
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
změna vyhledávače na go.ru + hláška nethost přestal pracovat
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
změna vyhledávače na go.ru + hláška nethost přestal pracovat
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jonas at 2015-04-09 16:54:10
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 41 GB (17%) free of 238 GB
Total RAM: 6142 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:54:13, on 9.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jonas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\RunOnce: [setsearch_delete_self] "C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE" --selfdelete
O4 - Global Startup: SafeEraser Service.lnk = C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8334 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2352
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Program Files\Microsoft Device Center\ipoint.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-de74994a-03db-48c9-bc2e-5a675d71c826 -SystemEventPortName:HostProcess-872f30ff-1b0d-44ff-93bb-f51524f86be9 -IoCancelEventPortName:HostProcess-5abb5a0f-d2dd-4e21-ab47-3b93be1fca04 -NonStateChangingEventPortName:HostProcess-05906115-3c44-4209-901a-d7018b4b2c3c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bde8fbd1-5b55-4744-b980-32dfaa864295 -DeviceGroupId:WpdFsGroup
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=308
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3312.0.1041979457\784843656" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x1002 --gpu-device-id=0x6738 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials=BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/PasswordGeneration/Disabled/QUIC/Control/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3312 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3312.2.1018545648\226086118" /prefetch:673131151
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe --install_url="http://g.anchovyonline.ru/?prod=setsear ... $__BROWSER"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {9A816600-2419-4D95-9D24-7FADA989C4B7}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Stable_NonMonotonicity_Control_PostPeriod/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Control/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3312 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3312.23.1016002493\1526770798" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Stable_NonMonotonicity_Control_PostPeriod/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Control/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3312 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3312.24.2097340804\1331046096" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Jonas\Desktop\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\
GoSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
"IntelliType Pro"=C:\Program Files\Microsoft Device Center\itype.exe [2000-01-01 1464928]
"IntelliPoint"=C:\Program Files\Microsoft Device Center\ipoint.exe [2000-01-01 2004584]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-30 809288]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"setsearch_delete_self"=C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE [2015-04-09 2655200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2000-01-01 43608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-10-31 2072928]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SafeEraser Service.lnk - C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-09 16:54:10 ----D---- C:\rsit
2015-04-07 14:55:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-07 00:24:07 ----SD---- C:\Windows\SYSWOW64\GWX
2015-04-07 00:24:07 ----SD---- C:\Windows\system32\GWX
2015-04-06 23:28:22 ----RD---- C:\Program Files (x86)\Skype
2015-04-06 23:27:36 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-04-06 23:27:36 ----D---- C:\Program Files\Realtek
2015-04-06 23:26:18 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\powertracker.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\perftrack.dll
2015-04-06 23:26:06 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-04-06 23:26:06 ----A---- C:\Windows\system32\oleaut32.dll
2015-03-26 17:52:11 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:49:59 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-03-26 17:30:20 ----D---- C:\ProgramData\Wondershare
2015-03-26 17:30:16 ----D---- C:\Users\Jonas\AppData\Roaming\HYXDevPsnList
2015-03-26 17:29:40 ----D---- C:\Users\Jonas\AppData\Roaming\Wondershare
2015-03-26 17:29:39 ----D---- C:\Program Files (x86)\Wondershare
2015-03-26 16:38:15 ----D---- C:\Users\Jonas\AppData\Roaming\.mono
2015-03-26 16:38:15 ----D---- C:\ProgramData\.mono
2015-03-26 16:27:53 ----D---- C:\Program Files (x86)\Cities Skylines
2015-03-26 16:20:42 ----D---- C:\Program Files\7-Zip
2015-03-26 15:44:54 ----D---- C:\Program Files (x86)\Apple Software Update
2015-03-26 15:43:30 ----D---- C:\Program Files\Bonjour
2015-03-26 15:43:30 ----D---- C:\Program Files (x86)\Bonjour
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files\Apple
2015-03-23 21:05:26 ----D---- C:\ProgramData\YTD Video Downloader
2015-03-23 21:05:19 ----D---- C:\Program Files (x86)\GreenTree Applications
2015-03-12 16:51:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-12 16:51:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 17:14:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 17:14:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 17:14:48 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 17:14:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 17:14:43 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 17:14:40 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 17:14:39 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 17:14:39 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 17:14:38 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\winload.exe
2015-03-11 17:14:38 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 17:14:37 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 17:14:37 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\ci.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\smss.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 17:14:33 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 17:14:32 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 17:14:32 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 17:14:07 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 17:14:07 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 17:13:58 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 17:13:58 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 17:13:57 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 17:13:56 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 17:13:55 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 17:13:49 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 17:13:42 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-11 17:13:42 ----A---- C:\Windows\system32\WMPhoto.dll
======List of files/folders modified in the last 1 month======
2015-04-09 16:54:13 ----D---- C:\Windows\Prefetch
2015-04-09 16:54:12 ----D---- C:\Program Files\trend micro
2015-04-09 16:53:32 ----D---- C:\Windows\Temp
2015-04-09 15:38:04 ----D---- C:\Windows\system32\config
2015-04-09 15:19:37 ----D---- C:\Windows\System32
2015-04-09 15:19:37 ----D---- C:\Windows\inf
2015-04-09 15:19:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-08 07:34:31 ----D---- C:\Windows
2015-04-08 07:34:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\AIMP3
2015-04-07 15:07:37 ----RD---- C:\Program Files (x86)
2015-04-07 10:41:45 ----D---- C:\Windows\Microsoft.NET
2015-04-07 10:01:11 ----D---- C:\Program Files (x86)\Full Tilt Poker
2015-04-07 10:00:02 ----D---- C:\Program Files (x86)\Full Tilt Poker.Eu
2015-04-07 09:57:03 ----D---- C:\Windows\Tasks
2015-04-07 09:57:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-07 09:42:50 ----D---- C:\Windows\winsxs
2015-04-07 09:42:43 ----D---- C:\Windows\Logs
2015-04-07 00:24:07 ----D---- C:\Windows\tracing
2015-04-07 00:24:07 ----D---- C:\Windows\SysWOW64
2015-04-06 23:36:31 ----SHD---- C:\Windows\Installer
2015-04-06 23:32:42 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 23:28:23 ----D---- C:\Program Files (x86)\Common Files
2015-04-06 23:28:16 ----D---- C:\ProgramData\Skype
2015-04-06 23:27:36 ----RD---- C:\Program Files
2015-04-06 23:27:36 ----D---- C:\Windows\system32\drivers
2015-04-06 23:27:30 ----D---- C:\Windows\system32\catroot2
2015-04-06 23:27:28 ----D---- C:\Windows\system32\DriverStore
2015-04-06 23:26:36 ----SHD---- C:\System Volume Information
2015-04-02 16:44:12 ----D---- C:\Program Files (x86)\War Thunder
2015-03-28 18:18:56 ----D---- C:\Program Files (x86)\AIMP3
2015-03-26 20:29:14 ----D---- C:\Windows\system32\catroot
2015-03-26 18:27:33 ----D---- C:\Program Files\CCleaner
2015-03-26 17:53:28 ----D---- C:\ProgramData\Apple Computer
2015-03-26 17:52:11 ----D---- C:\ProgramData
2015-03-26 17:49:59 ----DC---- C:\Windows\system32\DRVSTORE
2015-03-26 17:30:03 ----RSD---- C:\Windows\assembly
2015-03-26 16:00:07 ----D---- C:\Program Files (x86)\PokerStars
2015-03-26 15:44:56 ----D---- C:\Windows\system32\Tasks
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files
2015-03-26 15:41:45 ----D---- C:\ProgramData\Apple
2015-03-24 19:54:06 ----D---- C:\Windows\debug
2015-03-24 19:48:29 ----D---- C:\Program Files (x86)\Dying Light
2015-03-12 18:05:42 ----D---- C:\Windows\rescache
2015-03-12 16:37:10 ----D---- C:\Program Files\Windows Media Player
2015-03-12 16:37:10 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-12 16:37:08 ----D---- C:\Windows\system32\en-US
2015-03-12 16:37:08 ----D---- C:\Windows\system32\Dism
2015-03-12 16:37:08 ----D---- C:\Windows\system32\cs-CZ
2015-03-12 16:37:07 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-12 16:37:07 ----D---- C:\Windows\system32\Boot
2015-03-12 16:37:03 ----D---- C:\Program Files\Internet Explorer
2015-03-12 16:37:02 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-12 16:37:00 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 17:47:37 ----D---- C:\Windows\system32\MRT
2015-03-11 17:42:14 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-30 120920]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-05 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-07-21 231376]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 dc3d;MS Hardware Device Detection Driver; C:\Windows\system32\DRIVERS\dc3d.sys [2000-01-01 52320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2000-01-01 46176]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2000-01-01 685672]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2015-02-12 16088]
S3 ggsomc;SOMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsomc.sys [2015-02-12 30424]
S3 HWHandSet;HWUSBSERSP; C:\Windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 223232]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2000-01-01 23648]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-10-02 15712]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Lenovo USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2000-01-01 72280]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-29 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe -/service []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-07 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-07 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1900400]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
Run by Jonas at 2015-04-09 16:54:10
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 41 GB (17%) free of 238 GB
Total RAM: 6142 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:54:13, on 9.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jonas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\RunOnce: [setsearch_delete_self] "C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE" --selfdelete
O4 - Global Startup: SafeEraser Service.lnk = C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8334 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2352
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Program Files\Microsoft Device Center\ipoint.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-de74994a-03db-48c9-bc2e-5a675d71c826 -SystemEventPortName:HostProcess-872f30ff-1b0d-44ff-93bb-f51524f86be9 -IoCancelEventPortName:HostProcess-5abb5a0f-d2dd-4e21-ab47-3b93be1fca04 -NonStateChangingEventPortName:HostProcess-05906115-3c44-4209-901a-d7018b4b2c3c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bde8fbd1-5b55-4744-b980-32dfaa864295 -DeviceGroupId:WpdFsGroup
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=308
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3312.0.1041979457\784843656" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x1002 --gpu-device-id=0x6738 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials=BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/PasswordGeneration/Disabled/QUIC/Control/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3312 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3312.2.1018545648\226086118" /prefetch:673131151
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe --install_url="http://g.anchovyonline.ru/?prod=setsear ... $__BROWSER"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {9A816600-2419-4D95-9D24-7FADA989C4B7}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Stable_NonMonotonicity_Control_PostPeriod/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Control/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3312 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3312.23.1016002493\1526770798" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Stable_NonMonotonicity_Control_PostPeriod/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Control/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3312 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3312.24.2097340804\1331046096" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Jonas\Desktop\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\
GoSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
"IntelliType Pro"=C:\Program Files\Microsoft Device Center\itype.exe [2000-01-01 1464928]
"IntelliPoint"=C:\Program Files\Microsoft Device Center\ipoint.exe [2000-01-01 2004584]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-30 809288]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"setsearch_delete_self"=C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE [2015-04-09 2655200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2000-01-01 43608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-10-31 2072928]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SafeEraser Service.lnk - C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-09 16:54:10 ----D---- C:\rsit
2015-04-07 14:55:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-07 00:24:07 ----SD---- C:\Windows\SYSWOW64\GWX
2015-04-07 00:24:07 ----SD---- C:\Windows\system32\GWX
2015-04-06 23:28:22 ----RD---- C:\Program Files (x86)\Skype
2015-04-06 23:27:36 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-04-06 23:27:36 ----D---- C:\Program Files\Realtek
2015-04-06 23:26:18 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\powertracker.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\perftrack.dll
2015-04-06 23:26:06 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-04-06 23:26:06 ----A---- C:\Windows\system32\oleaut32.dll
2015-03-26 17:52:11 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:49:59 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-03-26 17:30:20 ----D---- C:\ProgramData\Wondershare
2015-03-26 17:30:16 ----D---- C:\Users\Jonas\AppData\Roaming\HYXDevPsnList
2015-03-26 17:29:40 ----D---- C:\Users\Jonas\AppData\Roaming\Wondershare
2015-03-26 17:29:39 ----D---- C:\Program Files (x86)\Wondershare
2015-03-26 16:38:15 ----D---- C:\Users\Jonas\AppData\Roaming\.mono
2015-03-26 16:38:15 ----D---- C:\ProgramData\.mono
2015-03-26 16:27:53 ----D---- C:\Program Files (x86)\Cities Skylines
2015-03-26 16:20:42 ----D---- C:\Program Files\7-Zip
2015-03-26 15:44:54 ----D---- C:\Program Files (x86)\Apple Software Update
2015-03-26 15:43:30 ----D---- C:\Program Files\Bonjour
2015-03-26 15:43:30 ----D---- C:\Program Files (x86)\Bonjour
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files\Apple
2015-03-23 21:05:26 ----D---- C:\ProgramData\YTD Video Downloader
2015-03-23 21:05:19 ----D---- C:\Program Files (x86)\GreenTree Applications
2015-03-12 16:51:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-12 16:51:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 17:14:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 17:14:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 17:14:48 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 17:14:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 17:14:43 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 17:14:40 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 17:14:39 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 17:14:39 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 17:14:38 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\winload.exe
2015-03-11 17:14:38 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 17:14:37 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 17:14:37 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\ci.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\smss.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 17:14:33 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 17:14:32 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 17:14:32 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 17:14:07 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 17:14:07 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 17:13:58 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 17:13:58 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 17:13:57 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 17:13:56 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 17:13:55 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 17:13:49 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 17:13:42 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-11 17:13:42 ----A---- C:\Windows\system32\WMPhoto.dll
======List of files/folders modified in the last 1 month======
2015-04-09 16:54:13 ----D---- C:\Windows\Prefetch
2015-04-09 16:54:12 ----D---- C:\Program Files\trend micro
2015-04-09 16:53:32 ----D---- C:\Windows\Temp
2015-04-09 15:38:04 ----D---- C:\Windows\system32\config
2015-04-09 15:19:37 ----D---- C:\Windows\System32
2015-04-09 15:19:37 ----D---- C:\Windows\inf
2015-04-09 15:19:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-08 07:34:31 ----D---- C:\Windows
2015-04-08 07:34:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\AIMP3
2015-04-07 15:07:37 ----RD---- C:\Program Files (x86)
2015-04-07 10:41:45 ----D---- C:\Windows\Microsoft.NET
2015-04-07 10:01:11 ----D---- C:\Program Files (x86)\Full Tilt Poker
2015-04-07 10:00:02 ----D---- C:\Program Files (x86)\Full Tilt Poker.Eu
2015-04-07 09:57:03 ----D---- C:\Windows\Tasks
2015-04-07 09:57:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-07 09:42:50 ----D---- C:\Windows\winsxs
2015-04-07 09:42:43 ----D---- C:\Windows\Logs
2015-04-07 00:24:07 ----D---- C:\Windows\tracing
2015-04-07 00:24:07 ----D---- C:\Windows\SysWOW64
2015-04-06 23:36:31 ----SHD---- C:\Windows\Installer
2015-04-06 23:32:42 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 23:28:23 ----D---- C:\Program Files (x86)\Common Files
2015-04-06 23:28:16 ----D---- C:\ProgramData\Skype
2015-04-06 23:27:36 ----RD---- C:\Program Files
2015-04-06 23:27:36 ----D---- C:\Windows\system32\drivers
2015-04-06 23:27:30 ----D---- C:\Windows\system32\catroot2
2015-04-06 23:27:28 ----D---- C:\Windows\system32\DriverStore
2015-04-06 23:26:36 ----SHD---- C:\System Volume Information
2015-04-02 16:44:12 ----D---- C:\Program Files (x86)\War Thunder
2015-03-28 18:18:56 ----D---- C:\Program Files (x86)\AIMP3
2015-03-26 20:29:14 ----D---- C:\Windows\system32\catroot
2015-03-26 18:27:33 ----D---- C:\Program Files\CCleaner
2015-03-26 17:53:28 ----D---- C:\ProgramData\Apple Computer
2015-03-26 17:52:11 ----D---- C:\ProgramData
2015-03-26 17:49:59 ----DC---- C:\Windows\system32\DRVSTORE
2015-03-26 17:30:03 ----RSD---- C:\Windows\assembly
2015-03-26 16:00:07 ----D---- C:\Program Files (x86)\PokerStars
2015-03-26 15:44:56 ----D---- C:\Windows\system32\Tasks
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files
2015-03-26 15:41:45 ----D---- C:\ProgramData\Apple
2015-03-24 19:54:06 ----D---- C:\Windows\debug
2015-03-24 19:48:29 ----D---- C:\Program Files (x86)\Dying Light
2015-03-12 18:05:42 ----D---- C:\Windows\rescache
2015-03-12 16:37:10 ----D---- C:\Program Files\Windows Media Player
2015-03-12 16:37:10 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-12 16:37:08 ----D---- C:\Windows\system32\en-US
2015-03-12 16:37:08 ----D---- C:\Windows\system32\Dism
2015-03-12 16:37:08 ----D---- C:\Windows\system32\cs-CZ
2015-03-12 16:37:07 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-12 16:37:07 ----D---- C:\Windows\system32\Boot
2015-03-12 16:37:03 ----D---- C:\Program Files\Internet Explorer
2015-03-12 16:37:02 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-12 16:37:00 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 17:47:37 ----D---- C:\Windows\system32\MRT
2015-03-11 17:42:14 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-30 120920]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-05 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-07-21 231376]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 dc3d;MS Hardware Device Detection Driver; C:\Windows\system32\DRIVERS\dc3d.sys [2000-01-01 52320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2000-01-01 46176]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2000-01-01 685672]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2015-02-12 16088]
S3 ggsomc;SOMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsomc.sys [2015-02-12 30424]
S3 HWHandSet;HWUSBSERSP; C:\Windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 223232]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2000-01-01 23648]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-10-02 15712]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Lenovo USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2000-01-01 72280]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-29 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe -/service []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-07 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-07 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1900400]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
# AdwCleaner v4.201 - Log vytvořen 09/04/2015 v 17:41:36
# Aktualizováno 08/04/2015 by Xplode
# Databáze : 2015-04-08.1 [Server]
# Operační system : Windows 7 Professional Service Pack 1 (x64)
# Uživatelské jméno : Jonas - JONAS-PC
# Spuštěno z : C:\Users\Jonas\Desktop\adwcleaner_4.201.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
Složka Smazáno : C:\ProgramData\ytd video downloader
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Složka Smazáno : C:\Program Files (x86)\GreenTree Applications
Složka Smazáno : C:\Users\Jonas\AppData\Local\Innovative Solutions
Soubor Smazáno : C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\GoSearch.xml
***** [ Naplánované úlohy ] *****
***** [ Zástupci ] *****
***** [ Registry ] *****
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Klíč Smazáno : HKU\.DEFAULT\Software\AskPartnerNetwork
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}
Data Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v37.0.1 (x86 cs)
-\\ Google Chrome v41.0.2272.118
[C:\Users\Jonas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Startup_URLs] : hxxp://search.babylon.com/?affID=112036&tt=060612_8_&babsrc=HP_ss&mntrId=dedd5f37000000000000001a4d560393
-\\ Chromium v
*************************
AdwCleaner[R0].txt - [1804 bytů] - [09/04/2015 17:40:52]
AdwCleaner[S0].txt - [1719 bytů] - [09/04/2015 17:41:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1777 bytů] ##########
# Aktualizováno 08/04/2015 by Xplode
# Databáze : 2015-04-08.1 [Server]
# Operační system : Windows 7 Professional Service Pack 1 (x64)
# Uživatelské jméno : Jonas - JONAS-PC
# Spuštěno z : C:\Users\Jonas\Desktop\adwcleaner_4.201.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
Složka Smazáno : C:\ProgramData\ytd video downloader
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Složka Smazáno : C:\Program Files (x86)\GreenTree Applications
Složka Smazáno : C:\Users\Jonas\AppData\Local\Innovative Solutions
Soubor Smazáno : C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\GoSearch.xml
***** [ Naplánované úlohy ] *****
***** [ Zástupci ] *****
***** [ Registry ] *****
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Klíč Smazáno : HKU\.DEFAULT\Software\AskPartnerNetwork
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}
Data Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v37.0.1 (x86 cs)
-\\ Google Chrome v41.0.2272.118
[C:\Users\Jonas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Startup_URLs] : hxxp://search.babylon.com/?affID=112036&tt=060612_8_&babsrc=HP_ss&mntrId=dedd5f37000000000000001a4d560393
-\\ Chromium v
*************************
AdwCleaner[R0].txt - [1804 bytů] - [09/04/2015 17:40:52]
AdwCleaner[S0].txt - [1719 bytů] - [09/04/2015 17:41:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1777 bytů] ##########
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jonas at 2015-04-10 15:42:30
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 48 GB (20%) free of 238 GB
Total RAM: 6142 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:42:33, on 10.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe
C:\Program Files\trend micro\Jonas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\RunOnce: [setsearch_delete_self] "C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE" --selfdelete
O4 - Global Startup: SafeEraser Service.lnk = C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8118 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {EB51AE21-5941-418C-BF22-E0CA99D914A0}
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
WLIDSvcM.exe 2384
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Program Files\Microsoft Device Center\ipoint.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d95e0458-613b-4d2b-9727-34aede9bbb06 -SystemEventPortName:HostProcess-45611363-afd7-4308-a5b9-8a5c901b2524 -IoCancelEventPortName:HostProcess-044f478e-20a8-42ec-87a0-70e91c68d678 -NonStateChangingEventPortName:HostProcess-e420f897-ba27-459f-8ba4-bb1d3def7dd9 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:43998a21-0aef-43fd-af70-1adbeda5787c -DeviceGroupId:WpdFsGroup
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=308
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3340.0.1581620666\928556613" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x1002 --gpu-device-id=0x6738 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials=BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/PasswordGeneration/Disabled/QUIC/Disabled/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3340 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3340.1.2063756669\2054450384" /prefetch:673131151
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe --install_url="http://g.anchovyonline.ru/?prod=setsear ... $__BROWSER"
C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe {8B14AA1C-03C4-49A3-A251-6F82DA5A88F1}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
taskeng.exe {3560A858-BEA2-40A1-8A9C-09CB3FEB17AF}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Jonas\Desktop\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\
GoSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
"IntelliType Pro"=C:\Program Files\Microsoft Device Center\itype.exe [2000-01-01 1464928]
"IntelliPoint"=C:\Program Files\Microsoft Device Center\ipoint.exe [2000-01-01 2004584]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-30 809288]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"setsearch_delete_self"=C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE [2015-04-10 2655200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2000-01-01 43608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-10-31 2072928]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SafeEraser Service.lnk - C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-09 17:40:49 ----D---- C:\AdwCleaner
2015-04-09 16:54:10 ----D---- C:\rsit
2015-04-07 14:55:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-07 00:24:07 ----SD---- C:\Windows\SYSWOW64\GWX
2015-04-07 00:24:07 ----SD---- C:\Windows\system32\GWX
2015-04-06 23:28:22 ----RD---- C:\Program Files (x86)\Skype
2015-04-06 23:27:36 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-04-06 23:27:36 ----D---- C:\Program Files\Realtek
2015-04-06 23:26:18 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\powertracker.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\perftrack.dll
2015-04-06 23:26:06 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-04-06 23:26:06 ----A---- C:\Windows\system32\oleaut32.dll
2015-03-26 17:52:11 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:49:59 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-03-26 17:30:20 ----D---- C:\ProgramData\Wondershare
2015-03-26 17:30:16 ----D---- C:\Users\Jonas\AppData\Roaming\HYXDevPsnList
2015-03-26 17:29:40 ----D---- C:\Users\Jonas\AppData\Roaming\Wondershare
2015-03-26 17:29:39 ----D---- C:\Program Files (x86)\Wondershare
2015-03-26 16:38:15 ----D---- C:\Users\Jonas\AppData\Roaming\.mono
2015-03-26 16:38:15 ----D---- C:\ProgramData\.mono
2015-03-26 16:27:53 ----D---- C:\Program Files (x86)\Cities Skylines
2015-03-26 16:20:42 ----D---- C:\Program Files\7-Zip
2015-03-26 15:44:54 ----D---- C:\Program Files (x86)\Apple Software Update
2015-03-26 15:43:30 ----D---- C:\Program Files\Bonjour
2015-03-26 15:43:30 ----D---- C:\Program Files (x86)\Bonjour
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files\Apple
2015-03-12 16:51:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-12 16:51:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 17:14:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 17:14:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 17:14:48 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 17:14:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 17:14:43 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 17:14:40 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 17:14:39 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 17:14:39 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 17:14:38 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\winload.exe
2015-03-11 17:14:38 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 17:14:37 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 17:14:37 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\ci.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\smss.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 17:14:33 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 17:14:32 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 17:14:32 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 17:14:07 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 17:14:07 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 17:13:58 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 17:13:58 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 17:13:57 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 17:13:56 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 17:13:55 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 17:13:49 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 17:13:42 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-11 17:13:42 ----A---- C:\Windows\system32\WMPhoto.dll
======List of files/folders modified in the last 1 month======
2015-04-10 15:42:32 ----D---- C:\Program Files\trend micro
2015-04-10 15:41:22 ----D---- C:\Windows\Temp
2015-04-10 15:39:26 ----D---- C:\Windows\Prefetch
2015-04-10 15:39:17 ----SHD---- C:\System Volume Information
2015-04-10 15:30:03 ----D---- C:\Windows\System32
2015-04-10 15:30:03 ----D---- C:\Windows\inf
2015-04-10 15:30:03 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-10 15:29:05 ----D---- C:\Windows\system32\config
2015-04-09 17:56:58 ----D---- C:\Program Files (x86)\GRID Autosport
2015-04-09 17:41:37 ----RD---- C:\Program Files (x86)
2015-04-09 17:41:36 ----D---- C:\ProgramData
2015-04-08 07:34:31 ----D---- C:\Windows
2015-04-08 07:34:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\AIMP3
2015-04-07 10:41:45 ----D---- C:\Windows\Microsoft.NET
2015-04-07 10:01:11 ----D---- C:\Program Files (x86)\Full Tilt Poker
2015-04-07 10:00:02 ----D---- C:\Program Files (x86)\Full Tilt Poker.Eu
2015-04-07 09:57:03 ----D---- C:\Windows\Tasks
2015-04-07 09:57:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-07 09:42:50 ----D---- C:\Windows\winsxs
2015-04-07 09:42:43 ----D---- C:\Windows\Logs
2015-04-07 00:24:07 ----D---- C:\Windows\tracing
2015-04-07 00:24:07 ----D---- C:\Windows\SysWOW64
2015-04-06 23:36:31 ----SHD---- C:\Windows\Installer
2015-04-06 23:32:42 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 23:28:23 ----D---- C:\Program Files (x86)\Common Files
2015-04-06 23:28:16 ----D---- C:\ProgramData\Skype
2015-04-06 23:27:36 ----RD---- C:\Program Files
2015-04-06 23:27:36 ----D---- C:\Windows\system32\drivers
2015-04-06 23:27:30 ----D---- C:\Windows\system32\catroot2
2015-04-06 23:27:28 ----D---- C:\Windows\system32\DriverStore
2015-04-02 16:44:12 ----D---- C:\Program Files (x86)\War Thunder
2015-03-28 18:18:56 ----D---- C:\Program Files (x86)\AIMP3
2015-03-26 20:29:14 ----D---- C:\Windows\system32\catroot
2015-03-26 18:27:33 ----D---- C:\Program Files\CCleaner
2015-03-26 17:53:28 ----D---- C:\ProgramData\Apple Computer
2015-03-26 17:49:59 ----DC---- C:\Windows\system32\DRVSTORE
2015-03-26 17:30:03 ----RSD---- C:\Windows\assembly
2015-03-26 16:00:07 ----D---- C:\Program Files (x86)\PokerStars
2015-03-26 15:44:56 ----D---- C:\Windows\system32\Tasks
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files
2015-03-26 15:41:45 ----D---- C:\ProgramData\Apple
2015-03-24 19:54:06 ----D---- C:\Windows\debug
2015-03-24 19:48:29 ----D---- C:\Program Files (x86)\Dying Light
2015-03-12 18:05:42 ----D---- C:\Windows\rescache
2015-03-12 16:37:10 ----D---- C:\Program Files\Windows Media Player
2015-03-12 16:37:10 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-12 16:37:08 ----D---- C:\Windows\system32\en-US
2015-03-12 16:37:08 ----D---- C:\Windows\system32\Dism
2015-03-12 16:37:08 ----D---- C:\Windows\system32\cs-CZ
2015-03-12 16:37:07 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-12 16:37:07 ----D---- C:\Windows\system32\Boot
2015-03-12 16:37:03 ----D---- C:\Program Files\Internet Explorer
2015-03-12 16:37:02 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-12 16:37:00 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 17:47:37 ----D---- C:\Windows\system32\MRT
2015-03-11 17:42:14 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-30 120920]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-05 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-07-21 231376]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 dc3d;MS Hardware Device Detection Driver; C:\Windows\system32\DRIVERS\dc3d.sys [2000-01-01 52320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2000-01-01 46176]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2000-01-01 685672]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2015-02-12 16088]
S3 ggsomc;SOMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsomc.sys [2015-02-12 30424]
S3 HWHandSet;HWUSBSERSP; C:\Windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 223232]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2000-01-01 23648]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-10-02 15712]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Lenovo USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2000-01-01 72280]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-29 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe -/service []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-07 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-07 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1900400]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
Run by Jonas at 2015-04-10 15:42:30
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 48 GB (20%) free of 238 GB
Total RAM: 6142 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:42:33, on 10.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe
C:\Program Files\trend micro\Jonas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\RunOnce: [setsearch_delete_self] "C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE" --selfdelete
O4 - Global Startup: SafeEraser Service.lnk = C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8118 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {EB51AE21-5941-418C-BF22-E0CA99D914A0}
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
WLIDSvcM.exe 2384
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Program Files\Microsoft Device Center\ipoint.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d95e0458-613b-4d2b-9727-34aede9bbb06 -SystemEventPortName:HostProcess-45611363-afd7-4308-a5b9-8a5c901b2524 -IoCancelEventPortName:HostProcess-044f478e-20a8-42ec-87a0-70e91c68d678 -NonStateChangingEventPortName:HostProcess-e420f897-ba27-459f-8ba4-bb1d3def7dd9 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:43998a21-0aef-43fd-af70-1adbeda5787c -DeviceGroupId:WpdFsGroup
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=308
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3340.0.1581620666\928556613" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x1002 --gpu-device-id=0x6738 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials=BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/PasswordGeneration/Disabled/QUIC/Disabled/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3340 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3340.1.2063756669\2054450384" /prefetch:673131151
C:\Users\Jonas\AppData\Local\SystemDir\setsearchm.exe --install_url="http://g.anchovyonline.ru/?prod=setsear ... $__BROWSER"
C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe {8B14AA1C-03C4-49A3-A251-6F82DA5A88F1}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
taskeng.exe {3560A858-BEA2-40A1-8A9C-09CB3FEB17AF}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Jonas\Desktop\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\
GoSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
"IntelliType Pro"=C:\Program Files\Microsoft Device Center\itype.exe [2000-01-01 1464928]
"IntelliPoint"=C:\Program Files\Microsoft Device Center\ipoint.exe [2000-01-01 2004584]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-30 809288]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"setsearch_delete_self"=C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE [2015-04-10 2655200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2000-01-01 43608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-10-31 2072928]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SafeEraser Service.lnk - C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-09 17:40:49 ----D---- C:\AdwCleaner
2015-04-09 16:54:10 ----D---- C:\rsit
2015-04-07 14:55:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-07 00:24:07 ----SD---- C:\Windows\SYSWOW64\GWX
2015-04-07 00:24:07 ----SD---- C:\Windows\system32\GWX
2015-04-06 23:28:22 ----RD---- C:\Program Files (x86)\Skype
2015-04-06 23:27:36 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-04-06 23:27:36 ----D---- C:\Program Files\Realtek
2015-04-06 23:26:18 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\powertracker.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\perftrack.dll
2015-04-06 23:26:06 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-04-06 23:26:06 ----A---- C:\Windows\system32\oleaut32.dll
2015-03-26 17:52:11 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:49:59 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-03-26 17:30:20 ----D---- C:\ProgramData\Wondershare
2015-03-26 17:30:16 ----D---- C:\Users\Jonas\AppData\Roaming\HYXDevPsnList
2015-03-26 17:29:40 ----D---- C:\Users\Jonas\AppData\Roaming\Wondershare
2015-03-26 17:29:39 ----D---- C:\Program Files (x86)\Wondershare
2015-03-26 16:38:15 ----D---- C:\Users\Jonas\AppData\Roaming\.mono
2015-03-26 16:38:15 ----D---- C:\ProgramData\.mono
2015-03-26 16:27:53 ----D---- C:\Program Files (x86)\Cities Skylines
2015-03-26 16:20:42 ----D---- C:\Program Files\7-Zip
2015-03-26 15:44:54 ----D---- C:\Program Files (x86)\Apple Software Update
2015-03-26 15:43:30 ----D---- C:\Program Files\Bonjour
2015-03-26 15:43:30 ----D---- C:\Program Files (x86)\Bonjour
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files\Apple
2015-03-12 16:51:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-12 16:51:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 17:15:01 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 17:14:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 17:14:49 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 17:14:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 17:14:48 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 17:14:47 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 17:14:46 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 17:14:44 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 17:14:43 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 17:14:43 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 17:14:43 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 17:14:42 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 17:14:42 ----A---- C:\Windows\system32\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 17:14:41 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 17:14:41 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 17:14:40 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 17:14:40 ----A---- C:\Windows\system32\winresume.exe
2015-03-11 17:14:40 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 17:14:39 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\mf.dll
2015-03-11 17:14:39 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 17:14:39 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 17:14:38 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\winload.exe
2015-03-11 17:14:38 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 17:14:38 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 17:14:37 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 17:14:37 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 17:14:37 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\ci.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 17:14:37 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 17:14:36 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\smss.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 17:14:36 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 17:14:36 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 17:14:35 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 17:14:35 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 17:14:34 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 17:14:33 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 17:14:32 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 17:14:32 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 17:14:21 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 17:14:07 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 17:14:07 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 17:14:04 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 17:14:03 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 17:14:03 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 17:14:03 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 17:14:02 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 17:14:02 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 17:13:58 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 17:13:58 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 17:13:57 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 17:13:56 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 17:13:55 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-11 17:13:52 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-11 17:13:52 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-11 17:13:51 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 17:13:51 ----A---- C:\Windows\system32\iernonce.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-11 17:13:50 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\urlmon.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 17:13:50 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-11 17:13:49 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 17:13:49 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\iesetup.dll
2015-03-11 17:13:49 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-11 17:13:48 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\iertutil.dll
2015-03-11 17:13:48 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-11 17:13:47 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-11 17:13:47 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieui.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\ieframe.dll
2015-03-11 17:13:46 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\wininet.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\vbscript.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-11 17:13:45 ----A---- C:\Windows\system32\jscript9.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\msrating.dll
2015-03-11 17:13:44 ----A---- C:\Windows\system32\mshtml.dll
2015-03-11 17:13:42 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-11 17:13:42 ----A---- C:\Windows\system32\WMPhoto.dll
======List of files/folders modified in the last 1 month======
2015-04-10 15:42:32 ----D---- C:\Program Files\trend micro
2015-04-10 15:41:22 ----D---- C:\Windows\Temp
2015-04-10 15:39:26 ----D---- C:\Windows\Prefetch
2015-04-10 15:39:17 ----SHD---- C:\System Volume Information
2015-04-10 15:30:03 ----D---- C:\Windows\System32
2015-04-10 15:30:03 ----D---- C:\Windows\inf
2015-04-10 15:30:03 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-10 15:29:05 ----D---- C:\Windows\system32\config
2015-04-09 17:56:58 ----D---- C:\Program Files (x86)\GRID Autosport
2015-04-09 17:41:37 ----RD---- C:\Program Files (x86)
2015-04-09 17:41:36 ----D---- C:\ProgramData
2015-04-08 07:34:31 ----D---- C:\Windows
2015-04-08 07:34:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\AIMP3
2015-04-07 10:41:45 ----D---- C:\Windows\Microsoft.NET
2015-04-07 10:01:11 ----D---- C:\Program Files (x86)\Full Tilt Poker
2015-04-07 10:00:02 ----D---- C:\Program Files (x86)\Full Tilt Poker.Eu
2015-04-07 09:57:03 ----D---- C:\Windows\Tasks
2015-04-07 09:57:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-07 09:42:50 ----D---- C:\Windows\winsxs
2015-04-07 09:42:43 ----D---- C:\Windows\Logs
2015-04-07 00:24:07 ----D---- C:\Windows\tracing
2015-04-07 00:24:07 ----D---- C:\Windows\SysWOW64
2015-04-06 23:36:31 ----SHD---- C:\Windows\Installer
2015-04-06 23:32:42 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 23:28:23 ----D---- C:\Program Files (x86)\Common Files
2015-04-06 23:28:16 ----D---- C:\ProgramData\Skype
2015-04-06 23:27:36 ----RD---- C:\Program Files
2015-04-06 23:27:36 ----D---- C:\Windows\system32\drivers
2015-04-06 23:27:30 ----D---- C:\Windows\system32\catroot2
2015-04-06 23:27:28 ----D---- C:\Windows\system32\DriverStore
2015-04-02 16:44:12 ----D---- C:\Program Files (x86)\War Thunder
2015-03-28 18:18:56 ----D---- C:\Program Files (x86)\AIMP3
2015-03-26 20:29:14 ----D---- C:\Windows\system32\catroot
2015-03-26 18:27:33 ----D---- C:\Program Files\CCleaner
2015-03-26 17:53:28 ----D---- C:\ProgramData\Apple Computer
2015-03-26 17:49:59 ----DC---- C:\Windows\system32\DRVSTORE
2015-03-26 17:30:03 ----RSD---- C:\Windows\assembly
2015-03-26 16:00:07 ----D---- C:\Program Files (x86)\PokerStars
2015-03-26 15:44:56 ----D---- C:\Windows\system32\Tasks
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files
2015-03-26 15:41:45 ----D---- C:\ProgramData\Apple
2015-03-24 19:54:06 ----D---- C:\Windows\debug
2015-03-24 19:48:29 ----D---- C:\Program Files (x86)\Dying Light
2015-03-12 18:05:42 ----D---- C:\Windows\rescache
2015-03-12 16:37:10 ----D---- C:\Program Files\Windows Media Player
2015-03-12 16:37:10 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-12 16:37:08 ----D---- C:\Windows\system32\en-US
2015-03-12 16:37:08 ----D---- C:\Windows\system32\Dism
2015-03-12 16:37:08 ----D---- C:\Windows\system32\cs-CZ
2015-03-12 16:37:07 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-12 16:37:07 ----D---- C:\Windows\system32\Boot
2015-03-12 16:37:03 ----D---- C:\Program Files\Internet Explorer
2015-03-12 16:37:02 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-12 16:37:00 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 17:47:37 ----D---- C:\Windows\system32\MRT
2015-03-11 17:42:14 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-30 120920]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-05 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-07-21 231376]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 dc3d;MS Hardware Device Detection Driver; C:\Windows\system32\DRIVERS\dc3d.sys [2000-01-01 52320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2000-01-01 46176]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2000-01-01 685672]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2015-02-12 16088]
S3 ggsomc;SOMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsomc.sys [2015-02-12 30424]
S3 HWHandSet;HWUSBSERSP; C:\Windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 223232]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2000-01-01 23648]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-10-02 15712]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Lenovo USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2000-01-01 72280]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-29 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe -/service []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-07 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-07 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1900400]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Users\Jonas\AppData\Local\SYSTEM~1\SETSEA~1.EXE
C:\Windows\SYSWOW64\GWX
C:\Windows\system32\GWX
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]/64
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"setsearch_delete_self"=-
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jonas at 2015-04-11 14:12:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 48 GB (20%) free of 238 GB
Total RAM: 6142 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:12:08, on 11.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files\trend micro\Jonas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - Global Startup: SafeEraser Service.lnk = C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7950 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\Windows\Explorer.EXE
taskeng.exe {5EAE08A3-2CE7-45EB-AEE8-35849AA040FF}
taskeng.exe {A147F3D0-6487-4260-8144-757AF9C24D84}
taskeng.exe {1C2D4560-A3FA-45E0-B333-4BADD1EE83E5}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2292
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-65d6a5a8-1305-48e3-b8e6-0f97e79bfb0b -SystemEventPortName:HostProcess-16201446-01ac-4369-bf79-3a9226b446ec -IoCancelEventPortName:HostProcess-45e8863f-e2eb-4a64-995a-610eefc6ebd2 -NonStateChangingEventPortName:HostProcess-b87aca08-00d9-4257-bf57-b4c75334053c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c88ae607-8d71-4384-81fe-97f4084491d0 -DeviceGroupId:WpdFsGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\04112015_140901.log
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Program Files\Microsoft Device Center\ipoint.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=308
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3104.0.1867624352\221645298" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x1002 --gpu-device-id=0x6738 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/PasswordGeneration/Disabled/QUIC/Enabled/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3104 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3104.1.85951259\416557384" /prefetch:673131151
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Users\Jonas\Desktop\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\
GoSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
"IntelliType Pro"=C:\Program Files\Microsoft Device Center\itype.exe [2000-01-01 1464928]
"IntelliPoint"=C:\Program Files\Microsoft Device Center\ipoint.exe [2000-01-01 2004584]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-30 809288]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2000-01-01 43608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-10-31 2072928]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SafeEraser Service.lnk - C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-11 14:09:01 ----D---- C:\_OTM
2015-04-09 17:40:49 ----D---- C:\AdwCleaner
2015-04-09 16:54:10 ----D---- C:\rsit
2015-04-07 14:55:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-07 00:24:07 ----SD---- C:\Windows\system32\GWX
2015-04-06 23:28:22 ----RD---- C:\Program Files (x86)\Skype
2015-04-06 23:27:36 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-04-06 23:27:36 ----D---- C:\Program Files\Realtek
2015-04-06 23:26:18 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\powertracker.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\perftrack.dll
2015-04-06 23:26:06 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-04-06 23:26:06 ----A---- C:\Windows\system32\oleaut32.dll
2015-03-26 17:52:11 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:49:59 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-03-26 17:30:20 ----D---- C:\ProgramData\Wondershare
2015-03-26 17:30:16 ----D---- C:\Users\Jonas\AppData\Roaming\HYXDevPsnList
2015-03-26 17:29:40 ----D---- C:\Users\Jonas\AppData\Roaming\Wondershare
2015-03-26 17:29:39 ----D---- C:\Program Files (x86)\Wondershare
2015-03-26 16:38:15 ----D---- C:\Users\Jonas\AppData\Roaming\.mono
2015-03-26 16:38:15 ----D---- C:\ProgramData\.mono
2015-03-26 16:27:53 ----D---- C:\Program Files (x86)\Cities Skylines
2015-03-26 16:20:42 ----D---- C:\Program Files\7-Zip
2015-03-26 15:44:54 ----D---- C:\Program Files (x86)\Apple Software Update
2015-03-26 15:43:30 ----D---- C:\Program Files\Bonjour
2015-03-26 15:43:30 ----D---- C:\Program Files (x86)\Bonjour
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files\Apple
2015-03-12 16:51:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-12 16:51:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
======List of files/folders modified in the last 1 month======
2015-04-11 14:12:07 ----D---- C:\Program Files\trend micro
2015-04-11 14:11:20 ----D---- C:\Windows\Temp
2015-04-11 14:09:14 ----D---- C:\Windows\system32\config
2015-04-11 14:09:01 ----D---- C:\Windows\Tasks
2015-04-11 14:09:01 ----D---- C:\Windows\SysWOW64
2015-04-11 14:08:48 ----D---- C:\Windows\Prefetch
2015-04-11 13:22:33 ----D---- C:\Windows\System32
2015-04-11 13:22:33 ----D---- C:\Windows\inf
2015-04-11 13:22:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-10 16:23:45 ----D---- C:\Users\Jonas\AppData\Roaming\AIMP3
2015-04-10 15:39:17 ----SHD---- C:\System Volume Information
2015-04-09 17:56:58 ----D---- C:\Program Files (x86)\GRID Autosport
2015-04-09 17:41:37 ----RD---- C:\Program Files (x86)
2015-04-09 17:41:36 ----D---- C:\ProgramData
2015-04-08 07:34:31 ----D---- C:\Windows
2015-04-08 07:34:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
2015-04-07 10:41:45 ----D---- C:\Windows\Microsoft.NET
2015-04-07 10:01:11 ----D---- C:\Program Files (x86)\Full Tilt Poker
2015-04-07 10:00:02 ----D---- C:\Program Files (x86)\Full Tilt Poker.Eu
2015-04-07 09:57:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-07 09:42:50 ----D---- C:\Windows\winsxs
2015-04-07 09:42:43 ----D---- C:\Windows\Logs
2015-04-07 00:24:07 ----D---- C:\Windows\tracing
2015-04-06 23:36:31 ----SHD---- C:\Windows\Installer
2015-04-06 23:32:42 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 23:28:23 ----D---- C:\Program Files (x86)\Common Files
2015-04-06 23:28:16 ----D---- C:\ProgramData\Skype
2015-04-06 23:27:36 ----RD---- C:\Program Files
2015-04-06 23:27:36 ----D---- C:\Windows\system32\drivers
2015-04-06 23:27:30 ----D---- C:\Windows\system32\catroot2
2015-04-06 23:27:28 ----D---- C:\Windows\system32\DriverStore
2015-04-02 16:44:12 ----D---- C:\Program Files (x86)\War Thunder
2015-03-28 18:18:56 ----D---- C:\Program Files (x86)\AIMP3
2015-03-26 20:29:14 ----D---- C:\Windows\system32\catroot
2015-03-26 18:27:33 ----D---- C:\Program Files\CCleaner
2015-03-26 17:53:28 ----D---- C:\ProgramData\Apple Computer
2015-03-26 17:49:59 ----DC---- C:\Windows\system32\DRVSTORE
2015-03-26 17:30:03 ----RSD---- C:\Windows\assembly
2015-03-26 16:00:07 ----D---- C:\Program Files (x86)\PokerStars
2015-03-26 15:44:56 ----D---- C:\Windows\system32\Tasks
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files
2015-03-26 15:41:45 ----D---- C:\ProgramData\Apple
2015-03-24 19:54:06 ----D---- C:\Windows\debug
2015-03-24 19:48:29 ----D---- C:\Program Files (x86)\Dying Light
2015-03-12 18:05:42 ----D---- C:\Windows\rescache
2015-03-12 16:37:10 ----D---- C:\Program Files\Windows Media Player
2015-03-12 16:37:10 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-12 16:37:08 ----D---- C:\Windows\system32\en-US
2015-03-12 16:37:08 ----D---- C:\Windows\system32\Dism
2015-03-12 16:37:08 ----D---- C:\Windows\system32\cs-CZ
2015-03-12 16:37:07 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-12 16:37:07 ----D---- C:\Windows\system32\Boot
2015-03-12 16:37:03 ----D---- C:\Program Files\Internet Explorer
2015-03-12 16:37:02 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-12 16:37:00 ----D---- C:\Program Files (x86)\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-30 120920]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-05 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-07-21 231376]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 dc3d;MS Hardware Device Detection Driver; C:\Windows\system32\DRIVERS\dc3d.sys [2000-01-01 52320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2000-01-01 46176]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2000-01-01 685672]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2015-02-12 16088]
S3 ggsomc;SOMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsomc.sys [2015-02-12 30424]
S3 HWHandSet;HWUSBSERSP; C:\Windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 223232]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2000-01-01 23648]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-10-02 15712]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Lenovo USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2000-01-01 72280]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-29 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe -/service []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-07 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-07 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1900400]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
Run by Jonas at 2015-04-11 14:12:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 48 GB (20%) free of 238 GB
Total RAM: 6142 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:12:08, on 11.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files\trend micro\Jonas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - Global Startup: SafeEraser Service.lnk = C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7950 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\Windows\Explorer.EXE
taskeng.exe {5EAE08A3-2CE7-45EB-AEE8-35849AA040FF}
taskeng.exe {A147F3D0-6487-4260-8144-757AF9C24D84}
taskeng.exe {1C2D4560-A3FA-45E0-B333-4BADD1EE83E5}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\SysWOW64\XSrvSetup.exe
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2292
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-65d6a5a8-1305-48e3-b8e6-0f97e79bfb0b -SystemEventPortName:HostProcess-16201446-01ac-4369-bf79-3a9226b446ec -IoCancelEventPortName:HostProcess-45e8863f-e2eb-4a64-995a-610eefc6ebd2 -NonStateChangingEventPortName:HostProcess-b87aca08-00d9-4257-bf57-b4c75334053c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c88ae607-8d71-4384-81fe-97f4084491d0 -DeviceGroupId:WpdFsGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\04112015_140901.log
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Program Files\Microsoft Device Center\ipoint.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=308
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3104.0.1867624352\221645298" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x1002 --gpu-device-id=0x6738 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/PasswordGeneration/Disabled/QUIC/Enabled/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=3104 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="3104.1.85951259\416557384" /prefetch:673131151
"C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe"
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Users\Jonas\Desktop\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.134 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jonas\AppData\Roaming\Mozilla\Firefox\Profiles\94czhu4y.default\searchplugins\
GoSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
"IntelliType Pro"=C:\Program Files\Microsoft Device Center\itype.exe [2000-01-01 1464928]
"IntelliPoint"=C:\Program Files\Microsoft Device Center\ipoint.exe [2000-01-01 2004584]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"GoogleChromeAutoLaunch_7F41DE71C33EFD8EC5D292FBB70B0F95"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-30 809288]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-12-23 833240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2000-01-01 43608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-10-31 2072928]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SafeEraser Service.lnk - C:\Program Files (x86)\Wondershare\SafeEraser\SafeEraserNotifier.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-11 14:09:01 ----D---- C:\_OTM
2015-04-09 17:40:49 ----D---- C:\AdwCleaner
2015-04-09 16:54:10 ----D---- C:\rsit
2015-04-07 14:55:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-07 00:24:07 ----SD---- C:\Windows\system32\GWX
2015-04-06 23:28:22 ----RD---- C:\Program Files (x86)\Skype
2015-04-06 23:27:36 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-04-06 23:27:36 ----D---- C:\Program Files\Realtek
2015-04-06 23:26:18 ----A---- C:\Windows\SYSWOW64\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\wdi.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\powertracker.dll
2015-04-06 23:26:18 ----A---- C:\Windows\system32\perftrack.dll
2015-04-06 23:26:06 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-04-06 23:26:06 ----A---- C:\Windows\system32\oleaut32.dll
2015-03-26 17:52:11 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-26 17:49:59 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-03-26 17:30:20 ----D---- C:\ProgramData\Wondershare
2015-03-26 17:30:16 ----D---- C:\Users\Jonas\AppData\Roaming\HYXDevPsnList
2015-03-26 17:29:40 ----D---- C:\Users\Jonas\AppData\Roaming\Wondershare
2015-03-26 17:29:39 ----D---- C:\Program Files (x86)\Wondershare
2015-03-26 16:38:15 ----D---- C:\Users\Jonas\AppData\Roaming\.mono
2015-03-26 16:38:15 ----D---- C:\ProgramData\.mono
2015-03-26 16:27:53 ----D---- C:\Program Files (x86)\Cities Skylines
2015-03-26 16:20:42 ----D---- C:\Program Files\7-Zip
2015-03-26 15:44:54 ----D---- C:\Program Files (x86)\Apple Software Update
2015-03-26 15:43:30 ----D---- C:\Program Files\Bonjour
2015-03-26 15:43:30 ----D---- C:\Program Files (x86)\Bonjour
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files\Apple
2015-03-12 16:51:13 ----A---- C:\Windows\system32\shell32.dll
2015-03-12 16:51:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
======List of files/folders modified in the last 1 month======
2015-04-11 14:12:07 ----D---- C:\Program Files\trend micro
2015-04-11 14:11:20 ----D---- C:\Windows\Temp
2015-04-11 14:09:14 ----D---- C:\Windows\system32\config
2015-04-11 14:09:01 ----D---- C:\Windows\Tasks
2015-04-11 14:09:01 ----D---- C:\Windows\SysWOW64
2015-04-11 14:08:48 ----D---- C:\Windows\Prefetch
2015-04-11 13:22:33 ----D---- C:\Windows\System32
2015-04-11 13:22:33 ----D---- C:\Windows\inf
2015-04-11 13:22:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-10 16:23:45 ----D---- C:\Users\Jonas\AppData\Roaming\AIMP3
2015-04-10 15:39:17 ----SHD---- C:\System Volume Information
2015-04-09 17:56:58 ----D---- C:\Program Files (x86)\GRID Autosport
2015-04-09 17:41:37 ----RD---- C:\Program Files (x86)
2015-04-09 17:41:36 ----D---- C:\ProgramData
2015-04-08 07:34:31 ----D---- C:\Windows
2015-04-08 07:34:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-07 20:16:14 ----D---- C:\Users\Jonas\AppData\Roaming\DAEMON Tools Lite
2015-04-07 10:41:45 ----D---- C:\Windows\Microsoft.NET
2015-04-07 10:01:11 ----D---- C:\Program Files (x86)\Full Tilt Poker
2015-04-07 10:00:02 ----D---- C:\Program Files (x86)\Full Tilt Poker.Eu
2015-04-07 09:57:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-07 09:42:50 ----D---- C:\Windows\winsxs
2015-04-07 09:42:43 ----D---- C:\Windows\Logs
2015-04-07 00:24:07 ----D---- C:\Windows\tracing
2015-04-06 23:36:31 ----SHD---- C:\Windows\Installer
2015-04-06 23:32:42 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 23:28:23 ----D---- C:\Program Files (x86)\Common Files
2015-04-06 23:28:16 ----D---- C:\ProgramData\Skype
2015-04-06 23:27:36 ----RD---- C:\Program Files
2015-04-06 23:27:36 ----D---- C:\Windows\system32\drivers
2015-04-06 23:27:30 ----D---- C:\Windows\system32\catroot2
2015-04-06 23:27:28 ----D---- C:\Windows\system32\DriverStore
2015-04-02 16:44:12 ----D---- C:\Program Files (x86)\War Thunder
2015-03-28 18:18:56 ----D---- C:\Program Files (x86)\AIMP3
2015-03-26 20:29:14 ----D---- C:\Windows\system32\catroot
2015-03-26 18:27:33 ----D---- C:\Program Files\CCleaner
2015-03-26 17:53:28 ----D---- C:\ProgramData\Apple Computer
2015-03-26 17:49:59 ----DC---- C:\Windows\system32\DRVSTORE
2015-03-26 17:30:03 ----RSD---- C:\Windows\assembly
2015-03-26 16:00:07 ----D---- C:\Program Files (x86)\PokerStars
2015-03-26 15:44:56 ----D---- C:\Windows\system32\Tasks
2015-03-26 15:42:47 ----D---- C:\Program Files\Common Files
2015-03-26 15:41:45 ----D---- C:\ProgramData\Apple
2015-03-24 19:54:06 ----D---- C:\Windows\debug
2015-03-24 19:48:29 ----D---- C:\Program Files (x86)\Dying Light
2015-03-12 18:05:42 ----D---- C:\Windows\rescache
2015-03-12 16:37:10 ----D---- C:\Program Files\Windows Media Player
2015-03-12 16:37:10 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-12 16:37:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-12 16:37:08 ----D---- C:\Windows\system32\en-US
2015-03-12 16:37:08 ----D---- C:\Windows\system32\Dism
2015-03-12 16:37:08 ----D---- C:\Windows\system32\cs-CZ
2015-03-12 16:37:07 ----D---- C:\Windows\system32\CodeIntegrity
2015-03-12 16:37:07 ----D---- C:\Windows\system32\Boot
2015-03-12 16:37:03 ----D---- C:\Program Files\Internet Explorer
2015-03-12 16:37:02 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-12 16:37:00 ----D---- C:\Program Files (x86)\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-30 120920]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-05 283064]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-07-21 231376]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 dc3d;MS Hardware Device Detection Driver; C:\Windows\system32\DRIVERS\dc3d.sys [2000-01-01 52320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2000-01-01 46176]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2000-01-01 685672]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SOMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2015-02-12 16088]
S3 ggsomc;SOMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsomc.sys [2015-02-12 30424]
S3 HWHandSet;HWUSBSERSP; C:\Windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 223232]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2000-01-01 23648]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-10-02 15712]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Lenovo USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2000-01-01 72280]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-05-29 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe -/service []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-07 268464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-15 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-02-20 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-07 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1900400]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-08-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Tak bohužel, ruský vyhledávač i hláška nethost přestal pracovat, se objevují stále
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 13.4.2015
Čas skenování: 22:05:50
Protokol:
Správce: Ano
Verze: 2.01.4.1018
Databáze malwaru: v2015.04.13.07
Databáze rootkitů: v2015.03.31.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Jonas
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 367404
Uplynulý čas: 10 min, 1 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 0
(Nenalezeny žádné škodlivé položky)
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 1
Trojan.Agent.E, C:\Windows\System32\Tasks\nethost task, , [72a9ee7edeac0d29066dd181d53004fc],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
www.malwarebytes.org
Datum skenování: 13.4.2015
Čas skenování: 22:05:50
Protokol:
Správce: Ano
Verze: 2.01.4.1018
Databáze malwaru: v2015.04.13.07
Databáze rootkitů: v2015.03.31.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Jonas
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 367404
Uplynulý čas: 10 min, 1 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 0
(Nenalezeny žádné škodlivé položky)
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 1
Trojan.Agent.E, C:\Windows\System32\Tasks\nethost task, , [72a9ee7edeac0d29066dd181d53004fc],
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
Nalezenou položku smažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
vyhledávač pořád go mail.ru hlášku o nethostu jsem nezahlédl přes dvě hodiny
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: změna vyhledávače na go.ru + hláška nethost přestal prac
V kterém prohlížeči?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?