
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
jeden svchost jede naplno (log z RSIT)
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
jeden svchost jede naplno (log z RSIT)
Zdravím, kamarádce se v NT naplno spouští jeden z svchostů a velmi zpomaluje stroj. Dělá to nepravidelně, několikrát denně. Prosím o kontrolu. Děkuji.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Zuzka at 2015-04-28 19:38:44
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 75 GB (61%) free of 122 GB
Total RAM: 1952 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:38:56, on 28.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\FaceLogon\smartlogon.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\Down2Home\Down2Home.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Zuzka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: Down2Home.lnk = C:\Program Files (x86)\Down2Home\Down2Home.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 10551 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-49f9-df00fb1f3444 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\FaceLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
"C:\Windows\system32\FBAgent.exe"
C:\Windows\system32\WLANExt.exe 5382960
\??\C:\Windows\system32\conhost.exe "-1224117123-1461304136-1210141135-243024695-1671482792-693983465-1748132687-2064893001
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
WLIDSvcM.exe 2532
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
ATKOSD.exe
KBFiltr.exe
WDC.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Down2Home\Down2Home.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
ctfmon.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\system32\svchost.exe -k netsvcs
taskeng.exe {20D5944D-D720-4FAF-99B3-6CD5484D0CD9}
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
taskmgr.exe /2
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Zuzka\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\ZEON/PDF,version=2.0]
"Description"=
"Path"=C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default\extensions\
{3d7eb24f-2740-49df-8937-200b1cc08f8a}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-11-03 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-11-03 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-11-03 416024]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2010-12-31 2587944]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2012-03-28 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [2011-07-29 737104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_305_Plugin.exe -update plugin []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10 20922016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicMasterTray]
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2012-09-23 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe [2012-03-28 12862]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2011-10-20 3331312]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22 5716608]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-07 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2011-10-19 2319536]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-04-15 3745232]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
Down2Home.lnk - C:\Program Files (x86)\Down2Home\Down2Home.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-11-03 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-28 18:41:34 ----DC---- C:\AdwCleaner
2015-04-28 18:25:42 ----DC---- C:\Program Files\trend micro
2015-04-28 18:25:40 ----DC---- C:\rsit
2015-04-28 17:44:37 ----DC---- C:\Program Files (x86)\Mozilla Firefox
2015-04-28 16:33:46 ----DC---- C:\Program Files (x86)\MozBackup
2015-04-27 20:55:26 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-04-27 20:55:26 ----A---- C:\Windows\system32\wpdshext.dll
2015-04-27 20:55:25 ----A---- C:\Windows\system32\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-04-27 20:55:24 ----A---- C:\Windows\system32\dwmapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups2.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wucltux.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-27 20:55:21 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-04-27 20:52:10 ----A---- C:\Windows\system32\iernonce.dll
2015-04-27 20:52:10 ----A---- C:\Windows\system32\ie4uinit.exe
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-04-27 20:52:09 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\urlmon.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\iedkcs32.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-27 20:52:06 ----A---- C:\Windows\system32\msfeeds.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\dxtrans.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\iesetup.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\ieapfltr.dll
2015-04-27 20:52:04 ----A---- C:\Windows\system32\iertutil.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\jsproxy.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\ieUnatt.exe
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieui.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieframe.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\dxtmsft.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmled.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\wininet.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\vbscript.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9diag.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9.dll
2015-04-27 20:51:58 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\msrating.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\mshtml.dll
2015-04-27 20:51:37 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\KernelBase.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\wow64win.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\schannel.dll
2015-04-27 20:51:32 ----A---- C:\Windows\system32\lsasrv.dll
2015-04-27 20:51:31 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\wow64.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\srcore.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\conhost.exe
2015-04-27 20:51:30 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\winsrv.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\rstrui.exe
2015-04-27 20:51:30 ----A---- C:\Windows\system32\kerberos.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\sspicli.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\srclient.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\smss.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\lsass.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\auditpol.exe
2015-04-27 20:51:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\wow64cpu.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\sspisrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\csrsrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\credssp.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\user.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\adtschema.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msaudite.dll
2015-04-27 20:39:49 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-27 20:39:39 ----A---- C:\Windows\system32\clfs.sys
2015-04-27 20:39:37 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\system32\gdi32.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\acmigration.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\invagent.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\devinv.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\aeinv.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepic.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepdu.dll
2015-04-27 20:34:10 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-27 20:34:10 ----A---- C:\Windows\system32\msxml3.dll
2015-04-27 20:34:09 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-27 20:34:09 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-27 20:12:41 ----DC---- C:\Program Files (x86)\Down2Home
2015-04-27 19:29:06 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-17 21:02:47 ----SHDC---- C:\$RECYCLE.BIN
2015-04-17 21:02:39 ----DC---- C:\Windows\temp
2015-04-17 21:02:37 ----AC---- C:\ComboFix.txt
2015-04-17 20:44:54 ----AC---- C:\Windows\zip.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWSC.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWREG.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\sed.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\PEV.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\NIRCMD.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\MBR.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\grep.exe
2015-04-17 20:44:39 ----DC---- C:\Qoobox
2015-04-17 20:43:36 ----DC---- C:\Windows\erdnt
2015-04-17 20:18:46 ----DC---- C:\ProgramData\AutoKMS
2015-04-17 20:13:31 ----DC---- C:\Users\Zuzka\AppData\Roaming\AVG2015
2015-04-17 20:11:57 ----DC---- C:\ProgramData\AVG2015
2015-04-17 20:11:57 ----DC---- C:\$AVG
2015-04-17 19:56:26 ----DC---- C:\Program Files (x86)\AVG
2015-04-15 13:06:02 ----AC---- C:\Windows\system32\drivers\avgldx64.sys
2015-04-09 14:11:14 ----AC---- C:\Windows\system32\drivers\avgidsdrivera.sys
2015-04-07 12:39:26 ----AC---- C:\Windows\system32\drivers\avgtdia.sys
2015-04-03 09:34:12 ----AC---- C:\Windows\system32\drivers\avgmfx64.sys
2015-03-29 20:54:48 ----DC---- C:\Config.Msi
2015-03-29 20:51:45 ----DC---- C:\47ed3544012e3891d1e8a8cddbefbd8f
2015-03-29 20:50:13 ----SDC---- C:\Windows\SYSWOW64\GWX
2015-03-29 20:50:11 ----SDC---- C:\Windows\system32\GWX
2015-03-29 18:35:33 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-29 18:35:33 ----A---- C:\Windows\system32\blackbox.dll
2015-03-29 18:35:32 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-29 18:35:31 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-29 18:35:30 ----A---- C:\Windows\system32\wmp.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-29 18:35:29 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-29 18:35:28 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\crypt32.dll
2015-03-29 18:35:25 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-29 18:35:25 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-29 18:35:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-29 18:35:24 ----A---- C:\Windows\system32\quartz.dll
2015-03-29 18:35:23 ----A---- C:\Windows\system32\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\system32\cryptui.dll
2015-03-29 18:35:20 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-29 18:35:20 ----A---- C:\Windows\system32\winresume.exe
2015-03-29 18:35:20 ----A---- C:\Windows\system32\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-29 18:35:19 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\msscp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\mf.dll
2015-03-29 18:35:16 ----A---- C:\Windows\system32\winload.exe
2015-03-29 18:35:15 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-29 18:35:14 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\ci.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-29 18:35:13 ----A---- C:\Windows\system32\audiodg.exe
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\qdvd.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-29 18:35:11 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\pcadm.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-29 18:35:10 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcalua.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\appidapi.dll
2015-03-29 18:35:08 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-29 18:35:08 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\EncDump.dll
2015-03-29 18:35:07 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-29 18:35:04 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-29 18:35:04 ----A---- C:\Windows\system32\spwmp.dll
2015-03-29 18:35:03 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-29 18:35:02 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-29 18:35:02 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-29 18:35:00 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-29 18:35:00 ----A---- C:\Windows\system32\mferror.dll
======List of files/folders modified in the last 1 month======
2015-04-28 19:30:15 ----DC---- C:\Windows\system32\config
2015-04-28 18:49:51 ----A---- C:\Windows\SYSWOW64\log.txt
2015-04-28 18:47:49 ----AC---- C:\Windows\SYSWOW64\acovcnt.exe
2015-04-28 18:47:35 ----DC---- C:\Windows
2015-04-28 18:45:16 ----DC---- C:\ProgramData
2015-04-28 18:25:42 ----RDC---- C:\Program Files
2015-04-28 18:14:14 ----DC---- C:\ProgramData\MFAData
2015-04-28 17:44:37 ----RDC---- C:\Program Files (x86)
2015-04-28 17:29:55 ----DC---- C:\Windows\inf
2015-04-28 17:29:55 ----DC---- C:\Windows\debug
2015-04-28 16:23:52 ----DC---- C:\Windows\AppCompat
2015-04-28 16:07:18 ----SHDC---- C:\Windows\Installer
2015-04-27 22:41:38 ----DC---- C:\Windows\Microsoft.NET
2015-04-27 22:23:55 ----RSDC---- C:\Windows\assembly
2015-04-27 22:13:25 ----AC---- C:\Windows\system32\AutoRunFilter.ini
2015-04-27 22:12:46 ----D---- C:\Windows\winsxs
2015-04-27 22:10:43 ----DC---- C:\Windows\SysWOW64
2015-04-27 22:10:43 ----DC---- C:\Windows\System32
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sr-Latn-CS
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sl-SI
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sk-SK
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\ro-RO
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\pl-PL
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lv-LV
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lt-LT
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hu-HU
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hr-HR
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\et-EE
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\cs-CZ
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\bg-BG
2015-04-27 22:10:42 ----D---- C:\Windows\system32\AdvancedInstallers
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sr-Latn-CS
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sl-SI
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sk-SK
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\ro-RO
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\pl-PL
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lv-LV
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lt-LT
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hu-HU
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hr-HR
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\et-EE
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\cs-CZ
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\bg-BG
2015-04-27 22:10:41 ----DC---- C:\Windows\PolicyDefinitions
2015-04-27 22:10:39 ----SDC---- C:\Windows\system32\CompatTel
2015-04-27 22:10:38 ----DC---- C:\Windows\system32\appraiser
2015-04-27 22:10:38 ----DC---- C:\Windows\AppPatch
2015-04-27 22:10:33 ----DC---- C:\Windows\SYSWOW64\en-US
2015-04-27 22:10:31 ----DC---- C:\Windows\system32\en-US
2015-04-27 22:10:28 ----DC---- C:\Windows\system32\drivers
2015-04-27 22:10:26 ----DC---- C:\Program Files\Internet Explorer
2015-04-27 22:10:19 ----DC---- C:\Program Files (x86)\Internet Explorer
2015-04-27 22:10:15 ----DC---- C:\Windows\system32\drivers\UMDF
2015-04-27 22:10:15 ----D---- C:\Windows\system32\DriverStore
2015-04-27 21:47:07 ----DC---- C:\Windows\SYSWOW64\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\drivers\en-US
2015-04-27 21:21:11 ----AC---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-27 21:20:57 ----AC---- C:\Windows\system32\PerfStringBackup.INI
2015-04-27 21:11:19 ----DC---- C:\Windows\system32\MRT
2015-04-27 21:03:52 ----AC---- C:\Windows\system32\MRT.exe
2015-04-27 20:57:18 ----SHD---- C:\System Volume Information
2015-04-27 20:54:33 ----DC---- C:\Windows\system32\catroot2
2015-04-17 20:57:26 ----C---- C:\Windows\system.ini
2015-04-17 20:57:19 ----DC---- C:\Windows\system32\drivers\etc
2015-04-17 20:51:44 ----DC---- C:\Windows\SYSWOW64\drivers
2015-04-17 20:51:42 ----DC---- C:\Program Files (x86)\Common Files
2015-04-17 19:26:22 ----AC---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-17 19:23:01 ----DC---- C:\ProgramData\Skype
2015-03-29 23:10:28 ----DC---- C:\Windows\system32\Tasks
2015-03-29 23:09:52 ----DC---- C:\Windows\SYSWOW64\RTCOM
2015-03-29 20:51:47 ----DC---- C:\Windows\Logs
2015-03-29 20:16:16 ----DC---- C:\Boot
2015-03-29 20:10:20 ----DC---- C:\Program Files\Windows Media Player
2015-03-29 20:10:20 ----DC---- C:\Program Files (x86)\Windows Media Player
2015-03-29 20:10:19 ----DC---- C:\Windows\SYSWOW64\Dism
2015-03-29 20:10:16 ----DC---- C:\Windows\system32\Dism
2015-03-29 20:10:00 ----D---- C:\Windows\system32\Boot
2015-03-29 20:09:59 ----DC---- C:\Windows\system32\CodeIntegrity
2015-03-29 18:17:36 ----DC---- C:\Windows\ModemLogs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2015-03-11 213984]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-03-11 344544]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-04-03 137184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2015-03-20 40928]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2015-03-11 162784]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2015-03-20 67040]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-04-09 284128]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2015-04-15 256992]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2015-04-07 291296]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 40816]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-10-04 129512]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-10-04 394728]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-04 2770944]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-12-31 138024]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-11-03 12310112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-11-03 317440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys []
S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys []
S3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys []
S3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys []
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys []
S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys []
S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys []
S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-10-19 80384]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-14 48488]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2011-03-04 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2011-12-01 92800]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-04-15 1517480]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-04-15 3438032]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-04-15 311792]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2013-11-26 8192]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17 268464]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-14 1492840]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-22 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-27 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-24 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Zuzka at 2015-04-28 19:38:44
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 75 GB (61%) free of 122 GB
Total RAM: 1952 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:38:56, on 28.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\FaceLogon\smartlogon.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\Down2Home\Down2Home.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Zuzka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: Down2Home.lnk = C:\Program Files (x86)\Down2Home\Down2Home.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 10551 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-49f9-df00fb1f3444 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\FaceLogon\smartlogon.exe" -switch-3be2f036c43042cdb03588591c9325c3
"C:\Windows\system32\FBAgent.exe"
C:\Windows\system32\WLANExt.exe 5382960
\??\C:\Windows\system32\conhost.exe "-1224117123-1461304136-1210141135-243024695-1671482792-693983465-1748132687-2064893001
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
WLIDSvcM.exe 2532
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
ATKOSD.exe
KBFiltr.exe
WDC.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Down2Home\Down2Home.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
ctfmon.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\system32\svchost.exe -k netsvcs
taskeng.exe {20D5944D-D720-4FAF-99B3-6CD5484D0CD9}
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
taskmgr.exe /2
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Zuzka\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\ZEON/PDF,version=2.0]
"Description"=
"Path"=C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default\extensions\
{3d7eb24f-2740-49df-8937-200b1cc08f8a}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-11-03 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-11-03 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-11-03 416024]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2010-12-31 2587944]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2012-03-28 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [2011-07-29 737104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_305_Plugin.exe -update plugin []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10 20922016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicMasterTray]
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2012-09-23 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe [2012-03-28 12862]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2011-10-20 3331312]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22 5716608]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-07 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2011-10-19 2319536]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-04-15 3745232]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
Down2Home.lnk - C:\Program Files (x86)\Down2Home\Down2Home.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-11-03 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-28 18:41:34 ----DC---- C:\AdwCleaner
2015-04-28 18:25:42 ----DC---- C:\Program Files\trend micro
2015-04-28 18:25:40 ----DC---- C:\rsit
2015-04-28 17:44:37 ----DC---- C:\Program Files (x86)\Mozilla Firefox
2015-04-28 16:33:46 ----DC---- C:\Program Files (x86)\MozBackup
2015-04-27 20:55:26 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-04-27 20:55:26 ----A---- C:\Windows\system32\wpdshext.dll
2015-04-27 20:55:25 ----A---- C:\Windows\system32\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-04-27 20:55:24 ----A---- C:\Windows\system32\dwmapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups2.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wucltux.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-27 20:55:21 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-04-27 20:52:10 ----A---- C:\Windows\system32\iernonce.dll
2015-04-27 20:52:10 ----A---- C:\Windows\system32\ie4uinit.exe
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-04-27 20:52:09 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\urlmon.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\iedkcs32.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-27 20:52:06 ----A---- C:\Windows\system32\msfeeds.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\dxtrans.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\iesetup.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\ieapfltr.dll
2015-04-27 20:52:04 ----A---- C:\Windows\system32\iertutil.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\jsproxy.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\ieUnatt.exe
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieui.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieframe.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\dxtmsft.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmled.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\wininet.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\vbscript.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9diag.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9.dll
2015-04-27 20:51:58 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\msrating.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\mshtml.dll
2015-04-27 20:51:37 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\KernelBase.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\wow64win.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\schannel.dll
2015-04-27 20:51:32 ----A---- C:\Windows\system32\lsasrv.dll
2015-04-27 20:51:31 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\wow64.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\srcore.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\conhost.exe
2015-04-27 20:51:30 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\winsrv.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\rstrui.exe
2015-04-27 20:51:30 ----A---- C:\Windows\system32\kerberos.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\sspicli.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\srclient.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\smss.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\lsass.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\auditpol.exe
2015-04-27 20:51:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\wow64cpu.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\sspisrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\csrsrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\credssp.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\user.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\adtschema.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msaudite.dll
2015-04-27 20:39:49 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-27 20:39:39 ----A---- C:\Windows\system32\clfs.sys
2015-04-27 20:39:37 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\system32\gdi32.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\acmigration.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\invagent.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\devinv.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\aeinv.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepic.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepdu.dll
2015-04-27 20:34:10 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-27 20:34:10 ----A---- C:\Windows\system32\msxml3.dll
2015-04-27 20:34:09 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-27 20:34:09 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-27 20:12:41 ----DC---- C:\Program Files (x86)\Down2Home
2015-04-27 19:29:06 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-17 21:02:47 ----SHDC---- C:\$RECYCLE.BIN
2015-04-17 21:02:39 ----DC---- C:\Windows\temp
2015-04-17 21:02:37 ----AC---- C:\ComboFix.txt
2015-04-17 20:44:54 ----AC---- C:\Windows\zip.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWSC.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWREG.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\sed.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\PEV.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\NIRCMD.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\MBR.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\grep.exe
2015-04-17 20:44:39 ----DC---- C:\Qoobox
2015-04-17 20:43:36 ----DC---- C:\Windows\erdnt
2015-04-17 20:18:46 ----DC---- C:\ProgramData\AutoKMS
2015-04-17 20:13:31 ----DC---- C:\Users\Zuzka\AppData\Roaming\AVG2015
2015-04-17 20:11:57 ----DC---- C:\ProgramData\AVG2015
2015-04-17 20:11:57 ----DC---- C:\$AVG
2015-04-17 19:56:26 ----DC---- C:\Program Files (x86)\AVG
2015-04-15 13:06:02 ----AC---- C:\Windows\system32\drivers\avgldx64.sys
2015-04-09 14:11:14 ----AC---- C:\Windows\system32\drivers\avgidsdrivera.sys
2015-04-07 12:39:26 ----AC---- C:\Windows\system32\drivers\avgtdia.sys
2015-04-03 09:34:12 ----AC---- C:\Windows\system32\drivers\avgmfx64.sys
2015-03-29 20:54:48 ----DC---- C:\Config.Msi
2015-03-29 20:51:45 ----DC---- C:\47ed3544012e3891d1e8a8cddbefbd8f
2015-03-29 20:50:13 ----SDC---- C:\Windows\SYSWOW64\GWX
2015-03-29 20:50:11 ----SDC---- C:\Windows\system32\GWX
2015-03-29 18:35:33 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-29 18:35:33 ----A---- C:\Windows\system32\blackbox.dll
2015-03-29 18:35:32 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-29 18:35:31 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-29 18:35:30 ----A---- C:\Windows\system32\wmp.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-29 18:35:29 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-29 18:35:28 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\crypt32.dll
2015-03-29 18:35:25 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-29 18:35:25 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-29 18:35:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-29 18:35:24 ----A---- C:\Windows\system32\quartz.dll
2015-03-29 18:35:23 ----A---- C:\Windows\system32\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\system32\cryptui.dll
2015-03-29 18:35:20 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-29 18:35:20 ----A---- C:\Windows\system32\winresume.exe
2015-03-29 18:35:20 ----A---- C:\Windows\system32\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-29 18:35:19 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\msscp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\mf.dll
2015-03-29 18:35:16 ----A---- C:\Windows\system32\winload.exe
2015-03-29 18:35:15 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-29 18:35:14 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\ci.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-29 18:35:13 ----A---- C:\Windows\system32\audiodg.exe
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\qdvd.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-29 18:35:11 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\pcadm.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-29 18:35:10 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcalua.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\appidapi.dll
2015-03-29 18:35:08 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-29 18:35:08 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\EncDump.dll
2015-03-29 18:35:07 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-29 18:35:04 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-29 18:35:04 ----A---- C:\Windows\system32\spwmp.dll
2015-03-29 18:35:03 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-29 18:35:02 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-29 18:35:02 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-29 18:35:00 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-29 18:35:00 ----A---- C:\Windows\system32\mferror.dll
======List of files/folders modified in the last 1 month======
2015-04-28 19:30:15 ----DC---- C:\Windows\system32\config
2015-04-28 18:49:51 ----A---- C:\Windows\SYSWOW64\log.txt
2015-04-28 18:47:49 ----AC---- C:\Windows\SYSWOW64\acovcnt.exe
2015-04-28 18:47:35 ----DC---- C:\Windows
2015-04-28 18:45:16 ----DC---- C:\ProgramData
2015-04-28 18:25:42 ----RDC---- C:\Program Files
2015-04-28 18:14:14 ----DC---- C:\ProgramData\MFAData
2015-04-28 17:44:37 ----RDC---- C:\Program Files (x86)
2015-04-28 17:29:55 ----DC---- C:\Windows\inf
2015-04-28 17:29:55 ----DC---- C:\Windows\debug
2015-04-28 16:23:52 ----DC---- C:\Windows\AppCompat
2015-04-28 16:07:18 ----SHDC---- C:\Windows\Installer
2015-04-27 22:41:38 ----DC---- C:\Windows\Microsoft.NET
2015-04-27 22:23:55 ----RSDC---- C:\Windows\assembly
2015-04-27 22:13:25 ----AC---- C:\Windows\system32\AutoRunFilter.ini
2015-04-27 22:12:46 ----D---- C:\Windows\winsxs
2015-04-27 22:10:43 ----DC---- C:\Windows\SysWOW64
2015-04-27 22:10:43 ----DC---- C:\Windows\System32
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sr-Latn-CS
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sl-SI
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sk-SK
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\ro-RO
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\pl-PL
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lv-LV
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lt-LT
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hu-HU
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hr-HR
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\et-EE
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\cs-CZ
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\bg-BG
2015-04-27 22:10:42 ----D---- C:\Windows\system32\AdvancedInstallers
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sr-Latn-CS
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sl-SI
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sk-SK
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\ro-RO
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\pl-PL
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lv-LV
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lt-LT
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hu-HU
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hr-HR
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\et-EE
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\cs-CZ
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\bg-BG
2015-04-27 22:10:41 ----DC---- C:\Windows\PolicyDefinitions
2015-04-27 22:10:39 ----SDC---- C:\Windows\system32\CompatTel
2015-04-27 22:10:38 ----DC---- C:\Windows\system32\appraiser
2015-04-27 22:10:38 ----DC---- C:\Windows\AppPatch
2015-04-27 22:10:33 ----DC---- C:\Windows\SYSWOW64\en-US
2015-04-27 22:10:31 ----DC---- C:\Windows\system32\en-US
2015-04-27 22:10:28 ----DC---- C:\Windows\system32\drivers
2015-04-27 22:10:26 ----DC---- C:\Program Files\Internet Explorer
2015-04-27 22:10:19 ----DC---- C:\Program Files (x86)\Internet Explorer
2015-04-27 22:10:15 ----DC---- C:\Windows\system32\drivers\UMDF
2015-04-27 22:10:15 ----D---- C:\Windows\system32\DriverStore
2015-04-27 21:47:07 ----DC---- C:\Windows\SYSWOW64\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\drivers\en-US
2015-04-27 21:21:11 ----AC---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-27 21:20:57 ----AC---- C:\Windows\system32\PerfStringBackup.INI
2015-04-27 21:11:19 ----DC---- C:\Windows\system32\MRT
2015-04-27 21:03:52 ----AC---- C:\Windows\system32\MRT.exe
2015-04-27 20:57:18 ----SHD---- C:\System Volume Information
2015-04-27 20:54:33 ----DC---- C:\Windows\system32\catroot2
2015-04-17 20:57:26 ----C---- C:\Windows\system.ini
2015-04-17 20:57:19 ----DC---- C:\Windows\system32\drivers\etc
2015-04-17 20:51:44 ----DC---- C:\Windows\SYSWOW64\drivers
2015-04-17 20:51:42 ----DC---- C:\Program Files (x86)\Common Files
2015-04-17 19:26:22 ----AC---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-17 19:23:01 ----DC---- C:\ProgramData\Skype
2015-03-29 23:10:28 ----DC---- C:\Windows\system32\Tasks
2015-03-29 23:09:52 ----DC---- C:\Windows\SYSWOW64\RTCOM
2015-03-29 20:51:47 ----DC---- C:\Windows\Logs
2015-03-29 20:16:16 ----DC---- C:\Boot
2015-03-29 20:10:20 ----DC---- C:\Program Files\Windows Media Player
2015-03-29 20:10:20 ----DC---- C:\Program Files (x86)\Windows Media Player
2015-03-29 20:10:19 ----DC---- C:\Windows\SYSWOW64\Dism
2015-03-29 20:10:16 ----DC---- C:\Windows\system32\Dism
2015-03-29 20:10:00 ----D---- C:\Windows\system32\Boot
2015-03-29 20:09:59 ----DC---- C:\Windows\system32\CodeIntegrity
2015-03-29 18:17:36 ----DC---- C:\Windows\ModemLogs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2015-03-11 213984]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-03-11 344544]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-04-03 137184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2015-03-20 40928]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2015-03-11 162784]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2015-03-20 67040]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-04-09 284128]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2015-04-15 256992]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2015-04-07 291296]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 40816]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-10-04 129512]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-10-04 394728]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-04 2770944]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-12-31 138024]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-11-03 12310112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-11-03 317440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys []
S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys []
S3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys []
S3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys []
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys []
S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys []
S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys []
S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-10-19 80384]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-14 48488]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2011-03-04 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2011-12-01 92800]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-04-15 1517480]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-04-15 3438032]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-04-15 311792]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2013-11-26 8192]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17 268464]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-14 1492840]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-22 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-27 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-24 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
# AdwCleaner v4.202 - Log vytvořen 28/04/2015 v 20:19:25
# Aktualizováno 23/04/2015 by Xplode
# Databáze : 2015-04-27.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : Zuzka - ZUZKA-PC
# Spuštěno z : C:\Users\Zuzka\Desktop\adwcleaner_4.202.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
***** [ Naplánované úlohy ] *****
***** [ Zástupci ] *****
***** [ Registry ] *****
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Mozilla Firefox v37.0.2 (x86 cs)
*************************
AdwCleaner[R0].txt - [3843 bytů] - [28/04/2015 18:42:08]
AdwCleaner[R1].txt - [880 bytů] - [28/04/2015 20:17:35]
AdwCleaner[S0].txt - [3637 bytů] - [28/04/2015 18:45:15]
AdwCleaner[S1].txt - [806 bytů] - [28/04/2015 20:19:25]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [863 bytů] ##########
# Aktualizováno 23/04/2015 by Xplode
# Databáze : 2015-04-27.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : Zuzka - ZUZKA-PC
# Spuštěno z : C:\Users\Zuzka\Desktop\adwcleaner_4.202.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
***** [ Naplánované úlohy ] *****
***** [ Zástupci ] *****
***** [ Registry ] *****
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Mozilla Firefox v37.0.2 (x86 cs)
*************************
AdwCleaner[R0].txt - [3843 bytů] - [28/04/2015 18:42:08]
AdwCleaner[R1].txt - [880 bytů] - [28/04/2015 20:17:35]
AdwCleaner[S0].txt - [3637 bytů] - [28/04/2015 18:45:15]
AdwCleaner[S1].txt - [806 bytů] - [28/04/2015 20:19:25]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [863 bytů] ##########
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.:files
C:\Program Files (x86)\Google\GoogleToolbarNotifier
C:\Windows\SYSWOW64\acovcnt.exe
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
Logfile of random's system information tool 1.10 (written by random/random)
Run by Zuzka at 2015-04-28 21:35:17
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 75 GB (61%) free of 122 GB
Total RAM: 1952 MB (25% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:22, on 28.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Down2Home\Down2Home.exe
C:\Program Files (x86)\ASUS\APRP\aprp.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Zuzka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: Down2Home.lnk = C:\Program Files (x86)\Down2Home\Down2Home.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 10380 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-2cf3-027871cb8640 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
C:\Windows\system32\WLANExt.exe 4525248
\??\C:\Windows\system32\conhost.exe "-5209975691829567887166858077126129765682634715159137381343106112-1768669546
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
taskeng.exe {95996C2C-023C-4FB6-A7A7-8AD0B6A09E31}
C:\Windows\System32\spoolsv.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
ATKOSD.exe
taskeng.exe {8E13B040-2884-4190-8155-42597D3D904E}
KBFiltr.exe
WDC.exe
"C:\Windows\AsScrPro.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
WLIDSvcM.exe 2172
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Down2Home\Down2Home.exe"
"C:\Program Files (x86)\ASUS\APRP\aprp.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
ctfmon.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Users\Zuzka\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\ZEON/PDF,version=2.0]
"Description"=
"Path"=C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default\extensions\
{3d7eb24f-2740-49df-8937-200b1cc08f8a}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-11-03 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-11-03 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-11-03 416024]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2010-12-31 2587944]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2012-03-28 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [2011-07-29 737104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_305_Plugin.exe -update plugin []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10 20922016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicMasterTray]
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe [2012-03-28 12862]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2011-10-20 3331312]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22 5716608]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-07 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2011-10-19 2319536]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-04-15 3745232]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
Down2Home.lnk - C:\Program Files (x86)\Down2Home\Down2Home.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-11-03 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-28 21:33:20 ----AC---- C:\Windows\SYSWOW64\acovcnt.exe
2015-04-28 21:27:17 ----DC---- C:\_OTM
2015-04-28 18:41:34 ----DC---- C:\AdwCleaner
2015-04-28 18:25:42 ----DC---- C:\Program Files\trend micro
2015-04-28 18:25:40 ----DC---- C:\rsit
2015-04-28 17:44:37 ----DC---- C:\Program Files (x86)\Mozilla Firefox
2015-04-28 16:33:46 ----DC---- C:\Program Files (x86)\MozBackup
2015-04-27 20:55:26 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-04-27 20:55:26 ----A---- C:\Windows\system32\wpdshext.dll
2015-04-27 20:55:25 ----A---- C:\Windows\system32\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-04-27 20:55:24 ----A---- C:\Windows\system32\dwmapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups2.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wucltux.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-27 20:55:21 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-04-27 20:52:10 ----A---- C:\Windows\system32\iernonce.dll
2015-04-27 20:52:10 ----A---- C:\Windows\system32\ie4uinit.exe
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-04-27 20:52:09 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\urlmon.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\iedkcs32.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-27 20:52:06 ----A---- C:\Windows\system32\msfeeds.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\dxtrans.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\iesetup.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\ieapfltr.dll
2015-04-27 20:52:04 ----A---- C:\Windows\system32\iertutil.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\jsproxy.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\ieUnatt.exe
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieui.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieframe.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\dxtmsft.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmled.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\wininet.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\vbscript.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9diag.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9.dll
2015-04-27 20:51:58 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\msrating.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\mshtml.dll
2015-04-27 20:51:37 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\KernelBase.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\wow64win.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\schannel.dll
2015-04-27 20:51:32 ----A---- C:\Windows\system32\lsasrv.dll
2015-04-27 20:51:31 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\wow64.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\srcore.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\conhost.exe
2015-04-27 20:51:30 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\winsrv.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\rstrui.exe
2015-04-27 20:51:30 ----A---- C:\Windows\system32\kerberos.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\sspicli.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\srclient.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\smss.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\lsass.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\auditpol.exe
2015-04-27 20:51:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\wow64cpu.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\sspisrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\csrsrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\credssp.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\user.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\adtschema.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msaudite.dll
2015-04-27 20:39:49 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-27 20:39:39 ----A---- C:\Windows\system32\clfs.sys
2015-04-27 20:39:37 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\system32\gdi32.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\acmigration.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\invagent.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\devinv.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\aeinv.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepic.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepdu.dll
2015-04-27 20:34:10 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-27 20:34:10 ----A---- C:\Windows\system32\msxml3.dll
2015-04-27 20:34:09 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-27 20:34:09 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-27 20:12:41 ----DC---- C:\Program Files (x86)\Down2Home
2015-04-27 19:29:06 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-17 21:02:47 ----SHDC---- C:\$RECYCLE.BIN
2015-04-17 21:02:39 ----DC---- C:\Windows\temp
2015-04-17 21:02:37 ----AC---- C:\ComboFix.txt
2015-04-17 20:44:54 ----AC---- C:\Windows\zip.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWSC.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWREG.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\sed.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\PEV.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\NIRCMD.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\MBR.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\grep.exe
2015-04-17 20:44:39 ----DC---- C:\Qoobox
2015-04-17 20:43:36 ----DC---- C:\Windows\erdnt
2015-04-17 20:18:46 ----DC---- C:\ProgramData\AutoKMS
2015-04-17 20:13:31 ----DC---- C:\Users\Zuzka\AppData\Roaming\AVG2015
2015-04-17 20:11:57 ----DC---- C:\ProgramData\AVG2015
2015-04-17 20:11:57 ----DC---- C:\$AVG
2015-04-17 19:56:26 ----DC---- C:\Program Files (x86)\AVG
2015-04-15 13:06:02 ----AC---- C:\Windows\system32\drivers\avgldx64.sys
2015-04-09 14:11:14 ----AC---- C:\Windows\system32\drivers\avgidsdrivera.sys
2015-04-07 12:39:26 ----AC---- C:\Windows\system32\drivers\avgtdia.sys
2015-04-03 09:34:12 ----AC---- C:\Windows\system32\drivers\avgmfx64.sys
2015-03-29 20:54:48 ----DC---- C:\Config.Msi
2015-03-29 20:51:45 ----DC---- C:\47ed3544012e3891d1e8a8cddbefbd8f
2015-03-29 20:50:13 ----SDC---- C:\Windows\SYSWOW64\GWX
2015-03-29 20:50:11 ----SDC---- C:\Windows\system32\GWX
2015-03-29 18:35:33 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-29 18:35:33 ----A---- C:\Windows\system32\blackbox.dll
2015-03-29 18:35:32 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-29 18:35:31 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-29 18:35:30 ----A---- C:\Windows\system32\wmp.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-29 18:35:29 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-29 18:35:28 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\crypt32.dll
2015-03-29 18:35:25 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-29 18:35:25 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-29 18:35:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-29 18:35:24 ----A---- C:\Windows\system32\quartz.dll
2015-03-29 18:35:23 ----A---- C:\Windows\system32\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\system32\cryptui.dll
2015-03-29 18:35:20 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-29 18:35:20 ----A---- C:\Windows\system32\winresume.exe
2015-03-29 18:35:20 ----A---- C:\Windows\system32\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-29 18:35:19 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\msscp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\mf.dll
2015-03-29 18:35:16 ----A---- C:\Windows\system32\winload.exe
2015-03-29 18:35:15 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-29 18:35:14 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\ci.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-29 18:35:13 ----A---- C:\Windows\system32\audiodg.exe
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\qdvd.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-29 18:35:11 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\pcadm.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-29 18:35:10 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcalua.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\appidapi.dll
2015-03-29 18:35:08 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-29 18:35:08 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\EncDump.dll
2015-03-29 18:35:07 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-29 18:35:04 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-29 18:35:04 ----A---- C:\Windows\system32\spwmp.dll
2015-03-29 18:35:03 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-29 18:35:02 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-29 18:35:02 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-29 18:35:00 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-29 18:35:00 ----A---- C:\Windows\system32\mferror.dll
======List of files/folders modified in the last 1 month======
2015-04-28 21:33:20 ----DC---- C:\Windows\SysWOW64
2015-04-28 21:31:23 ----DC---- C:\Windows\system32\config
2015-04-28 21:27:23 ----DC---- C:\Program Files (x86)\Google
2015-04-28 20:23:33 ----A---- C:\Windows\SYSWOW64\log.txt
2015-04-28 20:21:31 ----DC---- C:\Windows\inf
2015-04-28 20:14:13 ----DC---- C:\ProgramData\MFAData
2015-04-28 18:47:35 ----DC---- C:\Windows
2015-04-28 18:45:16 ----DC---- C:\ProgramData
2015-04-28 18:25:42 ----RDC---- C:\Program Files
2015-04-28 17:44:37 ----RDC---- C:\Program Files (x86)
2015-04-28 17:29:55 ----DC---- C:\Windows\debug
2015-04-28 16:23:52 ----DC---- C:\Windows\AppCompat
2015-04-28 16:07:18 ----SHDC---- C:\Windows\Installer
2015-04-27 22:41:38 ----DC---- C:\Windows\Microsoft.NET
2015-04-27 22:23:55 ----RSDC---- C:\Windows\assembly
2015-04-27 22:13:25 ----AC---- C:\Windows\system32\AutoRunFilter.ini
2015-04-27 22:12:46 ----D---- C:\Windows\winsxs
2015-04-27 22:10:43 ----DC---- C:\Windows\System32
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sr-Latn-CS
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sl-SI
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sk-SK
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\ro-RO
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\pl-PL
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lv-LV
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lt-LT
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hu-HU
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hr-HR
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\et-EE
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\cs-CZ
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\bg-BG
2015-04-27 22:10:42 ----D---- C:\Windows\system32\AdvancedInstallers
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sr-Latn-CS
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sl-SI
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sk-SK
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\ro-RO
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\pl-PL
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lv-LV
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lt-LT
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hu-HU
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hr-HR
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\et-EE
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\cs-CZ
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\bg-BG
2015-04-27 22:10:41 ----DC---- C:\Windows\PolicyDefinitions
2015-04-27 22:10:39 ----SDC---- C:\Windows\system32\CompatTel
2015-04-27 22:10:38 ----DC---- C:\Windows\system32\appraiser
2015-04-27 22:10:38 ----DC---- C:\Windows\AppPatch
2015-04-27 22:10:33 ----DC---- C:\Windows\SYSWOW64\en-US
2015-04-27 22:10:31 ----DC---- C:\Windows\system32\en-US
2015-04-27 22:10:28 ----DC---- C:\Windows\system32\drivers
2015-04-27 22:10:26 ----DC---- C:\Program Files\Internet Explorer
2015-04-27 22:10:19 ----DC---- C:\Program Files (x86)\Internet Explorer
2015-04-27 22:10:15 ----DC---- C:\Windows\system32\drivers\UMDF
2015-04-27 22:10:15 ----D---- C:\Windows\system32\DriverStore
2015-04-27 21:47:07 ----DC---- C:\Windows\SYSWOW64\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\drivers\en-US
2015-04-27 21:21:11 ----AC---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-27 21:20:57 ----AC---- C:\Windows\system32\PerfStringBackup.INI
2015-04-27 21:11:19 ----DC---- C:\Windows\system32\MRT
2015-04-27 21:03:52 ----AC---- C:\Windows\system32\MRT.exe
2015-04-27 20:57:18 ----SHD---- C:\System Volume Information
2015-04-27 20:54:33 ----DC---- C:\Windows\system32\catroot2
2015-04-17 20:57:26 ----C---- C:\Windows\system.ini
2015-04-17 20:57:19 ----DC---- C:\Windows\system32\drivers\etc
2015-04-17 20:51:44 ----DC---- C:\Windows\SYSWOW64\drivers
2015-04-17 20:51:42 ----DC---- C:\Program Files (x86)\Common Files
2015-04-17 19:26:22 ----AC---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-17 19:23:01 ----DC---- C:\ProgramData\Skype
2015-03-29 23:10:28 ----DC---- C:\Windows\system32\Tasks
2015-03-29 23:09:52 ----DC---- C:\Windows\SYSWOW64\RTCOM
2015-03-29 20:51:47 ----DC---- C:\Windows\Logs
2015-03-29 20:16:16 ----DC---- C:\Boot
2015-03-29 20:10:20 ----DC---- C:\Program Files\Windows Media Player
2015-03-29 20:10:20 ----DC---- C:\Program Files (x86)\Windows Media Player
2015-03-29 20:10:19 ----DC---- C:\Windows\SYSWOW64\Dism
2015-03-29 20:10:16 ----DC---- C:\Windows\system32\Dism
2015-03-29 20:10:00 ----D---- C:\Windows\system32\Boot
2015-03-29 20:09:59 ----DC---- C:\Windows\system32\CodeIntegrity
2015-03-29 18:17:36 ----DC---- C:\Windows\ModemLogs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2015-03-11 213984]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-03-11 344544]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-04-03 137184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2015-03-20 40928]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2015-03-11 162784]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2015-03-20 67040]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-04-09 284128]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2015-04-15 256992]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2015-04-07 291296]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 40816]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-10-04 129512]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-10-04 394728]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-04 2770944]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-12-31 138024]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-11-03 12310112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-11-03 317440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys []
S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys []
S3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys []
S3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys []
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys []
S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys []
S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys []
S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-10-19 80384]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-14 48488]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2011-03-04 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2011-12-01 92800]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-04-15 1517480]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-04-15 3438032]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-04-15 311792]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2013-11-26 8192]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17 268464]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-14 1492840]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-22 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-27 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-24 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Run by Zuzka at 2015-04-28 21:35:17
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 75 GB (61%) free of 122 GB
Total RAM: 1952 MB (25% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:22, on 28.4.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17728)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Down2Home\Down2Home.exe
C:\Program Files (x86)\ASUS\APRP\aprp.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Zuzka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - Global Startup: Down2Home.lnk = C:\Program Files (x86)\Down2Home\Down2Home.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 10380 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-2cf3-027871cb8640 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
C:\Windows\system32\WLANExt.exe 4525248
\??\C:\Windows\system32\conhost.exe "-5209975691829567887166858077126129765682634715159137381343106112-1768669546
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
taskeng.exe {95996C2C-023C-4FB6-A7A7-8AD0B6A09E31}
C:\Windows\System32\spoolsv.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
ATKOSD.exe
taskeng.exe {8E13B040-2884-4190-8155-42597D3D904E}
KBFiltr.exe
WDC.exe
"C:\Windows\AsScrPro.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
WLIDSvcM.exe 2172
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Down2Home\Down2Home.exe"
"C:\Program Files (x86)\ASUS\APRP\aprp.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
ctfmon.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Users\Zuzka\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\ZEON/PDF,version=2.0]
"Description"=
"Path"=C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
C:\Users\Zuzka\AppData\Roaming\Mozilla\Firefox\Profiles\dlcoufrb.default\extensions\
{3d7eb24f-2740-49df-8937-200b1cc08f8a}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-11-03 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-11-03 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-11-03 416024]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2010-12-31 2587944]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2012-03-28 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [2011-07-29 737104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_305_Plugin.exe -update plugin []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10 20922016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicMasterTray]
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]
C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe [2012-03-28 12862]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2011-10-20 3331312]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22 5716608]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-07 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2011-10-19 2319536]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-04-15 3745232]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
Down2Home.lnk - C:\Program Files (x86)\Down2Home\Down2Home.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-11-03 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-04-28 21:33:20 ----AC---- C:\Windows\SYSWOW64\acovcnt.exe
2015-04-28 21:27:17 ----DC---- C:\_OTM
2015-04-28 18:41:34 ----DC---- C:\AdwCleaner
2015-04-28 18:25:42 ----DC---- C:\Program Files\trend micro
2015-04-28 18:25:40 ----DC---- C:\rsit
2015-04-28 17:44:37 ----DC---- C:\Program Files (x86)\Mozilla Firefox
2015-04-28 16:33:46 ----DC---- C:\Program Files (x86)\MozBackup
2015-04-27 20:55:26 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-04-27 20:55:26 ----A---- C:\Windows\system32\wpdshext.dll
2015-04-27 20:55:25 ----A---- C:\Windows\system32\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-04-27 20:55:24 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-04-27 20:55:24 ----A---- C:\Windows\system32\dwmapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups2.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wups.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wudriver.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wucltux.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapp.exe
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wuapi.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-27 20:55:22 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-27 20:55:21 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-04-27 20:52:11 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-04-27 20:52:11 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-04-27 20:52:10 ----A---- C:\Windows\system32\iernonce.dll
2015-04-27 20:52:10 ----A---- C:\Windows\system32\ie4uinit.exe
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-04-27 20:52:09 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-04-27 20:52:09 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-04-27 20:52:07 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\urlmon.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-04-27 20:52:07 ----A---- C:\Windows\system32\iedkcs32.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-04-27 20:52:06 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-27 20:52:06 ----A---- C:\Windows\system32\msfeeds.dll
2015-04-27 20:52:06 ----A---- C:\Windows\system32\dxtrans.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\iesetup.dll
2015-04-27 20:52:05 ----A---- C:\Windows\system32\ieapfltr.dll
2015-04-27 20:52:04 ----A---- C:\Windows\system32\iertutil.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-04-27 20:52:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-04-27 20:52:02 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\jsproxy.dll
2015-04-27 20:52:02 ----A---- C:\Windows\system32\ieUnatt.exe
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieui.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\ieframe.dll
2015-04-27 20:52:01 ----A---- C:\Windows\system32\dxtmsft.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-04-27 20:52:00 ----A---- C:\Windows\system32\mshtmled.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\wininet.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\vbscript.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9diag.dll
2015-04-27 20:51:59 ----A---- C:\Windows\system32\jscript9.dll
2015-04-27 20:51:58 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\msrating.dll
2015-04-27 20:51:57 ----A---- C:\Windows\system32\mshtml.dll
2015-04-27 20:51:37 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-04-27 20:51:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\ntdll.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\KernelBase.dll
2015-04-27 20:51:35 ----A---- C:\Windows\system32\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-04-27 20:51:33 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\wow64win.dll
2015-04-27 20:51:33 ----A---- C:\Windows\system32\schannel.dll
2015-04-27 20:51:32 ----A---- C:\Windows\system32\lsasrv.dll
2015-04-27 20:51:31 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\wow64.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\srcore.dll
2015-04-27 20:51:31 ----A---- C:\Windows\system32\conhost.exe
2015-04-27 20:51:30 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\winsrv.dll
2015-04-27 20:51:30 ----A---- C:\Windows\system32\rstrui.exe
2015-04-27 20:51:30 ----A---- C:\Windows\system32\kerberos.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\wdigest.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\TSpkg.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\sspicli.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\srclient.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\smss.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\ncrypt.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\msv1_0.dll
2015-04-27 20:51:29 ----A---- C:\Windows\system32\lsass.exe
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-04-27 20:51:29 ----A---- C:\Windows\system32\auditpol.exe
2015-04-27 20:51:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-04-27 20:51:28 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\wow64cpu.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\sspisrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\secur32.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\ntvdm64.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\csrsrv.dll
2015-04-27 20:51:28 ----A---- C:\Windows\system32\credssp.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-27 20:51:27 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\user.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\apisetschema.dll
2015-04-27 20:51:27 ----A---- C:\Windows\system32\adtschema.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msobjs.dll
2015-04-27 20:51:26 ----A---- C:\Windows\system32\msaudite.dll
2015-04-27 20:39:49 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-27 20:39:39 ----A---- C:\Windows\system32\clfs.sys
2015-04-27 20:39:37 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-27 20:34:17 ----A---- C:\Windows\system32\gdi32.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-04-27 20:34:14 ----A---- C:\Windows\system32\acmigration.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\invagent.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\devinv.dll
2015-04-27 20:34:13 ----A---- C:\Windows\system32\aeinv.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepic.dll
2015-04-27 20:34:12 ----A---- C:\Windows\system32\aepdu.dll
2015-04-27 20:34:10 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-27 20:34:10 ----A---- C:\Windows\system32\msxml3.dll
2015-04-27 20:34:09 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-27 20:34:09 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-27 20:12:41 ----DC---- C:\Program Files (x86)\Down2Home
2015-04-27 19:29:06 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-17 21:02:47 ----SHDC---- C:\$RECYCLE.BIN
2015-04-17 21:02:39 ----DC---- C:\Windows\temp
2015-04-17 21:02:37 ----AC---- C:\ComboFix.txt
2015-04-17 20:44:54 ----AC---- C:\Windows\zip.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWSC.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\SWREG.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\sed.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\PEV.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\NIRCMD.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\MBR.exe
2015-04-17 20:44:54 ----AC---- C:\Windows\grep.exe
2015-04-17 20:44:39 ----DC---- C:\Qoobox
2015-04-17 20:43:36 ----DC---- C:\Windows\erdnt
2015-04-17 20:18:46 ----DC---- C:\ProgramData\AutoKMS
2015-04-17 20:13:31 ----DC---- C:\Users\Zuzka\AppData\Roaming\AVG2015
2015-04-17 20:11:57 ----DC---- C:\ProgramData\AVG2015
2015-04-17 20:11:57 ----DC---- C:\$AVG
2015-04-17 19:56:26 ----DC---- C:\Program Files (x86)\AVG
2015-04-15 13:06:02 ----AC---- C:\Windows\system32\drivers\avgldx64.sys
2015-04-09 14:11:14 ----AC---- C:\Windows\system32\drivers\avgidsdrivera.sys
2015-04-07 12:39:26 ----AC---- C:\Windows\system32\drivers\avgtdia.sys
2015-04-03 09:34:12 ----AC---- C:\Windows\system32\drivers\avgmfx64.sys
2015-03-29 20:54:48 ----DC---- C:\Config.Msi
2015-03-29 20:51:45 ----DC---- C:\47ed3544012e3891d1e8a8cddbefbd8f
2015-03-29 20:50:13 ----SDC---- C:\Windows\SYSWOW64\GWX
2015-03-29 20:50:11 ----SDC---- C:\Windows\system32\GWX
2015-03-29 18:35:33 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-29 18:35:33 ----A---- C:\Windows\system32\blackbox.dll
2015-03-29 18:35:32 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-29 18:35:31 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-29 18:35:30 ----A---- C:\Windows\system32\wmp.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-29 18:35:29 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-29 18:35:29 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-29 18:35:28 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-29 18:35:27 ----A---- C:\Windows\system32\crypt32.dll
2015-03-29 18:35:25 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-29 18:35:25 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-29 18:35:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-29 18:35:24 ----A---- C:\Windows\system32\quartz.dll
2015-03-29 18:35:23 ----A---- C:\Windows\system32\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-29 18:35:21 ----A---- C:\Windows\system32\cryptui.dll
2015-03-29 18:35:20 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-29 18:35:20 ----A---- C:\Windows\system32\winresume.exe
2015-03-29 18:35:20 ----A---- C:\Windows\system32\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-29 18:35:19 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-29 18:35:19 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-29 18:35:19 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\msscp.dll
2015-03-29 18:35:18 ----A---- C:\Windows\system32\mf.dll
2015-03-29 18:35:16 ----A---- C:\Windows\system32\winload.exe
2015-03-29 18:35:15 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-29 18:35:14 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\ci.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-29 18:35:14 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-29 18:35:13 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\wintrust.dll
2015-03-29 18:35:13 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-29 18:35:13 ----A---- C:\Windows\system32\audiodg.exe
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-29 18:35:12 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\qdvd.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-29 18:35:12 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-29 18:35:11 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\pcadm.dll
2015-03-29 18:35:11 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-29 18:35:10 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-29 18:35:10 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-29 18:35:09 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\pcalua.exe
2015-03-29 18:35:09 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\mfps.dll
2015-03-29 18:35:09 ----A---- C:\Windows\system32\appidapi.dll
2015-03-29 18:35:08 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-29 18:35:08 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-29 18:35:08 ----A---- C:\Windows\system32\EncDump.dll
2015-03-29 18:35:07 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-29 18:35:04 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-29 18:35:04 ----A---- C:\Windows\system32\spwmp.dll
2015-03-29 18:35:03 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-29 18:35:03 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-29 18:35:02 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-29 18:35:02 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-29 18:35:00 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-29 18:35:00 ----A---- C:\Windows\system32\mferror.dll
======List of files/folders modified in the last 1 month======
2015-04-28 21:33:20 ----DC---- C:\Windows\SysWOW64
2015-04-28 21:31:23 ----DC---- C:\Windows\system32\config
2015-04-28 21:27:23 ----DC---- C:\Program Files (x86)\Google
2015-04-28 20:23:33 ----A---- C:\Windows\SYSWOW64\log.txt
2015-04-28 20:21:31 ----DC---- C:\Windows\inf
2015-04-28 20:14:13 ----DC---- C:\ProgramData\MFAData
2015-04-28 18:47:35 ----DC---- C:\Windows
2015-04-28 18:45:16 ----DC---- C:\ProgramData
2015-04-28 18:25:42 ----RDC---- C:\Program Files
2015-04-28 17:44:37 ----RDC---- C:\Program Files (x86)
2015-04-28 17:29:55 ----DC---- C:\Windows\debug
2015-04-28 16:23:52 ----DC---- C:\Windows\AppCompat
2015-04-28 16:07:18 ----SHDC---- C:\Windows\Installer
2015-04-27 22:41:38 ----DC---- C:\Windows\Microsoft.NET
2015-04-27 22:23:55 ----RSDC---- C:\Windows\assembly
2015-04-27 22:13:25 ----AC---- C:\Windows\system32\AutoRunFilter.ini
2015-04-27 22:12:46 ----D---- C:\Windows\winsxs
2015-04-27 22:10:43 ----DC---- C:\Windows\System32
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sr-Latn-CS
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sl-SI
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\sk-SK
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\ro-RO
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\pl-PL
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lv-LV
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\lt-LT
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hu-HU
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\hr-HR
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\et-EE
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\cs-CZ
2015-04-27 22:10:42 ----DC---- C:\Windows\SYSWOW64\bg-BG
2015-04-27 22:10:42 ----D---- C:\Windows\system32\AdvancedInstallers
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sr-Latn-CS
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sl-SI
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\sk-SK
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\ro-RO
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\pl-PL
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lv-LV
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\lt-LT
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hu-HU
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\hr-HR
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\et-EE
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\cs-CZ
2015-04-27 22:10:41 ----DC---- C:\Windows\system32\bg-BG
2015-04-27 22:10:41 ----DC---- C:\Windows\PolicyDefinitions
2015-04-27 22:10:39 ----SDC---- C:\Windows\system32\CompatTel
2015-04-27 22:10:38 ----DC---- C:\Windows\system32\appraiser
2015-04-27 22:10:38 ----DC---- C:\Windows\AppPatch
2015-04-27 22:10:33 ----DC---- C:\Windows\SYSWOW64\en-US
2015-04-27 22:10:31 ----DC---- C:\Windows\system32\en-US
2015-04-27 22:10:28 ----DC---- C:\Windows\system32\drivers
2015-04-27 22:10:26 ----DC---- C:\Program Files\Internet Explorer
2015-04-27 22:10:19 ----DC---- C:\Program Files (x86)\Internet Explorer
2015-04-27 22:10:15 ----DC---- C:\Windows\system32\drivers\UMDF
2015-04-27 22:10:15 ----D---- C:\Windows\system32\DriverStore
2015-04-27 21:47:07 ----DC---- C:\Windows\SYSWOW64\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\wbem
2015-04-27 21:47:06 ----DC---- C:\Windows\system32\drivers\en-US
2015-04-27 21:21:11 ----AC---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-27 21:20:57 ----AC---- C:\Windows\system32\PerfStringBackup.INI
2015-04-27 21:11:19 ----DC---- C:\Windows\system32\MRT
2015-04-27 21:03:52 ----AC---- C:\Windows\system32\MRT.exe
2015-04-27 20:57:18 ----SHD---- C:\System Volume Information
2015-04-27 20:54:33 ----DC---- C:\Windows\system32\catroot2
2015-04-17 20:57:26 ----C---- C:\Windows\system.ini
2015-04-17 20:57:19 ----DC---- C:\Windows\system32\drivers\etc
2015-04-17 20:51:44 ----DC---- C:\Windows\SYSWOW64\drivers
2015-04-17 20:51:42 ----DC---- C:\Program Files (x86)\Common Files
2015-04-17 19:26:22 ----AC---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-04-17 19:23:01 ----DC---- C:\ProgramData\Skype
2015-03-29 23:10:28 ----DC---- C:\Windows\system32\Tasks
2015-03-29 23:09:52 ----DC---- C:\Windows\SYSWOW64\RTCOM
2015-03-29 20:51:47 ----DC---- C:\Windows\Logs
2015-03-29 20:16:16 ----DC---- C:\Boot
2015-03-29 20:10:20 ----DC---- C:\Program Files\Windows Media Player
2015-03-29 20:10:20 ----DC---- C:\Program Files (x86)\Windows Media Player
2015-03-29 20:10:19 ----DC---- C:\Windows\SYSWOW64\Dism
2015-03-29 20:10:16 ----DC---- C:\Windows\system32\Dism
2015-03-29 20:10:00 ----D---- C:\Windows\system32\Boot
2015-03-29 20:09:59 ----DC---- C:\Windows\system32\CodeIntegrity
2015-03-29 18:17:36 ----DC---- C:\Windows\ModemLogs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2015-03-11 213984]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-03-11 344544]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-04-03 137184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2015-03-20 40928]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2015-03-11 162784]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2015-03-20 67040]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-04-09 284128]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2015-04-15 256992]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2015-04-07 291296]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 40816]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-10-04 129512]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-10-04 394728]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-04 2770944]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-12-31 138024]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-11-03 12310112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-11-03 317440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys []
S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys []
S3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys []
S3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys []
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys []
S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys []
S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys []
S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-10-19 80384]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-14 48488]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2011-03-04 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2011-12-01 92800]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-04-15 1517480]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-04-15 3438032]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-04-15 311792]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2013-11-26 8192]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17 268464]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-14 1492840]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-10-22 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-27 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-24 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
Zatím díky, je to v klidu. Dělalo to nepravidelně, takže po dvou třech dnech pozorování se ozvu.
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
OK. Zatím není zač! 

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
Tak bohužel je stejný stav. Včera večer a dnes v poledne bez problému a teď to samý. Svchost - host process for windows services.
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 29.4.2015
Čas skenování: 19:08:33
Protokol:
Správce: Ano
Verze: 2.01.6.1022
Databáze malwaru: v2015.04.29.04
Databáze rootkitů: v2015.04.21.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Zuzka
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 361602
Uplynulý čas: 30 min, 28 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 3
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-2901497629-216978468-1755851068-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [abade989098106302dd8e6697c87d927],
PUP.Optional.DefaultTab.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kdidombaedgpfiiedeimiebkmbilgmlc, , [1f39a3cfaedce25446ec9b5ebe4555ab],
PUP.Optional.DefaultTab.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [283077fbc3c73df925e69f7b23e1a65a],
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 0
(Nenalezeny žádné škodlivé položky)
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
www.malwarebytes.org
Datum skenování: 29.4.2015
Čas skenování: 19:08:33
Protokol:
Správce: Ano
Verze: 2.01.6.1022
Databáze malwaru: v2015.04.29.04
Databáze rootkitů: v2015.04.21.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Zuzka
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 361602
Uplynulý čas: 30 min, 28 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 3
PUP.Optional.DefaultTab.A, HKU\S-1-5-21-2901497629-216978468-1755851068-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7F6AFBF1-E065-4627-A2FD-810366367D01}, , [abade989098106302dd8e6697c87d927],
PUP.Optional.DefaultTab.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\kdidombaedgpfiiedeimiebkmbilgmlc, , [1f39a3cfaedce25446ec9b5ebe4555ab],
PUP.Optional.DefaultTab.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\DefaultTab, , [283077fbc3c73df925e69f7b23e1a65a],
Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 0
(Nenalezeny žádné škodlivé položky)
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
Vše, co MBAM nalezl, smažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
Vypadalo to nadějně, bohužel po 4 hodinách opět chvost úřaduje. Zítra se podívám jestli to nemá něco společnýho s updatem. Asusu nebo windowsů.
- Rudy
- Site Admin
- Příspěvky: 119400
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: jeden svchost jede naplno (log z RSIT)
Na zkoušku vypněte aut. aktualizace, příp. přeinstalujte antivir.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: jeden svchost jede naplno (log z RSIT)
Tak problém byl asi v ,,Asus update,,. Nechal jsem ho udělat všechny aktualizace ale stále se nic neměnilo. Tak jsem ho odinstaloval a týden už je klid.
Rozhodně Vám děkuji za věnovaný čas.
Rozhodně Vám děkuji za věnovaný čas.