Logfile of random's system information tool 1.10 (written by random/random)
Run by preshing at 2015-05-03 12:10:28
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 99 GB (21%) free of 477 GB
Total RAM: 6143 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:10:36, on 3.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
C:\Program Files\trend micro\preshing.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&f ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/search?q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.bing.com/search?q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yamdex.net/?searchid=1&l10n=ru&f ... 6afa&text=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://yamdex.net/?searchid=1&l10n=ru&f ... 6afa&text=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - DefaultPrefix: http://yamdex.net/?searchid=1&l10n=ru&f ... 6afa&text=
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7961 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\Windows\system32\HPSIsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 88ad1d5a-b61c-42fd-97f8-67e4ec0ded71 1
\??\C:\Windows\system32\conhost.exe "-1579093880-1374973233-16640291941534876583226508999-561490049-1039126740-843332046
C:\Windows\system32\SearchIndexer.exe /Embedding
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0672c624-38f2-4e75-90d4-aa34f55d6b69 -SystemEventPortName:HostProcess-73b0f3e9-91fb-45d4-8bd2-8a5591171cdd -IoCancelEventPortName:HostProcess-6082d30f-ca40-4e97-b25b-12b0097209b4 -NonStateChangingEventPortName:HostProcess-872d9df9-7206-4eba-8467-ccfee0aa798a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2683b5a5-5c1a-4d1e-add2-b40ccf96d3e7
WLIDSvcM.exe 1944
"taskhost.exe"
taskeng.exe {9BC8A130-A567-4237-8A65-49AA8BCDF287}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-7584263621494865183-7031108171984914819959443851715262243-1270678818319250483
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=5112.1c596e00.1681435848 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5112 "\\.\pipe\gecko-crash-server-pipe.5112" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe" --proxy-stub-channel=Flash1132.6EC3AF38.6225 --host-broker-channel=Flash1132.6EC3AF38.13637 --host-pid=1132 --host-npapi-version=28 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe" --channel=2552.001DF1DC.684813406 --proxy-stub-channel=Flash1132.6EC3AF38.6225 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll" --host-npapi-version=28 --type=renderer
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\preshing\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293
prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "keyword.URL" - "http://www.google.com/search?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\searchplugins\
Google.xml
Web Search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-09-17 2461504]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-09-17 2799784]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-01-30 1332296]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-09-11 2087264]
"YTDownloader"=C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-05-03 12:10:28 ----D---- C:\rsit
2015-05-03 12:10:28 ----D---- C:\Program Files\trend micro
2015-05-03 11:37:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-29 22:20:04 ----D---- C:\Users\preshing\AppData\Roaming\QuickScan
2015-04-29 22:18:05 ----D---- C:\Users\preshing\AppData\Roaming\Opera Software
2015-04-29 22:16:05 ----D---- C:\Program Files (x86)\globalUpdate
2015-04-29 22:02:26 ----D---- C:\ProgramData\Wondershare
2015-04-29 22:01:31 ----D---- C:\Users\preshing\AppData\Roaming\Wondershare
2015-04-29 20:58:36 ----A---- C:\log.txt
2015-04-29 20:58:34 ----H---- C:\iехplоrе.bаt.exe
2015-04-29 20:58:34 ----H---- C:\iexplore.bat
2015-04-29 20:58:32 ----H---- C:\firеfох.bаt.exe
2015-04-29 20:58:32 ----H---- C:\firefox.bat
2015-04-29 13:04:36 ----D---- C:\ProgramData\Tencent
2015-04-29 12:53:12 ----A---- C:\Windows\system32\drivers\{b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64.sys
2015-04-29 12:52:30 ----D---- C:\Users\preshing\AppData\Roaming\Tencent
2015-04-29 12:52:11 ----D---- C:\Users\preshing\AppData\Roaming\Shuame
2015-04-29 12:06:53 ----A---- C:\Windows\system32\WinUSBCoInstaller2.dll
2015-04-29 12:06:53 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2015-04-24 07:11:45 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-15 10:20:12 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-15 10:20:12 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-15 10:20:12 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-15 10:20:12 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-15 10:20:12 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wups2.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wups.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wudriver.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wucltux.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wuapp.exe
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wuapi.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 10:20:12 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-15 10:20:11 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-15 10:20:11 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-15 10:20:09 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-15 10:20:09 ----A---- C:\Windows\system32\msxml3.dll
2015-04-15 10:20:09 ----A---- C:\Windows\system32\gdi32.dll
2015-04-15 10:20:08 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-15 10:20:08 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-15 10:20:08 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-15 10:20:06 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-04-15 10:20:05 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-04-15 10:20:05 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-04-15 10:20:05 ----A---- C:\Windows\system32\ntdll.dll
2015-04-15 10:20:05 ----A---- C:\Windows\system32\KernelBase.dll
2015-04-15 10:20:05 ----A---- C:\Windows\system32\kernel32.dll
2015-04-15 10:20:04 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-04-15 10:20:04 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-04-15 10:20:04 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-04-15 10:20:04 ----A---- C:\Windows\system32\wow64win.dll
2015-04-15 10:20:04 ----A---- C:\Windows\system32\schannel.dll
2015-04-15 10:20:04 ----A---- C:\Windows\system32\lsasrv.dll
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-04-15 10:20:03 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-04-15 10:20:03 ----A---- C:\Windows\system32\wow64.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\winsrv.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\wdigest.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\TSpkg.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\sspicli.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\srcore.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\smss.exe
2015-04-15 10:20:03 ----A---- C:\Windows\system32\rstrui.exe
2015-04-15 10:20:03 ----A---- C:\Windows\system32\ncrypt.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\msv1_0.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\lsass.exe
2015-04-15 10:20:03 ----A---- C:\Windows\system32\kerberos.dll
2015-04-15 10:20:03 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-04-15 10:20:03 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-04-15 10:20:03 ----A---- C:\Windows\system32\conhost.exe
2015-04-15 10:20:03 ----A---- C:\Windows\system32\auditpol.exe
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 10:20:02 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-04-15 10:20:02 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\wow64cpu.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\sspisrv.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\srclient.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\secur32.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\ntvdm64.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\csrsrv.dll
2015-04-15 10:20:02 ----A---- C:\Windows\system32\credssp.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 10:20:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 10:20:01 ----A---- C:\Windows\SYSWOW64\user.exe
2015-04-15 10:20:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-04-15 10:20:01 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-04-15 10:20:01 ----A---- C:\Windows\system32\apisetschema.dll
2015-04-15 10:20:00 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-04-15 10:20:00 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-04-15 10:20:00 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-04-15 10:20:00 ----A---- C:\Windows\system32\msobjs.dll
2015-04-15 10:20:00 ----A---- C:\Windows\system32\msaudite.dll
2015-04-15 10:20:00 ----A---- C:\Windows\system32\adtschema.dll
2015-04-15 10:19:53 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-15 10:19:52 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-04-15 10:19:52 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-04-15 10:19:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-04-15 10:19:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-04-15 10:19:51 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-04-15 10:19:51 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-04-15 10:19:51 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-04-15 10:19:51 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-04-15 10:19:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-04-15 10:19:51 ----A---- C:\Windows\system32\iernonce.dll
2015-04-15 10:19:51 ----A---- C:\Windows\system32\ie4uinit.exe
2015-04-15 10:19:50 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-04-15 10:19:50 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-04-15 10:19:50 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-04-15 10:19:50 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 10:19:49 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-04-15 10:19:49 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-04-15 10:19:48 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-04-15 10:19:48 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-04-15 10:19:48 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-04-15 10:19:48 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-04-15 10:19:48 ----A---- C:\Windows\system32\urlmon.dll
2015-04-15 10:19:48 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 10:19:48 ----A---- C:\Windows\system32\iedkcs32.dll
2015-04-15 10:19:47 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-04-15 10:19:47 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-04-15 10:19:47 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-04-15 10:19:47 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 10:19:47 ----A---- C:\Windows\system32\msfeeds.dll
2015-04-15 10:19:47 ----A---- C:\Windows\system32\iesetup.dll
2015-04-15 10:19:47 ----A---- C:\Windows\system32\dxtrans.dll
2015-04-15 10:19:46 ----A---- C:\Windows\system32\iertutil.dll
2015-04-15 10:19:46 ----A---- C:\Windows\system32\ieapfltr.dll
2015-04-15 10:19:45 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-04-15 10:19:45 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-04-15 10:19:45 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-04-15 10:19:45 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-04-15 10:19:45 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-04-15 10:19:45 ----A---- C:\Windows\system32\jsproxy.dll
2015-04-15 10:19:45 ----A---- C:\Windows\system32\ieUnatt.exe
2015-04-15 10:19:44 ----A---- C:\Windows\system32\mshtmled.dll
2015-04-15 10:19:44 ----A---- C:\Windows\system32\ieui.dll
2015-04-15 10:19:44 ----A---- C:\Windows\system32\ieframe.dll
2015-04-15 10:19:44 ----A---- C:\Windows\system32\dxtmsft.dll
2015-04-15 10:19:43 ----A---- C:\Windows\system32\wininet.dll
2015-04-15 10:19:43 ----A---- C:\Windows\system32\vbscript.dll
2015-04-15 10:19:43 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-04-15 10:19:43 ----A---- C:\Windows\system32\jscript9diag.dll
2015-04-15 10:19:43 ----A---- C:\Windows\system32\jscript9.dll
2015-04-15 10:19:42 ----A---- C:\Windows\system32\msrating.dll
2015-04-15 10:19:42 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-04-15 10:19:41 ----A---- C:\Windows\system32\mshtml.dll
2015-04-15 10:19:36 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-15 10:19:36 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-15 10:19:36 ----A---- C:\Windows\system32\clfs.sys
2015-04-14 23:44:02 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2015-04-04 14:19:40 ----SHD---- C:\found.000
======List of files/folders modified in the last 1 month======
2015-05-03 12:10:36 ----D---- C:\Windows\Prefetch
2015-05-03 12:10:28 ----RD---- C:\Program Files
2015-05-03 11:43:18 ----D---- C:\Windows\system32\config
2015-05-03 11:37:33 ----D---- C:\Windows\Temp
2015-05-03 11:37:02 ----RD---- C:\Program Files (x86)
2015-05-03 11:36:52 ----D---- C:\Windows\System32
2015-05-03 11:36:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-03 11:29:54 ----D---- C:\ProgramData\NVIDIA
2015-05-03 11:23:36 ----SHD---- C:\System Volume Information
2015-05-03 11:12:21 ----D---- C:\Windows\Tasks
2015-05-03 11:12:21 ----D---- C:\Windows\system32\Tasks
2015-04-29 22:35:27 ----HD---- C:\ProgramData
2015-04-29 22:33:33 ----SHD---- C:\Windows\Installer
2015-04-29 22:29:12 ----D---- C:\Windows\SysWOW64
2015-04-29 22:23:49 ----D---- C:\Windows\SYSWOW64\wbem
2015-04-29 22:20:17 ----D---- C:\Program Files\Common Files\System
2015-04-29 22:17:15 ----SD---- C:\ProgramData\Microsoft
2015-04-29 22:07:20 ----D---- C:\Windows\Microsoft.NET
2015-04-29 22:01:57 ----RSD---- C:\Windows\assembly
2015-04-29 22:01:46 ----D---- C:\Program Files (x86)\Common Files
2015-04-29 20:58:36 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2015-04-29 12:53:12 ----D---- C:\Windows\system32\drivers
2015-04-29 12:53:11 ----A---- C:\Windows\win.ini
2015-04-29 12:44:57 ----D---- C:\Windows\inf
2015-04-29 12:44:56 ----D---- C:\Windows\system32\DriverStore
2015-04-23 01:38:11 ----D---- C:\Windows\system32\NDF
2015-04-18 21:45:19 ----D---- C:\Windows\system32\MRT
2015-04-18 21:41:48 ----A---- C:\Windows\system32\MRT.exe
2015-04-16 13:23:43 ----D---- C:\Windows\rescache
2015-04-15 11:29:11 ----D---- C:\Windows\winsxs
2015-04-15 11:27:22 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-04-15 11:27:21 ----D---- C:\Windows\system32\cs-CZ
2015-04-15 11:27:21 ----D---- C:\Windows\PolicyDefinitions
2015-04-15 11:27:19 ----D---- C:\Windows\AppPatch
2015-04-15 11:27:18 ----D---- C:\Program Files\Internet Explorer
2015-04-15 11:27:17 ----D---- C:\Windows\SYSWOW64\en-US
2015-04-15 11:27:17 ----D---- C:\Windows\system32\en-US
2015-04-15 11:27:16 ----D---- C:\Program Files (x86)\Internet Explorer
2015-04-15 10:18:45 ----D---- C:\Windows\system32\catroot2
2015-04-14 23:44:16 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-06 11:35:26 ----D---- C:\KMPlayer
2015-04-04 15:32:25 ----D---- C:\Windows
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-11-15 274696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 {b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64;{b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64; C:\Windows\system32\drivers\{b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64.sys [2015-04-28 48784]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-10-08 283064]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-11-15 124560]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-02-05 195728]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-09-17 20288]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-02 187392]
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2011-04-04 20480]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [2012-12-10 44544]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-09-17 1149760]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2011-05-11 126520]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-01-30 23784]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-09-17 1796928]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-09-17 19440960]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-03-13 935056]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-03-13 410768]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-01-30 366512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-06 107848]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14 268464]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-06 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-03-13 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-16 148080]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-10-06 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o kontrolu logu, vyskakující bannery s reklamou
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: prosím o kontrolu logu, vyskakující bannery s reklamou
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: prosím o kontrolu logu, vyskakující bannery s reklamou
# AdwCleaner v4.203 - Log vytvořen 03/05/2015 v 12:28:20
# Aktualizováno 30/04/2015 by Xplode
# Databáze : 2015-05-02.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : preshing - PRESHING-PC
# Spuštěno z : C:\Users\preshing\Downloads\adwcleaner_4.203.exe
# Nastavení : Sken
***** [ Služby ] *****
Služba Nalezeno : {b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64
***** [ Soubory / Složky ] *****
Složka Nalezeno : C:\Program Files (x86)\globalUpdate
Složka Nalezeno : C:\Users\Administrator\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\Guest\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\HomeGroupUser$\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\preshing\AppData\Local\BrowserHelper
Složka Nalezeno : C:\Users\preshing\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Složka Nalezeno : C:\Users\preshing\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\knlpigpfaognbholppaembpfphilacie
Složka Nalezeno : C:\Users\preshing\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\preshing\AppData\Local\globalUpdate
Složka Nalezeno : C:\Users\preshing\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Složka Nalezeno : C:\Users\preshing\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\knlpigpfaognbholppaembpfphilacie
Složka Nalezeno : C:\Users\preshing\AppData\Local\Temp\Metal Maker
Soubor Nalezeno : C:\Program Files (x86)\Mozilla Firefox\browser\defaults\preferences\prefs.js
Soubor Nalezeno : C:\Program Files\Common Files\System\SysMenu.dll
Soubor Nalezeno : C:\Program Files\Common Files\System\SysMenu64.dll
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\invalidprefs.js
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\searchplugins\Web Search.xml
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\user.js
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\j5ry6f02.default-1417684149347\user.js
Soubor Nalezeno : C:\Windows\System32\drivers\{b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64.sys
***** [ Naplánované úlohy ] *****
Úloha Nalezeno : SMupdate1
Úloha Nalezeno : Microsoft\Windows\Multimedia\SMupdate3
Úloha Nalezeno : Microsoft\Windows\Maintenance\SMupdate2
***** [ Zástupci ] *****
***** [ Registry ] *****
Hodnota Nalezeno : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Klíč Nalezeno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Nalezeno : HKCU\Software\ArenaHD
Klíč Nalezeno : HKCU\Software\Crossbrowse
Klíč Nalezeno : HKCU\Software\GlobalUpdate
Klíč Nalezeno : HKCU\Software\HighDefAction
Klíč Nalezeno : HKCU\Software\IM
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
Klíč Nalezeno : HKCU\Software\SavePass1.1
Klíč Nalezeno : HKCU\Software\YorkNewCin
Klíč Nalezeno : [x64] HKCU\Software\ArenaHD
Klíč Nalezeno : [x64] HKCU\Software\Crossbrowse
Klíč Nalezeno : [x64] HKCU\Software\GlobalUpdate
Klíč Nalezeno : [x64] HKCU\Software\HighDefAction
Klíč Nalezeno : [x64] HKCU\Software\IM
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
Klíč Nalezeno : [x64] HKCU\Software\SavePass1.1
Klíč Nalezeno : [x64] HKCU\Software\YorkNewCin
Klíč Nalezeno : HKLM\SOFTWARE\ArenaHD
Klíč Nalezeno : HKLM\SOFTWARE\c7d1c14d-982e-6648-a7fc-d52cbb3ae4bd
Klíč Nalezeno : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Klíč Nalezeno : HKLM\SOFTWARE\Crossbrowse
Klíč Nalezeno : HKLM\SOFTWARE\GlobalUpdate
Klíč Nalezeno : HKLM\SOFTWARE\HighDefAction
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}
Klíč Nalezeno : HKLM\SOFTWARE\YorkNewCin
Klíč Nalezeno : [x64] HKLM\SOFTWARE\ArenaHD
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\HighDefAction
Klíč Nalezeno : [x64] HKLM\SOFTWARE\YorkNewCin
Klíč Nalezeno : [x64] HKLM\SOFTWARE\YTDownloader
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17728
Nastavení Nalezeno : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=b2bfae7b62fe7d119479b75e7ed26afa&text={searchTerms}
Nastavení Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch] - hxxp://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=b2bfae7b62fe7d119479b75e7ed26afa&text=
Nastavení Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=b2bfae7b62fe7d119479b75e7ed26afa&text=
-\\ Mozilla Firefox v37.0.2 (x86 en-US)
-\\ Google Chrome v
-\\ Comodo Dragon v
-\\ Chrome Canary v
*************************
AdwCleaner[R0].txt - [6369 bytů] - [03/05/2015 12:28:20]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6427 bytů] ##########
# Aktualizováno 30/04/2015 by Xplode
# Databáze : 2015-05-02.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : preshing - PRESHING-PC
# Spuštěno z : C:\Users\preshing\Downloads\adwcleaner_4.203.exe
# Nastavení : Sken
***** [ Služby ] *****
Služba Nalezeno : {b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64
***** [ Soubory / Složky ] *****
Složka Nalezeno : C:\Program Files (x86)\globalUpdate
Složka Nalezeno : C:\Users\Administrator\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\Guest\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\HomeGroupUser$\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\preshing\AppData\Local\BrowserHelper
Složka Nalezeno : C:\Users\preshing\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Složka Nalezeno : C:\Users\preshing\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\knlpigpfaognbholppaembpfphilacie
Složka Nalezeno : C:\Users\preshing\AppData\Local\Crossbrowse
Složka Nalezeno : C:\Users\preshing\AppData\Local\globalUpdate
Složka Nalezeno : C:\Users\preshing\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Složka Nalezeno : C:\Users\preshing\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\knlpigpfaognbholppaembpfphilacie
Složka Nalezeno : C:\Users\preshing\AppData\Local\Temp\Metal Maker
Soubor Nalezeno : C:\Program Files (x86)\Mozilla Firefox\browser\defaults\preferences\prefs.js
Soubor Nalezeno : C:\Program Files\Common Files\System\SysMenu.dll
Soubor Nalezeno : C:\Program Files\Common Files\System\SysMenu64.dll
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\invalidprefs.js
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\searchplugins\Web Search.xml
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\38977qqp.default-1420387755293\user.js
Soubor Nalezeno : C:\Users\preshing\AppData\Roaming\Mozilla\Firefox\Profiles\j5ry6f02.default-1417684149347\user.js
Soubor Nalezeno : C:\Windows\System32\drivers\{b94c3215-569a-484c-84dc-f0bcf79c44cc}Gw64.sys
***** [ Naplánované úlohy ] *****
Úloha Nalezeno : SMupdate1
Úloha Nalezeno : Microsoft\Windows\Multimedia\SMupdate3
Úloha Nalezeno : Microsoft\Windows\Maintenance\SMupdate2
***** [ Zástupci ] *****
***** [ Registry ] *****
Hodnota Nalezeno : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Klíč Nalezeno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Nalezeno : HKCU\Software\ArenaHD
Klíč Nalezeno : HKCU\Software\Crossbrowse
Klíč Nalezeno : HKCU\Software\GlobalUpdate
Klíč Nalezeno : HKCU\Software\HighDefAction
Klíč Nalezeno : HKCU\Software\IM
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
Klíč Nalezeno : HKCU\Software\SavePass1.1
Klíč Nalezeno : HKCU\Software\YorkNewCin
Klíč Nalezeno : [x64] HKCU\Software\ArenaHD
Klíč Nalezeno : [x64] HKCU\Software\Crossbrowse
Klíč Nalezeno : [x64] HKCU\Software\GlobalUpdate
Klíč Nalezeno : [x64] HKCU\Software\HighDefAction
Klíč Nalezeno : [x64] HKCU\Software\IM
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
Klíč Nalezeno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
Klíč Nalezeno : [x64] HKCU\Software\SavePass1.1
Klíč Nalezeno : [x64] HKCU\Software\YorkNewCin
Klíč Nalezeno : HKLM\SOFTWARE\ArenaHD
Klíč Nalezeno : HKLM\SOFTWARE\c7d1c14d-982e-6648-a7fc-d52cbb3ae4bd
Klíč Nalezeno : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Klíč Nalezeno : HKLM\SOFTWARE\Crossbrowse
Klíč Nalezeno : HKLM\SOFTWARE\GlobalUpdate
Klíč Nalezeno : HKLM\SOFTWARE\HighDefAction
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}
Klíč Nalezeno : HKLM\SOFTWARE\YorkNewCin
Klíč Nalezeno : [x64] HKLM\SOFTWARE\ArenaHD
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Klíč Nalezeno : [x64] HKLM\SOFTWARE\HighDefAction
Klíč Nalezeno : [x64] HKLM\SOFTWARE\YorkNewCin
Klíč Nalezeno : [x64] HKLM\SOFTWARE\YTDownloader
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17728
Nastavení Nalezeno : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=b2bfae7b62fe7d119479b75e7ed26afa&text={searchTerms}
Nastavení Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch] - hxxp://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=b2bfae7b62fe7d119479b75e7ed26afa&text=
Nastavení Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=b2bfae7b62fe7d119479b75e7ed26afa&text=
-\\ Mozilla Firefox v37.0.2 (x86 en-US)
-\\ Google Chrome v
-\\ Comodo Dragon v
-\\ Chrome Canary v
*************************
AdwCleaner[R0].txt - [6369 bytů] - [03/05/2015 12:28:20]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6427 bytů] ##########
- Rudy
- Site Admin

- Příspěvky: 119677
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: prosím o kontrolu logu, vyskakující bannery s reklamou
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?