:59:18 ----D---- C:\Program Files\Windows Media Player
2015-03-11 18:59:18 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-11 18:59:17 ----D---- C:\Windows\system32\en-US
2015-03-11 18:59:17 ----D---- C:\Windows\system32\Dism
2015-03-11 18:59:17 ----D---- C:\Windows\system32\cs-CZ
2015-03-11 18:59:16 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-11 18:59:16 ----D---- C:\Windows\system32\Boot
2015-03-11 18:59:12 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-11 18:59:12 ----D---- C:\Program Files\Internet Explorer
2015-03-11 18:59:11 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 18:50:41 ----D---- C:\Windows\system32\MRT
2015-03-11 18:41:36 ----A---- C:\Windows\system32\MRT.exe
2015-03-11 18:34:40 ----D---- C:\Windows\system32\catroot2
2015-03-10 22:46:29 ----D---- C:\Program Files (x86)\TeamViewer
2015-03-09 22:21:43 ----D---- C:\Users\Linda\AppData\Roaming\Samsung
2015-03-09 22:21:07 ----D---- C:\Windows\system32\DriverStore
2015-03-09 22:21:00 ----D---- C:\Program Files (x86)\Samsung
2015-03-09 22:20:22 ----D---- C:\ProgramData\Samsung
2015-03-09 22:19:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-03-09 17:12:33 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2015-03-09 17:11:54 ----D---- C:\Program Files\Java
2015-03-06 21:14:48 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-06 20:20:02 ----D---- C:\Program Files\CCleaner
2015-02-24 03:17:24 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-03-19 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-03-19 268640]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2012-02-01 568600]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2015-02-05 31376]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2013-09-30 19152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-03-19 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-03-19 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-03-19 441728]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-03-19 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-03-19 88408]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-03-19 136752]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2011-03-14 11576]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-01-10 2801664]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service; C:\Windows\system32\DRIVERS\b57xdbd.sys [2011-11-04 68648]
R3 b57xdmp;Broadcom xD Picture vstorp client drv; C:\Windows\system32\DRIVERS\b57xdmp.sys [2011-11-04 19496]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2013-10-23 22592]
R3 bScsiMSa;bScsiMSa; C:\Windows\system32\DRIVERS\bScsiMSa.sys [2011-09-02 51752]
R3 bScsiSDa;bScsiSDa; C:\Windows\system32\DRIVERS\bScsiSDa.sys [2012-05-03 81928]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-03 4730344]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2012-01-19 435240]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-03-20 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 63704]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 SmbDrv;SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver.sys [2012-02-14 22800]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2012-02-14 412944]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys []
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2014-07-16 44640]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
S3 BcmVWL;Broadcom Virtual Wireless; C:\Windows\system32\DRIVERS\bcmvwl64.sys [2013-10-23 21568]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-10-13 110336]
S3 MWAC;MWAC; \??\C:\Windows\system32\drivers\ []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2013-09-30 12504]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RT-USB;Ross-Tech USB driver; C:\Windows\system32\drivers\RT-USB64.SYS [2010-06-16 70984]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-10-13 206080]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-03-19 343336]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-02-05 935056]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE [2013-10-23 48128]
S2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-13 268464]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-02-23 1436424]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-06 148080]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-22 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23 116648]
S4 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-23 194032]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 743688]
S4 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Dlouhý start noťasu

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

malina
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 15 bře 2007 22:17

Re: Dlouhý start noťasu

#3 Příspěvek od malina »

Po cleaningu se noťas restartoval a pak po startu W7 vyběhl log (viz. níže). Snad to tak mělo být.

# AdwCleaner v4.112 - Logfile created 20/03/2015 at 18:22:13
# Updated 09/03/2015 by Xplode
# Database : 2015-03-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Linda - LINDA-PC
# Running from : C:\Users\Linda\Desktop\adwcleaner_4.112.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\smdmf
Folder Deleted : C:\ProgramData\Systweak
Folder Deleted : C:\Program Files (x86)\Assets Manager
Folder Deleted : C:\Users\Linda\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Linda\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Linda\AppData\Roaming\dll-files.com
Folder Deleted : C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\3znkgufj.default\searchplugins\default-search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml
File Deleted : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\3znkgufj.default\user.js

***** [ Scheduled tasks ] *****

Task Deleted : ASP
Task Deleted : RDReminder

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\iomphmdalfmaifjccmagmllnicjoghhk
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F3374A4D-303A-439F-B4D4-584B60DFF31D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\VIS
Key Deleted : HKCU\Software\dll-files.com
Key Deleted : HKLM\SOFTWARE\SmdmF
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\dll-files.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\B696D3C37BD0D6C33A65D38BEC459181
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\B696D3C37BD0D6C33A65D38BEC459181
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B696D3C37BD0D6C33A65D38BEC459181

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17689

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v36.0.1 (x86 cs)

[3znkgufj.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "default-search.net");
[3znkgufj.default\prefs.js] - Line Deleted : user_pref("browser.search.order.1", "default-search.net");
[3znkgufj.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "default-search.net");
[3znkgufj.default\prefs.js] - Line Deleted : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=498&a ... &src=ds&p=");

-\\ Google Chrome v41.0.2272.89

[C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovigo.com/Results.aspx?gd=&ctid=C ... rms}&SSPV=
[C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovigo.com/Results.aspx?gd=&ctid=C ... rms}&SSPV=

-\\ Opera v0.0.0.0

[C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovigo.com/Results.aspx?gd=&ctid=C ... rms}&SSPV=
[C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovigo.com/Results.aspx?gd=&ctid=C ... rms}&SSPV=

*************************

AdwCleaner[R0].txt - [5892 bytes] - [20/03/2015 18:20:16]
AdwCleaner[S0].txt - [5960 bytes] - [20/03/2015 18:22:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6019 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Dlouhý start noťasu

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

malina
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 15 bře 2007 22:17

Re: Dlouhý start noťasu

#5 Příspěvek od malina »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Linda at 2015-03-20 19:16:03
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 353 GB (75%) free of 473 GB
Total RAM: 3912 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:16:05, on 20.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Samsung\Easy Printer Manager\SpoolerComp.exe
C:\Program Files\trend micro\Linda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://www.samsungsetup.com
O20 - AppInit_DLLs: , C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - Unknown owner - C:\Program Files\AVAST Software\Avast\afwServ.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8631 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 35660288
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
\??\C:\Windows\system32\conhost.exe "-13816136301645767405-475199723538975519-1671196919-2083967753-733190977878785420
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 150b85fc-c378-4d54-aa65-c60e9c0d5003 1
\??\C:\Windows\system32\conhost.exe "-1088971916132272904-13168601311280720334947637162-1958486372-1762835101283086473
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-1176877658-660815530-51919381220602215281487660085-1757152080-628843686-1456878490
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=gpu-process --channel="4536.0.1298659726\1880912428" --no-sandbox --lang=en-US --log-file="C:\Users\Linda\AppData\Roaming\AVAST Software\Avast\log\avastium.log" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Avastium (10.2.2214)" --proxy-auto-detect --disable-gpu --disable-software-rasterizer --no-sandbox --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.3347 --lang=en-US --log-file="C:\Users\Linda\AppData\Roaming\AVAST Software\Avast\log\avastium.log" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Avastium (10.2.2214)" --proxy-auto-detect --disable-gpu --disable-software-rasterizer --no-sandbox /prefetch:822062411
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\System32\svchost.exe -k secsvcs

taskhost.exe $(Arg0)
"C:\Program Files (x86)\Samsung\Easy Printer Manager\SpoolerComp.exe" -Embedding
taskeng.exe {534CF5C0-9A59-482A-8051-502764E7F007}
"C:\Users\Linda\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\3znkgufj.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09 551848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-19 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09 212904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-19 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05 194504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05 194504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-10-23 7138816]
"CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2010-12-17 438784]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-12-27 12343400]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-02-14 2868496]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-11-07 442328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]
""= []
"ShowBatteryBar"=C:\Program Files\BatteryBar\ShowBatteryBar.exe [2014-09-19 89600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2015-02-24 311616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2014-11-19 1092448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-03-19 5511352]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-02-29 56088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-07 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2015-03-20 18:20:13 ----D---- C:\AdwCleaner
2015-03-20 15:22:04 ----D---- C:\rsit
2015-03-20 15:22:04 ----D---- C:\Program Files\trend micro
2015-03-19 22:48:56 ----D---- C:\ProgramData\Auslogics
2015-03-19 22:48:49 ----D---- C:\Program Files (x86)\Auslogics
2015-03-19 22:20:33 ----N---- C:\bootsqm.dat
2015-03-19 21:32:12 ----D---- C:\Users\Linda\AppData\Roaming\AVG
2015-03-19 21:30:27 ----HD---- C:\ProgramData\Common Files
2015-03-19 21:30:23 ----D---- C:\ProgramData\AVG
2015-03-19 21:15:22 ----D---- C:\Windows\pss
2015-03-19 17:46:04 ----A---- C:\Windows\system32\aswBoot.exe
2015-03-19 17:45:47 ----A---- C:\Windows\avastSS.scr
2015-03-18 17:54:09 ----D---- C:\Users\Linda\AppData\Roaming\ZIP RAR ACE Password Recovery
2015-03-13 20:48:30 ----D---- C:\Users\Linda\AppData\Roaming\Kingosoft
2015-03-13 18:41:35 ----A---- C:\Windows\system32\pwNative.exe
2015-03-13 18:41:34 ----N---- C:\Windows\system32\pwdspio.sys
2015-03-13 18:41:34 ----N---- C:\Windows\system32\pwdrvio.sys
2015-03-13 17:40:48 ----D---- C:\Program Files (x86)\MiniTool Partition Wizard Free 9.0
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 18:38:08 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 18:38:08 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 18:38:01 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 18:38:01 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 18:38:01 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 18:37:59 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 18:37:57 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 18:37:55 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 18:37:55 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 18:37:55 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 18:37:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 18:37:53 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 18:37:52 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 18:37:51 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 18:37:51 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 18:37:51 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 18:37:49 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 18:37:49 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 18:37:48 ----A---- C:\Windows\system32\evr.dll
2015-03-11 18:37:47 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 18:37:46 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 18:37:44 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 18:37:43 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 18:37:42 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 18:37:42 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 18:37:42 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 18:37:41 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 18:37:41 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 18:37:41 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 18:37:40 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 18:37:40 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 18:37:40 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 18:37:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 18:37:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 18:37:36 ----A---- C:\Windows\system32\winload.exe
2015-03-11 18:37:35 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 18:37:35 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 18:37:34 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\ci.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 18:37:33 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 18:37:33 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 18:37:33 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 18:37:32 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 18:37:32 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 18:37:31 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 18:37:31 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 18:37:31 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 18:37:31 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 18:37:30 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 18:37:30 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 18:37:30 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 18:37:29 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 18:37:28 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 18:37:27 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 18:37:27 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 18:37:27 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 18:37:26 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 18:37:26 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 18:37:26 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 18:37:25 ----A---- C:\Windows\system32\smss.exe
2015-03-11 18:37:25 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 18:37:24 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 18:37:24 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 18:37:24 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 18:37:24 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 18:37:24 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 18:37:23 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 18:37:23 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 18:37:23 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 18:37:23 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 18:37:22 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 18:37:22 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 18:37:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 18:37:21 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 18:37:20 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 18:37:20 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 18:37:20 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 18:37:17 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 18:37:14 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 18:37:14 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 18:37:09 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 18:37:09 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 18:37:01 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 18:37:01 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 18:36:53 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 18:36:52 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 18:36:52 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 18:36:19 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 18:36:19 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 18:36:16 ----A---- C:\Windows\system32\shell32.dll
2015-03-11 18:36:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 18:36:06 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 18:36:06 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 18:36:06 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 18:36:05 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 18:36:05 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 18:36:05 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 18:36:04 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 18:36:04 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 18:36:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 18:36:02 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 18:36:01 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 18:36:01 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 18:36:01 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 18:36:00 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 18:35:58 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 18:35:58 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 18:35:58 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 18:35:58 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 18:35:57 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 18:35:57 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 18:35:51 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 18:35:50 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 18:35:49 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 18:35:48 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 18:35:45 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 18:35:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 18:35:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 18:35:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 18:35:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 18:35:41 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 18:35:41 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 18:35:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 18:35:39 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 18:35:39 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 18:35:39 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 18:35:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 18:35:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 18:35:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 18:35:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 18:35:35 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 18:35:34 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 18:35:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 18:35:33 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 18:35:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 18:35:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 18:35:32 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 18:35:32 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 18:35:32 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 18:35:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 18:35:31 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 18:35:30 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 18:35:29 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 18:35:28 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 18:35:28 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 18:35:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 18:35:27 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 18:35:26 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 18:35:26 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 18:35:26 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 18:35:24 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 18:35:24 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 18:35:24 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 18:35:22 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 18:35:22 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 18:35:21 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 18:35:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 18:35:20 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 18:35:19 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 18:35:16 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-11 18:35:15 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\WinUSBCoInstaller.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\drivers\ssudmdm.sys
2015-03-09 22:21:00 ----A---- C:\Windows\system32\drivers\ssudbus.sys
2015-03-09 22:19:32 ----A---- C:\Windows\SYSWOW64\secman.dll
2015-03-09 22:19:28 ----A---- C:\Windows\SYSWOW64\Redemption.dll
2015-03-06 20:05:03 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2015-03-20 19:16:04 ----D---- C:\Windows\Temp
2015-03-20 19:14:43 ----D---- C:\Windows\Prefetch
2015-03-20 18:22:31 ----D---- C:\Windows\system32\config
2015-03-20 18:22:14 ----D---- C:\Windows\System32
2015-03-20 18:22:13 ----HD---- C:\ProgramData
2015-03-20 18:22:13 ----D---- C:\Program Files (x86)
2015-03-20 18:01:27 ----D---- C:\Windows
2015-03-20 15:22:04 ----D---- C:\Program Files
2015-03-20 15:01:07 ----D---- C:\Windows\Microsoft.NET
2015-03-20 15:01:04 ----RSD---- C:\Windows\assembly
2015-03-20 14:51:41 ----D---- C:\Windows\inf
2015-03-20 14:46:27 ----D---- C:\Windows\SoftwareDistribution
2015-03-20 14:10:29 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-20 14:09:31 ----SHD---- C:\System Volume Information
2015-03-20 13:44:18 ----SHD---- C:\Windows\Installer
2015-03-20 13:43:23 ----D---- C:\Windows\SysWOW64
2015-03-20 13:37:38 ----D---- C:\Windows\system32\Tasks
2015-03-20 12:44:40 ----D---- C:\ProgramData\Microsoft Help
2015-03-20 12:43:41 ----SD---- C:\ProgramData\Microsoft
2015-03-20 12:43:41 ----D---- C:\Program Files\Microsoft Office
2015-03-20 12:43:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-03-20 12:43:41 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-03-20 12:42:49 ----RSD---- C:\Windows\Fonts
2015-03-20 12:42:34 ----D---- C:\Windows\ShellNew
2015-03-20 12:42:32 ----D---- C:\Program Files (x86)\MSBuild
2015-03-20 12:42:24 ----D---- C:\Program Files\Common Files
2015-03-20 12:41:05 ----D---- C:\Program Files\Common Files\System
2015-03-20 12:41:04 ----A---- C:\Windows\win.ini
2015-03-20 12:23:24 ----D---- C:\Users\Linda\AppData\Roaming\PDF Architect
2015-03-20 12:21:22 ----D---- C:\Program Files (x86)\Common Files
2015-03-20 00:08:09 ----D---- C:\Windows\system32\LogFiles
2015-03-20 00:08:09 ----D---- C:\Windows\debug
2015-03-19 21:50:52 ----D---- C:\Windows\system32\sysprep
2015-03-19 21:50:51 ----D---- C:\Windows\Tasks
2015-03-19 17:52:30 ----D---- C:\Windows\system32\drivers
2015-03-16 17:59:48 ----D---- C:\Windows\rescache
2015-03-13 22:37:59 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-11 19:03:26 ----D---- C:\Windows\winsxs
2015-03-11 19:03:25 ----SHD---- C:\Boot
2015-03-11 18:59:18 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-11 18:59:18 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-11 18:59:18 ----D---- C:\Program Files\Windows Media Player
2015-03-11 18:59:18 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-11 18:59:17 ----D---- C:\Windows\system32\en-US
2015-03-11 18:59:17 ----D---- C:\Windows\system32\Dism
2015-03-11 18:59:17 ----D---- C:\Windows\system32\cs-CZ
2015-03-11 18:59:16 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-11 18:59:16 ----D---- C:\Windows\system32\Boot
2015-03-11 18:59:12 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-11 18:59:12 ----D---- C:\Program Files\Internet Explorer
2015-03-11 18:59:11 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 18:50:41 ----D---- C:\Windows\system32\MRT
2015-03-11 18:41:36 ----A---- C:\Windows\system32\MRT.exe
2015-03-11 18:34:40 ----D---- C:\Windows\system32\catroot2
2015-03-10 22:46:29 ----D---- C:\Program Files (x86)\TeamViewer
2015-03-09 22:21:43 ----D---- C:\Users\Linda\AppData\Roaming\Samsung
2015-03-09 22:21:07 ----D---- C:\Windows\system32\DriverStore
2015-03-09 22:21:00 ----D---- C:\Program Files (x86)\Samsung
2015-03-09 22:20:22 ----D---- C:\ProgramData\Samsung
2015-03-09 22:19:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-03-09 17:12:33 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2015-03-09 17:11:54 ----D---- C:\Program Files\Java
2015-03-06 21:14:48 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-06 20:20:02 ----D---- C:\Program Files\CCleaner
2015-02-24 03:17:24 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-03-19 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-03-19 268640]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2012-02-01 568600]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2015-02-05 31376]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2013-09-30 19152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-03-19 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-03-19 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-03-19 441728]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-03-19 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-03-19 88408]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-03-19 136752]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2011-03-14 11576]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-01-10 2801664]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service; C:\Windows\system32\DRIVERS\b57xdbd.sys [2011-11-04 68648]
R3 b57xdmp;Broadcom xD Picture vstorp client drv; C:\Windows\system32\DRIVERS\b57xdmp.sys [2011-11-04 19496]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2013-10-23 22592]
R3 bScsiMSa;bScsiMSa; C:\Windows\system32\DRIVERS\bScsiMSa.sys [2011-09-02 51752]
R3 bScsiSDa;bScsiSDa; C:\Windows\system32\DRIVERS\bScsiSDa.sys [2012-05-03 81928]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-03 4730344]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2012-01-19 435240]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-03-20 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 63704]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 SmbDrv;SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver.sys [2012-02-14 22800]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2012-02-14 412944]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys []
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2014-07-16 44640]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
S3 BcmVWL;Broadcom Virtual Wireless; C:\Windows\system32\DRIVERS\bcmvwl64.sys [2013-10-23 21568]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-10-13 110336]
S3 MWAC;MWAC; \??\C:\Windows\system32\drivers\ []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2013-09-30 12504]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RT-USB;Ross-Tech USB driver; C:\Windows\system32\drivers\RT-USB64.SYS [2010-06-16 70984]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-10-13 206080]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-03-19 343336]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-02-05 935056]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE [2013-10-23 48128]
S2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-13 268464]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-02-23 1436424]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-06 148080]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-22 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23 116648]
S4 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-23 194032]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 743688]
S4 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Dlouhý start noťasu

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\Google\Google Toolbar
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]/64

:services
MWAC

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

malina
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 15 bře 2007 22:17

Re: Dlouhý start noťasu

#7 Příspěvek od malina »

Díky moc za pomoc. Při startu pozoruji zlepšení. Černá obrazovka sice naskočí, ale na výrazně kratší dobu.
Ať žije Plzeň - bydlím na Slovanech

Logfile of random's system information tool 1.10 (written by random/random)
Run by Linda at 2015-03-20 20:37:10
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 353 GB (75%) free of 473 GB
Total RAM: 3912 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:37:15, on 20.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Samsung\Easy Printer Manager\SpoolerComp.exe
C:\Users\Linda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\Linda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://www.samsungsetup.com
O20 - AppInit_DLLs: , C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - Unknown owner - C:\Program Files\AVAST Software\Avast\afwServ.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8438 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 34849584
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
\??\C:\Windows\system32\conhost.exe "-177160201617498127347760136567139567252018796130-1902553891-867723136-1223334423
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 150b85fc-c378-4d54-aa65-c60e9c0d5003 1
\??\C:\Windows\system32\conhost.exe "1953037689-19371029531742447576-16691210471899200291762057583-1447827884-1472445440
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-417344833213542360-2140886157-7353154412346935321292915300-2069843941598810370
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
taskeng.exe {66A8F17C-ED34-4FC1-A488-EFE73D714FB8}
taskeng.exe {1C41A859-D86E-411A-8DBA-C2F8F0453CF6}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Samsung\Easy Printer Manager\SpoolerComp.exe" -Embedding
C:\Users\Linda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=gpu-process --channel="1984.0.1020612046\498858242" --no-sandbox --lang=en-US --log-file="C:\Users\Linda\AppData\Roaming\AVAST Software\Avast\log\avastium.log" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Avastium (10.2.2214)" --proxy-auto-detect --disable-gpu --disable-software-rasterizer --no-sandbox --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.3347 --lang=en-US --log-file="C:\Users\Linda\AppData\Roaming\AVAST Software\Avast\log\avastium.log" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Avastium (10.2.2214)" --proxy-auto-detect --disable-gpu --disable-software-rasterizer --no-sandbox /prefetch:822062411
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Users\Linda\Desktop\RSITx64.exe"
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\igfxsrvc.exe" -Embedding
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\3znkgufj.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-09 551848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-19 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-09 212904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-19 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-10-23 7138816]
"CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2010-12-17 438784]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-12-27 12343400]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-02-14 2868496]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-11-07 442328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-02-19 7416088]
""= []
"ShowBatteryBar"=C:\Program Files\BatteryBar\ShowBatteryBar.exe [2014-09-19 89600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2015-02-24 311616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2014-11-19 1092448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-03-19 5511352]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-02-29 56088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-07 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2015-03-20 20:27:42 ----D---- C:\_OTM
2015-03-20 18:20:13 ----D---- C:\AdwCleaner
2015-03-20 15:22:04 ----D---- C:\rsit
2015-03-20 15:22:04 ----D---- C:\Program Files\trend micro
2015-03-19 22:48:56 ----D---- C:\ProgramData\Auslogics
2015-03-19 22:48:49 ----D---- C:\Program Files (x86)\Auslogics
2015-03-19 22:20:33 ----N---- C:\bootsqm.dat
2015-03-19 21:32:12 ----D---- C:\Users\Linda\AppData\Roaming\AVG
2015-03-19 21:30:27 ----HD---- C:\ProgramData\Common Files
2015-03-19 21:30:23 ----D---- C:\ProgramData\AVG
2015-03-19 21:15:22 ----D---- C:\Windows\pss
2015-03-19 17:46:04 ----A---- C:\Windows\system32\aswBoot.exe
2015-03-19 17:45:47 ----A---- C:\Windows\avastSS.scr
2015-03-18 17:54:09 ----D---- C:\Users\Linda\AppData\Roaming\ZIP RAR ACE Password Recovery
2015-03-13 20:48:30 ----D---- C:\Users\Linda\AppData\Roaming\Kingosoft
2015-03-13 18:41:35 ----A---- C:\Windows\system32\pwNative.exe
2015-03-13 18:41:34 ----N---- C:\Windows\system32\pwdspio.sys
2015-03-13 18:41:34 ----N---- C:\Windows\system32\pwdrvio.sys
2015-03-13 17:40:48 ----D---- C:\Program Files (x86)\MiniTool Partition Wizard Free 9.0
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 18:38:09 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 18:38:09 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 18:38:08 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 18:38:08 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 18:38:01 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 18:38:01 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 18:38:01 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 18:37:59 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 18:37:57 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 18:37:55 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 18:37:55 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 18:37:55 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 18:37:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 18:37:53 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 18:37:52 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 18:37:51 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 18:37:51 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 18:37:51 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 18:37:49 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 18:37:49 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 18:37:48 ----A---- C:\Windows\system32\evr.dll
2015-03-11 18:37:47 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 18:37:46 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 18:37:44 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 18:37:43 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 18:37:42 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 18:37:42 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 18:37:42 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 18:37:41 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 18:37:41 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 18:37:41 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 18:37:40 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 18:37:40 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 18:37:40 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 18:37:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 18:37:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 18:37:36 ----A---- C:\Windows\system32\winload.exe
2015-03-11 18:37:35 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 18:37:35 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 18:37:34 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\ci.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 18:37:34 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 18:37:33 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 18:37:33 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 18:37:33 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 18:37:32 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 18:37:32 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 18:37:31 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 18:37:31 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 18:37:31 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 18:37:31 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 18:37:30 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 18:37:30 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 18:37:30 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 18:37:29 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 18:37:28 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 18:37:27 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 18:37:27 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 18:37:27 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 18:37:26 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 18:37:26 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 18:37:26 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 18:37:25 ----A---- C:\Windows\system32\smss.exe
2015-03-11 18:37:25 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 18:37:24 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 18:37:24 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 18:37:24 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 18:37:24 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 18:37:24 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 18:37:23 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 18:37:23 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 18:37:23 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 18:37:23 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 18:37:23 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 18:37:22 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 18:37:22 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 18:37:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 18:37:21 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 18:37:20 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 18:37:20 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 18:37:20 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 18:37:17 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 18:37:14 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 18:37:14 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 18:37:09 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 18:37:09 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 18:37:01 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 18:37:01 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 18:36:53 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 18:36:52 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 18:36:52 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 18:36:19 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 18:36:19 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 18:36:16 ----A---- C:\Windows\system32\shell32.dll
2015-03-11 18:36:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 18:36:06 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 18:36:06 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 18:36:06 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 18:36:05 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 18:36:05 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 18:36:05 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 18:36:04 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 18:36:04 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 18:36:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 18:36:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 18:36:02 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 18:36:02 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 18:36:02 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 18:36:01 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 18:36:01 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 18:36:01 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 18:36:00 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 18:36:00 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 18:35:58 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 18:35:58 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 18:35:58 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 18:35:58 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 18:35:57 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 18:35:57 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 18:35:51 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 18:35:50 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 18:35:49 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 18:35:48 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 18:35:45 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 18:35:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 18:35:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 18:35:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 18:35:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 18:35:41 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 18:35:41 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 18:35:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 18:35:39 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 18:35:39 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 18:35:39 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 18:35:38 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 18:35:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 18:35:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 18:35:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 18:35:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 18:35:35 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 18:35:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 18:35:34 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 18:35:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 18:35:33 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 18:35:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 18:35:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 18:35:32 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 18:35:32 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 18:35:32 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 18:35:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 18:35:31 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 18:35:30 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 18:35:29 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 18:35:28 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 18:35:28 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 18:35:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 18:35:27 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 18:35:26 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 18:35:26 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 18:35:26 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 18:35:24 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 18:35:24 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 18:35:24 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 18:35:23 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 18:35:22 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 18:35:22 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 18:35:21 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 18:35:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 18:35:20 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 18:35:19 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 18:35:16 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-11 18:35:15 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\WinUSBCoInstaller.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2015-03-09 22:21:00 ----A---- C:\Windows\system32\drivers\ssudmdm.sys
2015-03-09 22:21:00 ----A---- C:\Windows\system32\drivers\ssudbus.sys
2015-03-09 22:19:32 ----A---- C:\Windows\SYSWOW64\secman.dll
2015-03-09 22:19:28 ----A---- C:\Windows\SYSWOW64\Redemption.dll
2015-03-06 20:05:03 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2015-03-20 20:37:07 ----D---- C:\Windows\Temp
2015-03-20 20:34:10 ----D---- C:\Windows\system32\config
2015-03-20 20:27:42 ----D---- C:\Windows\Tasks
2015-03-20 20:27:42 ----D---- C:\Program Files (x86)\Google
2015-03-20 19:14:43 ----D---- C:\Windows\Prefetch
2015-03-20 18:22:14 ----D---- C:\Windows\System32
2015-03-20 18:22:13 ----HD---- C:\ProgramData
2015-03-20 18:22:13 ----D---- C:\Program Files (x86)
2015-03-20 18:01:27 ----D---- C:\Windows
2015-03-20 15:22:04 ----D---- C:\Program Files
2015-03-20 15:01:07 ----D---- C:\Windows\Microsoft.NET
2015-03-20 15:01:04 ----RSD---- C:\Windows\assembly
2015-03-20 14:51:41 ----D---- C:\Windows\inf
2015-03-20 14:46:27 ----D---- C:\Windows\SoftwareDistribution
2015-03-20 14:10:29 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-20 14:09:31 ----SHD---- C:\System Volume Information
2015-03-20 13:44:18 ----SHD---- C:\Windows\Installer
2015-03-20 13:43:23 ----D---- C:\Windows\SysWOW64
2015-03-20 13:37:38 ----D---- C:\Windows\system32\Tasks
2015-03-20 12:44:40 ----D---- C:\ProgramData\Microsoft Help
2015-03-20 12:43:41 ----SD---- C:\ProgramData\Microsoft
2015-03-20 12:43:41 ----D---- C:\Program Files\Microsoft Office
2015-03-20 12:43:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-03-20 12:43:41 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-03-20 12:42:49 ----RSD---- C:\Windows\Fonts
2015-03-20 12:42:34 ----D---- C:\Windows\ShellNew
2015-03-20 12:42:32 ----D---- C:\Program Files (x86)\MSBuild
2015-03-20 12:42:24 ----D---- C:\Program Files\Common Files
2015-03-20 12:41:05 ----D---- C:\Program Files\Common Files\System
2015-03-20 12:41:04 ----A---- C:\Windows\win.ini
2015-03-20 12:23:24 ----D---- C:\Users\Linda\AppData\Roaming\PDF Architect
2015-03-20 12:21:22 ----D---- C:\Program Files (x86)\Common Files
2015-03-20 00:08:09 ----D---- C:\Windows\system32\LogFiles
2015-03-20 00:08:09 ----D---- C:\Windows\debug
2015-03-19 21:50:52 ----D---- C:\Windows\system32\sysprep
2015-03-19 17:52:30 ----D---- C:\Windows\system32\drivers
2015-03-16 17:59:48 ----D---- C:\Windows\rescache
2015-03-13 22:37:59 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-11 19:03:26 ----D---- C:\Windows\winsxs
2015-03-11 19:03:25 ----SHD---- C:\Boot
2015-03-11 18:59:18 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-11 18:59:18 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-11 18:59:18 ----D---- C:\Program Files\Windows Media Player
2015-03-11 18:59:18 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-11 18:59:17 ----D---- C:\Windows\system32\en-US
2015-03-11 18:59:17 ----D---- C:\Windows\system32\Dism
2015-03-11 18:59:17 ----D---- C:\Windows\system32\cs-CZ
2015-03-11 18:59:16 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-11 18:59:16 ----D---- C:\Windows\system32\Boot
2015-03-11 18:59:12 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-11 18:59:12 ----D---- C:\Program Files\Internet Explorer
2015-03-11 18:59:11 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 18:50:41 ----D---- C:\Windows\system32\MRT
2015-03-11 18:41:36 ----A---- C:\Windows\system32\MRT.exe
2015-03-11 18:34:40 ----D---- C:\Windows\system32\catroot2
2015-03-10 22:46:29 ----D---- C:\Program Files (x86)\TeamViewer
2015-03-09 22:21:43 ----D---- C:\Users\Linda\AppData\Roaming\Samsung
2015-03-09 22:21:07 ----D---- C:\Windows\system32\DriverStore
2015-03-09 22:21:00 ----D---- C:\Program Files (x86)\Samsung
2015-03-09 22:20:22 ----D---- C:\ProgramData\Samsung
2015-03-09 22:19:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-03-09 17:12:33 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2015-03-09 17:11:54 ----D---- C:\Program Files\Java
2015-03-06 21:14:48 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-06 20:20:02 ----D---- C:\Program Files\CCleaner
2015-02-24 03:17:24 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-03-19 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-03-19 268640]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2012-02-01 568600]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2015-02-05 31376]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2013-09-30 19152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-03-19 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-03-19 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-03-19 441728]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-03-19 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-03-19 88408]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-03-19 136752]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2011-03-14 11576]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-01-10 2801664]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service; C:\Windows\system32\DRIVERS\b57xdbd.sys [2011-11-04 68648]
R3 b57xdmp;Broadcom xD Picture vstorp client drv; C:\Windows\system32\DRIVERS\b57xdmp.sys [2011-11-04 19496]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2013-10-23 22592]
R3 bScsiMSa;bScsiMSa; C:\Windows\system32\DRIVERS\bScsiMSa.sys [2011-09-02 51752]
R3 bScsiSDa;bScsiSDa; C:\Windows\system32\DRIVERS\bScsiSDa.sys [2012-05-03 81928]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-03 4730344]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2012-01-19 435240]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-03-20 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 63704]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 SmbDrv;SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver.sys [2012-02-14 22800]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2012-02-14 412944]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys []
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2014-07-16 44640]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
S3 BcmVWL;Broadcom Virtual Wireless; C:\Windows\system32\DRIVERS\bcmvwl64.sys [2013-10-23 21568]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-10-13 110336]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2013-09-30 12504]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RT-USB;Ross-Tech USB driver; C:\Windows\system32\drivers\RT-USB64.SYS [2010-06-16 70984]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-10-13 206080]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-03-19 343336]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-02-05 935056]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE [2013-10-23 48128]
S2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-13 268464]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-02-23 1436424]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-06 148080]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-10-22 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23 116648]
S4 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-23 194032]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 743688]
S4 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Dlouhý start noťasu

#8 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Linda.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O15 - Trusted Zone: http://www.samsungsetup.com
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

malina
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 15 bře 2007 22:17

Re: Dlouhý start noťasu

#9 Příspěvek od malina »

Výborná práce - díky moc. Nyní naběhne svižně, veliké zlepšení proti původnímu stavu.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Dlouhý start noťasu

#10 Příspěvek od Rudy »

Tak to jsem rád. Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět