
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Spomalený PC a deaktivovaný defender
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Spomalený PC a deaktivovaný defender
Dobrý večer. Chcel by som Vás požiadať o kontrolo logu, pretože mám pomalý PC a win defender je neaktívny dik
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2015-09-20 19:11:15
Microsoft Windows 8.1
System drive C: has 257 GB (54%) free of 477 GB
Total RAM: 2814 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:11:29, on 20.9.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\GWX\GWX.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\skydrive.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files\WindowsApps\Microsoft.Taptiles_2.4.1412.201_x86__8wekyb3d8bbwe\Taptiles.exe
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\3VAPJPY9\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Launcher6015N] "C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 6015N
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort14reminder] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFProHook] "C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [V0260Cfg.exe] V0260Cfg.exe /d:4
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: ImageRetriever.lnk = C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.1 ... rol_32.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sentinel LDK License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 7765 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll [2011-06-30 245016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-13 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPUsageTrackingLEDM"=C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
"Launcher6015N"=C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-05-19 2571264]
"IndexSearch"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe [2013-02-26 51616]
"PaperPort PTD"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe [2013-02-26 39328]
"PPort14reminder"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe [2013-01-14 334152]
"PDFProHook"=C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe [2012-11-05 641424]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [2014-04-17 748256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-27 6111824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"V0260Cfg.exe"=V0260Cfg.exe /d:4 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
""= []
"GarminExpressTrayApp"=C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2015-09-11 1403192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageRetriever.lnk - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.I420"=msh263.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-20 19:11:15 ----D---- C:\rsit
2015-09-20 19:11:15 ----D---- C:\Program Files\trend micro
2015-09-20 17:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-20 17:03:47 ----A---- C:\WINDOWS\system32\winload.exe
2015-09-20 17:03:46 ----A---- C:\WINDOWS\system32\winresume.exe
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\nshwfp.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\BFE.DLL
2015-09-10 13:39:22 ----D---- C:\Users\Admin\AppData\Roaming\EasyFileOpener
2015-09-10 13:39:22 ----D---- C:\ProgramData\Appverifier
2015-09-09 12:37:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:37:29 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\wininet.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:36:17 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\authui.dll
2015-09-09 12:36:15 ----A---- C:\WINDOWS\system32\shacct.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\win32k.sys
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-31 08:13:31 ----D---- C:\ProgramData\VIPRE
2015-08-31 08:04:30 ----D---- C:\Users\Admin\AppData\Roaming\ParetoLogic
2015-08-31 08:04:30 ----A---- C:\Users\Admin\AppData\Roaming\LogFile.txt
2015-08-31 08:04:17 ----D---- C:\ProgramData\ParetoLogic
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\rascfg.dll
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2015-08-31 07:37:09 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\WSDApi.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\untfs.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\spoolsv.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WSDMon.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WinSCard.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\VSSVC.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vsstrace.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vssapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vpnike.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasser.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasmxs.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasdiag.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasapi32.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\eventcls.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\splwow64.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2015-08-31 07:35:58 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\consent.exe
2015-08-31 07:35:12 ----A---- C:\WINDOWS\system32\tdh.dll
2015-08-31 07:30:10 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-08-27 10:41:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppwinob.dll
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppsvc.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-08-25 08:44:23 ----D---- C:\Program Files\GUM5DC0.tmp
======List of files/folders modified in the last 1 month======
2015-09-20 19:11:15 ----RD---- C:\Program Files
2015-09-20 19:07:51 ----RD---- C:\WINDOWS\System32
2015-09-20 19:07:51 ----D---- C:\WINDOWS\inf
2015-09-20 19:07:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-20 19:07:01 ----D---- C:\WINDOWS\Temp
2015-09-20 19:06:33 ----D---- C:\WINDOWS\Prefetch
2015-09-20 19:02:46 ----D---- C:\WINDOWS\system32\config
2015-09-20 19:02:42 ----D---- C:\WINDOWS\WinSxS
2015-09-20 19:02:01 ----D---- C:\WINDOWS\debug
2015-09-20 19:01:55 ----D---- C:\Windows
2015-09-20 19:00:41 ----D---- C:\WINDOWS\system32\sru
2015-09-20 18:59:34 ----D---- C:\WINDOWS\system32\Boot
2015-09-20 17:06:30 ----D---- C:\WINDOWS\CbsTemp
2015-09-20 17:06:15 ----D---- C:\WINDOWS\apppatch
2015-09-20 17:04:40 ----SHD---- C:\System Volume Information
2015-09-20 09:10:32 ----SHD---- C:\WINDOWS\Installer
2015-09-19 16:28:49 ----D---- C:\WINDOWS\system32\NDF
2015-09-19 12:10:32 ----D---- C:\WINDOWS\Microsoft.NET
2015-09-17 19:32:49 ----D---- C:\WINDOWS\system32\Tasks
2015-09-17 19:32:49 ----D---- C:\Program Files\Opera
2015-09-17 08:36:21 ----HD---- C:\Program Files\WindowsApps
2015-09-15 11:10:02 ----HD---- C:\Config.Msi
2015-09-15 11:05:11 ----D---- C:\WINDOWS\Tasks
2015-09-12 16:26:26 ----D---- C:\ProgramData\Package Cache
2015-09-12 16:26:13 ----D---- C:\Program Files\Garmin
2015-09-10 13:56:10 ----HD---- C:\ProgramData
2015-09-10 13:24:05 ----D---- C:\WINDOWS\rescache
2015-09-10 12:30:42 ----D---- C:\WINDOWS\AppReadiness
2015-09-10 05:57:40 ----RSD---- C:\WINDOWS\assembly
2015-09-09 20:49:51 ----D---- C:\WINDOWS\PolicyDefinitions
2015-09-09 20:49:51 ----D---- C:\Program Files\Internet Explorer
2015-09-09 20:49:50 ----D---- C:\WINDOWS\system32\sk-SK
2015-09-09 13:31:51 ----D---- C:\WINDOWS\system32\MRT
2015-09-09 13:25:16 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 13:24:05 ----D---- C:\Program Files\Windows Journal
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\setup
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\Drivers
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\wbem
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\en-US
2015-08-31 12:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-31 09:40:39 ----D---- C:\Program Files\Common Files
2015-08-31 07:36:49 ----D---- C:\WINDOWS\system32\catroot2
2015-08-30 07:28:31 ----D---- C:\WINDOWS\system32\migration
2015-08-28 11:40:20 ----D---- C:\Program Files\CCleaner
2015-08-26 18:36:06 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-13 49776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-13 208664]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-13 81728]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 788784]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-13 433264]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys [2014-04-29 425352]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-13 24016]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-13 76000]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-13 113592]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [2014-04-29 609624]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-04 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-07-04 290304]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 V0260VID;@oem68.inf,%szDeviceDesc%;Live! Cam Vista IM; C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S3 dg_ssudbus;@oem113.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
S3 dot4;@oem2.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 137632]
S3 Dot4Print;@oem13.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 22432]
S3 dot4usb;@oem2.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 42912]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-02-02 17488]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2012-04-18 15720]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 mvusbews;@oem5.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 17408]
S3 nmwcd;@oem72.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;@oem75.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 ssudmdm;@oem114.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 37888]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2014-11-04 26624]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 64000]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2012-07-04 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 276992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-13 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
R2 hasplms;Sentinel LDK License Manager; C:\WINDOWS\system32\hasplms.exe [2014-04-29 4683144]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe [2013-02-26 220488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-09-11 762272]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-02 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2015-09-20 19:11:15
Microsoft Windows 8.1
System drive C: has 257 GB (54%) free of 477 GB
Total RAM: 2814 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:11:29, on 20.9.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\GWX\GWX.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\skydrive.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files\WindowsApps\Microsoft.Taptiles_2.4.1412.201_x86__8wekyb3d8bbwe\Taptiles.exe
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\3VAPJPY9\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Launcher6015N] "C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 6015N
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort14reminder] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFProHook] "C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [V0260Cfg.exe] V0260Cfg.exe /d:4
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: ImageRetriever.lnk = C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.1 ... rol_32.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sentinel LDK License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 7765 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll [2011-06-30 245016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-13 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPUsageTrackingLEDM"=C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
"Launcher6015N"=C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-05-19 2571264]
"IndexSearch"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe [2013-02-26 51616]
"PaperPort PTD"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe [2013-02-26 39328]
"PPort14reminder"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe [2013-01-14 334152]
"PDFProHook"=C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe [2012-11-05 641424]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [2014-04-17 748256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-27 6111824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"V0260Cfg.exe"=V0260Cfg.exe /d:4 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
""= []
"GarminExpressTrayApp"=C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2015-09-11 1403192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageRetriever.lnk - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.I420"=msh263.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-20 19:11:15 ----D---- C:\rsit
2015-09-20 19:11:15 ----D---- C:\Program Files\trend micro
2015-09-20 17:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-20 17:03:47 ----A---- C:\WINDOWS\system32\winload.exe
2015-09-20 17:03:46 ----A---- C:\WINDOWS\system32\winresume.exe
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\nshwfp.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\BFE.DLL
2015-09-10 13:39:22 ----D---- C:\Users\Admin\AppData\Roaming\EasyFileOpener
2015-09-10 13:39:22 ----D---- C:\ProgramData\Appverifier
2015-09-09 12:37:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:37:29 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\wininet.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:36:17 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\authui.dll
2015-09-09 12:36:15 ----A---- C:\WINDOWS\system32\shacct.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\win32k.sys
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-31 08:13:31 ----D---- C:\ProgramData\VIPRE
2015-08-31 08:04:30 ----D---- C:\Users\Admin\AppData\Roaming\ParetoLogic
2015-08-31 08:04:30 ----A---- C:\Users\Admin\AppData\Roaming\LogFile.txt
2015-08-31 08:04:17 ----D---- C:\ProgramData\ParetoLogic
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\rascfg.dll
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2015-08-31 07:37:09 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\WSDApi.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\untfs.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\spoolsv.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WSDMon.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WinSCard.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\VSSVC.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vsstrace.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vssapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vpnike.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasser.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasmxs.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasdiag.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasapi32.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\eventcls.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\splwow64.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2015-08-31 07:35:58 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\consent.exe
2015-08-31 07:35:12 ----A---- C:\WINDOWS\system32\tdh.dll
2015-08-31 07:30:10 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-08-27 10:41:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppwinob.dll
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppsvc.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-08-25 08:44:23 ----D---- C:\Program Files\GUM5DC0.tmp
======List of files/folders modified in the last 1 month======
2015-09-20 19:11:15 ----RD---- C:\Program Files
2015-09-20 19:07:51 ----RD---- C:\WINDOWS\System32
2015-09-20 19:07:51 ----D---- C:\WINDOWS\inf
2015-09-20 19:07:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-20 19:07:01 ----D---- C:\WINDOWS\Temp
2015-09-20 19:06:33 ----D---- C:\WINDOWS\Prefetch
2015-09-20 19:02:46 ----D---- C:\WINDOWS\system32\config
2015-09-20 19:02:42 ----D---- C:\WINDOWS\WinSxS
2015-09-20 19:02:01 ----D---- C:\WINDOWS\debug
2015-09-20 19:01:55 ----D---- C:\Windows
2015-09-20 19:00:41 ----D---- C:\WINDOWS\system32\sru
2015-09-20 18:59:34 ----D---- C:\WINDOWS\system32\Boot
2015-09-20 17:06:30 ----D---- C:\WINDOWS\CbsTemp
2015-09-20 17:06:15 ----D---- C:\WINDOWS\apppatch
2015-09-20 17:04:40 ----SHD---- C:\System Volume Information
2015-09-20 09:10:32 ----SHD---- C:\WINDOWS\Installer
2015-09-19 16:28:49 ----D---- C:\WINDOWS\system32\NDF
2015-09-19 12:10:32 ----D---- C:\WINDOWS\Microsoft.NET
2015-09-17 19:32:49 ----D---- C:\WINDOWS\system32\Tasks
2015-09-17 19:32:49 ----D---- C:\Program Files\Opera
2015-09-17 08:36:21 ----HD---- C:\Program Files\WindowsApps
2015-09-15 11:10:02 ----HD---- C:\Config.Msi
2015-09-15 11:05:11 ----D---- C:\WINDOWS\Tasks
2015-09-12 16:26:26 ----D---- C:\ProgramData\Package Cache
2015-09-12 16:26:13 ----D---- C:\Program Files\Garmin
2015-09-10 13:56:10 ----HD---- C:\ProgramData
2015-09-10 13:24:05 ----D---- C:\WINDOWS\rescache
2015-09-10 12:30:42 ----D---- C:\WINDOWS\AppReadiness
2015-09-10 05:57:40 ----RSD---- C:\WINDOWS\assembly
2015-09-09 20:49:51 ----D---- C:\WINDOWS\PolicyDefinitions
2015-09-09 20:49:51 ----D---- C:\Program Files\Internet Explorer
2015-09-09 20:49:50 ----D---- C:\WINDOWS\system32\sk-SK
2015-09-09 13:31:51 ----D---- C:\WINDOWS\system32\MRT
2015-09-09 13:25:16 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 13:24:05 ----D---- C:\Program Files\Windows Journal
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\setup
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\Drivers
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\wbem
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\en-US
2015-08-31 12:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-31 09:40:39 ----D---- C:\Program Files\Common Files
2015-08-31 07:36:49 ----D---- C:\WINDOWS\system32\catroot2
2015-08-30 07:28:31 ----D---- C:\WINDOWS\system32\migration
2015-08-28 11:40:20 ----D---- C:\Program Files\CCleaner
2015-08-26 18:36:06 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-13 49776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-13 208664]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-13 81728]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 788784]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-13 433264]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys [2014-04-29 425352]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-13 24016]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-13 76000]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-13 113592]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [2014-04-29 609624]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-04 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-07-04 290304]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 V0260VID;@oem68.inf,%szDeviceDesc%;Live! Cam Vista IM; C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S3 dg_ssudbus;@oem113.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
S3 dot4;@oem2.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 137632]
S3 Dot4Print;@oem13.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 22432]
S3 dot4usb;@oem2.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 42912]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-02-02 17488]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2012-04-18 15720]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 mvusbews;@oem5.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 17408]
S3 nmwcd;@oem72.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;@oem75.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 ssudmdm;@oem114.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 37888]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2014-11-04 26624]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 64000]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2012-07-04 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 276992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-13 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
R2 hasplms;Sentinel LDK License Manager; C:\WINDOWS\system32\hasplms.exe [2014-04-29 4683144]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe [2013-02-26 220488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-09-11 762272]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-02 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Tu to je
# AdwCleaner v5.008 - Logfile created 20/09/2015 at 21:13:50
# Updated 18/09/2015 by Xplode
# Database : 2015-09-20.1 [Server]
# Operating system : Windows 8.1 (x86)
# Username : Admin - STEFAN
# Running from : C:\Users\Admin\Desktop\adwcleaner_5.008.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\Movies App
[-] Folder Deleted : C:\ProgramData\ParetoLogic
[-] Folder Deleted : C:\ProgramData\AppVerifier
[-] Folder Deleted : C:\ProgramData\{9559969E-5786-48CA-87AB-B7695EC37420}
[-] Folder Deleted : C:\ProgramData\{BDDB56DE-AE4E-48A2-B856-FB60C8498453}
[-] Folder Deleted : C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\video download converter
[-] Folder Deleted : C:\Users\Admin\AppData\Local\ilividbandoomoviestoolbar
[-] Folder Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
[-] Folder Deleted : C:\Users\Admin\AppData\LocalLow\searchresultstb
[-] Folder Deleted : C:\Users\Admin\AppData\LocalLow\ilividbandoomoviestoolbar
[-] Folder Deleted : C:\Users\Admin\AppData\Roaming\ParetoLogic
[-] Folder Deleted : C:\Users\Admin\AppData\Roaming\EasyFileOpener
[-] Folder Deleted : C:\Users\Admin\Documents\video download converter
***** [ Files ] *****
[-] File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fjoijdanhaiflhibkljeklcghcmmfffh_0.localstorage
[-] File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaaaaigjndjblmpeckabiffcpogflfgl_0.localstorage
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
[-] Key Deleted : HKCU\Software\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66D59105-FE06-43A4-B292-EB0097E9EB74}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C0CAA5FE-7C9C-4DCA-A265-63CF55379D1A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0CAA5FE-7C9C-4DCA-A265-63CF55379D1A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9103C314-C4E2-4463-8934-B19BCB46236D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{97CEF41C-5055-474A-855A-892D4FE3E596}
[-] Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
[-] Key Deleted : HKCU\Software\APNDTX
[-] Key Deleted : HKCU\Software\DataMngr
[-] Key Deleted : HKCU\Software\ilivid
[-] Key Deleted : HKCU\Software\ParetoLogic
[-] Key Deleted : HKCU\Software\IObit Apps
[-] Key Deleted : HKCU\Software\Appscion
[-] Key Deleted : HKCU\Software\AppDataLow\Software\IObit Apps
[-] Key Deleted : HKLM\SOFTWARE\DataMngr
[-] Key Deleted : HKLM\SOFTWARE\ParetoLogic
[-] Key Deleted : HKLM\SOFTWARE\IObit Apps
[!] Key Not Deleted : HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\Software\AppDataLow\Software\IObit Apps
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
[!] Key Not Deleted : HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
***** [ Web browsers ] *****
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaafeopjhkcolncjbedbhofpocmdbn
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaaigjndjblmpeckabiffcpogflfgl
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : glmfgahfleepmdfffonfckpmkondpdkg
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4738 bytes] ##########
# AdwCleaner v5.008 - Logfile created 20/09/2015 at 21:13:50
# Updated 18/09/2015 by Xplode
# Database : 2015-09-20.1 [Server]
# Operating system : Windows 8.1 (x86)
# Username : Admin - STEFAN
# Running from : C:\Users\Admin\Desktop\adwcleaner_5.008.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\Movies App
[-] Folder Deleted : C:\ProgramData\ParetoLogic
[-] Folder Deleted : C:\ProgramData\AppVerifier
[-] Folder Deleted : C:\ProgramData\{9559969E-5786-48CA-87AB-B7695EC37420}
[-] Folder Deleted : C:\ProgramData\{BDDB56DE-AE4E-48A2-B856-FB60C8498453}
[-] Folder Deleted : C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\video download converter
[-] Folder Deleted : C:\Users\Admin\AppData\Local\ilividbandoomoviestoolbar
[-] Folder Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
[-] Folder Deleted : C:\Users\Admin\AppData\LocalLow\searchresultstb
[-] Folder Deleted : C:\Users\Admin\AppData\LocalLow\ilividbandoomoviestoolbar
[-] Folder Deleted : C:\Users\Admin\AppData\Roaming\ParetoLogic
[-] Folder Deleted : C:\Users\Admin\AppData\Roaming\EasyFileOpener
[-] Folder Deleted : C:\Users\Admin\Documents\video download converter
***** [ Files ] *****
[-] File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fjoijdanhaiflhibkljeklcghcmmfffh_0.localstorage
[-] File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaaaaigjndjblmpeckabiffcpogflfgl_0.localstorage
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
[-] Key Deleted : HKCU\Software\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66D59105-FE06-43A4-B292-EB0097E9EB74}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C0CAA5FE-7C9C-4DCA-A265-63CF55379D1A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0CAA5FE-7C9C-4DCA-A265-63CF55379D1A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9103C314-C4E2-4463-8934-B19BCB46236D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{97CEF41C-5055-474A-855A-892D4FE3E596}
[-] Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
[-] Key Deleted : HKCU\Software\APNDTX
[-] Key Deleted : HKCU\Software\DataMngr
[-] Key Deleted : HKCU\Software\ilivid
[-] Key Deleted : HKCU\Software\ParetoLogic
[-] Key Deleted : HKCU\Software\IObit Apps
[-] Key Deleted : HKCU\Software\Appscion
[-] Key Deleted : HKCU\Software\AppDataLow\Software\IObit Apps
[-] Key Deleted : HKLM\SOFTWARE\DataMngr
[-] Key Deleted : HKLM\SOFTWARE\ParetoLogic
[-] Key Deleted : HKLM\SOFTWARE\IObit Apps
[!] Key Not Deleted : HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\Software\AppDataLow\Software\IObit Apps
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
[!] Key Not Deleted : HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
***** [ Web browsers ] *****
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaafeopjhkcolncjbedbhofpocmdbn
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : aaaaaigjndjblmpeckabiffcpogflfgl
[-] [C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : glmfgahfleepmdfffonfckpmkondpdkg
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4738 bytes] ##########
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2015-09-20 22:16:01
Microsoft Windows 8.1
System drive C: has 257 GB (54%) free of 477 GB
Total RAM: 2814 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:16:10, on 20.9.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\GWX\GWX.exe
C:\Windows\System32\skydrive.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files\WindowsApps\Microsoft.Taptiles_2.4.1412.201_x86__8wekyb3d8bbwe\Taptiles.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\WindowsApps\Microsoft.MicrosoftTreasureHunt_1.0.1405.747_x86__8wekyb3d8bbwe\Treasure Hunt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x86__8wekyb3d8bbwe\LiveComm.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\A8GCIH12\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Launcher6015N] "C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 6015N
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort14reminder] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFProHook] "C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [V0260Cfg.exe] V0260Cfg.exe /d:4
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: ImageRetriever.lnk = C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.1 ... rol_32.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sentinel LDK License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 8110 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll [2011-06-30 245016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-13 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPUsageTrackingLEDM"=C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
"Launcher6015N"=C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-05-19 2571264]
"IndexSearch"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe [2013-02-26 51616]
"PaperPort PTD"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe [2013-02-26 39328]
"PPort14reminder"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe [2013-01-14 334152]
"PDFProHook"=C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe [2012-11-05 641424]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [2014-04-17 748256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-27 6111824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"V0260Cfg.exe"=V0260Cfg.exe /d:4 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
""= []
"GarminExpressTrayApp"=C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2015-09-11 1403192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageRetriever.lnk - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.I420"=msh263.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-20 21:13:04 ----D---- C:\AdwCleaner
2015-09-20 19:11:15 ----D---- C:\rsit
2015-09-20 19:11:15 ----D---- C:\Program Files\trend micro
2015-09-20 17:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-20 17:03:47 ----A---- C:\WINDOWS\system32\winload.exe
2015-09-20 17:03:46 ----A---- C:\WINDOWS\system32\winresume.exe
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\nshwfp.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\BFE.DLL
2015-09-09 12:37:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:37:29 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\wininet.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:36:17 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\authui.dll
2015-09-09 12:36:15 ----A---- C:\WINDOWS\system32\shacct.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\win32k.sys
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-31 08:13:31 ----D---- C:\ProgramData\VIPRE
2015-08-31 08:04:30 ----A---- C:\Users\Admin\AppData\Roaming\LogFile.txt
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\rascfg.dll
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2015-08-31 07:37:09 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\WSDApi.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\untfs.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\spoolsv.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WSDMon.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WinSCard.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\VSSVC.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vsstrace.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vssapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vpnike.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasser.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasmxs.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasdiag.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasapi32.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\eventcls.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\splwow64.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2015-08-31 07:35:58 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\consent.exe
2015-08-31 07:35:12 ----A---- C:\WINDOWS\system32\tdh.dll
2015-08-31 07:30:10 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-08-27 10:41:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppwinob.dll
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppsvc.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-08-25 08:44:23 ----D---- C:\Program Files\GUM5DC0.tmp
======List of files/folders modified in the last 1 month======
2015-09-20 22:02:00 ----D---- C:\WINDOWS\system32\sru
2015-09-20 21:58:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-09-20 21:58:30 ----D---- C:\WINDOWS\Temp
2015-09-20 21:58:11 ----D---- C:\WINDOWS\system32\config
2015-09-20 21:58:01 ----D---- C:\WINDOWS\Prefetch
2015-09-20 21:13:51 ----RD---- C:\Program Files
2015-09-20 21:13:51 ----HD---- C:\ProgramData
2015-09-20 20:51:20 ----D---- C:\WINDOWS\rescache
2015-09-20 19:59:44 ----D---- C:\WINDOWS\system32\catroot2
2015-09-20 19:07:51 ----RD---- C:\WINDOWS\System32
2015-09-20 19:07:51 ----D---- C:\WINDOWS\inf
2015-09-20 19:07:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-20 19:02:42 ----D---- C:\WINDOWS\WinSxS
2015-09-20 19:02:01 ----D---- C:\WINDOWS\debug
2015-09-20 19:01:55 ----D---- C:\Windows
2015-09-20 18:59:34 ----D---- C:\WINDOWS\system32\Boot
2015-09-20 17:06:35 ----D---- C:\WINDOWS\CbsTemp
2015-09-20 17:06:15 ----D---- C:\WINDOWS\apppatch
2015-09-20 17:04:40 ----SHD---- C:\System Volume Information
2015-09-20 09:10:32 ----SHD---- C:\WINDOWS\Installer
2015-09-19 16:28:49 ----D---- C:\WINDOWS\system32\NDF
2015-09-17 19:32:49 ----D---- C:\WINDOWS\system32\Tasks
2015-09-17 19:32:49 ----D---- C:\Program Files\Opera
2015-09-17 08:36:23 ----D---- C:\WINDOWS\AppReadiness
2015-09-17 08:36:21 ----HD---- C:\Program Files\WindowsApps
2015-09-15 11:10:02 ----HD---- C:\Config.Msi
2015-09-15 11:05:11 ----D---- C:\WINDOWS\Tasks
2015-09-12 16:26:26 ----D---- C:\ProgramData\Package Cache
2015-09-12 16:26:13 ----D---- C:\Program Files\Garmin
2015-09-10 05:57:40 ----RSD---- C:\WINDOWS\assembly
2015-09-09 20:49:51 ----D---- C:\WINDOWS\PolicyDefinitions
2015-09-09 20:49:51 ----D---- C:\Program Files\Internet Explorer
2015-09-09 20:49:50 ----D---- C:\WINDOWS\system32\sk-SK
2015-09-09 13:31:51 ----D---- C:\WINDOWS\system32\MRT
2015-09-09 13:25:16 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 13:24:05 ----D---- C:\Program Files\Windows Journal
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\setup
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\Drivers
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\wbem
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\en-US
2015-08-31 12:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-31 09:40:39 ----D---- C:\Program Files\Common Files
2015-08-30 07:28:31 ----D---- C:\WINDOWS\system32\migration
2015-08-28 11:40:20 ----D---- C:\Program Files\CCleaner
2015-08-26 18:36:06 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-13 49776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-13 208664]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-13 81728]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 788784]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-13 433264]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys [2014-04-29 425352]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-13 24016]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-13 76000]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-13 113592]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [2014-04-29 609624]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-04 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-07-04 290304]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 V0260VID;@oem68.inf,%szDeviceDesc%;Live! Cam Vista IM; C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S3 dg_ssudbus;@oem113.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
S3 dot4;@oem2.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 137632]
S3 Dot4Print;@oem13.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 22432]
S3 dot4usb;@oem2.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 42912]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-02-02 17488]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2012-04-18 15720]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 mvusbews;@oem5.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 17408]
S3 nmwcd;@oem72.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;@oem75.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 ssudmdm;@oem114.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 37888]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2014-11-04 26624]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 64000]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2012-07-04 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 276992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-13 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
R2 hasplms;Sentinel LDK License Manager; C:\WINDOWS\system32\hasplms.exe [2014-04-29 4683144]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe [2013-02-26 220488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-09-11 762272]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-02 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
-----------------EOF-----------------
Run by Admin at 2015-09-20 22:16:01
Microsoft Windows 8.1
System drive C: has 257 GB (54%) free of 477 GB
Total RAM: 2814 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:16:10, on 20.9.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\GWX\GWX.exe
C:\Windows\System32\skydrive.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files\WindowsApps\Microsoft.Taptiles_2.4.1412.201_x86__8wekyb3d8bbwe\Taptiles.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\WindowsApps\Microsoft.MicrosoftTreasureHunt_1.0.1405.747_x86__8wekyb3d8bbwe\Treasure Hunt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x86__8wekyb3d8bbwe\LiveComm.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\A8GCIH12\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Launcher6015N] "C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 6015N
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort14reminder] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFProHook] "C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [V0260Cfg.exe] V0260Cfg.exe /d:4
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: ImageRetriever.lnk = C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.1 ... rol_32.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sentinel LDK License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 8110 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll [2011-06-30 245016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-13 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-20 194504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPUsageTrackingLEDM"=C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
"Launcher6015N"=C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-05-19 2571264]
"IndexSearch"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe [2013-02-26 51616]
"PaperPort PTD"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe [2013-02-26 39328]
"PPort14reminder"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe [2013-01-14 334152]
"PDFProHook"=C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe [2012-11-05 641424]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [2014-04-17 748256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-27 6111824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"V0260Cfg.exe"=V0260Cfg.exe /d:4 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
""= []
"GarminExpressTrayApp"=C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2015-09-11 1403192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageRetriever.lnk - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.I420"=msh263.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-20 21:13:04 ----D---- C:\AdwCleaner
2015-09-20 19:11:15 ----D---- C:\rsit
2015-09-20 19:11:15 ----D---- C:\Program Files\trend micro
2015-09-20 17:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-20 17:03:47 ----A---- C:\WINDOWS\system32\winload.exe
2015-09-20 17:03:46 ----A---- C:\WINDOWS\system32\winresume.exe
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\nshwfp.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\BFE.DLL
2015-09-09 12:37:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:37:29 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\wininet.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:36:17 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\authui.dll
2015-09-09 12:36:15 ----A---- C:\WINDOWS\system32\shacct.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\win32k.sys
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-31 08:13:31 ----D---- C:\ProgramData\VIPRE
2015-08-31 08:04:30 ----A---- C:\Users\Admin\AppData\Roaming\LogFile.txt
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\rascfg.dll
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2015-08-31 07:37:09 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\WSDApi.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\untfs.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\spoolsv.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WSDMon.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WinSCard.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\VSSVC.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vsstrace.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vssapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vpnike.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasser.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasmxs.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasdiag.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasapi32.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\eventcls.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\splwow64.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2015-08-31 07:35:58 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\consent.exe
2015-08-31 07:35:12 ----A---- C:\WINDOWS\system32\tdh.dll
2015-08-31 07:30:10 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-08-27 10:41:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppwinob.dll
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppsvc.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-08-25 08:44:23 ----D---- C:\Program Files\GUM5DC0.tmp
======List of files/folders modified in the last 1 month======
2015-09-20 22:02:00 ----D---- C:\WINDOWS\system32\sru
2015-09-20 21:58:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-09-20 21:58:30 ----D---- C:\WINDOWS\Temp
2015-09-20 21:58:11 ----D---- C:\WINDOWS\system32\config
2015-09-20 21:58:01 ----D---- C:\WINDOWS\Prefetch
2015-09-20 21:13:51 ----RD---- C:\Program Files
2015-09-20 21:13:51 ----HD---- C:\ProgramData
2015-09-20 20:51:20 ----D---- C:\WINDOWS\rescache
2015-09-20 19:59:44 ----D---- C:\WINDOWS\system32\catroot2
2015-09-20 19:07:51 ----RD---- C:\WINDOWS\System32
2015-09-20 19:07:51 ----D---- C:\WINDOWS\inf
2015-09-20 19:07:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-20 19:02:42 ----D---- C:\WINDOWS\WinSxS
2015-09-20 19:02:01 ----D---- C:\WINDOWS\debug
2015-09-20 19:01:55 ----D---- C:\Windows
2015-09-20 18:59:34 ----D---- C:\WINDOWS\system32\Boot
2015-09-20 17:06:35 ----D---- C:\WINDOWS\CbsTemp
2015-09-20 17:06:15 ----D---- C:\WINDOWS\apppatch
2015-09-20 17:04:40 ----SHD---- C:\System Volume Information
2015-09-20 09:10:32 ----SHD---- C:\WINDOWS\Installer
2015-09-19 16:28:49 ----D---- C:\WINDOWS\system32\NDF
2015-09-17 19:32:49 ----D---- C:\WINDOWS\system32\Tasks
2015-09-17 19:32:49 ----D---- C:\Program Files\Opera
2015-09-17 08:36:23 ----D---- C:\WINDOWS\AppReadiness
2015-09-17 08:36:21 ----HD---- C:\Program Files\WindowsApps
2015-09-15 11:10:02 ----HD---- C:\Config.Msi
2015-09-15 11:05:11 ----D---- C:\WINDOWS\Tasks
2015-09-12 16:26:26 ----D---- C:\ProgramData\Package Cache
2015-09-12 16:26:13 ----D---- C:\Program Files\Garmin
2015-09-10 05:57:40 ----RSD---- C:\WINDOWS\assembly
2015-09-09 20:49:51 ----D---- C:\WINDOWS\PolicyDefinitions
2015-09-09 20:49:51 ----D---- C:\Program Files\Internet Explorer
2015-09-09 20:49:50 ----D---- C:\WINDOWS\system32\sk-SK
2015-09-09 13:31:51 ----D---- C:\WINDOWS\system32\MRT
2015-09-09 13:25:16 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 13:24:05 ----D---- C:\Program Files\Windows Journal
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\setup
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\Drivers
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\wbem
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\en-US
2015-08-31 12:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-31 09:40:39 ----D---- C:\Program Files\Common Files
2015-08-30 07:28:31 ----D---- C:\WINDOWS\system32\migration
2015-08-28 11:40:20 ----D---- C:\Program Files\CCleaner
2015-08-26 18:36:06 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-13 49776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-13 208664]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-13 81728]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 788784]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-13 433264]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys [2014-04-29 425352]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-13 24016]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-13 76000]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-13 113592]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [2014-04-29 609624]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-04 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-07-04 290304]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 V0260VID;@oem68.inf,%szDeviceDesc%;Live! Cam Vista IM; C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S3 dg_ssudbus;@oem113.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
S3 dot4;@oem2.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 137632]
S3 Dot4Print;@oem13.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 22432]
S3 dot4usb;@oem2.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 42912]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-02-02 17488]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2012-04-18 15720]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 mvusbews;@oem5.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 17408]
S3 nmwcd;@oem72.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;@oem75.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 ssudmdm;@oem114.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 37888]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2014-11-04 26624]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 64000]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2012-07-04 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 276992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-13 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
R2 hasplms;Sentinel LDK License Manager; C:\WINDOWS\system32\hasplms.exe [2014-04-29 4683144]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe [2013-02-26 220488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-09-11 762272]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-02 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.:files
C:\Program Files\Google\Google Toolbar
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files\GUM5DC0.tmp
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Po reštarte mi vygenerovalo
All processes killed
========== FILES ==========
C:\Program Files\Google\Google Toolbar\Component folder moved successfully.
C:\Program Files\Google\Google Toolbar folder moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Program Files\GUM5DC0.tmp folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 40559574 bytes
->Temporary Internet Files folder emptied: 132402994 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 588 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default.migrated
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26976874 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 191,00 mb
[EMPTYFLASH]
User: Admin
->Flash cache emptied: 0 bytes
User: All Users
User: Default
User: Default User
User: Default.migrated
User: Public
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 09202015_225708
Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.
Registry entries deleted on Reboot...
log RSIT
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2015-09-20 23:10:06
Microsoft Windows 8.1
System drive C: has 257 GB (54%) free of 477 GB
Total RAM: 2814 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:10:13, on 20.9.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\GWX\GWX.exe
C:\Windows\System32\SettingSyncHost.exe
C:\WINDOWS\notepad.exe
C:\Windows\System32\skydrive.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WindowsApps\Microsoft.Taptiles_2.4.1412.201_x86__8wekyb3d8bbwe\Taptiles.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\1ITCBRV3\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Launcher6015N] "C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 6015N
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort14reminder] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFProHook] "C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [V0260Cfg.exe] V0260Cfg.exe /d:4
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: ImageRetriever.lnk = C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.1 ... rol_32.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sentinel LDK License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 7608 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll [2011-06-30 245016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-13 559624]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPUsageTrackingLEDM"=C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
"Launcher6015N"=C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-05-19 2571264]
"IndexSearch"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe [2013-02-26 51616]
"PaperPort PTD"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe [2013-02-26 39328]
"PPort14reminder"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe [2013-01-14 334152]
"PDFProHook"=C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe [2012-11-05 641424]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [2014-04-17 748256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-27 6111824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"V0260Cfg.exe"=V0260Cfg.exe /d:4 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
""= []
"GarminExpressTrayApp"=C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2015-09-11 1403192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageRetriever.lnk - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.I420"=msh263.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-20 22:57:08 ----D---- C:\_OTM
2015-09-20 21:13:04 ----D---- C:\AdwCleaner
2015-09-20 19:11:15 ----D---- C:\rsit
2015-09-20 19:11:15 ----D---- C:\Program Files\trend micro
2015-09-20 17:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-20 17:03:47 ----A---- C:\WINDOWS\system32\winload.exe
2015-09-20 17:03:46 ----A---- C:\WINDOWS\system32\winresume.exe
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\nshwfp.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\BFE.DLL
2015-09-09 12:37:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:37:29 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\wininet.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:36:17 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\authui.dll
2015-09-09 12:36:15 ----A---- C:\WINDOWS\system32\shacct.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\win32k.sys
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-31 08:13:31 ----D---- C:\ProgramData\VIPRE
2015-08-31 08:04:30 ----A---- C:\Users\Admin\AppData\Roaming\LogFile.txt
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\rascfg.dll
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2015-08-31 07:37:09 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\WSDApi.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\untfs.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\spoolsv.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WSDMon.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WinSCard.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\VSSVC.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vsstrace.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vssapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vpnike.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasser.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasmxs.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasdiag.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasapi32.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\eventcls.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\splwow64.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2015-08-31 07:35:58 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\consent.exe
2015-08-31 07:35:12 ----A---- C:\WINDOWS\system32\tdh.dll
2015-08-31 07:30:10 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-08-27 10:41:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppwinob.dll
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppsvc.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppobjs.dll
======List of files/folders modified in the last 1 month======
2015-09-20 23:03:55 ----D---- C:\WINDOWS\Temp
2015-09-20 23:00:57 ----D---- C:\WINDOWS\Prefetch
2015-09-20 22:57:26 ----D---- C:\Windows
2015-09-20 22:57:09 ----RD---- C:\Program Files
2015-09-20 22:57:09 ----D---- C:\WINDOWS\Tasks
2015-09-20 22:57:09 ----D---- C:\Program Files\Google
2015-09-20 22:45:40 ----D---- C:\WINDOWS\system32\config
2015-09-20 22:02:00 ----D---- C:\WINDOWS\system32\sru
2015-09-20 21:58:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-09-20 21:13:51 ----HD---- C:\ProgramData
2015-09-20 20:51:20 ----D---- C:\WINDOWS\rescache
2015-09-20 19:59:44 ----D---- C:\WINDOWS\system32\catroot2
2015-09-20 19:07:51 ----RD---- C:\WINDOWS\System32
2015-09-20 19:07:51 ----D---- C:\WINDOWS\inf
2015-09-20 19:07:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-20 19:02:42 ----D---- C:\WINDOWS\WinSxS
2015-09-20 19:02:01 ----D---- C:\WINDOWS\debug
2015-09-20 18:59:34 ----D---- C:\WINDOWS\system32\Boot
2015-09-20 17:06:35 ----D---- C:\WINDOWS\CbsTemp
2015-09-20 17:06:15 ----D---- C:\WINDOWS\apppatch
2015-09-20 17:04:40 ----SHD---- C:\System Volume Information
2015-09-20 09:10:32 ----SHD---- C:\WINDOWS\Installer
2015-09-19 16:28:49 ----D---- C:\WINDOWS\system32\NDF
2015-09-17 19:32:49 ----D---- C:\WINDOWS\system32\Tasks
2015-09-17 19:32:49 ----D---- C:\Program Files\Opera
2015-09-17 08:36:23 ----D---- C:\WINDOWS\AppReadiness
2015-09-17 08:36:21 ----HD---- C:\Program Files\WindowsApps
2015-09-15 11:10:02 ----HD---- C:\Config.Msi
2015-09-12 16:26:26 ----D---- C:\ProgramData\Package Cache
2015-09-12 16:26:13 ----D---- C:\Program Files\Garmin
2015-09-10 05:57:40 ----RSD---- C:\WINDOWS\assembly
2015-09-09 20:49:51 ----D---- C:\WINDOWS\PolicyDefinitions
2015-09-09 20:49:51 ----D---- C:\Program Files\Internet Explorer
2015-09-09 20:49:50 ----D---- C:\WINDOWS\system32\sk-SK
2015-09-09 13:31:51 ----D---- C:\WINDOWS\system32\MRT
2015-09-09 13:25:16 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 13:24:05 ----D---- C:\Program Files\Windows Journal
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\setup
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\Drivers
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\wbem
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\en-US
2015-08-31 12:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-31 09:40:39 ----D---- C:\Program Files\Common Files
2015-08-30 07:28:31 ----D---- C:\WINDOWS\system32\migration
2015-08-28 11:40:20 ----D---- C:\Program Files\CCleaner
2015-08-26 18:36:06 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-13 49776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-13 208664]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-13 81728]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 788784]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-13 433264]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys [2014-04-29 425352]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-13 24016]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-13 76000]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-13 113592]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [2014-04-29 609624]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-04 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-07-04 290304]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 V0260VID;@oem68.inf,%szDeviceDesc%;Live! Cam Vista IM; C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S3 dg_ssudbus;@oem113.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
S3 dot4;@oem2.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 137632]
S3 Dot4Print;@oem13.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 22432]
S3 dot4usb;@oem2.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 42912]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-02-02 17488]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2012-04-18 15720]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 mvusbews;@oem5.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 17408]
S3 nmwcd;@oem72.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;@oem75.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 ssudmdm;@oem114.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 37888]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2014-11-04 26624]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 64000]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2012-07-04 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 276992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-13 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
R2 hasplms;Sentinel LDK License Manager; C:\WINDOWS\system32\hasplms.exe [2014-04-29 4683144]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe [2013-02-26 220488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-09-11 762272]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-02 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
-----------------EOF-----------------
All processes killed
========== FILES ==========
C:\Program Files\Google\Google Toolbar\Component folder moved successfully.
C:\Program Files\Google\Google Toolbar folder moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Program Files\GUM5DC0.tmp folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 40559574 bytes
->Temporary Internet Files folder emptied: 132402994 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 588 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default.migrated
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26976874 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 191,00 mb
[EMPTYFLASH]
User: Admin
->Flash cache emptied: 0 bytes
User: All Users
User: Default
User: Default User
User: Default.migrated
User: Public
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 09202015_225708
Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.
Registry entries deleted on Reboot...
log RSIT
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2015-09-20 23:10:06
Microsoft Windows 8.1
System drive C: has 257 GB (54%) free of 477 GB
Total RAM: 2814 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:10:13, on 20.9.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\GWX\GWX.exe
C:\Windows\System32\SettingSyncHost.exe
C:\WINDOWS\notepad.exe
C:\Windows\System32\skydrive.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WindowsApps\Microsoft.Taptiles_2.4.1412.201_x86__8wekyb3d8bbwe\Taptiles.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\1ITCBRV3\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [Launcher6015N] "C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe" /S Xerox WorkCentre 6015N
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort14reminder] "C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFProHook] "C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [V0260Cfg.exe] V0260Cfg.exe /d:4
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: ImageRetriever.lnk = C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.1 ... rol_32.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sentinel LDK License Manager (hasplms) - SafeNet Inc. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XRcnStatutsDatabase (XRNADB) - Unknown owner - C:\Program Files\Xerox Office Printing\WorkCentre SSW\PrintingScout\xrksmdb.exe
--
End of file - 7608 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}]
PlusIEEventHelper Class - C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\Bin\PlusIEContextMenu.dll [2011-06-30 245016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-13 559624]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPUsageTrackingLEDM"=C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
"Launcher6015N"=C:\Program Files\Xerox Office Printing\WorkCentre SSW\Launcher\xrlaunch.exe [2011-05-19 2571264]
"IndexSearch"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\IndexSearch.exe [2013-02-26 51616]
"PaperPort PTD"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\pptd40nt.exe [2013-02-26 39328]
"PPort14reminder"=C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\Ereg\Ereg.exe [2013-01-14 334152]
"PDFProHook"=C:\Program Files\Xerox Scan To PC Desktop 12\PDF Viewer 7\pdfpro7hook.exe [2012-11-05 641424]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [2014-04-17 748256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-27 6111824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"V0260Cfg.exe"=V0260Cfg.exe /d:4 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
""= []
"GarminExpressTrayApp"=C:\Program Files\Garmin\Express Tray\ExpressTray.exe [2015-09-11 1403192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageRetriever.lnk - C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\xdcla.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.I420"=msh263.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-20 22:57:08 ----D---- C:\_OTM
2015-09-20 21:13:04 ----D---- C:\AdwCleaner
2015-09-20 19:11:15 ----D---- C:\rsit
2015-09-20 19:11:15 ----D---- C:\Program Files\trend micro
2015-09-20 17:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-09-20 17:04:11 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-09-20 17:04:10 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-20 17:03:56 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-20 17:03:47 ----A---- C:\WINDOWS\system32\winload.exe
2015-09-20 17:03:46 ----A---- C:\WINDOWS\system32\winresume.exe
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\nshwfp.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-20 17:03:45 ----A---- C:\WINDOWS\system32\BFE.DLL
2015-09-09 12:37:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:37:29 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\wininet.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\jscript.dll
2015-09-09 12:37:28 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:37:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:37:26 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:36:21 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:36:17 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:36:16 ----A---- C:\WINDOWS\system32\authui.dll
2015-09-09 12:36:15 ----A---- C:\WINDOWS\system32\shacct.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-09-09 12:36:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-09-09 12:36:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:36:11 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\win32k.sys
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:36:10 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-31 08:13:31 ----D---- C:\ProgramData\VIPRE
2015-08-31 08:04:30 ----A---- C:\Users\Admin\AppData\Roaming\LogFile.txt
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\rascfg.dll
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2015-08-31 07:37:58 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2015-08-31 07:37:09 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\WSDApi.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\untfs.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\spoolsv.exe
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2015-08-31 07:37:00 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WSDMon.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\WinSCard.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\VSSVC.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vsstrace.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vssapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\vpnike.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasser.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasmxs.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasdiag.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\rasapi32.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\eventcls.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-31 07:36:59 ----A---- C:\WINDOWS\splwow64.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-08-31 07:36:00 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2015-08-31 07:35:58 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-08-31 07:35:13 ----A---- C:\WINDOWS\system32\consent.exe
2015-08-31 07:35:12 ----A---- C:\WINDOWS\system32\tdh.dll
2015-08-31 07:30:10 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-08-27 10:41:13 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppwinob.dll
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppsvc.exe
2015-08-27 10:37:50 ----A---- C:\WINDOWS\system32\sppobjs.dll
======List of files/folders modified in the last 1 month======
2015-09-20 23:03:55 ----D---- C:\WINDOWS\Temp
2015-09-20 23:00:57 ----D---- C:\WINDOWS\Prefetch
2015-09-20 22:57:26 ----D---- C:\Windows
2015-09-20 22:57:09 ----RD---- C:\Program Files
2015-09-20 22:57:09 ----D---- C:\WINDOWS\Tasks
2015-09-20 22:57:09 ----D---- C:\Program Files\Google
2015-09-20 22:45:40 ----D---- C:\WINDOWS\system32\config
2015-09-20 22:02:00 ----D---- C:\WINDOWS\system32\sru
2015-09-20 21:58:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-09-20 21:13:51 ----HD---- C:\ProgramData
2015-09-20 20:51:20 ----D---- C:\WINDOWS\rescache
2015-09-20 19:59:44 ----D---- C:\WINDOWS\system32\catroot2
2015-09-20 19:07:51 ----RD---- C:\WINDOWS\System32
2015-09-20 19:07:51 ----D---- C:\WINDOWS\inf
2015-09-20 19:07:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-20 19:02:42 ----D---- C:\WINDOWS\WinSxS
2015-09-20 19:02:01 ----D---- C:\WINDOWS\debug
2015-09-20 18:59:34 ----D---- C:\WINDOWS\system32\Boot
2015-09-20 17:06:35 ----D---- C:\WINDOWS\CbsTemp
2015-09-20 17:06:15 ----D---- C:\WINDOWS\apppatch
2015-09-20 17:04:40 ----SHD---- C:\System Volume Information
2015-09-20 09:10:32 ----SHD---- C:\WINDOWS\Installer
2015-09-19 16:28:49 ----D---- C:\WINDOWS\system32\NDF
2015-09-17 19:32:49 ----D---- C:\WINDOWS\system32\Tasks
2015-09-17 19:32:49 ----D---- C:\Program Files\Opera
2015-09-17 08:36:23 ----D---- C:\WINDOWS\AppReadiness
2015-09-17 08:36:21 ----HD---- C:\Program Files\WindowsApps
2015-09-15 11:10:02 ----HD---- C:\Config.Msi
2015-09-12 16:26:26 ----D---- C:\ProgramData\Package Cache
2015-09-12 16:26:13 ----D---- C:\Program Files\Garmin
2015-09-10 05:57:40 ----RSD---- C:\WINDOWS\assembly
2015-09-09 20:49:51 ----D---- C:\WINDOWS\PolicyDefinitions
2015-09-09 20:49:51 ----D---- C:\Program Files\Internet Explorer
2015-09-09 20:49:50 ----D---- C:\WINDOWS\system32\sk-SK
2015-09-09 13:31:51 ----D---- C:\WINDOWS\system32\MRT
2015-09-09 13:25:16 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 13:24:05 ----D---- C:\Program Files\Windows Journal
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\setup
2015-08-31 12:17:09 ----D---- C:\WINDOWS\system32\Drivers
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\wbem
2015-08-31 12:17:05 ----D---- C:\WINDOWS\system32\en-US
2015-08-31 12:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-31 09:40:39 ----D---- C:\Program Files\Common Files
2015-08-30 07:28:31 ----D---- C:\WINDOWS\system32\migration
2015-08-28 11:40:20 ----D---- C:\Program Files\CCleaner
2015-08-26 18:36:06 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-13 49776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-13 208664]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-13 81728]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 788784]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-13 433264]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys [2014-04-29 425352]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-13 24016]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-13 76000]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-13 113592]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [2014-04-29 609624]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-04 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-07-04 290304]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 V0260VID;@oem68.inf,%szDeviceDesc%;Live! Cam Vista IM; C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2014-02-11 50400]
S3 dg_ssudbus;@oem113.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576]
S3 dot4;@oem2.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 137632]
S3 Dot4Print;@oem13.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 22432]
S3 dot4usb;@oem2.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 42912]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-02-02 17488]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2012-04-18 15720]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 mvusbews;@oem5.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 17408]
S3 nmwcd;@oem72.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;@oem75.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 ssudmdm;@oem114.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 37888]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2014-11-04 26624]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 64000]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2012-07-04 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 276992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-13 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
R2 hasplms;Sentinel LDK License Manager; C:\WINDOWS\system32\hasplms.exe [2014-04-29 4683144]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP; C:\Program Files\Xerox Scan To PC Desktop 12\PaperPort 14\PDFProFiltSrvPP.exe [2013-02-26 220488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 33088]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-09-11 762272]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-02-02 194032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Trošku sa to zlepšilo ale defender stále nefunguje
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Malwarebytes Anti-Malware
www.malwarebytes.org
Dátum skenovania: 21.9.2015
Scan ??as: 21:30
Logfile: MBM.txt
Správca: áno
Verzia: 2.1.8.1057
Malware databázy: v2015.09.21.06
Rootkit databázy: v2015.09.18.01
Licencia: Skúšobná verzia
Ochrana pred škodlivým softvérom: Povolené
Škodlivých webových stránok Ochrana: Povolené
Sebaobrany: Telesne
OS: Windows 8.1
CPU: x86
Systém súborov: NTFS
Používateľ: Admin
Typ skenu: Hrozba Scan
Výsledok: Dokon??ené
Objekty naskenované: 323167
Uplynulý ??as: 14 min, 10 sec
Pamäť: Povolené
Pri spustení: Povolené
Súborový systém: Povolené
Archív: Povolené
Rootkity: Telesne
Heuristiky: Povolené
ŠTEŇA: Povolené
VYKUROVAC: Povolené
Procesy: 0
(Žiadne zákernej položky neboli zistené)
Moduly: 0
(Žiadne zákernej položky neboli zistené)
Kľú??e databázy Registry: 9
PUP.Optional.SpeedDial, HKLM\SOFTWARE\CLASSES\SpeedDial.TSpeedDial, , [bdcd1b17810a3cfa1ae44e9c4fb37e82],
PUP.Optional.Bandoo, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\aaaaafeopjhkcolncjbedbhofpocmdbn, , [15758ba7b5d6122493975e298f753ec2],
PUP.Optional.DataMngr, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\${dtUserElevationPolicyID}, , [cdbd48ea404bbc7ade9618b652b2d828],
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6DE3381-A119-46CE-B1C9-E811BD7B4AA1}, , [b8d2d65c3952f640cc65276015ef4fb1],
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D147A0D1-9332-4656-8651-EBBCB663D4BF}, , [7e0c44eec4c79b9bca6776114db7be42],
PUP.Optional.MindSpark, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D375EE64-F893-498A-A0E9-0E9829C88C3D}, , [06840f2398f3e3536028c3e77391d729],
PUP.Optional.PCSpeedUp, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PCSUUCDRV, , [dbafbd7596f5a09661d83c74da2a9f61],
PUP.Optional.Bandoo, HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\SOFTWARE\ilividbandoomoviestoolbar, , [ccbe9b97eba07bbbf82d96f16d97827e],
PUP.Optional.Bandoo, HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\SOFTWARE\APPDATALOW\SOFTWARE\ilividbandoomoviestoolbar, , [800a3cf6c4c757dfdf4791f62ed6748c],
Hodnoty databázy Registry: 3
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6DE3381-A119-46CE-B1C9-E811BD7B4AA1}|AppPath, C:\PROGRA~1\Movies App\Datamngr\SRToolBar\IE, , [b8d2d65c3952f640cc65276015ef4fb1]
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D147A0D1-9332-4656-8651-EBBCB663D4BF}|AppPath, C:\PROGRA~1\Movies App\Datamngr\SRToolBar\IE, , [7e0c44eec4c79b9bca6776114db7be42]
PUP.Optional.MindSpark, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{d375ee64-f893-498a-a0e9-0e9829c88c3d}|AppPath, C:\Program Files\VideoDownloadConverter_4z\bar\1.bin, , [06840f2398f3e3536028c3e77391d729]
Údaje databázy Registry: 0
(Žiadne zákernej položky neboli zistené)
Prie??inky: 1
PUP.Optional.DataMngr, C:\ProgramData\Datamngr, , [67234ee4a3e83afc39206331df2510f0],
Súbory: 3
PUP.Optional.DataMngr, C:\ProgramData\Datamngr\COORDINATOR.CFG, , [67234ee4a3e83afc39206331df2510f0],
PUP.Optional.DataMngr, C:\ProgramData\Datamngr\general.cfg, , [67234ee4a3e83afc39206331df2510f0],
PUP.Optional.DataMngr, C:\ProgramData\Datamngr\S-1-5-21-1998989806-2990118016-3208609371-1001.cfg, , [67234ee4a3e83afc39206331df2510f0],
Fyzický sektory: 0
(Žiadne zákernej položky neboli zistené)
(end)
www.malwarebytes.org
Dátum skenovania: 21.9.2015
Scan ??as: 21:30
Logfile: MBM.txt
Správca: áno
Verzia: 2.1.8.1057
Malware databázy: v2015.09.21.06
Rootkit databázy: v2015.09.18.01
Licencia: Skúšobná verzia
Ochrana pred škodlivým softvérom: Povolené
Škodlivých webových stránok Ochrana: Povolené
Sebaobrany: Telesne
OS: Windows 8.1
CPU: x86
Systém súborov: NTFS
Používateľ: Admin
Typ skenu: Hrozba Scan
Výsledok: Dokon??ené
Objekty naskenované: 323167
Uplynulý ??as: 14 min, 10 sec
Pamäť: Povolené
Pri spustení: Povolené
Súborový systém: Povolené
Archív: Povolené
Rootkity: Telesne
Heuristiky: Povolené
ŠTEŇA: Povolené
VYKUROVAC: Povolené
Procesy: 0
(Žiadne zákernej položky neboli zistené)
Moduly: 0
(Žiadne zákernej položky neboli zistené)
Kľú??e databázy Registry: 9
PUP.Optional.SpeedDial, HKLM\SOFTWARE\CLASSES\SpeedDial.TSpeedDial, , [bdcd1b17810a3cfa1ae44e9c4fb37e82],
PUP.Optional.Bandoo, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\aaaaafeopjhkcolncjbedbhofpocmdbn, , [15758ba7b5d6122493975e298f753ec2],
PUP.Optional.DataMngr, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\${dtUserElevationPolicyID}, , [cdbd48ea404bbc7ade9618b652b2d828],
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6DE3381-A119-46CE-B1C9-E811BD7B4AA1}, , [b8d2d65c3952f640cc65276015ef4fb1],
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D147A0D1-9332-4656-8651-EBBCB663D4BF}, , [7e0c44eec4c79b9bca6776114db7be42],
PUP.Optional.MindSpark, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D375EE64-F893-498A-A0E9-0E9829C88C3D}, , [06840f2398f3e3536028c3e77391d729],
PUP.Optional.PCSpeedUp, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PCSUUCDRV, , [dbafbd7596f5a09661d83c74da2a9f61],
PUP.Optional.Bandoo, HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\SOFTWARE\ilividbandoomoviestoolbar, , [ccbe9b97eba07bbbf82d96f16d97827e],
PUP.Optional.Bandoo, HKU\S-1-5-21-1998989806-2990118016-3208609371-1001\SOFTWARE\APPDATALOW\SOFTWARE\ilividbandoomoviestoolbar, , [800a3cf6c4c757dfdf4791f62ed6748c],
Hodnoty databázy Registry: 3
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B6DE3381-A119-46CE-B1C9-E811BD7B4AA1}|AppPath, C:\PROGRA~1\Movies App\Datamngr\SRToolBar\IE, , [b8d2d65c3952f640cc65276015ef4fb1]
PUP.Optional.Bandoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D147A0D1-9332-4656-8651-EBBCB663D4BF}|AppPath, C:\PROGRA~1\Movies App\Datamngr\SRToolBar\IE, , [7e0c44eec4c79b9bca6776114db7be42]
PUP.Optional.MindSpark, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{d375ee64-f893-498a-a0e9-0e9829c88c3d}|AppPath, C:\Program Files\VideoDownloadConverter_4z\bar\1.bin, , [06840f2398f3e3536028c3e77391d729]
Údaje databázy Registry: 0
(Žiadne zákernej položky neboli zistené)
Prie??inky: 1
PUP.Optional.DataMngr, C:\ProgramData\Datamngr, , [67234ee4a3e83afc39206331df2510f0],
Súbory: 3
PUP.Optional.DataMngr, C:\ProgramData\Datamngr\COORDINATOR.CFG, , [67234ee4a3e83afc39206331df2510f0],
PUP.Optional.DataMngr, C:\ProgramData\Datamngr\general.cfg, , [67234ee4a3e83afc39206331df2510f0],
PUP.Optional.DataMngr, C:\ProgramData\Datamngr\S-1-5-21-1998989806-2990118016-3208609371-1001.cfg, , [67234ee4a3e83afc39206331df2510f0],
Fyzický sektory: 0
(Žiadne zákernej položky neboli zistené)
(end)
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Všechny nálezy smažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Asi s tým defenderom nič nespravíme. Diky za spoluprácu a prajem všetko dobre, nech sa Vám darí
- Rudy
- Site Admin

- Příspěvky: 119675
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Spomalený PC a deaktivovaný defender
Leda, že byste zkusil obnovu systému k datu, kdy korektně fungoval.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Spomalený PC a deaktivovaný defender
Ten dátum už nemám v ponuke

Přispějete na provoz fóra?