
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu - nalezen malware
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu - nalezen malware
Dobrý večer, prosím o kontrolu logu, pc je dost pomalý při startu a otevírání prohlížeče. Stáhl jsem MBAM a našel nějakou havěť, přikládám log i z něj. Děkuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Blanka at 2015-08-15 22:20:24
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 22 GB (9%) free of 238 GB
Total RAM: 3835 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:20:40, on 15.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Blanka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - (no file)
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8255 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1924
C:\Windows\system32\SearchIndexer.exe /Embedding
atieclxx
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {0AAA1014-31A3-4E17-BC35-B6168E72BB94}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"taskhost.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4164 CREDAT:275457 /prefetch:2
AdblockPlusEngine.exe cs-CZ
taskeng.exe {DD98141F-626B-4CC2-A539-2068D8826C84}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-819589781-1855769215-1360403588-10007_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-819589781-1855769215-1360403588-10007 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Blanka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, personas@christopher.beard:1.6.2, silvermelxt@pardal.de:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17, flaminglow-ff3-30@glowplug.bitasylum.net:4.0.3.06, penguin@loic.com:3.0, {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91, silvermel@pardal.de:1.3.6, {333b42b0-9c75-11db-b606-0800200c9a66}:2.200100126"
prefs.js - "keyword.URL" - "https://www.google.com/search"
prefs.js - "keyword.enabled" - false
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpplugin.dll
QuickTimePlugin.class
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\extensions\
{07b2a769-ed19-4483-87ce-c643914c81bb}
{333b42b0-9c75-11db-b606-0800200c9a66}
{e7348bc0-16f6-11de-8c30-0800200c9a66}
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-11 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25 728840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-11 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25 617736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2015-08-11 6109776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-23 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-08-15 22:20:24 ----D---- C:\rsit
2015-08-15 21:37:09 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-15 21:36:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-13 21:25:52 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 21:25:52 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\invagent.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\generaltel.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\devinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\appraiser.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\aeinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\acmigration.dll
2015-08-13 19:51:10 ----A---- C:\Windows\system32\aepdu.dll
2015-08-13 19:51:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-13 19:51:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-13 19:51:01 ----A---- C:\Windows\system32\ntdll.dll
2015-08-13 19:51:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-13 19:51:00 ----A---- C:\Windows\system32\kernel32.dll
2015-08-13 19:50:59 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-13 19:50:59 ----A---- C:\Windows\system32\sysmain.dll
2015-08-13 19:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 19:50:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-13 19:50:56 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\wow64.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rstrui.exe
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\winsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\srcore.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\smss.exe
2015-08-13 19:50:55 ----A---- C:\Windows\system32\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-13 19:50:55 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\conhost.exe
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\sspicli.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\lsass.exe
2015-08-13 19:50:54 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-13 19:50:53 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\auditpol.exe
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64win.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\credssp.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-13 19:50:50 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-13 19:50:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:47 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-13 19:50:46 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-13 19:50:46 ----A---- C:\Windows\system32\adtschema.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msaudite.dll
2015-08-13 19:50:33 ----A---- C:\Windows\system32\mstscax.dll
2015-08-13 19:50:32 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\aaclient.dll
2015-08-13 19:50:08 ----A---- C:\Windows\system32\basesrv.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\iernonce.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-13 19:49:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-13 19:49:41 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-13 19:49:40 ----A---- C:\Windows\system32\urlmon.dll
2015-08-13 19:49:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 19:49:39 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\iesetup.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-13 19:49:37 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\vbscript.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\ieui.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\ieframe.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\wininet.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\msrating.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-13 19:49:31 ----A---- C:\Windows\system32\mshtml.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\davclnt.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml3.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-13 19:48:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\FntCache.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\DWrite.dll
2015-08-13 19:48:50 ----A---- C:\Windows\system32\win32k.sys
2015-08-13 19:48:50 ----A---- C:\Windows\system32\atmfd.dll
2015-08-13 19:48:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-13 19:48:48 ----A---- C:\Windows\system32\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\atmlib.dll
2015-08-13 19:48:43 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\notepad.exe
2015-08-13 19:48:41 ----A---- C:\Windows\system32\shell32.dll
2015-08-13 19:48:40 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wucltux.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups2.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-13 19:48:20 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-11 21:17:33 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-11 21:17:25 ----A---- C:\Windows\avastSS.scr
2015-08-09 20:33:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2015-08-15 22:20:32 ----D---- C:\Windows\Prefetch
2015-08-15 22:20:29 ----D---- C:\Windows\Temp
2015-08-15 22:20:27 ----D---- C:\Program Files\trend micro
2015-08-15 22:01:10 ----D---- C:\Windows\Microsoft.NET
2015-08-15 21:59:50 ----RSD---- C:\Windows\assembly
2015-08-15 21:37:09 ----D---- C:\Windows\system32\drivers
2015-08-15 21:36:47 ----RD---- C:\Program Files (x86)
2015-08-15 21:25:53 ----D---- C:\Windows\system32\config
2015-08-15 21:25:52 ----D---- C:\Windows\winsxs
2015-08-15 21:22:35 ----SD---- C:\Windows\system32\CompatTel
2015-08-15 21:22:35 ----D---- C:\Windows\system32\appraiser
2015-08-15 21:22:35 ----D---- C:\Windows\System32
2015-08-15 21:22:34 ----D---- C:\Windows\AppPatch
2015-08-15 21:22:32 ----D---- C:\Windows\SysWOW64
2015-08-15 21:22:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\cs-CZ
2015-08-15 21:22:20 ----D---- C:\Program Files\Internet Explorer
2015-08-15 21:22:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-15 21:22:17 ----D---- C:\Windows\system32\en-US
2015-08-15 21:22:14 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-15 21:22:10 ----D---- C:\Windows
2015-08-13 21:14:22 ----D---- C:\Windows\system32\MRT
2015-08-13 21:14:15 ----A---- C:\Windows\system32\MRT.exe
2015-08-13 21:13:22 ----SHD---- C:\System Volume Information
2015-08-13 20:16:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 20:07:36 ----D---- C:\Program Files (x86)\rajce
2015-08-13 19:45:13 ----D---- C:\Windows\system32\catroot2
2015-08-13 19:28:47 ----D---- C:\$RECYCLE.BIN
2015-08-11 21:18:02 ----D---- C:\Windows\system32\Tasks
2015-08-10 20:29:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 13:45:49 ----HD---- C:\$Windows.~BT
2015-08-06 13:30:34 ----D---- C:\Windows\Panther
2015-08-06 13:16:04 ----D---- C:\Windows\Logs
2015-08-06 10:38:11 ----D---- C:\Windows\inf
2015-08-06 10:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 20:59:18 ----D---- C:\Windows\SoftwareDistribution
2015-08-05 20:53:54 ----SD---- C:\Windows\system32\GWX
2015-07-18 22:56:42 ----D---- C:\Windows\Minidump
2015-07-17 21:26:46 ----D---- C:\Windows\rescache
2015-07-17 19:30:35 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-17 19:30:35 ----D---- C:\Windows\PolicyDefinitions
2015-07-17 19:30:23 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-11 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-11 274808]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-11 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-11 447944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-11 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-11 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-11 150672]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 25816]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\Windows\system32\DRIVERS\s916bus.sys [2007-11-02 108072]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 19496]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s916mdm.sys [2007-11-02 145448]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2015-08-11 146600]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe []
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-09 148136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
-----------------EOF-----------------
Log z MBAM:
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 15.8.2015
Čas skenování: 21:37
Protokol: 01.txt
Správce: Ano
Verze: 2.1.8.1057
Databáze malwaru: v2015.08.15.05
Databáze rootkitů: v2015.08.06.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Blanka
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 364614
Uplynulý čas: 28 min, 46 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-819589781-1855769215-1360403588-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E87B63F5-7DEF-4358-B069-FE7AEA203EB7}, , [6eb3a4656823bb7bc15a041cf3100cf4],
Hodnoty registru: 2
PUP.Optional.Spigot.A, HKU\S-1-5-21-819589781-1855769215-1360403588-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E87B63F5-7DEF-4358-B069-FE7AEA203EB7}|URL, http://search.yahoo.com/search?fr=chr-g ... earchTerms}, , [6eb3a4656823bb7bc15a041cf3100cf4]
PUP.Optional.Spigot.A, HKU\S-1-5-21-819589781-1855769215-1360403588-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E87B63F5-7DEF-4358-B069-FE7AEA203EB7}|OSDFileURL, file:///C:/Program%20Files%20(x86)/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, , [57caa366dbb04ceafd6df6afb54f1de3]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 0
(Nenalezeny žádné škodlivé položky)
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
Logfile of random's system information tool 1.09 (written by random/random)
Run by Blanka at 2015-08-15 22:20:24
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 22 GB (9%) free of 238 GB
Total RAM: 3835 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:20:40, on 15.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Blanka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - (no file)
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8255 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1924
C:\Windows\system32\SearchIndexer.exe /Embedding
atieclxx
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {0AAA1014-31A3-4E17-BC35-B6168E72BB94}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"taskhost.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4164 CREDAT:275457 /prefetch:2
AdblockPlusEngine.exe cs-CZ
taskeng.exe {DD98141F-626B-4CC2-A539-2068D8826C84}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-819589781-1855769215-1360403588-10007_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-819589781-1855769215-1360403588-10007 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Blanka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, personas@christopher.beard:1.6.2, silvermelxt@pardal.de:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17, flaminglow-ff3-30@glowplug.bitasylum.net:4.0.3.06, penguin@loic.com:3.0, {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91, silvermel@pardal.de:1.3.6, {333b42b0-9c75-11db-b606-0800200c9a66}:2.200100126"
prefs.js - "keyword.URL" - "https://www.google.com/search"
prefs.js - "keyword.enabled" - false
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpplugin.dll
QuickTimePlugin.class
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\extensions\
{07b2a769-ed19-4483-87ce-c643914c81bb}
{333b42b0-9c75-11db-b606-0800200c9a66}
{e7348bc0-16f6-11de-8c30-0800200c9a66}
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-11 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25 728840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-11 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25 617736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2015-08-11 6109776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-23 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-08-15 22:20:24 ----D---- C:\rsit
2015-08-15 21:37:09 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-15 21:36:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-13 21:25:52 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 21:25:52 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\invagent.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\generaltel.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\devinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\appraiser.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\aeinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\acmigration.dll
2015-08-13 19:51:10 ----A---- C:\Windows\system32\aepdu.dll
2015-08-13 19:51:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-13 19:51:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-13 19:51:01 ----A---- C:\Windows\system32\ntdll.dll
2015-08-13 19:51:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-13 19:51:00 ----A---- C:\Windows\system32\kernel32.dll
2015-08-13 19:50:59 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-13 19:50:59 ----A---- C:\Windows\system32\sysmain.dll
2015-08-13 19:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 19:50:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-13 19:50:56 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\wow64.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rstrui.exe
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\winsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\srcore.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\smss.exe
2015-08-13 19:50:55 ----A---- C:\Windows\system32\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-13 19:50:55 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\conhost.exe
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\sspicli.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\lsass.exe
2015-08-13 19:50:54 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-13 19:50:53 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\auditpol.exe
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64win.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\credssp.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-13 19:50:50 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-13 19:50:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:47 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-13 19:50:46 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-13 19:50:46 ----A---- C:\Windows\system32\adtschema.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msaudite.dll
2015-08-13 19:50:33 ----A---- C:\Windows\system32\mstscax.dll
2015-08-13 19:50:32 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\aaclient.dll
2015-08-13 19:50:08 ----A---- C:\Windows\system32\basesrv.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\iernonce.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-13 19:49:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-13 19:49:41 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-13 19:49:40 ----A---- C:\Windows\system32\urlmon.dll
2015-08-13 19:49:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 19:49:39 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\iesetup.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-13 19:49:37 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\vbscript.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\ieui.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\ieframe.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\wininet.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\msrating.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-13 19:49:31 ----A---- C:\Windows\system32\mshtml.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\davclnt.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml3.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-13 19:48:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\FntCache.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\DWrite.dll
2015-08-13 19:48:50 ----A---- C:\Windows\system32\win32k.sys
2015-08-13 19:48:50 ----A---- C:\Windows\system32\atmfd.dll
2015-08-13 19:48:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-13 19:48:48 ----A---- C:\Windows\system32\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\atmlib.dll
2015-08-13 19:48:43 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\notepad.exe
2015-08-13 19:48:41 ----A---- C:\Windows\system32\shell32.dll
2015-08-13 19:48:40 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wucltux.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups2.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-13 19:48:20 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-11 21:17:33 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-11 21:17:25 ----A---- C:\Windows\avastSS.scr
2015-08-09 20:33:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2015-08-15 22:20:32 ----D---- C:\Windows\Prefetch
2015-08-15 22:20:29 ----D---- C:\Windows\Temp
2015-08-15 22:20:27 ----D---- C:\Program Files\trend micro
2015-08-15 22:01:10 ----D---- C:\Windows\Microsoft.NET
2015-08-15 21:59:50 ----RSD---- C:\Windows\assembly
2015-08-15 21:37:09 ----D---- C:\Windows\system32\drivers
2015-08-15 21:36:47 ----RD---- C:\Program Files (x86)
2015-08-15 21:25:53 ----D---- C:\Windows\system32\config
2015-08-15 21:25:52 ----D---- C:\Windows\winsxs
2015-08-15 21:22:35 ----SD---- C:\Windows\system32\CompatTel
2015-08-15 21:22:35 ----D---- C:\Windows\system32\appraiser
2015-08-15 21:22:35 ----D---- C:\Windows\System32
2015-08-15 21:22:34 ----D---- C:\Windows\AppPatch
2015-08-15 21:22:32 ----D---- C:\Windows\SysWOW64
2015-08-15 21:22:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\cs-CZ
2015-08-15 21:22:20 ----D---- C:\Program Files\Internet Explorer
2015-08-15 21:22:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-15 21:22:17 ----D---- C:\Windows\system32\en-US
2015-08-15 21:22:14 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-15 21:22:10 ----D---- C:\Windows
2015-08-13 21:14:22 ----D---- C:\Windows\system32\MRT
2015-08-13 21:14:15 ----A---- C:\Windows\system32\MRT.exe
2015-08-13 21:13:22 ----SHD---- C:\System Volume Information
2015-08-13 20:16:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 20:07:36 ----D---- C:\Program Files (x86)\rajce
2015-08-13 19:45:13 ----D---- C:\Windows\system32\catroot2
2015-08-13 19:28:47 ----D---- C:\$RECYCLE.BIN
2015-08-11 21:18:02 ----D---- C:\Windows\system32\Tasks
2015-08-10 20:29:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 13:45:49 ----HD---- C:\$Windows.~BT
2015-08-06 13:30:34 ----D---- C:\Windows\Panther
2015-08-06 13:16:04 ----D---- C:\Windows\Logs
2015-08-06 10:38:11 ----D---- C:\Windows\inf
2015-08-06 10:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 20:59:18 ----D---- C:\Windows\SoftwareDistribution
2015-08-05 20:53:54 ----SD---- C:\Windows\system32\GWX
2015-07-18 22:56:42 ----D---- C:\Windows\Minidump
2015-07-17 21:26:46 ----D---- C:\Windows\rescache
2015-07-17 19:30:35 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-17 19:30:35 ----D---- C:\Windows\PolicyDefinitions
2015-07-17 19:30:23 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-11 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-11 274808]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-11 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-11 447944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-11 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-11 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-11 150672]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 25816]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\Windows\system32\DRIVERS\s916bus.sys [2007-11-02 108072]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 19496]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s916mdm.sys [2007-11-02 145448]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2015-08-11 146600]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe []
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-09 148136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
-----------------EOF-----------------
Log z MBAM:
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 15.8.2015
Čas skenování: 21:37
Protokol: 01.txt
Správce: Ano
Verze: 2.1.8.1057
Databáze malwaru: v2015.08.15.05
Databáze rootkitů: v2015.08.06.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Blanka
Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 364614
Uplynulý čas: 28 min, 46 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Nenalezeny žádné škodlivé položky)
Moduly: 0
(Nenalezeny žádné škodlivé položky)
Klíče registru: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-819589781-1855769215-1360403588-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E87B63F5-7DEF-4358-B069-FE7AEA203EB7}, , [6eb3a4656823bb7bc15a041cf3100cf4],
Hodnoty registru: 2
PUP.Optional.Spigot.A, HKU\S-1-5-21-819589781-1855769215-1360403588-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E87B63F5-7DEF-4358-B069-FE7AEA203EB7}|URL, http://search.yahoo.com/search?fr=chr-g ... earchTerms}, , [6eb3a4656823bb7bc15a041cf3100cf4]
PUP.Optional.Spigot.A, HKU\S-1-5-21-819589781-1855769215-1360403588-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E87B63F5-7DEF-4358-B069-FE7AEA203EB7}|OSDFileURL, file:///C:/Program%20Files%20(x86)/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, , [57caa366dbb04ceafd6df6afb54f1de3]
Data registru: 0
(Nenalezeny žádné škodlivé položky)
Složky: 0
(Nenalezeny žádné škodlivé položky)
Soubory: 0
(Nenalezeny žádné škodlivé položky)
Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)
(end)
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - nalezen malware
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - nalezen malware
Tak zde je log:
# AdwCleaner v5.000 - Logfile created 15/08/2015 at 23:02:26
# Updated 14/08/2015 by Xplode
# Database : 2015-08-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Blanka - BLANKA-T
# Running from : C:\Users\Blanka\Desktop\adwcleaner_5.000.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Users\Blanka\AppData\Roaming\Solvusoft
***** [ Files ] *****
[-] File Deleted : C:\Windows\Sysnative\roboot64.exe
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66D59105-FE06-43A4-B292-EB0097E9EB74}
***** [ Web browsers ] *****
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.firstKnownVersion", "5.78.3.8660");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=7D6F157D-8022-4EC2-9090-97B78535C9EB&n=77fd55f0&p2=^HJ^xdm007^YYA^cz&si=CKmn8_KZyLkCFcmV3god-mgAY[...]
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2013091312");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "^HJ^xdm007^YYA^cz");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "CKmn8_KZyLkCFcmV3god-mgAYA");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "7D6F157D-8022-4EC2-9090-97B78535C9EB");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.isCompliantUninstallImplementation", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1401394772783");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastKnownVersion", "5.78.3.8660");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.toolbarCollapsed", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
*************************
:: Proxy settings cleared
:: Winsock settings cleared
*************************
C:\AdwCleaner[C1].txt - [5069 octets] - [15/08/2015 23:02:26]
C:\AdwCleaner[S1].txt - [4970 octets] - [15/08/2015 22:57:47]
C:\AdwCleaner[S2].txt - [5033 octets] - [15/08/2015 23:00:01]
########## EOF - C:\AdwCleaner[C1].txt - [5258 octets] ##########
# AdwCleaner v5.000 - Logfile created 15/08/2015 at 23:02:26
# Updated 14/08/2015 by Xplode
# Database : 2015-08-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Blanka - BLANKA-T
# Running from : C:\Users\Blanka\Desktop\adwcleaner_5.000.exe
# Option : Cleaning
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Users\Blanka\AppData\Roaming\Solvusoft
***** [ Files ] *****
[-] File Deleted : C:\Windows\Sysnative\roboot64.exe
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66D59105-FE06-43A4-B292-EB0097E9EB74}
***** [ Web browsers ] *****
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.firstKnownVersion", "5.78.3.8660");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=7D6F157D-8022-4EC2-9090-97B78535C9EB&n=77fd55f0&p2=^HJ^xdm007^YYA^cz&si=CKmn8_KZyLkCFcmV3god-mgAY[...]
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.initialized", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.contextKey", "");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.installDate", "2013091312");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerId", "^HJ^xdm007^YYA^cz");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.partnerSubId", "CKmn8_KZyLkCFcmV3god-mgAYA");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.success", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.installation.toolbarId", "7D6F157D-8022-4EC2-9090-97B78535C9EB");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.isCompliantUninstallImplementation", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1401394772783");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastKnownVersion", "5.78.3.8660");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.defaultSearch", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.homePageEnabled", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.keywordEnabled", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.options.tabEnabled", false);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.toolbarCollapsed", true);
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[-] [C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
*************************
:: Proxy settings cleared
:: Winsock settings cleared
*************************
C:\AdwCleaner[C1].txt - [5069 octets] - [15/08/2015 23:02:26]
C:\AdwCleaner[S1].txt - [4970 octets] - [15/08/2015 22:57:47]
C:\AdwCleaner[S2].txt - [5033 octets] - [15/08/2015 23:00:01]
########## EOF - C:\AdwCleaner[C1].txt - [5258 octets] ##########
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - nalezen malware
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - nalezen malware
Dávám nový log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Blanka at 2015-08-16 11:36:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 20 GB (8%) free of 238 GB
Total RAM: 3835 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:36:34, on 16.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\trend micro\Blanka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - (no file)
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8255 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
taskeng.exe {B6A53E64-B412-4963-BE74-FCBE7DF1B9D8}
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
WLIDSvcM.exe 2204
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2824 CREDAT:275457 /prefetch:2
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
AdblockPlusEngine.exe cs-CZ
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\System32\MsSpellCheckingFacility.exe" -Embedding
C:\Windows\servicing\TrustedInstaller.exe
"C:\Users\Blanka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, personas@christopher.beard:1.6.2, silvermelxt@pardal.de:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17, flaminglow-ff3-30@glowplug.bitasylum.net:4.0.3.06, penguin@loic.com:3.0, {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91, silvermel@pardal.de:1.3.6, {333b42b0-9c75-11db-b606-0800200c9a66}:2.200100126"
prefs.js - "keyword.URL" - "https://www.google.com/search"
prefs.js - "keyword.enabled" - false
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpplugin.dll
QuickTimePlugin.class
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\extensions\
{07b2a769-ed19-4483-87ce-c643914c81bb}
{333b42b0-9c75-11db-b606-0800200c9a66}
{e7348bc0-16f6-11de-8c30-0800200c9a66}
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-11 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25 728840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-11 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25 617736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2015-08-11 6109776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-23 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-08-15 23:02:26 ----A---- C:\AdwCleaner[C1].txt
2015-08-15 23:00:01 ----A---- C:\AdwCleaner[S2].txt
2015-08-15 22:57:47 ----A---- C:\AdwCleaner[S1].txt
2015-08-15 22:57:42 ----D---- C:\AdwCleaner
2015-08-15 22:20:24 ----D---- C:\rsit
2015-08-15 21:37:09 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-15 21:36:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-13 21:25:52 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 21:25:52 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\invagent.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\generaltel.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\devinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\appraiser.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\aeinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\acmigration.dll
2015-08-13 19:51:10 ----A---- C:\Windows\system32\aepdu.dll
2015-08-13 19:51:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-13 19:51:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-13 19:51:01 ----A---- C:\Windows\system32\ntdll.dll
2015-08-13 19:51:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-13 19:51:00 ----A---- C:\Windows\system32\kernel32.dll
2015-08-13 19:50:59 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-13 19:50:59 ----A---- C:\Windows\system32\sysmain.dll
2015-08-13 19:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 19:50:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-13 19:50:56 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\wow64.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rstrui.exe
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\winsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\srcore.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\smss.exe
2015-08-13 19:50:55 ----A---- C:\Windows\system32\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-13 19:50:55 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\conhost.exe
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\sspicli.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\lsass.exe
2015-08-13 19:50:54 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-13 19:50:53 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\auditpol.exe
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64win.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\credssp.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-13 19:50:50 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-13 19:50:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:47 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-13 19:50:46 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-13 19:50:46 ----A---- C:\Windows\system32\adtschema.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msaudite.dll
2015-08-13 19:50:33 ----A---- C:\Windows\system32\mstscax.dll
2015-08-13 19:50:32 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\aaclient.dll
2015-08-13 19:50:08 ----A---- C:\Windows\system32\basesrv.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\iernonce.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-13 19:49:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-13 19:49:41 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-13 19:49:40 ----A---- C:\Windows\system32\urlmon.dll
2015-08-13 19:49:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 19:49:39 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\iesetup.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-13 19:49:37 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\vbscript.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\ieui.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\ieframe.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\wininet.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\msrating.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-13 19:49:31 ----A---- C:\Windows\system32\mshtml.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\davclnt.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml3.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-13 19:48:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\FntCache.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\DWrite.dll
2015-08-13 19:48:50 ----A---- C:\Windows\system32\win32k.sys
2015-08-13 19:48:50 ----A---- C:\Windows\system32\atmfd.dll
2015-08-13 19:48:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-13 19:48:48 ----A---- C:\Windows\system32\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\atmlib.dll
2015-08-13 19:48:43 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\notepad.exe
2015-08-13 19:48:41 ----A---- C:\Windows\system32\shell32.dll
2015-08-13 19:48:40 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wucltux.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups2.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-13 19:48:20 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-11 21:17:33 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-11 21:17:25 ----A---- C:\Windows\avastSS.scr
2015-08-09 20:33:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2015-08-16 11:36:30 ----D---- C:\Windows\Prefetch
2015-08-16 11:36:21 ----D---- C:\Program Files\trend micro
2015-08-16 11:36:20 ----D---- C:\Windows\Temp
2015-08-16 01:54:56 ----D---- C:\Windows\rescache
2015-08-15 23:08:14 ----D---- C:\Windows\system32\config
2015-08-15 23:02:27 ----D---- C:\Windows\System32
2015-08-15 22:30:59 ----SD---- C:\Users\Blanka\AppData\Roaming\Microsoft
2015-08-15 22:01:10 ----D---- C:\Windows\Microsoft.NET
2015-08-15 21:59:50 ----RSD---- C:\Windows\assembly
2015-08-15 21:37:09 ----D---- C:\Windows\system32\drivers
2015-08-15 21:36:47 ----RD---- C:\Program Files (x86)
2015-08-15 21:25:52 ----D---- C:\Windows\winsxs
2015-08-15 21:22:35 ----SD---- C:\Windows\system32\CompatTel
2015-08-15 21:22:35 ----D---- C:\Windows\system32\appraiser
2015-08-15 21:22:34 ----D---- C:\Windows\AppPatch
2015-08-15 21:22:32 ----D---- C:\Windows\SysWOW64
2015-08-15 21:22:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\cs-CZ
2015-08-15 21:22:20 ----D---- C:\Program Files\Internet Explorer
2015-08-15 21:22:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-15 21:22:17 ----D---- C:\Windows\system32\en-US
2015-08-15 21:22:14 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-15 21:22:10 ----D---- C:\Windows
2015-08-13 21:18:46 ----D---- C:\Windows\system32\MRT
2015-08-13 21:14:15 ----A---- C:\Windows\system32\MRT.exe
2015-08-13 21:13:22 ----SHD---- C:\System Volume Information
2015-08-13 20:16:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 20:07:36 ----D---- C:\Program Files (x86)\rajce
2015-08-13 19:45:13 ----D---- C:\Windows\system32\catroot2
2015-08-13 19:28:47 ----D---- C:\$RECYCLE.BIN
2015-08-11 21:18:02 ----D---- C:\Windows\system32\Tasks
2015-08-10 20:29:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 13:45:49 ----HD---- C:\$Windows.~BT
2015-08-06 13:30:34 ----D---- C:\Windows\Panther
2015-08-06 13:16:04 ----D---- C:\Windows\Logs
2015-08-06 10:38:11 ----D---- C:\Windows\inf
2015-08-06 10:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 20:59:18 ----D---- C:\Windows\SoftwareDistribution
2015-08-05 20:53:54 ----SD---- C:\Windows\system32\GWX
2015-07-18 22:56:42 ----D---- C:\Windows\Minidump
2015-07-17 19:30:35 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-17 19:30:35 ----D---- C:\Windows\PolicyDefinitions
2015-07-17 19:30:23 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-11 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-11 274808]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-11 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-11 447944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-11 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-11 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-11 150672]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\Windows\system32\DRIVERS\s916bus.sys [2007-11-02 108072]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 19496]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s916mdm.sys [2007-11-02 145448]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2015-08-11 146600]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe []
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-09 148136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Blanka at 2015-08-16 11:36:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 20 GB (8%) free of 238 GB
Total RAM: 3835 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:36:34, on 16.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\trend micro\Blanka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - (no file)
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8255 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
taskeng.exe {B6A53E64-B412-4963-BE74-FCBE7DF1B9D8}
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
WLIDSvcM.exe 2204
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2824 CREDAT:275457 /prefetch:2
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
AdblockPlusEngine.exe cs-CZ
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\System32\MsSpellCheckingFacility.exe" -Embedding
C:\Windows\servicing\TrustedInstaller.exe
"C:\Users\Blanka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, personas@christopher.beard:1.6.2, silvermelxt@pardal.de:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17, flaminglow-ff3-30@glowplug.bitasylum.net:4.0.3.06, penguin@loic.com:3.0, {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91, silvermel@pardal.de:1.3.6, {333b42b0-9c75-11db-b606-0800200c9a66}:2.200100126"
prefs.js - "keyword.URL" - "https://www.google.com/search"
prefs.js - "keyword.enabled" - false
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpplugin.dll
QuickTimePlugin.class
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\extensions\
{07b2a769-ed19-4483-87ce-c643914c81bb}
{333b42b0-9c75-11db-b606-0800200c9a66}
{e7348bc0-16f6-11de-8c30-0800200c9a66}
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-11 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25 728840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-11 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25 617736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2015-08-11 6109776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-23 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-08-15 23:02:26 ----A---- C:\AdwCleaner[C1].txt
2015-08-15 23:00:01 ----A---- C:\AdwCleaner[S2].txt
2015-08-15 22:57:47 ----A---- C:\AdwCleaner[S1].txt
2015-08-15 22:57:42 ----D---- C:\AdwCleaner
2015-08-15 22:20:24 ----D---- C:\rsit
2015-08-15 21:37:09 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-15 21:36:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-13 21:25:52 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 21:25:52 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\invagent.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\generaltel.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\devinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\appraiser.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\aeinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\acmigration.dll
2015-08-13 19:51:10 ----A---- C:\Windows\system32\aepdu.dll
2015-08-13 19:51:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-13 19:51:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-13 19:51:01 ----A---- C:\Windows\system32\ntdll.dll
2015-08-13 19:51:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-13 19:51:00 ----A---- C:\Windows\system32\kernel32.dll
2015-08-13 19:50:59 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-13 19:50:59 ----A---- C:\Windows\system32\sysmain.dll
2015-08-13 19:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 19:50:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-13 19:50:56 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\wow64.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rstrui.exe
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\winsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\srcore.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\smss.exe
2015-08-13 19:50:55 ----A---- C:\Windows\system32\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-13 19:50:55 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\conhost.exe
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\sspicli.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\lsass.exe
2015-08-13 19:50:54 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-13 19:50:53 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\auditpol.exe
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64win.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\credssp.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-13 19:50:50 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-13 19:50:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:47 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-13 19:50:46 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-13 19:50:46 ----A---- C:\Windows\system32\adtschema.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msaudite.dll
2015-08-13 19:50:33 ----A---- C:\Windows\system32\mstscax.dll
2015-08-13 19:50:32 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\aaclient.dll
2015-08-13 19:50:08 ----A---- C:\Windows\system32\basesrv.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\iernonce.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-13 19:49:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-13 19:49:41 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-13 19:49:40 ----A---- C:\Windows\system32\urlmon.dll
2015-08-13 19:49:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 19:49:39 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\iesetup.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-13 19:49:37 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\vbscript.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\ieui.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\ieframe.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\wininet.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\msrating.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-13 19:49:31 ----A---- C:\Windows\system32\mshtml.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\davclnt.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml3.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-13 19:48:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\FntCache.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\DWrite.dll
2015-08-13 19:48:50 ----A---- C:\Windows\system32\win32k.sys
2015-08-13 19:48:50 ----A---- C:\Windows\system32\atmfd.dll
2015-08-13 19:48:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-13 19:48:48 ----A---- C:\Windows\system32\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\atmlib.dll
2015-08-13 19:48:43 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\notepad.exe
2015-08-13 19:48:41 ----A---- C:\Windows\system32\shell32.dll
2015-08-13 19:48:40 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wucltux.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups2.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-13 19:48:20 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-11 21:17:33 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-11 21:17:25 ----A---- C:\Windows\avastSS.scr
2015-08-09 20:33:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2015-08-16 11:36:30 ----D---- C:\Windows\Prefetch
2015-08-16 11:36:21 ----D---- C:\Program Files\trend micro
2015-08-16 11:36:20 ----D---- C:\Windows\Temp
2015-08-16 01:54:56 ----D---- C:\Windows\rescache
2015-08-15 23:08:14 ----D---- C:\Windows\system32\config
2015-08-15 23:02:27 ----D---- C:\Windows\System32
2015-08-15 22:30:59 ----SD---- C:\Users\Blanka\AppData\Roaming\Microsoft
2015-08-15 22:01:10 ----D---- C:\Windows\Microsoft.NET
2015-08-15 21:59:50 ----RSD---- C:\Windows\assembly
2015-08-15 21:37:09 ----D---- C:\Windows\system32\drivers
2015-08-15 21:36:47 ----RD---- C:\Program Files (x86)
2015-08-15 21:25:52 ----D---- C:\Windows\winsxs
2015-08-15 21:22:35 ----SD---- C:\Windows\system32\CompatTel
2015-08-15 21:22:35 ----D---- C:\Windows\system32\appraiser
2015-08-15 21:22:34 ----D---- C:\Windows\AppPatch
2015-08-15 21:22:32 ----D---- C:\Windows\SysWOW64
2015-08-15 21:22:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\cs-CZ
2015-08-15 21:22:20 ----D---- C:\Program Files\Internet Explorer
2015-08-15 21:22:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-15 21:22:17 ----D---- C:\Windows\system32\en-US
2015-08-15 21:22:14 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-15 21:22:10 ----D---- C:\Windows
2015-08-13 21:18:46 ----D---- C:\Windows\system32\MRT
2015-08-13 21:14:15 ----A---- C:\Windows\system32\MRT.exe
2015-08-13 21:13:22 ----SHD---- C:\System Volume Information
2015-08-13 20:16:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 20:07:36 ----D---- C:\Program Files (x86)\rajce
2015-08-13 19:45:13 ----D---- C:\Windows\system32\catroot2
2015-08-13 19:28:47 ----D---- C:\$RECYCLE.BIN
2015-08-11 21:18:02 ----D---- C:\Windows\system32\Tasks
2015-08-10 20:29:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 13:45:49 ----HD---- C:\$Windows.~BT
2015-08-06 13:30:34 ----D---- C:\Windows\Panther
2015-08-06 13:16:04 ----D---- C:\Windows\Logs
2015-08-06 10:38:11 ----D---- C:\Windows\inf
2015-08-06 10:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 20:59:18 ----D---- C:\Windows\SoftwareDistribution
2015-08-05 20:53:54 ----SD---- C:\Windows\system32\GWX
2015-07-18 22:56:42 ----D---- C:\Windows\Minidump
2015-07-17 19:30:35 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-17 19:30:35 ----D---- C:\Windows\PolicyDefinitions
2015-07-17 19:30:23 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-11 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-11 274808]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-11 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-11 447944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-11 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-11 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-11 150672]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\Windows\system32\DRIVERS\s916bus.sys [2007-11-02 108072]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 19496]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s916mdm.sys [2007-11-02 145448]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2015-08-11 146600]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe []
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-09 148136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - nalezen malware
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]/64
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - nalezen malware
Dávám log RSIT:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Blanka at 2015-08-16 12:24:46
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 23 GB (10%) free of 238 GB
Total RAM: 3835 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:25:04, on 16.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Blanka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7959 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {BB16D9BF-408E-4E5B-B3C5-234EDD7C87ED}
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2248
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\08162015_121440.log
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3052 CREDAT:275457 /prefetch:2
AdblockPlusEngine.exe cs-CZ
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
taskeng.exe {F298BE9E-FAE8-4337-AD25-56550B3A23EF}
"C:\Users\Blanka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, personas@christopher.beard:1.6.2, silvermelxt@pardal.de:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17, flaminglow-ff3-30@glowplug.bitasylum.net:4.0.3.06, penguin@loic.com:3.0, {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91, silvermel@pardal.de:1.3.6, {333b42b0-9c75-11db-b606-0800200c9a66}:2.200100126"
prefs.js - "keyword.URL" - "https://www.google.com/search"
prefs.js - "keyword.enabled" - false
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpplugin.dll
QuickTimePlugin.class
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\extensions\
{07b2a769-ed19-4483-87ce-c643914c81bb}
{333b42b0-9c75-11db-b606-0800200c9a66}
{e7348bc0-16f6-11de-8c30-0800200c9a66}
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-11 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25 728840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-11 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25 617736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2015-08-11 6109776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-23 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-08-16 12:14:40 ----D---- C:\_OTM
2015-08-15 23:02:26 ----A---- C:\AdwCleaner[C1].txt
2015-08-15 23:00:01 ----A---- C:\AdwCleaner[S2].txt
2015-08-15 22:57:47 ----A---- C:\AdwCleaner[S1].txt
2015-08-15 22:57:42 ----D---- C:\AdwCleaner
2015-08-15 22:20:24 ----D---- C:\rsit
2015-08-15 21:37:09 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-15 21:36:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-13 21:25:52 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 21:25:52 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\invagent.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\generaltel.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\devinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\appraiser.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\aeinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\acmigration.dll
2015-08-13 19:51:10 ----A---- C:\Windows\system32\aepdu.dll
2015-08-13 19:51:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-13 19:51:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-13 19:51:01 ----A---- C:\Windows\system32\ntdll.dll
2015-08-13 19:51:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-13 19:51:00 ----A---- C:\Windows\system32\kernel32.dll
2015-08-13 19:50:59 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-13 19:50:59 ----A---- C:\Windows\system32\sysmain.dll
2015-08-13 19:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 19:50:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-13 19:50:56 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\wow64.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rstrui.exe
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\winsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\srcore.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\smss.exe
2015-08-13 19:50:55 ----A---- C:\Windows\system32\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-13 19:50:55 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\conhost.exe
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\sspicli.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\lsass.exe
2015-08-13 19:50:54 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-13 19:50:53 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\auditpol.exe
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64win.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\credssp.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-13 19:50:50 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-13 19:50:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:47 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-13 19:50:46 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-13 19:50:46 ----A---- C:\Windows\system32\adtschema.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msaudite.dll
2015-08-13 19:50:33 ----A---- C:\Windows\system32\mstscax.dll
2015-08-13 19:50:32 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\aaclient.dll
2015-08-13 19:50:08 ----A---- C:\Windows\system32\basesrv.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\iernonce.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-13 19:49:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-13 19:49:41 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-13 19:49:40 ----A---- C:\Windows\system32\urlmon.dll
2015-08-13 19:49:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 19:49:39 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\iesetup.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-13 19:49:37 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\vbscript.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\ieui.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\ieframe.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\wininet.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\msrating.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-13 19:49:31 ----A---- C:\Windows\system32\mshtml.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\davclnt.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml3.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-13 19:48:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\FntCache.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\DWrite.dll
2015-08-13 19:48:50 ----A---- C:\Windows\system32\win32k.sys
2015-08-13 19:48:50 ----A---- C:\Windows\system32\atmfd.dll
2015-08-13 19:48:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-13 19:48:48 ----A---- C:\Windows\system32\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\atmlib.dll
2015-08-13 19:48:43 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\notepad.exe
2015-08-13 19:48:41 ----A---- C:\Windows\system32\shell32.dll
2015-08-13 19:48:40 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wucltux.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups2.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-13 19:48:20 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-11 21:17:33 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-11 21:17:25 ----A---- C:\Windows\avastSS.scr
2015-08-09 20:33:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2015-08-16 12:24:51 ----D---- C:\Windows\Temp
2015-08-16 12:24:49 ----D---- C:\Program Files\trend micro
2015-08-16 12:22:05 ----D---- C:\Windows\Prefetch
2015-08-16 01:54:56 ----D---- C:\Windows\rescache
2015-08-15 23:08:14 ----D---- C:\Windows\system32\config
2015-08-15 23:02:27 ----D---- C:\Windows\System32
2015-08-15 22:30:59 ----SD---- C:\Users\Blanka\AppData\Roaming\Microsoft
2015-08-15 22:01:10 ----D---- C:\Windows\Microsoft.NET
2015-08-15 21:59:50 ----RSD---- C:\Windows\assembly
2015-08-15 21:37:09 ----D---- C:\Windows\system32\drivers
2015-08-15 21:36:47 ----RD---- C:\Program Files (x86)
2015-08-15 21:25:52 ----D---- C:\Windows\winsxs
2015-08-15 21:22:35 ----SD---- C:\Windows\system32\CompatTel
2015-08-15 21:22:35 ----D---- C:\Windows\system32\appraiser
2015-08-15 21:22:34 ----D---- C:\Windows\AppPatch
2015-08-15 21:22:32 ----D---- C:\Windows\SysWOW64
2015-08-15 21:22:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\cs-CZ
2015-08-15 21:22:20 ----D---- C:\Program Files\Internet Explorer
2015-08-15 21:22:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-15 21:22:17 ----D---- C:\Windows\system32\en-US
2015-08-15 21:22:14 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-15 21:22:10 ----D---- C:\Windows
2015-08-13 21:18:46 ----D---- C:\Windows\system32\MRT
2015-08-13 21:14:15 ----A---- C:\Windows\system32\MRT.exe
2015-08-13 21:13:22 ----SHD---- C:\System Volume Information
2015-08-13 20:16:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 20:07:36 ----D---- C:\Program Files (x86)\rajce
2015-08-13 19:45:13 ----D---- C:\Windows\system32\catroot2
2015-08-13 19:28:47 ----D---- C:\$RECYCLE.BIN
2015-08-11 21:18:02 ----D---- C:\Windows\system32\Tasks
2015-08-10 20:29:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 13:45:49 ----HD---- C:\$Windows.~BT
2015-08-06 13:30:34 ----D---- C:\Windows\Panther
2015-08-06 13:16:04 ----D---- C:\Windows\Logs
2015-08-06 10:38:11 ----D---- C:\Windows\inf
2015-08-06 10:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 20:59:18 ----D---- C:\Windows\SoftwareDistribution
2015-08-05 20:53:54 ----SD---- C:\Windows\system32\GWX
2015-07-18 22:56:42 ----D---- C:\Windows\Minidump
2015-07-17 19:30:35 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-17 19:30:35 ----D---- C:\Windows\PolicyDefinitions
2015-07-17 19:30:23 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-11 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-11 274808]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-11 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-11 447944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-11 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-11 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-11 150672]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\Windows\system32\DRIVERS\s916bus.sys [2007-11-02 108072]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 19496]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s916mdm.sys [2007-11-02 145448]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2015-08-11 146600]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe []
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-09 148136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Blanka at 2015-08-16 12:24:46
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 23 GB (10%) free of 238 GB
Total RAM: 3835 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:25:04, on 16.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Blanka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7959 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
taskeng.exe {BB16D9BF-408E-4E5B-B3C5-234EDD7C87ED}
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2248
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\08162015_121440.log
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3052 CREDAT:275457 /prefetch:2
AdblockPlusEngine.exe cs-CZ
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
taskeng.exe {F298BE9E-FAE8-4337-AD25-56550B3A23EF}
"C:\Users\Blanka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, personas@christopher.beard:1.6.2, silvermelxt@pardal.de:1.3.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17, flaminglow-ff3-30@glowplug.bitasylum.net:4.0.3.06, penguin@loic.com:3.0, {e7348bc0-16f6-11de-8c30-0800200c9a66}:3.6.19.02.10, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91, silvermel@pardal.de:1.3.6, {333b42b0-9c75-11db-b606-0800200c9a66}:2.200100126"
prefs.js - "keyword.URL" - "https://www.google.com/search"
prefs.js - "keyword.enabled" - false
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprpplugin.dll
QuickTimePlugin.class
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\extensions\
{07b2a769-ed19-4483-87ce-c643914c81bb}
{333b42b0-9c75-11db-b606-0800200c9a66}
{e7348bc0-16f6-11de-8c30-0800200c9a66}
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\ptcpvet8.default\searchplugins\
Google.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2015-08-11 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25 728840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2015-08-11 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25 617736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2015-08-11 6109776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2013-11-23 243200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-08-16 12:14:40 ----D---- C:\_OTM
2015-08-15 23:02:26 ----A---- C:\AdwCleaner[C1].txt
2015-08-15 23:00:01 ----A---- C:\AdwCleaner[S2].txt
2015-08-15 22:57:47 ----A---- C:\AdwCleaner[S1].txt
2015-08-15 22:57:42 ----D---- C:\AdwCleaner
2015-08-15 22:20:24 ----D---- C:\rsit
2015-08-15 21:37:09 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-15 21:36:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-15 21:36:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-13 21:25:52 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 21:25:52 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\invagent.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\generaltel.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\devinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\appraiser.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\aeinv.dll
2015-08-13 19:51:12 ----A---- C:\Windows\system32\acmigration.dll
2015-08-13 19:51:10 ----A---- C:\Windows\system32\aepdu.dll
2015-08-13 19:51:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-13 19:51:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-13 19:51:01 ----A---- C:\Windows\system32\ntdll.dll
2015-08-13 19:51:00 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-13 19:51:00 ----A---- C:\Windows\system32\kernel32.dll
2015-08-13 19:50:59 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-13 19:50:59 ----A---- C:\Windows\system32\sysmain.dll
2015-08-13 19:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-13 19:50:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-13 19:50:56 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\wow64.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rstrui.exe
2015-08-13 19:50:56 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-13 19:50:56 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\winsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\wdigest.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\srcore.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\smss.exe
2015-08-13 19:50:55 ----A---- C:\Windows\system32\schannel.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\kerberos.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-13 19:50:55 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-13 19:50:55 ----A---- C:\Windows\system32\conhost.exe
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\sspicli.dll
2015-08-13 19:50:54 ----A---- C:\Windows\system32\lsass.exe
2015-08-13 19:50:54 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-13 19:50:53 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\srclient.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\secur32.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-13 19:50:53 ----A---- C:\Windows\system32\auditpol.exe
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 19:50:52 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-13 19:50:52 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64win.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-13 19:50:52 ----A---- C:\Windows\system32\credssp.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:51 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 19:50:50 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 19:50:50 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-13 19:50:50 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-13 19:50:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 19:50:48 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 19:50:47 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-13 19:50:46 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-13 19:50:46 ----A---- C:\Windows\system32\adtschema.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msobjs.dll
2015-08-13 19:50:44 ----A---- C:\Windows\system32\msaudite.dll
2015-08-13 19:50:33 ----A---- C:\Windows\system32\mstscax.dll
2015-08-13 19:50:32 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-13 19:50:31 ----A---- C:\Windows\system32\aaclient.dll
2015-08-13 19:50:08 ----A---- C:\Windows\system32\basesrv.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-13 19:49:44 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\iertutil.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-13 19:49:44 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-13 19:49:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\iernonce.dll
2015-08-13 19:49:43 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-13 19:49:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-13 19:49:42 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-13 19:49:41 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-13 19:49:41 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-13 19:49:40 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-13 19:49:40 ----A---- C:\Windows\system32\urlmon.dll
2015-08-13 19:49:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-13 19:49:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 19:49:39 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-13 19:49:39 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\iesetup.dll
2015-08-13 19:49:38 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-13 19:49:37 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-13 19:49:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\vbscript.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-13 19:49:36 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-13 19:49:35 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\ieui.dll
2015-08-13 19:49:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-13 19:49:34 ----A---- C:\Windows\system32\ieframe.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\wininet.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript9.dll
2015-08-13 19:49:33 ----A---- C:\Windows\system32\jscript.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\msrating.dll
2015-08-13 19:49:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-13 19:49:31 ----A---- C:\Windows\system32\mshtml.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-13 19:48:58 ----A---- C:\Windows\system32\davclnt.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml6.dll
2015-08-13 19:48:56 ----A---- C:\Windows\system32\msxml3.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-13 19:48:55 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-13 19:48:51 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\FntCache.dll
2015-08-13 19:48:51 ----A---- C:\Windows\system32\DWrite.dll
2015-08-13 19:48:50 ----A---- C:\Windows\system32\win32k.sys
2015-08-13 19:48:50 ----A---- C:\Windows\system32\atmfd.dll
2015-08-13 19:48:49 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-13 19:48:48 ----A---- C:\Windows\system32\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\fontsub.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\dciman32.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-13 19:48:47 ----A---- C:\Windows\system32\atmlib.dll
2015-08-13 19:48:43 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-13 19:48:43 ----A---- C:\Windows\notepad.exe
2015-08-13 19:48:41 ----A---- C:\Windows\system32\shell32.dll
2015-08-13 19:48:40 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wucltux.dll
2015-08-13 19:48:37 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups2.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wups.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wudriver.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapp.exe
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wuapi.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 19:48:36 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-13 19:48:20 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-11 21:17:33 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-11 21:17:25 ----A---- C:\Windows\avastSS.scr
2015-08-09 20:33:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2015-08-16 12:24:51 ----D---- C:\Windows\Temp
2015-08-16 12:24:49 ----D---- C:\Program Files\trend micro
2015-08-16 12:22:05 ----D---- C:\Windows\Prefetch
2015-08-16 01:54:56 ----D---- C:\Windows\rescache
2015-08-15 23:08:14 ----D---- C:\Windows\system32\config
2015-08-15 23:02:27 ----D---- C:\Windows\System32
2015-08-15 22:30:59 ----SD---- C:\Users\Blanka\AppData\Roaming\Microsoft
2015-08-15 22:01:10 ----D---- C:\Windows\Microsoft.NET
2015-08-15 21:59:50 ----RSD---- C:\Windows\assembly
2015-08-15 21:37:09 ----D---- C:\Windows\system32\drivers
2015-08-15 21:36:47 ----RD---- C:\Program Files (x86)
2015-08-15 21:25:52 ----D---- C:\Windows\winsxs
2015-08-15 21:22:35 ----SD---- C:\Windows\system32\CompatTel
2015-08-15 21:22:35 ----D---- C:\Windows\system32\appraiser
2015-08-15 21:22:34 ----D---- C:\Windows\AppPatch
2015-08-15 21:22:32 ----D---- C:\Windows\SysWOW64
2015-08-15 21:22:30 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-15 21:22:29 ----D---- C:\Windows\system32\cs-CZ
2015-08-15 21:22:20 ----D---- C:\Program Files\Internet Explorer
2015-08-15 21:22:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-15 21:22:17 ----D---- C:\Windows\system32\en-US
2015-08-15 21:22:14 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-15 21:22:10 ----D---- C:\Windows
2015-08-13 21:18:46 ----D---- C:\Windows\system32\MRT
2015-08-13 21:14:15 ----A---- C:\Windows\system32\MRT.exe
2015-08-13 21:13:22 ----SHD---- C:\System Volume Information
2015-08-13 20:16:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-13 20:07:36 ----D---- C:\Program Files (x86)\rajce
2015-08-13 19:45:13 ----D---- C:\Windows\system32\catroot2
2015-08-13 19:28:47 ----D---- C:\$RECYCLE.BIN
2015-08-11 21:18:02 ----D---- C:\Windows\system32\Tasks
2015-08-10 20:29:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 13:45:49 ----HD---- C:\$Windows.~BT
2015-08-06 13:30:34 ----D---- C:\Windows\Panther
2015-08-06 13:16:04 ----D---- C:\Windows\Logs
2015-08-06 10:38:11 ----D---- C:\Windows\inf
2015-08-06 10:38:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 20:59:18 ----D---- C:\Windows\SoftwareDistribution
2015-08-05 20:53:54 ----SD---- C:\Windows\system32\GWX
2015-07-18 22:56:42 ----D---- C:\Windows\Minidump
2015-07-17 19:30:35 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-17 19:30:35 ----D---- C:\Windows\PolicyDefinitions
2015-07-17 19:30:23 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-11 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-11 274808]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-11 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-11 447944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-11 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-11 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-11 150672]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\Alwil Software\Avast5\ng\vbox\VBoxAswDrv.sys []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\Windows\system32\DRIVERS\s916bus.sys [2007-11-02 108072]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s916mdfl.sys [2007-11-02 19496]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s916mdm.sys [2007-11-02 145448]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2015-08-11 146600]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\Alwil Software\Avast5\ng\vbox\AvastVBoxSVC.exe []
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-09 148136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
S3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-26 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - nalezen malware
Dvouklikem na soubor C:\Program Files\trend micro\Blanka.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - nalezen malware
Je to hotovo, co dál?
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - nalezen malware
Pokud je malware pryč, je to vše.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu - nalezen malware
Super, je to ok, děkuji za pomoc.
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu - nalezen malware
Rádo se stalo! 
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?