Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o pomoc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
tomaskrahulec
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 16 črc 2015 14:46

Prosím o pomoc

#1 Příspěvek od tomaskrahulec »

Dobrý den, včera mě najednou přestal fungovat office, a Stormware Pohoda. Office při spustění načítá a pak pouze hláška že přstal pracovat. Nejde spustit ani v nouzovém režimu. Pohoda na spuštění nereaguje vůbec, ani žádná chybová hláška. Při startu Windows proběhla chybná hláška s iastoricon.exe Tento proces jsem při startu zakázal hláška se už nezobrazuje ale problém s Pohodou i Office přetrvává. Zkoušel jsem opravy registrů, adwcleaner, combfix, vše možné ale nic nepomohlo. Posílám log a doufám že někdo bude tak hodný a pomůže mě. Nechci celý počítač reinstalovat :-(

Logfile of random's system information tool 1.10 (written by random/random)
Run by Server at 2015-07-16 15:37:18
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 87 GB (56%) free of 155 GB
Total RAM: 7989 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:37:23, on 16.7.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17910)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Server\AppData\Local\Dropbox\Update\DropboxUpdate.exe
C:\Users\Server\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Server.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [FUFAXRCV] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Server\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
O4 - HKCU\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHCE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-7515 Series" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000002] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHCE.EXE /EPT "EPLTarget\P0000000000000002" /M "WF-7515 Series" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000003] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHDA.EXE /EPT "EPLTarget\P0000000000000003" /M "WF-7520 Series" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000004] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHDA.EXE /EPT "EPLTarget\P0000000000000004" /M "WF-7520 Series" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHCE.EXE /EPT "EPLTarget\P0000000000000001" /M "WF-7515 Series" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user')
O4 - Startup: Dropbox.lnk = Server\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{90D51FE2-8FA6-4BE7-A628-0FBF4E2935E4}: NameServer = 192.168.1.2,8.8.8.8
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ABBYY FineReader 11 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.11.0) - ABBYY InfoPoisk LLC - C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: BUILDpower S HW Agent v2 (BPSHWAgent) - RTS, a.s. - c:\BUILDpowerS\System\BPSHWAgentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: INFOpower SQL Agent (IPSQLAgent) - Unknown owner - C:\BUILDpowerS\system\IPSQLAgentService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Solar Keyboard Service (L4301_Solar) - Logitech, Inc. - C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10556 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Logitech\SolarApp\L4301_Solar.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
c:\BUILDpowerS\System\BPSHWAgentService.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe"
C:\BUILDpowerS\system\IPSQLAgentService.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.BUILDPOWERS\MSSQL\Binn\sqlservr.exe" -sBUILDPOWERS
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL mmsys.cpl
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
taskeng.exe {01CEA47E-AC25-4FAA-821A-C2BD0B2388B0}
\??\C:\Windows\system32\conhost.exe "1886571580-1237142635592570594-1662880774-3694353581426804211838375705-761881246
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Users\Server\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
"C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe"
"C:\Users\Server\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
"C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
"C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe"
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4300.0.60744282\533741470" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,9,21,44 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0042 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2622 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser2/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A7_Stable_R2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_08/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=4300 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --disable-accelerated-video-decode --channel="4300.5.1530296924\880730887" /prefetch:673131151
taskeng.exe {591587C1-BCEA-492D-8ED1-66A0CF2BCA55}
"C:\Users\Server\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-316058563-1589628678-385188037-1000Core.job - C:\Users\Server\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-316058563-1589628678-385188037-1000UA.job - C:\Users\Server\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-05-07 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-05-07 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2013-12-10 1100248]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-05-07 10810912]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-01-10 417560]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2013-12-10 2279712]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-01-10 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-01-10 392984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Dropbox Update"=C:\Users\Server\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18 134512]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2014-03-05 1415048]
"Advanced SystemCare 8"=C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896]
"FUFAXSTM"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [2013-12-24 863848]
"FUFAXRCV"=C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [2013-12-24 642664]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-03-27 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

C:\Users\Server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Server\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-01-10 390656]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=145
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2015-07-16 15:37:18 ----D---- C:\rsit
2015-07-16 15:37:18 ----D---- C:\Program Files\trend micro
2015-07-16 15:25:11 ----A---- C:\Windows\ntbtlog.txt
2015-07-16 15:04:30 ----A---- C:\Windows\system32\roboot64.exe
2015-07-16 14:08:56 ----D---- C:\Program Files\Microsoft Office
2015-07-16 14:08:50 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2015-07-16 14:08:46 ----D---- C:\Program Files (x86)\Microsoft Office
2015-07-16 14:08:38 ----RHD---- C:\MSOCache
2015-07-16 12:20:53 ----D---- C:\ProgramData\Malwarebytes
2015-07-16 12:13:34 ----SHD---- C:\$RECYCLE.BIN
2015-07-16 11:46:41 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-07-16 11:46:41 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2015-07-16 11:46:41 ----A---- C:\Windows\system32\tsgqec.dll
2015-07-16 11:46:41 ----A---- C:\Windows\system32\mstsc.exe
2015-07-16 11:46:41 ----A---- C:\Windows\system32\aaclient.dll
2015-07-16 11:46:40 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-07-16 11:46:40 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-07-16 11:46:40 ----A---- C:\Windows\system32\mstscax.dll
2015-07-16 11:44:56 ----A---- C:\Windows\system32\rdpudd.dll
2015-07-16 11:44:56 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-07-16 11:44:56 ----A---- C:\Windows\system32\rdpcorets.dll
2015-07-16 11:44:19 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-07-15 23:31:18 ----D---- C:\Windows\pss
2015-07-15 22:49:13 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-07-15 22:49:08 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-07-15 22:49:08 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-07-15 22:49:08 ----A---- C:\Windows\system32\dwmcore.dll
2015-07-15 22:49:08 ----A---- C:\Windows\system32\dwmapi.dll
2015-07-15 22:48:54 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2015-07-15 22:48:54 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2015-07-15 22:48:54 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2015-07-15 22:48:54 ----A---- C:\Windows\system32\wksprtPS.dll
2015-07-15 22:48:54 ----A---- C:\Windows\system32\wksprt.exe
2015-07-15 22:48:54 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-07-15 22:48:54 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-07-15 22:48:54 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-07-15 22:48:54 ----A---- C:\Windows\system32\rdpendp_winip.dll
2015-07-15 22:48:54 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2015-07-15 22:48:54 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2015-07-15 22:48:54 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2015-07-15 22:48:54 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2015-07-15 22:44:59 ----D---- C:\Users\Server\AppData\Roaming\ProductData
2015-07-15 22:43:58 ----D---- C:\Users\Server\AppData\Roaming\Apple Computer
2015-07-15 22:43:57 ----D---- C:\ProgramData\ProductData
2015-07-15 22:43:56 ----D---- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-07-15 22:43:44 ----D---- C:\Users\Server\AppData\Roaming\IObit
2015-07-15 22:43:41 ----D---- C:\ProgramData\IObit
2015-07-15 22:43:41 ----D---- C:\Program Files (x86)\IObit
2015-07-15 17:15:51 ----D---- C:\AdwCleaner
2015-07-15 03:10:08 ----D---- C:\found.000
2015-07-15 03:02:48 ----D---- C:\Config.Msi
2015-07-14 20:03:21 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-07-14 20:03:21 ----A---- C:\Windows\system32\cewmdm.dll
2015-07-14 20:03:20 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-07-14 20:03:20 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-07-14 20:03:20 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-07-14 20:03:20 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-07-14 20:03:20 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-07-14 20:03:20 ----A---- C:\Windows\system32\wucltux.dll
2015-07-14 20:03:20 ----A---- C:\Windows\system32\wuauclt.exe
2015-07-14 20:03:20 ----A---- C:\Windows\system32\wuapp.exe
2015-07-14 20:03:20 ----A---- C:\Windows\system32\wuapi.dll
2015-07-14 20:03:20 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-07-14 20:03:19 ----A---- C:\Windows\system32\wuwebv.dll
2015-07-14 20:03:19 ----A---- C:\Windows\system32\wups2.dll
2015-07-14 20:03:19 ----A---- C:\Windows\system32\wups.dll
2015-07-14 20:03:19 ----A---- C:\Windows\system32\wudriver.dll
2015-07-14 20:03:19 ----A---- C:\Windows\system32\wuaueng.dll
2015-07-14 20:03:19 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-07-14 20:03:17 ----A---- C:\Windows\system32\win32k.sys
2015-07-14 20:03:16 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-07-14 20:03:16 ----A---- C:\Windows\system32\gdi32.dll
2015-07-14 20:03:15 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-07-14 20:03:15 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-07-14 20:03:15 ----A---- C:\Windows\system32\jscript9diag.dll
2015-07-14 20:03:15 ----A---- C:\Windows\system32\jscript9.dll
2015-07-14 20:03:13 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-07-14 20:03:13 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-07-14 20:03:12 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-07-14 20:03:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-07-14 20:03:11 ----A---- C:\Windows\system32\urlmon.dll
2015-07-14 20:03:11 ----A---- C:\Windows\system32\ieui.dll
2015-07-14 20:03:11 ----A---- C:\Windows\system32\ieframe.dll
2015-07-14 20:03:10 ----A---- C:\Windows\system32\mshtml.dll
2015-07-14 20:03:09 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-07-14 20:03:09 ----A---- C:\Windows\system32\iertutil.dll
2015-07-14 20:03:06 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-07-14 20:03:06 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-07-14 20:03:06 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-07-14 20:03:05 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-07-14 20:03:05 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-07-14 20:03:05 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-07-14 20:03:05 ----A---- C:\Windows\system32\iernonce.dll
2015-07-14 20:03:05 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-07-14 20:03:05 ----A---- C:\Windows\system32\ie4uinit.exe
2015-07-14 20:03:04 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-07-14 20:03:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-07-14 20:03:04 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-07-14 20:03:04 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-07-14 20:03:04 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-07-14 20:03:02 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-07-14 20:03:02 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-07-14 20:03:02 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-07-14 20:03:02 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-07-14 20:03:02 ----A---- C:\Windows\system32\iedkcs32.dll
2015-07-14 20:03:01 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-07-14 20:03:01 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-07-14 20:03:01 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-07-14 20:03:01 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-07-14 20:03:01 ----A---- C:\Windows\system32\dxtrans.dll
2015-07-14 20:03:00 ----A---- C:\Windows\system32\msfeeds.dll
2015-07-14 20:03:00 ----A---- C:\Windows\system32\iesetup.dll
2015-07-14 20:02:59 ----A---- C:\Windows\system32\ieapfltr.dll
2015-07-14 20:02:58 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-07-14 20:02:58 ----A---- C:\Windows\system32\vbscript.dll
2015-07-14 20:02:57 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-07-14 20:02:57 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-07-14 20:02:57 ----A---- C:\Windows\system32\jsproxy.dll
2015-07-14 20:02:57 ----A---- C:\Windows\system32\ieUnatt.exe
2015-07-14 20:02:56 ----A---- C:\Windows\system32\mshtmled.dll
2015-07-14 20:02:56 ----A---- C:\Windows\system32\dxtmsft.dll
2015-07-14 20:02:55 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-07-14 20:02:55 ----A---- C:\Windows\system32\jscript.dll
2015-07-14 20:02:54 ----A---- C:\Windows\system32\wininet.dll
2015-07-14 20:02:53 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-07-14 20:02:52 ----A---- C:\Windows\system32\msrating.dll
2015-07-14 20:02:41 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-07-14 20:02:41 ----A---- C:\Windows\system32\ole32.dll
2015-07-14 20:02:39 ----A---- C:\Windows\system32\cryptsvc.dll
2015-07-14 20:02:38 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-07-14 20:02:37 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-07-14 20:02:37 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-07-14 20:02:37 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-07-14 20:02:37 ----A---- C:\Windows\system32\wintrust.dll
2015-07-14 20:02:37 ----A---- C:\Windows\system32\cryptnet.dll
2015-07-14 20:02:37 ----A---- C:\Windows\system32\crypt32.dll
2015-07-14 20:02:31 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-07-14 20:02:31 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-07-14 20:02:31 ----A---- C:\Windows\system32\rpcrt4.dll
2015-07-14 20:02:31 ----A---- C:\Windows\system32\msv1_0.dll
2015-07-14 20:02:31 ----A---- C:\Windows\system32\lsasrv.dll
2015-07-14 20:02:31 ----A---- C:\Windows\system32\kerberos.dll
2015-07-14 20:02:31 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-07-14 20:02:31 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-07-14 20:02:31 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-07-14 20:02:30 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-07-14 20:02:30 ----A---- C:\Windows\system32\wdigest.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\TSpkg.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\sspisrv.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\sspicli.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\schannel.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\ncrypt.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\lsass.exe
2015-07-14 20:02:30 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-07-14 20:02:30 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-07-14 20:02:30 ----A---- C:\Windows\system32\cryptbase.dll
2015-07-14 20:02:30 ----A---- C:\Windows\system32\auditpol.exe
2015-07-14 20:02:29 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-07-14 20:02:29 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-07-14 20:02:29 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-07-14 20:02:29 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-07-14 20:02:29 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-07-14 20:02:29 ----A---- C:\Windows\system32\secur32.dll
2015-07-14 20:02:29 ----A---- C:\Windows\system32\msaudite.dll
2015-07-14 20:02:29 ----A---- C:\Windows\system32\credssp.dll
2015-07-14 20:02:29 ----A---- C:\Windows\system32\adtschema.dll
2015-07-14 20:02:27 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-07-14 20:02:27 ----A---- C:\Windows\system32\msobjs.dll
2015-07-14 20:02:24 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-07-14 20:02:24 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-07-14 20:02:24 ----A---- C:\Windows\system32\msiexec.exe
2015-07-14 20:02:24 ----A---- C:\Windows\system32\msi.dll
2015-07-14 20:02:24 ----A---- C:\Windows\system32\authui.dll
2015-07-14 20:02:23 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-07-14 20:02:23 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-07-14 20:02:23 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-07-14 20:02:23 ----A---- C:\Windows\system32\msimsg.dll
2015-07-14 20:02:23 ----A---- C:\Windows\system32\msihnd.dll
2015-07-14 20:02:23 ----A---- C:\Windows\system32\consent.exe
2015-07-14 20:02:23 ----A---- C:\Windows\system32\appinfo.dll
2015-06-17 20:39:59 ----D---- C:\ProgramData\Dropbox

======List of files/folders modified in the last 1 month======

2015-07-16 15:37:18 ----RD---- C:\Program Files
2015-07-16 15:37:08 ----D---- C:\Windows\temp
2015-07-16 15:34:57 ----D---- C:\Users\Server\AppData\Roaming\Dropbox
2015-07-16 15:33:50 ----A---- C:\Windows\SYSWOW64\log.txt
2015-07-16 15:33:34 ----D---- C:\ProgramData\NVIDIA
2015-07-16 15:32:17 ----D---- C:\Windows\System32
2015-07-16 15:32:17 ----D---- C:\Windows\inf
2015-07-16 15:32:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-07-16 15:31:55 ----SHD---- C:\System Volume Information
2015-07-16 15:31:18 ----D---- C:\Windows\system32\config
2015-07-16 15:30:59 ----D---- C:\Windows\Prefetch
2015-07-16 15:25:11 ----D---- C:\Windows
2015-07-16 15:19:09 ----D---- C:\Windows\system32\Tasks
2015-07-16 15:19:07 ----RD---- C:\Program Files (x86)
2015-07-16 15:04:36 ----D---- C:\Windows\Tasks
2015-07-16 14:40:06 ----SHD---- C:\Windows\Installer
2015-07-16 14:40:05 ----D---- C:\ProgramData\Microsoft Help
2015-07-16 14:37:48 ----D---- C:\Program Files (x86)\Common Files
2015-07-16 14:25:36 ----D---- C:\Windows\winsxs
2015-07-16 14:23:28 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-07-16 14:23:28 ----D---- C:\Windows\SysWOW64
2015-07-16 14:23:28 ----D---- C:\Windows\system32\cs-CZ
2015-07-16 14:11:39 ----RSD---- C:\Windows\assembly
2015-07-16 14:10:53 ----RSD---- C:\Windows\Fonts
2015-07-16 14:10:45 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-07-16 14:09:47 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-07-16 14:09:46 ----SD---- C:\ProgramData\Microsoft
2015-07-16 14:08:54 ----D---- C:\Windows\ShellNew
2015-07-16 13:28:18 ----D---- C:\Windows\rescache
2015-07-16 13:10:59 ----D---- C:\Windows\Microsoft.NET
2015-07-16 13:01:59 ----D---- C:\Windows\system32\drivers
2015-07-16 13:01:54 ----D---- C:\Program Files (x86)\CoinsUP
2015-07-16 12:55:03 ----A---- C:\Windows\win.ini
2015-07-16 12:49:58 ----D---- C:\Windows\cs-CZ
2015-07-16 12:20:53 ----D---- C:\ProgramData
2015-07-16 11:59:32 ----D---- C:\ProgramData\AVAST Software
2015-07-16 11:56:08 ----RD---- C:\Users
2015-07-16 11:44:46 ----D---- C:\Windows\system32\catroot2
2015-07-16 10:28:50 ----D---- C:\Windows\SoftwareDistribution
2015-07-15 23:33:23 ----D---- C:\Windows\system32\FxsTmp
2015-07-15 23:23:05 ----D---- C:\Program Files (x86)\Intel
2015-07-15 23:22:25 ----D---- C:\Windows\system32\catroot
2015-07-15 23:22:12 ----D---- C:\Windows\system32\DriverStore
2015-07-15 23:06:52 ----D---- C:\Windows\SYSWOW64\wbem
2015-07-15 23:06:52 ----D---- C:\Windows\SYSWOW64\en-US
2015-07-15 23:06:52 ----D---- C:\Windows\system32\wbem
2015-07-15 23:06:52 ----D---- C:\Windows\system32\en-US
2015-07-15 23:06:52 ----D---- C:\Windows\system32\drivers\en-US
2015-07-15 23:06:52 ----D---- C:\Windows\PolicyDefinitions
2015-07-15 23:04:46 ----D---- C:\Windows\debug
2015-07-15 22:47:43 ----D---- C:\Windows\system32\LogFiles
2015-07-15 22:47:42 ----D---- C:\Windows\Panther
2015-07-15 22:47:42 ----D---- C:\Windows\Minidump
2015-07-15 22:47:42 ----D---- C:\Windows\Logs
2015-07-15 22:47:42 ----D---- C:\Program Files (x86)\ABBYY FineReader 11
2015-07-15 17:42:49 ----AD---- C:\Qoobox
2015-07-15 17:40:31 ----A---- C:\Windows\system.ini
2015-07-15 17:40:27 ----D---- C:\Windows\system32\drivers\etc
2015-07-15 17:37:31 ----D---- C:\Windows\SYSWOW64\drivers
2015-07-15 17:37:31 ----D---- C:\Windows\AppPatch
2015-07-15 03:47:52 ----D---- C:\Program Files\Internet Explorer
2015-07-15 03:47:52 ----D---- C:\Program Files (x86)\Internet Explorer
2015-06-23 13:30:20 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-03-03 540696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\Windows\system32\DRIVERS\e1k62x64.sys [2010-04-05 301232]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-01-10 12311904]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-05-07 2366496]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2013-12-05 39200]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2012-03-26 33344]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-08-23 317440]
S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2015-07-15 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2011-07-01 31232]
S3 tapoas;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2011-08-19 30720]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2015-07-15 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2015-07-15 30208]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S3 WSDScan;Podpora skenování WSD přes UMB; C:\Windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.11.0;ABBYY FineReader 11 PE Licensing Service; C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [2013-05-15 821048]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-12-13 12288]
R2 BPSHWAgent;BUILDpower S HW Agent v2; c:\BUILDpowerS\System\BPSHWAgentService.exe [2012-01-06 2054656]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 EpsonCustomerParticipation;EpsonCustomerParticipation; C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2011-06-09 555392]
R2 IPSQLAgent;INFOpower SQL Agent; C:\BUILDpowerS\system\IPSQLAgentService.exe [2010-02-23 781824]
R2 L4301_Solar;Logitech Solar Keyboard Service; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [2013-01-30 405744]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-09 268824]
R2 MSSQL$BUILDPOWERS;SQL Server (BUILDPOWERS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.BUILDPOWERS\MSSQL\Binn\sqlservr.exe [2011-06-17 43040096]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 15129376]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-12-19 922912]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18 107912]
S2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-02-09 1471792]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18 107912]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-06-20 114688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-03-21 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 SQLAgent$BUILDPOWERS;SQL Server Agent (BUILDPOWERS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.BUILDPOWERS\MSSQL\Binn\SQLAGENT.EXE [2011-06-17 370016]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o pomoc

#2 Příspěvek od vyosek »

Zdravim :)

Jen se zeptam, jedna se o domaci nebo nejaky pracovni\firemni PC?? Vy jste spravce nebo uzivatel??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

tomaskrahulec
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 16 črc 2015 14:46

Re: Prosím o pomoc

#3 Příspěvek od tomaskrahulec »

Jedná se o firemní "server" kde probíhá záloha cloudu a je rozběhnutá pohoda, plus nějaký další programy. A jsem správce, dneska jsem nad tím strávil půl dne a jsem v koncích.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o pomoc

#4 Příspěvek od vyosek »

No ale my jsme tu zdarma a ve svem volem case, vy jste za to zrejme jako spravce placen. Nezlobte se na nas, sdilime sice vas problem, ale nikoli vas plat.

Nase pravidla fora hovori jasne
6. Fórum viry.cz se nezabývá odvirováním firemních PC - na toto jsou ve firmách placení (a někdy až hodně nadstandardně) IT technici, případně si je firma může najmout. My jsme tu zdarma a ve svém volném čase, nehodláme dělat práci za někoho jiného, kdo si pak jen slízne smetánku a plat. Taktéž ani neposkytujeme poradenství v oblasti zabezpečení firemních sítí či nastavení firemních sítí. Zkrátka a jednoduše, naše fórum poskytuje podporu pouze domácím uživatelům.
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

tomaskrahulec
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 16 črc 2015 14:46

Re: Prosím o pomoc

#5 Příspěvek od tomaskrahulec »

Sháním oddborníky, nebráním se tomu zaplatit.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o pomoc

#6 Příspěvek od vyosek »

Pak doporucuji nasi sluzbu vzdalene pomoci http://www.neslape.cz/ ktera je k tomuto urcena.
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět