Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu. Podezření na vir.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
vojta.kuca.kucera
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 14 kvě 2013 07:16

Prosím o kontrolu logu. Podezření na vir.

#1 Příspěvek od vojta.kuca.kucera »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Vojtěch at 2016-03-25 18:28:03
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 55 GB (12%) free of 458 GB
Total RAM: 3982 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:28:10, on 25. 3. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Vojtěch.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: VirtualKeyboardBrowserHelperObject - {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {93BC2EA7-2F17-4729-948A-D2E03FFB2412} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll
O2 - BHO: Safe Money Plugin - {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Power2GoExpress8] NA
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O9 - Extra button: PokerStars.eu - {07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Virtuální klávesnice - {5547CE1F-74E9-41E5-9CBF-5211ECC37341} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 15.0.2 (AVP15.0.2) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: qkseeService - Qksee Pvt Ltd. - C:\Program Files (x86)\qksee\qkseeSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9937 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 45630379952
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\qksee\qkseeSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\System32\svchost.exe -k utcsvc
"c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe"
dashost.exe {e90b03f8-14d1-40c2-808b06cc45d2fb43}
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
C:\Windows\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
igfxEM.exe
igfxHK.exe
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
taskhostex.exe
"C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /ANDREA_BF_BYPASS
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
szndesktop.exe default start
"C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Vojtěch\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=49.0.2623.108 --handshake-handle=0x144
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4960.0.1321385137\809808513" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,16,25,54 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3958 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding --disable-features=UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Control/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/*DataReductionProxyConfigService/Control_Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledTimeLossDetection/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_26/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4960.2.613292232\337123796" /prefetch:1
C:\Windows\system32\msiexec.exe /V
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding --disable-features=UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Control/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/*DataReductionProxyConfigService/Control_Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledTimeLossDetection/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_26/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4960.6.968181517\2061792655" /prefetch:1
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding --disable-features=UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Control/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/*DataReductionProxyConfigService/Control_Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledTimeLossDetection/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_26/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4960.12.1718126473\834055042" /prefetch:1

"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe" -r
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe" -splash
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
taskeng.exe {6C1FEE86-DFC8-49A0-86BF-EC970BBED64C}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding --disable-features=UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Control/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/*DataReductionProxyConfigService/Control_Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledTimeLossDetection/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_26/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4960.14.524069366\913686914" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding --disable-features=UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Control/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/*DataReductionProxyConfigService/Control_Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledTimeLossDetection/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_26/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4960.15.1249877952\1891958583" /prefetch:1
"C:\Users\Vojtěch\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForVojtěch.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForVojtěch (null)

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23 1865000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93BC2EA7-2F17-4729-948A-D2E03FFB2412}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23 1865000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB379017-4C03-4E00-8EDF-E6D6AF7CCF82}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23 1865000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23 1699112]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93BC2EA7-2F17-4729-948A-D2E03FFB2412}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23 1699112]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB379017-4C03-4E00-8EDF-E6D6AF7CCF82}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23 1699112]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2015-10-19 414920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-06-27 7636696]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-27 1396592]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-06-27 2818800]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Power2GoExpress8"=NA []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-06-01 8358680]
"cz.seznam.software.autoupdate"=C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"HPMessageService"=C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [2015-06-29 653576]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2016-03-10 839648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-03-25 18:21:08 ----A---- C:\Windows\system32\klfphc.dll
2016-03-25 18:20:01 ----D---- C:\Program Files (x86)\Kaspersky Lab
2016-03-25 18:20:00 ----D---- C:\ProgramData\Kaspersky Lab
2016-03-25 18:19:40 ----A---- C:\Windows\system32\drivers\klif.sys
2016-03-25 18:19:40 ----A---- C:\Windows\system32\drivers\klhk.sys
2016-03-25 18:19:40 ----A---- C:\Windows\system32\drivers\klflt.sys
2016-03-24 20:36:53 ----D---- C:\Users\Vojtěch\AppData\Roaming\eCyber
2016-03-24 20:17:32 ----D---- C:\Program Files (x86)\AdwCleaner
2016-03-24 19:21:39 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2016-03-24 19:20:12 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2016-03-24 19:20:11 ----D---- C:\ProgramData\Malwarebytes
2016-03-24 19:20:11 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-24 19:20:11 ----A---- C:\Windows\system32\drivers\mwac.sys
2016-03-24 19:20:11 ----A---- C:\Windows\system32\drivers\mbam.sys
2016-03-24 18:08:19 ----A---- C:\autoexec.bat
2016-03-24 18:06:25 ----A---- C:\Windows\system32\drivers\EsgScanner.sys
2016-03-24 12:17:17 ----D---- C:\Users\Vojtěch\AppData\Roaming\WinZiper
2016-03-24 12:14:34 ----D---- C:\Users\Vojtěch\AppData\Roaming\qksee
2016-03-24 12:14:34 ----D---- C:\Program Files (x86)\qksee
2016-03-24 12:13:49 ----D---- C:\Program Files (x86)\QQBrowser
2016-03-22 17:57:52 ----D---- C:\GOG Games
2016-03-20 17:32:42 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-03-20 15:49:16 ----D---- C:\Windows\pss
2016-03-20 15:25:19 ----D---- C:\Program Files\DivX
2016-03-20 15:25:06 ----D---- C:\Users\Vojtěch\AppData\Roaming\DivX
2016-03-20 15:20:35 ----A---- C:\Users\Vojtěch\AppData\Roaming\GiftBag.db
2016-03-20 15:20:06 ----A---- C:\Windows\system32\drivers\TAOKernelEx64.sys
2016-03-20 15:13:39 ----D---- C:\ProgramData\Thunder Network
2016-03-20 15:13:23 ----D---- C:\Program Files (x86)\DivX
2016-03-20 15:13:06 ----D---- C:\extensions
2016-03-09 23:06:21 ----A---- C:\Windows\system32\storagewmi.dll
2016-03-09 23:06:19 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2016-03-09 23:05:12 ----A---- C:\Windows\system32\appraiser.dll
2016-03-09 23:05:11 ----A---- C:\Windows\system32\generaltel.dll
2016-03-09 23:05:10 ----A---- C:\Windows\system32\invagent.dll
2016-03-09 23:05:10 ----A---- C:\Windows\system32\devinv.dll
2016-03-09 23:05:10 ----A---- C:\Windows\system32\aeinv.dll
2016-03-09 23:05:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-03-09 23:05:08 ----A---- C:\Windows\system32\acmigration.dll
2016-03-09 23:05:04 ----A---- C:\Windows\system32\msra.exe
2016-03-09 23:04:59 ----A---- C:\Windows\system32\comsvcs.dll
2016-03-09 23:04:57 ----A---- C:\Windows\SYSWOW64\comsvcs.dll
2016-03-09 23:04:43 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-03-09 23:04:40 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2016-03-09 23:04:39 ----A---- C:\Windows\system32\netlogon.dll
2016-03-09 23:04:36 ----A---- C:\Windows\system32\winlogon.exe
2016-03-09 23:04:34 ----A---- C:\Windows\system32\wscapi.dll
2016-03-09 23:04:32 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2016-03-09 23:04:31 ----A---- C:\Windows\system32\wscsvc.dll
2016-03-09 23:04:29 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-03-09 23:04:19 ----A---- C:\Windows\system32\drivers\storport.sys
2016-03-09 23:04:19 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2016-03-09 23:04:18 ----A---- C:\Windows\system32\mispace.dll
2016-03-09 23:04:18 ----A---- C:\Windows\system32\drivers\spaceport.sys
2016-03-09 23:04:16 ----A---- C:\Windows\SYSWOW64\mispace.dll
2016-03-09 23:02:25 ----A---- C:\Windows\system32\ucrtbase.dll
2016-03-09 23:02:24 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2016-03-09 23:02:21 ----A---- C:\Windows\system32\rsaenh.dll
2016-03-09 23:02:16 ----A---- C:\Windows\SYSWOW64\rsaenh.dll
2016-03-09 23:02:12 ----A---- C:\Windows\system32\drivers\netio.sys
2016-03-09 23:02:06 ----A---- C:\Windows\system32\kerberos.dll
2016-03-09 23:02:01 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-03-09 23:01:36 ----A---- C:\Windows\system32\drivers\srv.sys
2016-03-09 12:52:20 ----A---- C:\Windows\system32\mshtml.dll
2016-03-09 12:52:18 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-03-09 12:52:15 ----A---- C:\Windows\system32\ieframe.dll
2016-03-09 12:52:14 ----A---- C:\Windows\system32\jscript9.dll
2016-03-09 12:52:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-03-09 12:52:11 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-03-09 12:52:10 ----A---- C:\Windows\system32\wininet.dll
2016-03-09 12:52:09 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-03-09 12:52:09 ----A---- C:\Windows\system32\iertutil.dll
2016-03-09 12:52:08 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-03-09 12:52:08 ----A---- C:\Windows\system32\hlink.dll
2016-03-09 12:52:07 ----A---- C:\Windows\SYSWOW64\hlink.dll
2016-03-09 12:52:07 ----A---- C:\Windows\system32\msfeeds.dll
2016-03-09 12:52:06 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-03-09 12:52:06 ----A---- C:\Windows\system32\actxprxy.dll
2016-03-09 12:52:05 ----A---- C:\Windows\system32\urlmon.dll
2016-03-09 12:52:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-03-09 12:52:03 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\webcheck.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\vbscript.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\mshtmled.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\inetcomm.dll
2016-03-09 12:52:02 ----A---- C:\Windows\system32\jscript.dll
2016-03-09 12:52:01 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-03-09 12:52:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-03-09 12:52:01 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-03-09 12:52:00 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-03-09 12:52:00 ----A---- C:\Windows\system32\ieapfltr.dll
2016-03-09 12:51:18 ----A---- C:\Windows\SYSWOW64\msvcp120_clr0400.dll
2016-03-09 12:51:18 ----A---- C:\Windows\system32\msvcp120_clr0400.dll
2016-03-09 12:51:17 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll
2016-03-09 12:51:13 ----A---- C:\Windows\system32\msvcr120_clr0400.dll
2016-03-09 11:20:24 ----A---- C:\Windows\system32\glcndFilter.dll
2016-03-09 11:20:23 ----A---- C:\Windows\SYSWOW64\glcndFilter.dll
2016-03-09 11:20:23 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-03-09 11:20:22 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-03-09 11:15:41 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-03-09 11:15:41 ----A---- C:\Windows\system32\ole32.dll
2016-03-09 11:15:41 ----A---- C:\Windows\system32\asycfilt.dll
2016-03-09 11:15:40 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-03-09 11:15:40 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-03-09 11:15:40 ----A---- C:\Windows\system32\seclogon.dll
2016-03-09 11:15:37 ----A---- C:\Windows\system32\wuaueng.dll
2016-03-09 11:15:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-03-09 11:15:36 ----A---- C:\Windows\system32\wucltux.dll
2016-03-09 11:15:36 ----A---- C:\Windows\system32\wuauclt.exe
2016-03-09 11:15:36 ----A---- C:\Windows\system32\wuapi.dll
2016-03-09 11:15:35 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-03-09 11:15:35 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-03-09 11:15:35 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-03-09 11:15:35 ----A---- C:\Windows\system32\wuwebv.dll
2016-03-09 11:15:35 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2016-03-09 11:15:35 ----A---- C:\Windows\system32\wudriver.dll
2016-03-09 11:15:35 ----A---- C:\Windows\system32\wuapp.exe
2016-03-09 11:15:31 ----A---- C:\Windows\system32\wmp.dll
2016-03-09 11:15:25 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-03-09 11:15:24 ----A---- C:\Windows\SYSWOW64\WMASF.DLL
2016-03-09 11:15:24 ----A---- C:\Windows\system32\WMASF.DLL
2016-03-09 11:15:20 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2016-03-09 11:15:20 ----A---- C:\Windows\system32\atmfd.dll
2016-03-09 11:15:19 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2016-03-09 11:15:19 ----A---- C:\Windows\system32\win32k.sys
2016-03-09 11:15:19 ----A---- C:\Windows\system32\atmlib.dll
2016-03-09 11:15:16 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2016-03-09 11:15:13 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-03-09 11:15:13 ----A---- C:\Windows\system32\mfds.dll
2016-03-04 17:31:06 ----D---- C:\ProgramData\DivX

======List of files/folders modified in the last 1 month======

2016-03-25 18:28:07 ----D---- C:\Program Files\trend micro
2016-03-25 18:27:23 ----D---- C:\Windows\Prefetch
2016-03-25 18:25:28 ----HD---- C:\ProgramData
2016-03-25 18:23:38 ----D---- C:\Windows\Temp
2016-03-25 18:22:01 ----SHD---- C:\Windows\Installer
2016-03-25 18:21:25 ----D---- C:\Windows\system32\drivers
2016-03-25 18:21:24 ----D---- C:\Windows\system32\DriverStore
2016-03-25 18:21:24 ----D---- C:\Windows\Inf
2016-03-25 18:21:08 ----RD---- C:\Windows\System32
2016-03-25 18:20:30 ----D---- C:\Users\Vojtěch\AppData\Roaming\Seznam.cz
2016-03-25 18:20:03 ----HD---- C:\Windows\ELAMBKUP
2016-03-25 18:20:01 ----RD---- C:\Program Files (x86)
2016-03-25 18:19:58 ----SHD---- C:\System Volume Information
2016-03-25 18:15:37 ----D---- C:\Windows\system32\sru
2016-03-25 18:13:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-03-25 15:47:56 ----RD---- C:\Program Files
2016-03-24 20:22:21 ----D---- C:\Windows\SYSWOW64\drivers
2016-03-24 20:22:18 ----D---- C:\Program Files\Common Files
2016-03-24 20:22:18 ----D---- C:\Program Files (x86)\Common Files
2016-03-24 20:22:14 ----D---- C:\AdwCleaner
2016-03-24 20:14:08 ----D---- C:\Windows
2016-03-24 20:14:05 ----D---- C:\Windows\system32\Tasks
2016-03-24 09:03:44 ----D---- C:\Windows\system32\config
2016-03-24 08:52:34 ----D---- C:\Windows\Microsoft.NET
2016-03-24 08:52:17 ----D---- C:\Windows\CbsTemp
2016-03-24 08:51:52 ----D---- C:\Windows\WinSxS
2016-03-24 08:50:45 ----SD---- C:\Windows\SYSWOW64\GWX
2016-03-24 08:50:45 ----SD---- C:\Windows\system32\GWX
2016-03-22 19:35:08 ----D---- C:\Users\Vojtěch\AppData\Roaming\uTorrent
2016-03-22 15:52:46 ----D---- C:\KMPlayer
2016-03-22 07:40:40 ----D---- C:\Windows\system32\NDF
2016-03-21 07:21:45 ----RSD---- C:\Windows\assembly
2016-03-21 05:14:50 ----D---- C:\Users\Vojtěch\AppData\Roaming\vlc
2016-03-20 15:24:47 ----D---- C:\ProgramData\Package Cache
2016-03-20 15:21:39 ----D---- C:\Windows\SysWOW64
2016-03-20 15:20:11 ----RD---- C:\Users
2016-03-20 15:18:42 ----RSD---- C:\Windows\Fonts
2016-03-19 22:15:46 ----D---- C:\Windows\AppReadiness
2016-03-15 15:04:03 ----D---- C:\Windows\rescache
2016-03-13 17:44:56 ----HD---- C:\Program Files\WindowsApps
2016-03-10 00:29:35 ----D---- C:\Windows\system32\appraiser
2016-03-10 00:29:34 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-10 00:29:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-03-10 00:29:33 ----D---- C:\Program Files\Internet Explorer
2016-03-10 00:29:32 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-03-10 00:29:32 ----D---- C:\Windows\system32\cs-CZ
2016-03-10 00:27:37 ----D---- C:\Windows\system32\MRT
2016-03-10 00:20:53 ----A---- C:\Windows\system32\MRT.exe
2016-03-09 23:00:37 ----D---- C:\Windows\system32\catroot2
2016-03-08 08:00:28 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-03-05 12:04:24 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 cm_km_w;Kaspersky Lab Crypto Module (FDE PDK); C:\Windows\system32\DRIVERS\cm_km_w.sys [2015-07-03 247016]
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2015-07-03 478392]
R0 MBI;@oem12.inf,%MBI.SVCDESC%;Intel(R) Sideband Fabric Device Service; C:\Windows\System32\drivers\MBI.sys [2014-01-23 29464]
R1 CLVirtualDrive;CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 dtsoftbus01;@oem16.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2014-12-27 283064]
R1 klhk;klhk; C:\Windows\system32\DRIVERS\klhk.sys [2015-07-03 226480]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2015-07-03 831664]
R1 KLIM6;@oem26.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2015-07-03 39792]
R1 klpd;klpd; C:\Windows\system32\DRIVERS\klpd.sys [2015-07-03 24944]
R1 klwfp;klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [2015-07-03 77680]
R1 Klwtp;Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [2015-07-03 85360]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2015-07-03 190648]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-10-08 71680]
R2 kldisk;kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [2015-07-03 64368]
R3 clwvd;@oem21.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 GPIO;@oem14.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\Windows\System32\drivers\iaiogpioe.sys [2013-11-11 31232]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-12-21 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-06-27 4264536]
R3 IntcDAud;@oem22.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-12-21 454416]
R3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 klflt;Kaspersky Lab Kernel DLL; C:\Windows\system32\DRIVERS\klflt.sys [2015-07-03 159960]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 27008]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-03-25 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 65408]
R3 RSP2STOR;@oem29.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2015-06-27 294104]
R3 RTL8168;@oem31.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2015-06-27 874712]
R3 RTWlanE;@oem43.inf,%RTWlanE.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\Windows\system32\DRIVERS\rtwlane.sys [2015-08-11 3593432]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-06-27 33008]
R3 SynTP;@oem33.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2015-06-27 546032]
R3 TXEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-10-08 38912]
R4 klkbdflt2;Kaspersky Lab KlKbdFlt2; C:\Windows\system32\DRIVERS\klkbdflt2.sys []
S0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-11-06 632168]
S0 klelam;klelam; C:\Windows\system32\DRIVERS\klelam.sys [2012-07-27 29616]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2015-10-30 303616]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2015-10-30 35328]
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys []
S3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
S3 dg_ssudbus;@oem23.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2016-03-24 22704]
S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2015-07-03 40304]
S3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2015-07-03 39792]
S3 SmbDrv;SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [2013-12-13 29936]
S3 ssudmdm;@oem25.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2015-04-25 20992]

vojta.kuca.kucera
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 14 kvě 2013 07:16

Re: Prosím o kontrolu logu. Podezření na vir. pokračovaní lo

#2 Příspěvek od vojta.kuca.kucera »

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2014-10-29 38792]
R2 AVP15.0.2;Služba Kaspersky Anti-Virus 15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [2015-07-03 194000]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2016-02-18 26680]
R2 HPWMISVC;HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [2015-06-29 602888]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-12-21 318568]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2016-03-10 1514464]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2015-07-02 124928]
R2 PSI_SVC_2;Corel License Validation Service V2, Powered by arvato; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2013-09-13 277360]
R2 qkseeService;qkseeService; C:\Program Files (x86)\qksee\qkseeSvc.exe [2016-03-24 713216]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2015-06-27 291032]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-06-27 191728]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2015-04-28 1102472]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-03 327296]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-16 50864]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-12-21 280680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]
S3 w3logsvc;@%windir%\system32\inetsrv\iisres.dll,-30014; C:\Windows\system32\svchost.exe [2014-10-29 38792]
S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2014-10-29 38792]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu. Podezření na vir.

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

vojta.kuca.kucera
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 14 kvě 2013 07:16

Re: log adware

#4 Příspěvek od vojta.kuca.kucera »

# AdwCleaner v5.105 - Logfile created 25/03/2016 at 19:22:29
# Updated 21/03/2016 by Xplode
# Database : 2016-03-24.4 [Server]
# Operating system : Windows 8.1 Connected (x64)
# Username : Vojtěch - NAŠMILÁČEK
# Running from : C:\Users\Vojtěch\Desktop\adwcleaner_5.105.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Vojtěch\AppData\Roaming\eCyber

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\hdcode

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [10056 bytes] - [24/03/2016 20:22:14]
C:\AdwCleaner\AdwCleaner[C2].txt - [881 bytes] - [25/03/2016 19:22:29]
C:\AdwCleaner\AdwCleaner[R0].txt - [5996 bytes] - [14/08/2015 08:15:51]
C:\AdwCleaner\AdwCleaner[S0].txt - [4915 bytes] - [14/08/2015 08:18:11]
C:\AdwCleaner\AdwCleaner[S1].txt - [9374 bytes] - [24/03/2016 20:18:45]
C:\AdwCleaner\AdwCleaner[S2].txt - [1150 bytes] - [25/03/2016 19:19:20]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1245 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu. Podezření na vir.

#5 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

vojta.kuca.kucera
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 14 kvě 2013 07:16

log rsit

#6 Příspěvek od vojta.kuca.kucera »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Vojtěch at 2016-03-26 09:38:22
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 55 GB (12%) free of 458 GB
Total RAM: 3982 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:38:27, on 26. 3. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\szninstall.exe
C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\CyberLink\YouCam\Youcam_webcam_camera_video.exe
C:\Program Files\trend micro\Vojtěch.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Power2GoExpress8] NA
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O9 - Extra button: PokerStars.eu - {07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Corel License Validation Service V2, Powered by arvato (PSI_SVC_2) - arvato digital services llc - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: qkseeService - Qksee Pvt Ltd. - C:\Program Files (x86)\qksee\qkseeSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9090 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS

"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 580192638032
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\qksee\qkseeSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\System32\svchost.exe -k utcsvc
dashost.exe {b44a93a0-9808-4382-b3efeb654fd47f37}
"c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"

C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
C:\Windows\Explorer.EXE
igfxEM.exe
igfxHK.exe
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
taskeng.exe {D34DAD74-EB28-4803-BFAA-327A560039BC}
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
"C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe"
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /ANDREA_BF_BYPASS
"C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\szninstall.exe" -c
"C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe"
szndesktop.exe default start
"C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Vojtěch\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=49.0.2623.108 --handshake-handle=0x14c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5632.0.161910269\2045763004" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,16,25,54 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3958 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding --disable-features=UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Control/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/*DataReductionProxyConfigService/Control_Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_26/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="5632.4.1723340351\1923210067" /prefetch:1
"C:\Program Files (x86)\CyberLink\YouCam\Youcam_webcam_camera_video.exe" /d speedup
C:\Windows\system32\msfeedssync.exe sync
taskhost.exe $(Arg0)
"C:\Program Files (x86)\QQBrowser\Update\Download\89254ED44571CF34BFAC37469FB254FE\Update\BrowserUpdate.exe" 87B20C06-6890-4CFE-B40F-004064F87F12
C:\Windows\System32\wsqmcons.exe
C:\Windows\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
"C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe" /send
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L Analysis
C:\Windows\system32\GWX\GWXConfigManager.exe /RefreshConfigAndContent
\??\C:\Windows\system32\conhost.exe 0x4

"C:\Users\Vojtěch\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForVojtěch.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForVojtěch (null)

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2015-10-19 414920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-06-27 7636696]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-27 1396592]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-06-27 2818800]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Power2GoExpress8"=NA []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-06-01 8358680]
"cz.seznam.software.autoupdate"=C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Vojtěch\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"HPMessageService"=C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [2015-06-29 653576]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2016-03-10 839648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-03-25 19:09:01 ----D---- C:\ProgramData\ESET
2016-03-25 19:08:55 ----D---- C:\Program Files\ESET
2016-03-25 19:03:45 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2016-03-25 19:01:26 ----SHD---- C:\Config.Msi
2016-03-24 20:17:32 ----D---- C:\Program Files (x86)\AdwCleaner
2016-03-24 19:21:39 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2016-03-24 19:20:12 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2016-03-24 19:20:11 ----D---- C:\ProgramData\Malwarebytes
2016-03-24 19:20:11 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-24 19:20:11 ----A---- C:\Windows\system32\drivers\mwac.sys
2016-03-24 19:20:11 ----A---- C:\Windows\system32\drivers\mbam.sys
2016-03-24 18:08:19 ----A---- C:\autoexec.bat
2016-03-24 18:06:25 ----A---- C:\Windows\system32\drivers\EsgScanner.sys
2016-03-24 12:17:17 ----D---- C:\Users\Vojtěch\AppData\Roaming\WinZiper
2016-03-24 12:14:34 ----D---- C:\Users\Vojtěch\AppData\Roaming\qksee
2016-03-24 12:14:34 ----D---- C:\Program Files (x86)\qksee
2016-03-24 12:13:49 ----D---- C:\Program Files (x86)\QQBrowser
2016-03-22 17:57:52 ----D---- C:\GOG Games
2016-03-20 17:32:42 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-03-20 15:49:16 ----D---- C:\Windows\pss
2016-03-20 15:25:19 ----D---- C:\Program Files\DivX
2016-03-20 15:25:06 ----D---- C:\Users\Vojtěch\AppData\Roaming\DivX
2016-03-20 15:20:35 ----A---- C:\Users\Vojtěch\AppData\Roaming\GiftBag.db
2016-03-20 15:20:06 ----A---- C:\Windows\system32\drivers\TAOKernelEx64.sys
2016-03-20 15:13:39 ----D---- C:\ProgramData\Thunder Network
2016-03-20 15:13:23 ----D---- C:\Program Files (x86)\DivX
2016-03-20 15:13:06 ----D---- C:\extensions
2016-03-09 23:06:21 ----A---- C:\Windows\system32\storagewmi.dll
2016-03-09 23:06:19 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2016-03-09 23:05:12 ----A---- C:\Windows\system32\appraiser.dll
2016-03-09 23:05:11 ----A---- C:\Windows\system32\generaltel.dll
2016-03-09 23:05:10 ----A---- C:\Windows\system32\invagent.dll
2016-03-09 23:05:10 ----A---- C:\Windows\system32\devinv.dll
2016-03-09 23:05:10 ----A---- C:\Windows\system32\aeinv.dll
2016-03-09 23:05:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-03-09 23:05:08 ----A---- C:\Windows\system32\acmigration.dll
2016-03-09 23:05:04 ----A---- C:\Windows\system32\msra.exe
2016-03-09 23:04:59 ----A---- C:\Windows\system32\comsvcs.dll
2016-03-09 23:04:57 ----A---- C:\Windows\SYSWOW64\comsvcs.dll
2016-03-09 23:04:43 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-03-09 23:04:40 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2016-03-09 23:04:39 ----A---- C:\Windows\system32\netlogon.dll
2016-03-09 23:04:36 ----A---- C:\Windows\system32\winlogon.exe
2016-03-09 23:04:34 ----A---- C:\Windows\system32\wscapi.dll
2016-03-09 23:04:32 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2016-03-09 23:04:31 ----A---- C:\Windows\system32\wscsvc.dll
2016-03-09 23:04:29 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-03-09 23:04:19 ----A---- C:\Windows\system32\drivers\storport.sys
2016-03-09 23:04:19 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2016-03-09 23:04:18 ----A---- C:\Windows\system32\mispace.dll
2016-03-09 23:04:18 ----A---- C:\Windows\system32\drivers\spaceport.sys
2016-03-09 23:04:16 ----A---- C:\Windows\SYSWOW64\mispace.dll
2016-03-09 23:02:25 ----A---- C:\Windows\system32\ucrtbase.dll
2016-03-09 23:02:24 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2016-03-09 23:02:21 ----A---- C:\Windows\system32\rsaenh.dll
2016-03-09 23:02:16 ----A---- C:\Windows\SYSWOW64\rsaenh.dll
2016-03-09 23:02:12 ----A---- C:\Windows\system32\drivers\netio.sys
2016-03-09 23:02:06 ----A---- C:\Windows\system32\kerberos.dll
2016-03-09 23:02:01 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-03-09 23:01:36 ----A---- C:\Windows\system32\drivers\srv.sys
2016-03-09 12:52:20 ----A---- C:\Windows\system32\mshtml.dll
2016-03-09 12:52:18 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-03-09 12:52:15 ----A---- C:\Windows\system32\ieframe.dll
2016-03-09 12:52:14 ----A---- C:\Windows\system32\jscript9.dll
2016-03-09 12:52:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-03-09 12:52:11 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-03-09 12:52:10 ----A---- C:\Windows\system32\wininet.dll
2016-03-09 12:52:09 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-03-09 12:52:09 ----A---- C:\Windows\system32\iertutil.dll
2016-03-09 12:52:08 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-03-09 12:52:08 ----A---- C:\Windows\system32\hlink.dll
2016-03-09 12:52:07 ----A---- C:\Windows\SYSWOW64\hlink.dll
2016-03-09 12:52:07 ----A---- C:\Windows\system32\msfeeds.dll
2016-03-09 12:52:06 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-03-09 12:52:06 ----A---- C:\Windows\system32\actxprxy.dll
2016-03-09 12:52:05 ----A---- C:\Windows\system32\urlmon.dll
2016-03-09 12:52:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-03-09 12:52:03 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\webcheck.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\vbscript.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\mshtmled.dll
2016-03-09 12:52:03 ----A---- C:\Windows\system32\inetcomm.dll
2016-03-09 12:52:02 ----A---- C:\Windows\system32\jscript.dll
2016-03-09 12:52:01 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-03-09 12:52:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-03-09 12:52:01 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-03-09 12:52:00 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-03-09 12:52:00 ----A---- C:\Windows\system32\ieapfltr.dll
2016-03-09 12:51:18 ----A---- C:\Windows\SYSWOW64\msvcp120_clr0400.dll
2016-03-09 12:51:18 ----A---- C:\Windows\system32\msvcp120_clr0400.dll
2016-03-09 12:51:17 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll
2016-03-09 12:51:13 ----A---- C:\Windows\system32\msvcr120_clr0400.dll
2016-03-09 11:20:24 ----A---- C:\Windows\system32\glcndFilter.dll
2016-03-09 11:20:23 ----A---- C:\Windows\SYSWOW64\glcndFilter.dll
2016-03-09 11:20:23 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-03-09 11:20:22 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-03-09 11:15:41 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-03-09 11:15:41 ----A---- C:\Windows\system32\ole32.dll
2016-03-09 11:15:41 ----A---- C:\Windows\system32\asycfilt.dll
2016-03-09 11:15:40 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-03-09 11:15:40 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-03-09 11:15:40 ----A---- C:\Windows\system32\seclogon.dll
2016-03-09 11:15:37 ----A---- C:\Windows\system32\wuaueng.dll
2016-03-09 11:15:36 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-03-09 11:15:36 ----A---- C:\Windows\system32\wucltux.dll
2016-03-09 11:15:36 ----A---- C:\Windows\system32\wuauclt.exe
2016-03-09 11:15:36 ----A---- C:\Windows\system32\wuapi.dll
2016-03-09 11:15:35 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-03-09 11:15:35 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-03-09 11:15:35 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-03-09 11:15:35 ----A---- C:\Windows\system32\wuwebv.dll
2016-03-09 11:15:35 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2016-03-09 11:15:35 ----A---- C:\Windows\system32\wudriver.dll
2016-03-09 11:15:35 ----A---- C:\Windows\system32\wuapp.exe
2016-03-09 11:15:31 ----A---- C:\Windows\system32\wmp.dll
2016-03-09 11:15:25 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-03-09 11:15:24 ----A---- C:\Windows\SYSWOW64\WMASF.DLL
2016-03-09 11:15:24 ----A---- C:\Windows\system32\WMASF.DLL
2016-03-09 11:15:20 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2016-03-09 11:15:20 ----A---- C:\Windows\system32\atmfd.dll
2016-03-09 11:15:19 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2016-03-09 11:15:19 ----A---- C:\Windows\system32\win32k.sys
2016-03-09 11:15:19 ----A---- C:\Windows\system32\atmlib.dll
2016-03-09 11:15:16 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2016-03-09 11:15:13 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-03-09 11:15:13 ----A---- C:\Windows\system32\mfds.dll
2016-03-04 17:31:06 ----D---- C:\ProgramData\DivX

======List of files/folders modified in the last 1 month======

2016-03-26 09:38:26 ----D---- C:\Program Files\trend micro
2016-03-26 09:36:29 ----D---- C:\Windows\Temp
2016-03-26 09:36:04 ----D---- C:\Windows\Prefetch
2016-03-26 09:35:03 ----D---- C:\Windows\system32\sru
2016-03-25 19:39:55 ----D---- C:\Users\Vojtěch\AppData\Roaming\Seznam.cz
2016-03-25 19:29:49 ----RD---- C:\Windows\System32
2016-03-25 19:29:49 ----D---- C:\Windows\Inf
2016-03-25 19:29:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-03-25 19:22:29 ----D---- C:\AdwCleaner
2016-03-25 19:12:56 ----D---- C:\Windows\system32\drivers
2016-03-25 19:12:54 ----D---- C:\Windows\system32\DriverStore
2016-03-25 19:12:52 ----SHD---- C:\Windows\Installer
2016-03-25 19:12:25 ----HD---- C:\Windows\ELAMBKUP
2016-03-25 19:09:34 ----D---- C:\Users\Vojtěch\AppData\Roaming\TS3Client
2016-03-25 19:09:01 ----HD---- C:\ProgramData
2016-03-25 19:08:55 ----RD---- C:\Program Files
2016-03-25 19:04:05 ----RD---- C:\Program Files (x86)
2016-03-25 19:01:55 ----SHD---- C:\System Volume Information
2016-03-24 20:22:21 ----D---- C:\Windows\SYSWOW64\drivers
2016-03-24 20:22:18 ----D---- C:\Program Files\Common Files
2016-03-24 20:22:18 ----D---- C:\Program Files (x86)\Common Files
2016-03-24 20:14:08 ----D---- C:\Windows
2016-03-24 20:14:05 ----D---- C:\Windows\system32\Tasks
2016-03-24 09:03:44 ----D---- C:\Windows\system32\config
2016-03-24 08:52:34 ----D---- C:\Windows\Microsoft.NET
2016-03-24 08:52:17 ----D---- C:\Windows\CbsTemp
2016-03-24 08:51:52 ----D---- C:\Windows\WinSxS
2016-03-24 08:50:45 ----SD---- C:\Windows\SYSWOW64\GWX
2016-03-24 08:50:45 ----SD---- C:\Windows\system32\GWX
2016-03-22 19:35:08 ----D---- C:\Users\Vojtěch\AppData\Roaming\uTorrent
2016-03-22 15:52:46 ----D---- C:\KMPlayer
2016-03-22 07:40:40 ----D---- C:\Windows\system32\NDF
2016-03-21 07:21:45 ----RSD---- C:\Windows\assembly
2016-03-21 05:14:50 ----D---- C:\Users\Vojtěch\AppData\Roaming\vlc
2016-03-20 15:24:47 ----D---- C:\ProgramData\Package Cache
2016-03-20 15:21:39 ----D---- C:\Windows\SysWOW64
2016-03-20 15:20:11 ----RD---- C:\Users
2016-03-20 15:18:42 ----RSD---- C:\Windows\Fonts
2016-03-19 22:15:46 ----D---- C:\Windows\AppReadiness
2016-03-15 15:04:03 ----D---- C:\Windows\rescache
2016-03-13 17:44:56 ----HD---- C:\Program Files\WindowsApps
2016-03-10 00:29:35 ----D---- C:\Windows\system32\appraiser
2016-03-10 00:29:34 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-10 00:29:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-03-10 00:29:33 ----D---- C:\Program Files\Internet Explorer
2016-03-10 00:29:32 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-03-10 00:29:32 ----D---- C:\Windows\system32\cs-CZ
2016-03-10 00:27:37 ----D---- C:\Windows\system32\MRT
2016-03-10 00:20:53 ----A---- C:\Windows\system32\MRT.exe
2016-03-09 23:00:37 ----D---- C:\Windows\system32\catroot2
2016-03-08 08:00:28 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-03-05 12:04:24 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-02-09 84800]
R0 MBI;@oem12.inf,%MBI.SVCDESC%;Intel(R) Sideband Fabric Device Service; C:\Windows\System32\drivers\MBI.sys [2014-01-23 29464]
R1 CLVirtualDrive;CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 dtsoftbus01;@oem16.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2014-12-27 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-02-09 264552]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-02-09 186784]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-02-09 198096]
R1 EpfwLWF;@oem39.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-02-09 53384]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-10-08 71680]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-02-09 142976]
R3 clwvd;@oem21.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 GPIO;@oem14.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\Windows\System32\drivers\iaiogpioe.sys [2013-11-11 31232]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-12-21 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-06-27 4264536]
R3 IntcDAud;@oem22.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-12-21 454416]
R3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 27008]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-03-26 192216]
R3 RSP2STOR;@oem29.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2015-06-27 294104]
R3 RTL8168;@oem31.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2015-06-27 874712]
R3 RTWlanE;@oem43.inf,%RTWlanE.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\Windows\system32\DRIVERS\rtwlane.sys [2015-08-11 3593432]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-06-27 33008]
R3 SynTP;@oem33.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2015-06-27 546032]
R3 TXEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-10-08 38912]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2016-02-09 14976]
S0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-11-06 632168]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2015-10-30 303616]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2015-10-30 35328]
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys []
S3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
S3 dg_ssudbus;@oem23.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2016-03-24 22704]
S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 65408]
S3 SmbDrv;SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [2013-12-13 29936]
S3 ssudmdm;@oem25.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2015-04-25 20992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2014-10-29 38792]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-02-22 2521440]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2016-02-18 26680]
R2 HPWMISVC;HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [2015-06-29 602888]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-12-21 318568]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2016-03-10 1514464]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2015-07-02 124928]
R2 PSI_SVC_2;Corel License Validation Service V2, Powered by arvato; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2013-09-13 277360]
R2 qkseeService;qkseeService; C:\Program Files (x86)\qksee\qkseeSvc.exe [2016-03-24 713216]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2015-06-27 291032]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-06-27 191728]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2015-04-28 1102472]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-03 327296]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-16 50864]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-12-21 280680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]
S3 w3logsvc;@%windir%\system32\inetsrv\iisres.dll,-30014; C:\Windows\system32\svchost.exe [2014-10-29 38792]
S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2014-10-29 38792]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu. Podezření na vir.

#7 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files (x86)\qksee
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]/64

:services
qkseeService

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

vojta.kuca.kucera
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 14 kvě 2013 07:16

otm log

#8 Příspěvek od vojta.kuca.kucera »

All processes killed
========== FILES ==========
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall\style folder moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall\layout\default folder moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall\layout folder moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall\image\default\product folder moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall\image\default folder moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall\image folder moved successfully.
C:\Program Files (x86)\qksee\skin\oi_uninstall folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview\style folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview\layout\default folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview\layout folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview\image\default\product folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview\image\default folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview\image folder moved successfully.
C:\Program Files (x86)\qksee\skin\oiview folder moved successfully.
C:\Program Files (x86)\qksee\skin folder moved successfully.
C:\Program Files (x86)\qksee\log folder moved successfully.
C:\Program Files (x86)\qksee\lang folder moved successfully.
C:\Program Files (x86)\qksee\itools folder moved successfully.
C:\Program Files (x86)\qksee folder moved successfully.
File/Folder C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat not found.
========== REGISTRY ==========
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}\ not found.
========== SERVICES/DRIVERS ==========
Service qkseeService stopped successfully!
Service qkseeService deleted successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Vojtěch
->Temp folder emptied: 121673637 bytes
->Temporary Internet Files folder emptied: 6669289 bytes
->Google Chrome cache emptied: 401138049 bytes
->Flash cache emptied: 314151 bytes

User: Vojt靋h

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 23255945 bytes
RecycleBin emptied: 12116 bytes

Total Files Cleaned = 527,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Vojtěch
->Flash cache emptied: 0 bytes

User: Vojt靋h

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 03262016_113402

Files moved on Reboot...
C:\Users\Vojtěch\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
C:\Windows\temp\HP Support Framework\HPSF_Config1.dll moved successfully.

Registry entries deleted on Reboot...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu. Podezření na vir.

#9 Příspěvek od Rudy »

Smazáno. Log by již měl být OK. Pokud vaše podezření stále trvá, udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět