Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý NB

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
tominaxx
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 20 zář 2006 00:03
Kontaktovat uživatele:

Pomalý NB

#1 Příspěvek od tominaxx »

Prosím o kontrolu logu - NB najíždí několik desítek minut, W7 najedou na plochu bez ikon, pak následuje cca 20 min pauza bez jakékoliv aktivity HD, .. programy se spouštějí řádově minuty a při jakémkoli kliknutí do programů zamrznou, objeví se v záhlaví "neodpovídá", rozmrznou, kliknu a zase zamrznou. Díky moc. .. musím dát log nadvakrát, je to dlouhé přes 10000 znaků.

Logfile of random's system information tool 1.14 (written by random/random)
Run by TOMASHEK at 2016-11-08 20:33:29
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 78 GB (17%) free of 461 GB
Total RAM: 8181 MB (75% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:33:32, on 8.11.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18500)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Launch Manager\LManager.EXE
C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe
C:\Program Files (x86)\NaturalPoint\SmartNAV\SmartNAV.exe
C:\Program Files (x86)\Keyboard & Mouse Driver\StartAutorun.exe
C:\Program Files (x86)\Keyboard & Mouse Driver\KMConfig.exe
C:\Program Files (x86)\Keyboard & Mouse Driver\KMProcess.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\NaturalPoint\SmartNAV\DwellClicker.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files\trend micro\TOMASHEK_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t4791y217
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t4791y217
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office16\URLREDIR.DLL
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [VitaKeyPdtWzd] "C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe"
O4 - HKLM\..\Run: [NaturalPoint] C:\Program Files (x86)\NaturalPoint\SmartNAV\SmartNAV.exe
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files (x86)\Keyboard & Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [SystemExplorerAutoStart] "C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKCU\..\Run: [Advanced SystemCare 9] "C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MyPhoneExplorer] "C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe" autorun
O4 - HKCU\..\Run: [JetVoice] "C:\Program Files (x86)\Petit\JetVoice\Jetvoice.exe" AUTORUN
O4 - HKCU\..\Run: [PC Remote Server] C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe /silent
O4 - HKCU\..\Run: [Viber] "C:\Users\TOMASHEK\AppData\Local\Viber\Viber.exe" StartMinimized
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Clip2Net] C:\Program Files (x86)\Clip2Net\Clip2net.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user')
O4 - Startup: MyVoice.lnk = C:\Program Files (x86)\MyVoice\MyVoice.exe
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bi-LINK Gateway.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Macro Express Pro.lnk = C:\Program Files (x86)\Macro Express Pro\MacExp.exe
O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~2\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Poslat do On&eNotu - res://C:\PROGRA~1\MICROS~2\Office16\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Poslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Poslat do On&eNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: @%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430 - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: @%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430 - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 9 (AdvancedSystemCareService9) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files (x86)\Keyboard & Mouse Driver\KMWDSrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: PCNetSoftware RAC Server - Miloslav Novotny N+P - C:\Program Files (x86)\PCNetSoftware\RAC Server\RACs.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe

--
End of file - 19687 bytes

======Enumerating Processes======

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe"
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe"
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\Acer Bio Protection\CompPtcVUI.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe" /Task
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Keyboard & Mouse Driver\KMWDSrv.exe"
"C:\Program Files\NDAS\System\ndassvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\PrintIsolationHost.exe -Embedding
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe"
"C:\Program Files (x86)\Launch Manager\LManager.EXE"
"C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe"
"C:\Program Files (x86)\NaturalPoint\SmartNAV\SmartNAV.exe"
"C:\Program Files (x86)\Keyboard & Mouse Driver\StartAutorun.exe" KMConfig.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
C:\Program Files (x86)\Keyboard & Mouse Driver\KMConfig.exe
"C:\Program Files\NDAS\System\ndasmgmt.exe" /startup
"C:\Program Files (x86)\Keyboard & Mouse Driver\KMProcess.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe"
"C:\Program Files (x86)\NaturalPoint\SmartNAV\DwellClicker.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpWareSE4.exe"
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /systemstart /autostart
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe"
"C:\Windows\system32\taskmgr.exe" /4
"C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Users\TOMASHEK\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\ASC9_PerformanceMonitor - C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe /Task
C:\Windows\system32\tasks\ASC9_SkipUac_TOMASHEK - "C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe" /SkipUac
C:\Windows\system32\tasks\avast! Emergency Update - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1459064889 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\Uninstaller_SkipUac_TOMASHEK - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-834667704-2025353903-2447425861-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Recovery Management\Burn Notification - C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe
C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - %systemroot%\system32\sc.exe start osppsvc
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup - %systemroot%\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor - %systemroot%\system32\sdclt.exe /CHECKSKIPPED
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate_scheduled - %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\Microsoft\Office\Office 15 Subscription Heartbeat - %ProgramFiles%\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 - "C:\Program Files\Microsoft Office\Office16\msoia.exe" scan upload mininterval:2880
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 - "C:\Program Files\Microsoft Office\Office16\msoia.exe" scan upload
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.207 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.91.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.91.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Skype for Business Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.207 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll

C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\
cs@dictionaries.addons.mozilla.org
fxdevtools-adapters@mozilla.org
iobitascsurfingprotection@iobit.com
LogMeInClient@logmein.com
low_quality_flash@pie2k.com
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\searchplugins\
abz-slovnik-cizich-slov.xml
firmycz.xml
mapycz.xml
mystartsearch.xml
youtube.xml
zbocz.xml

C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\addons.json
Personas Plus - extension - personas@christopher.beard
Walnut for Firefox - theme - {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}
Plná Peněženka Lištička - extension - @plnapenezenkacz-firefox-extension
Refundo Toolbar - extension - toolbar@refundo.cz
Český slovník pro kontrolu pravopisu - dictionary - cs@dictionaries.addons.mozilla.org
ReloadEvery - extension - {888d99e7-e8b5-46a3-851e-1ec45da1e644}
Text to Voice - extension - text2voice@vik.josh
Download Manager (S3) - extension - s3download@statusbar
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Context Search - extension - {902D2C4A-457A-4EF9-AD43-7014562929FF}
Sky Pilot Classic - theme - {dbd63b80-1735-11df-8a39-0800200c9a66}
Low Quality Flash - extension - low_quality_flash@pie2k.com
Classic Theme Restorer - extension - ClassicThemeRestorer@ArisT2Noia4dev
Flagfox - extension - {1018e4d6-728f-4b20-ad56-37578a4de76b}
Noia Fox options - extension - NoiaFoxoption@davidvincent.tld
AdBlocker Ultimate - extension - adblockultimate@adblockultimate.net
VratnePenize.cz - extension - toolbar@vratnepenize.cz
FlashGot Mass Downloader - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
Country Flag + - extension - jid1-s7swGsO2vJBPMv@jetpack
Find All - extension - findall@codedawn.com
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b}
Legacy Test Pilot (Outdated) - extension - testpilot@labs.mozilla.com
Pinguin - theme - penguin@loic.com
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d}

C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions.json
Advanced SystemCare Surfing Protection - extension - iobitascsurfingprotection@iobit.com - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\iobitascsurfingprotection@iobit.com
LogMeIn, Inc. Remote Access Plugin - extension - LogMeInClient@logmein.com - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\LogMeInClient@logmein.com
Penguin - theme - penguin@loic.com - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\penguin@loic.com.xpi
Toggle Persona - extension - togglepersona@davidvincent.tld - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\togglepersona@davidvincent.tld.xpi
neurowise - extension - {8d952e73-e32f-45f1-97c1-085cacb7c7a3} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{8d952e73-e32f-45f1-97c1-085cacb7c7a3}.xpi
Sky Pilot - theme - {dbd63b80-1735-11df-8a39-0800200c9a66} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{dbd63b80-1735-11df-8a39-0800200c9a66}.xpi
FoxTab - extension - {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
ReloadEvery - extension - {888d99e7-e8b5-46a3-851e-1ec45da1e644} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
Text to Voice - extension - text2voice@vik.josh - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\text2voice@vik.josh.xpi
Context Search - extension - {902D2C4A-457A-4EF9-AD43-7014562929FF} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{902D2C4A-457A-4EF9-AD43-7014562929FF}.xpi
FlashGot - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
Valence - extension - fxdevtools-adapters@mozilla.org - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\fxdevtools-adapters@mozilla.org
AdBlock Ultimate - extension - adblockultimate@adblockultimate.net - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\adblockultimate@adblockultimate.net.xpi
Noia Fox options - extension - NoiaFoxoption@davidvincent.tld - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\NoiaFoxoption@davidvincent.tld.xpi
Find All - extension - findall@codedawn.com - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\findall@codedawn.com.xpi
Low Quality Flash - extension - low_quality_flash@pie2k.com - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\low_quality_flash@pie2k.com
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Download Manager (S3) - extension - s3download@statusbar - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\s3download@statusbar.xpi
Country Flag + - extension - jid1-s7swGsO2vJBPMv@jetpack - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\jid1-s7swGsO2vJBPMv@jetpack.xpi
Personas Plus - extension - personas@christopher.beard - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\personas@christopher.beard.xpi
VratnePenize.cz - extension - toolbar@vratnepenize.cz - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\toolbar@vratnepenize.cz.xpi
Refundo Toolbar - extension - toolbar@refundo.cz - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\toolbar@refundo.cz.xpi
Český slovník pro kontrolu pravopisu - dictionary - cs@dictionaries.addons.mozilla.org - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\cs@dictionaries.addons.mozilla.org
Test Pilot - extension - testpilot@labs.mozilla.com - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\testpilot@labs.mozilla.com.xpi
Plná Peněženka Lištička - extension - @plnapenezenkacz-firefox-extension - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\@plnapenezenkacz-firefox-extension.xpi
Avast Online Security - extension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF
Avast SafePrice - extension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Flagfox - extension - {1018e4d6-728f-4b20-ad56-37578a4de76b} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Walnut for Firefox - theme - {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Classic Theme Restorer - extension - ClassicThemeRestorer@ArisT2Noia4dev - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi
Asynchronous Plugin Rendering - extension - asyncrendering@mozilla.org - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\features\{1b9a9b18-35bd-45f9-b4da-923411371815}\asyncrendering@mozilla.org.xpi
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\pluginreg.dat
Plugin - Adobe Acrobat - 9.1.0.163 - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
Plugin - VLC Web Plugin - 2.2.2.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
Plugin - Google Update - 1.3.31.5 - C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
Plugin - Windows Live™ Photo Gallery - 15.4.3502.922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
Plugin - Microsoft Office 2016 - 16.0.4266.1001 - C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL
Plugin - Silverlight Plug-In - 5.1.50901.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll
Plugin - Microsoft Office 2016 - 16.0.4288.1000 - C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
Plugin - Java(TM) Platform SE 8 U91 - 11.91.2.14 - C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll
Plugin - Java Deployment Toolkit 8.0.910.14 - 11.91.2.14 - C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npdeployJava1.dll
Plugin - Shockwave Flash - 23.0.0.207 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll

=========Google Chrome=========

C:\Users\TOMASHEK\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 1 Avast SafePrice 12.0.102
Extension felcaaldnbdncclmgdcncolpebgiejap
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi
Extension gomekmidlodglbbmalcneegieacbdmki 0 Avast Online Security 12.0.124
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5416.905.0.6
Homepage: https://www.seznam.cz/
default_search_provider.search_url:
C:\Users\TOMASHEK\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={67A2568C-7A0A-4EED-AECC-B5405DE63B64}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}]
"URL"=http://www.google.com/search?sourceid=i ... lz=1I7ACAW
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12 2472224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2016-10-18 236744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2016-10-21 551520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\Partner64.dll [2009-09-08 750064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24 790552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27 255088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office16\URLREDIR.DLL [2015-07-31 580312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\PROGRA~1\MICROS~2\Office16\GROOVEEX.DLL [2016-10-18 2179888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-10-21 212576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll [2012-02-10 1307928]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31 161448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25 462400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\Partner.dll [2009-09-08 433648]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24 664848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27 193136]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office16\URLREDIR.DLL [2015-07-31 403672]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL [2016-10-18 1524528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25 173120]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27 255088]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
{eec0f710-38b5-4aba-99bf-ec87564a4e13} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll [2012-02-10 1307928]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27 193136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-07 186904]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-08-19 496160]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-09-03 8098848]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-08-14 1814312]
"PLFSetI"=C:\Windows\PLFSetI.exe [2008-07-29 200704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"=C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2016-07-27 2023712]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"MyPhoneExplorer"=C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe [2015-12-08 5557144]
"JetVoice"=C:\Program Files (x86)\Petit\JetVoice\Jetvoice.exe [2011-12-22 210944]
"PC Remote Server"=C:\Program Files (x86)\PC Remote\PC Remote\PCRemote.exe [2014-10-12 1190648]
"Viber"=C:\Users\TOMASHEK\AppData\Local\Viber\Viber.exe [2016-11-03 45485648]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
"Clip2Net"=C:\Program Files (x86)\Clip2Net\Clip2net.exe [2015-12-14 14790656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-08-18 825864]
"VitaKeyPdtWzd"=C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe [2009-08-28 3567616]
"NaturalPoint"=C:\Program Files (x86)\NaturalPoint\SmartNAV\SmartNAV.exe [2008-07-06 386560]
""= []
"KMCONFIG"=C:\Program Files (x86)\Keyboard & Mouse Driver\StartAutorun.exe [2007-03-06 212992]
"IJNetworkScannerSelectorEX"=C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2012-08-31 452272]
"SystemExplorerAutoStart"=C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2015-08-19 3389160]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-28 9099440]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-04-01 596504]
"SSBkgdUpdate"=C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-09-28 185896]
"OpwareSE4"=C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-10-11 75304]
"IObit Malware Fighter"=C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [2016-06-28 5976864]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Bi-LINK Gateway.lnk - C:\Windows\Installer\{CCB9C45C-26C0-4C81-A159-6DF9239DE1B5}\NewShortcut1_8188288DFAC14FF2859A19505BA528D5.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Macro Express Pro.lnk - C:\Program Files (x86)\Macro Express Pro\MacExp.exe
NDAS Device Management.lnk - C:\Program Files\NDAS\System\ndasmgmt.exe

C:\Users\TOMASHEK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyVoice.lnk - C:\Program Files (x86)\MyVoice\MyVoice.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=C:\Program Files (x86)\Acer Bio Protection\PwdFilterV64

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\PCNetSoftware\RAC Server\RACs.exe"="C:\Program Files (x86)\PCNetSoftware\RAC Server\RACs.exe:*:Enabled:Remote Administrator Control Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"VIDC.ACDV"=ACDV.dll
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2016-11-08 19:25:00 ----D---- C:\Program Files\trend micro
2016-11-08 19:24:59 ----D---- C:\rsit
2016-11-07 18:56:45 ----D---- C:\Users\TOMASHEK\AppData\Roaming\NewYu.Omron.Staging.Gateway
2016-11-07 18:56:28 ----D---- C:\Users\TOMASHEK\AppData\Roaming\Omron
2016-11-07 18:56:25 ----D---- C:\ProgramData\Omron
2016-11-07 18:56:24 ----D---- C:\Program Files (x86)\BiLink Gateway
2016-11-07 18:55:13 ----D---- C:\ProgramData\Download Installations
2016-10-30 07:57:22 ----SD---- C:\Windows\SYSWOW64\Microsoft
2016-10-21 18:06:15 ----D---- C:\Program Files (x86)\IPCamera
2016-10-21 13:47:36 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2016-10-21 13:46:48 ----D---- C:\Program Files (x86)\Max Local Application
2016-10-21 13:46:31 ----HDC---- C:\ProgramData\{4B18F527-ABF5-4D76-990D-64B33D9692BB}
2016-10-21 08:17:37 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-10-19 15:52:46 ----A---- C:\Windows\SYSWOW64\RACServerLogon.dll
2016-10-19 14:50:21 ----SHD---- C:\found.000
2016-10-12 07:15:18 ----A---- C:\Windows\system32\mshtml.dll
2016-10-12 07:15:16 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-12 07:15:13 ----A---- C:\Windows\system32\ieframe.dll
2016-10-12 07:15:12 ----A---- C:\Windows\system32\wmp.dll
2016-10-12 07:15:11 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-10-12 07:15:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-12 07:15:10 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-12 07:15:10 ----A---- C:\Windows\system32\jscript9.dll
2016-10-12 07:15:09 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-10-12 07:15:09 ----A---- C:\Windows\system32\wininet.dll
2016-10-12 07:15:09 ----A---- C:\Windows\system32\mf.dll
2016-10-12 07:15:08 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-10-12 07:15:08 ----A---- C:\Windows\system32\drmv2clt.dll
2016-10-12 07:15:08 ----A---- C:\Windows\system32\blackbox.dll
2016-10-12 07:15:07 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-12 07:15:07 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-10-12 07:15:07 ----A---- C:\Windows\system32\WsmSvc.dll
2016-10-12 07:15:07 ----A---- C:\Windows\system32\iertutil.dll
2016-10-12 07:15:06 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-12 07:15:05 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-10-12 07:15:05 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-10-12 07:15:05 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-12 07:15:05 ----A---- C:\Windows\SYSWOW64\quartz.dll
2016-10-12 07:15:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-12 07:15:05 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-10-12 07:15:05 ----A---- C:\Windows\system32\urlmon.dll
2016-10-12 07:15:05 ----A---- C:\Windows\system32\scavengeui.dll
2016-10-12 07:15:05 ----A---- C:\Windows\system32\quartz.dll
2016-10-12 07:15:05 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-12 07:15:04 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-12 07:15:04 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-10-12 07:15:04 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-12 07:15:04 ----A---- C:\Windows\system32\audiosrv.dll
2016-10-12 07:15:04 ----A---- C:\Windows\system32\AUDIOKSE.dll
2016-10-12 07:15:03 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2016-10-12 07:15:03 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-12 07:15:03 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-10-12 07:15:03 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2016-10-12 07:15:03 ----A---- C:\Windows\system32\vbscript.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\evr.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\DWrite.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-10-12 07:15:03 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2016-10-12 07:15:03 ----A---- C:\Windows\system32\cryptui.dll
2016-10-12 07:15:02 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-10-12 07:15:02 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2016-10-12 07:15:02 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-12 07:15:02 ----A---- C:\Windows\system32\qdvd.dll
2016-10-12 07:15:02 ----A---- C:\Windows\system32\AudioEng.dll
2016-10-12 07:15:01 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2016-10-12 07:15:01 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-10-12 07:15:01 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-10-12 07:15:01 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2016-10-12 07:15:01 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2016-10-12 07:15:01 ----A---- C:\Windows\system32\WsmAuto.dll
2016-10-12 07:15:01 ----A---- C:\Windows\system32\win32k.sys
2016-10-12 07:15:01 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-12 07:15:01 ----A---- C:\Windows\system32\mfplat.dll
2016-10-12 07:15:01 ----A---- C:\Windows\system32\FntCache.dll
2016-10-12 07:15:01 ----A---- C:\Windows\system32\AudioSes.dll
2016-10-12 07:15:00 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-10-12 07:15:00 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-10-12 07:15:00 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-12 07:15:00 ----A---- C:\Windows\system32\EncDump.dll
2016-10-12 07:15:00 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2016-10-12 07:14:59 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-10-12 07:14:59 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-12 07:14:59 ----A---- C:\Windows\system32\wmploc.DLL
2016-10-12 07:14:58 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-12 07:14:58 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-12 07:14:58 ----A---- C:\Windows\system32\audiodg.exe
2016-10-12 07:14:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-10-12 07:14:57 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-10-12 07:14:57 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-12 07:14:57 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-12 07:14:57 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2016-10-12 07:14:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-10-12 07:14:57 ----A---- C:\Windows\system32\msscp.dll
2016-10-12 07:14:57 ----A---- C:\Windows\system32\mfps.dll
2016-10-12 07:14:57 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-12 07:14:57 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-12 07:14:57 ----A---- C:\Windows\system32\cryptsp.dll
2016-10-12 07:14:57 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-12 07:14:56 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-10-12 07:14:56 ----A---- C:\Windows\system32\ntdll.dll
2016-10-12 07:14:56 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-10-12 07:14:56 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-10-12 07:14:55 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2016-10-12 07:14:55 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-10-12 07:14:55 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-10-12 07:14:55 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-12 07:14:55 ----A---- C:\Windows\system32\WebClnt.dll
2016-10-12 07:14:55 ----A---- C:\Windows\system32\msnetobj.dll
2016-10-12 07:14:54 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-10-12 07:14:54 ----A---- C:\Windows\system32\rrinstaller.exe
2016-10-12 07:14:54 ----A---- C:\Windows\system32\pcadm.dll
2016-10-12 07:14:54 ----A---- C:\Windows\system32\mfpmp.exe
2016-10-12 07:14:54 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-12 07:14:54 ----A---- C:\Windows\system32\davclnt.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\wsmprovhost.exe
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\wsmplpxy.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2016-10-12 07:14:53 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\wsmprovhost.exe
2016-10-12 07:14:53 ----A---- C:\Windows\system32\wsmplpxy.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\webcheck.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\spwmp.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\rpcrt4.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\pcawrk.exe
2016-10-12 07:14:53 ----A---- C:\Windows\system32\pcalua.exe
2016-10-12 07:14:53 ----A---- C:\Windows\system32\pcaevts.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\msmmsp.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\jscript.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\INETRES.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\ieui.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\dxtrans.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\dxmasf.dll
2016-10-12 07:14:53 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-10-12 07:14:52 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\smss.exe
2016-10-12 07:14:52 ----A---- C:\Windows\system32\schannel.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\occache.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\msv1_0.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\msrating.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\mshtmled.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\kerberos.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\jsproxy.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\jscript9diag.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\inseng.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\ieUnatt.exe
2016-10-12 07:14:52 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\dxtmsft.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-10-12 07:14:52 ----A---- C:\Windows\system32\crypt32.dll
2016-10-12 07:14:52 ----A---- C:\Windows\system32\advapi32.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-10-12 07:14:51 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\wintrust.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\wdigest.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\TSpkg.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\sspicli.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\rpchttp.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\ncrypt.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\kernel32.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\iesetup.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\iernonce.dll
2016-10-12 07:14:51 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-10-12 07:14:51 ----A---- C:\Windows\system32\cryptsvc.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\WsmRes.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2016-10-12 07:14:50 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\WsmRes.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\wow64win.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\wow64.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\winsrv.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\sspisrv.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\srcore.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\secur32.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\mferror.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\lsass.exe
2016-10-12 07:14:50 ----A---- C:\Windows\system32\KernelBase.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-10-12 07:14:50 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-10-12 07:14:50 ----A---- C:\Windows\system32\csrsrv.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\cryptnet.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\cryptbase.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\credssp.dll
2016-10-12 07:14:50 ----A---- C:\Windows\system32\conhost.exe
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 07:14:49 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\user.exe
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-10-12 07:14:49 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\wow64cpu.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\srclient.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\rstrui.exe
2016-10-12 07:14:49 ----A---- C:\Windows\system32\ntvdm64.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\msobjs.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\msaudite.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\drivers\appid.sys
2016-10-12 07:14:49 ----A---- C:\Windows\system32\auditpol.exe
2016-10-12 07:14:49 ----A---- C:\Windows\system32\appidsvc.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 07:14:49 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 07:14:49 ----A---- C:\Windows\system32\appidapi.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\apisetschema.dll
2016-10-12 07:14:49 ----A---- C:\Windows\system32\adtschema.dll
2016-10-11 23:56:49 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-10-11 23:56:49 ----A---- C:\Windows\system32\shell32.dll
2016-10-11 23:56:49 ----A---- C:\Windows\explorer.exe
2016-10-11 23:56:48 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-10-11 23:56:48 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-10-11 23:56:48 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-10-11 23:56:48 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-10-11 23:56:48 ----A---- C:\Windows\system32\authui.dll
2016-10-11 23:24:54 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-10-11 23:24:54 ----A---- C:\Windows\system32\poqexec.exe
2016-10-11 22:21:42 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-11 22:21:42 ----A---- C:\Windows\system32\appraiser.dll
2016-10-11 22:21:42 ----A---- C:\Windows\system32\acmigration.dll
2016-10-11 22:21:41 ----A---- C:\Windows\system32\invagent.dll
2016-10-11 22:21:41 ----A---- C:\Windows\system32\generaltel.dll
2016-10-11 22:21:41 ----A---- C:\Windows\system32\devinv.dll
2016-10-11 22:21:41 ----A---- C:\Windows\system32\centel.dll
2016-10-11 22:21:41 ----A---- C:\Windows\system32\aepic.dll
2016-10-11 22:21:41 ----A---- C:\Windows\system32\aeinv.dll
2016-10-11 22:03:15 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-10-11 22:03:11 ----A---- C:\Windows\system32\drivers\usbport.sys
2016-10-11 22:03:00 ----A---- C:\Windows\system32\drivers\usbhub.sys
2016-10-11 22:02:42 ----A---- C:\Windows\system32\drivers\usbohci.sys
2016-10-11 22:02:42 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-10-11 22:02:41 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2016-10-11 22:02:41 ----A---- C:\Windows\system32\drivers\usbd.sys

======List of files/folders modified in the last 1 month======

2016-11-08 20:32:10 ----D---- C:\Windows\Prefetch
2016-11-08 19:25:00 ----RD---- C:\Program Files
2016-11-08 18:26:40 ----D---- C:\Users\TOMASHEK\AppData\Roaming\vlc
2016-11-08 18:22:52 ----D---- C:\ProgramData\MAX
2016-11-08 15:55:36 ----SHD---- C:\System Volume Information
2016-11-08 15:46:29 ----D---- C:\Windows\SysWOW64
2016-11-08 15:46:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-11-08 15:46:20 ----D---- C:\Windows\system32\Macromed
2016-11-08 15:46:18 ----D---- C:\Windows\SYSWOW64\Macromed
2016-11-08 15:46:16 ----D---- C:\Windows\Temp
2016-11-08 15:29:37 ----D---- C:\Windows\System32
2016-11-08 15:29:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-11-08 15:29:34 ----D---- C:\Windows\inf
2016-11-08 15:16:25 ----D---- C:\Users\TOMASHEK\AppData\Roaming\ViberPC
2016-11-08 15:16:07 ----D---- C:\Users\TOMASHEK\AppData\Roaming\MyPhoneExplorer
2016-11-08 12:35:00 ----D---- C:\Windows\Logs
2016-11-08 12:08:03 ----D---- C:\Windows\system32\config
2016-11-08 08:22:11 ----D---- C:\Users\TOMASHEK\AppData\Roaming\Clip2Net
2016-11-08 03:38:46 ----D---- C:\ProgramData\X10 Settings
2016-11-08 01:25:02 ----D---- C:\Windows\system32\drivers
2016-11-07 18:56:35 ----SHD---- C:\Windows\Installer
2016-11-07 18:56:25 ----HD---- C:\ProgramData
2016-11-07 18:56:24 ----RD---- C:\Program Files (x86)
2016-11-07 07:53:53 ----D---- C:\Windows
2016-11-06 08:13:31 ----D---- C:\ProgramData\ProductData
2016-11-06 03:21:21 ----D---- C:\ProgramData\Microsoft Help
2016-11-05 12:21:15 ----D---- C:\Users\TOMASHEK\AppData\Roaming\Skype
2016-11-04 08:37:41 ----D---- C:\Users\TOMASHEK\AppData\Roaming\ICQ
2016-10-30 08:05:35 ----D---- C:\Windows\system32\Tasks
2016-10-27 08:09:11 ----D---- C:\Users\TOMASHEK\AppData\Roaming\WhatsApp
2016-10-24 13:50:47 ----D---- C:\Windows\system32\catroot2
2016-10-24 13:50:47 ----D---- C:\Windows\debug
2016-10-21 20:33:36 ----D---- C:\Windows\Minidump
2016-10-21 20:32:44 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-21 18:07:06 ----D---- C:\ProgramData\InstallShield
2016-10-21 18:06:37 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-10-21 16:25:48 ----D---- C:\ProgramData\Skype
2016-10-21 13:46:59 ----D---- C:\Program Files\Java
2016-10-21 13:46:17 ----HDC---- C:\ProgramData\{20F973F1-36F1-4DC9-BE8D-B3C33C88AD1C}
2016-10-19 15:52:45 ----D---- C:\Program Files (x86)\PCNetSoftware
2016-10-19 15:16:30 ----RD---- C:\Program Files (x86)\Skype
2016-10-19 15:16:30 ----D---- C:\Program Files (x86)\Common Files
2016-10-15 17:39:05 ----D---- C:\Windows\system32\DriverStore
2016-10-15 12:53:36 ----D---- C:\Windows\system32\drivers\UMDF
2016-10-15 10:33:31 ----D---- C:\Windows\rescache
2016-10-15 08:45:19 ----SD---- C:\Users\TOMASHEK\AppData\Roaming\Microsoft
2016-10-14 20:26:41 ----D---- C:\Windows\winsxs
2016-10-14 08:35:20 ----D---- C:\Windows\Microsoft.NET
2016-10-14 08:35:19 ----RSD---- C:\Windows\assembly
2016-10-14 07:01:45 ----D---- C:\Program Files (x86)\Windows Media Player
2016-10-14 07:01:45 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-14 07:01:44 ----D---- C:\Program Files\Windows Media Player
2016-10-14 07:01:44 ----D---- C:\Program Files\Internet Explorer
2016-10-14 07:01:43 ----D---- C:\Windows\SYSWOW64\en-US
2016-10-14 07:01:43 ----D---- C:\Windows\SYSWOW64\Dism
2016-10-14 07:01:43 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-10-14 07:01:36 ----D---- C:\Windows\system32\Dism
2016-10-14 07:01:36 ----D---- C:\Windows\system32\cs-CZ
2016-10-14 07:01:35 ----D---- C:\Windows\system32\en-US
2016-10-14 07:01:24 ----D---- C:\Windows\AppPatch
2016-10-14 07:01:22 ----D---- C:\Windows\system32\Boot
2016-10-14 07:01:21 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 07:01:21 ----D---- C:\Windows\system32\appraiser
2016-10-14 07:01:19 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-10-14 07:01:15 ----D---- C:\Windows\cs-CZ
2016-10-13 06:55:15 ----D---- C:\Program Files\Microsoft Silverlight
2016-10-13 03:19:18 ----D---- C:\Windows\system32\MRT
2016-10-13 03:07:17 ----AC---- C:\Windows\system32\MRT.exe
2016-10-13 03:05:46 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-10-10 13:20:13 ----D---- C:\Users\TOMASHEK\AppData\Roaming\IObit

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

tominaxx
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 20 zář 2006 00:03
Kontaktovat uživatele:

Re: Pomalý NB

#2 Příspěvek od tominaxx »

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-09-26 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-10-13 293352]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-07 408600]
R0 johci;JMicron 1394 Filter Driver; C:\Windows\system32\DRIVERS\johci.sys [2009-08-24 22640]
R0 lfsfilt;Lean File Sharing; C:\Windows\system32\DRIVERS\lfsfilt.sys [2007-11-27 339944]
R0 lpx;LPX Protocol; C:\Windows\system32\DRIVERS\lpx.sys [2007-11-27 97256]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2016-03-22 503352]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-09-26 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-09-26 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-09-26 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-09-26 513632]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-10-06 27552]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
R1 ndasfat;NDAS FAT; \??\C:\Windows\system32\DRIVERS\ndasfat.sys [2007-11-27 537064]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-09-26 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-09-26 163416]
R2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys); C:\Windows\System32\Drivers\FPSensor.sys [2016-03-15 29184]
R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [2014-04-09 31920]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
R3 cpuz138;cpuz138; \??\C:\Users\TOMASHEK\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [2016-11-08 27320]
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); SysWOW64\Drivers\DKbFltr.sys []
R3 IMFFilter;IMFFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [2016-04-01 22208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-09-03 1994272]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
R3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
R3 Ltn_stk7770P;PCTV LITEON TT128xDA based TV tuner device; C:\Windows\system32\DRIVERS\Ltn_stk7770P.sys [2009-06-23 694272]
R3 ndasbus;NDAS Bus Driver; C:\Windows\system32\DRIVERS\ndasbus.sys [2007-11-27 108520]
R3 npusbio;npusbio; C:\Windows\System32\Drivers\npusbio_x64.sys [2008-04-25 55328]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-05 18432]
R3 nuvotoncir;Nuvoton IR Transceiver; C:\Windows\system32\DRIVERS\nuvotoncir.sys [2009-06-24 48128]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-06-26 83488]
R3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2016-01-11 34848]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-08-14 286768]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-05 16896]
S2 RACDriver;RAC driver; \??\C:\Program Files (x86)\PCNetSoftware\RAC Server\RACDriver.sys [2007-03-20 8208]
S3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [2014-02-11 34136]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-09-26 37656]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2009-05-18 143320]
S3 ndasscsi;NDAS SCSI Miniport Driver; C:\Windows\system32\DRIVERS\ndasscsi.sys [2007-11-27 235496]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-05-14 5435904]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2016-06-30 19456]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 109056]
S3 Trufos;Trufos; C:\Windows\system32\DRIVERS\TRUFOS.sys [2016-03-31 452040]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2016-06-30 57856]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdvancedSystemCareService9;Advanced SystemCare Service 9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [2016-07-25 452384]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-09-26 197128]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-17 864032]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-08-19 796192]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-07 354840]
R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2016-06-13 1597728]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service; C:\Program Files (x86)\Keyboard & Mouse Driver\KMWDSrv.exe [2007-04-05 208896]
R2 ndassvc;NDAS Service; C:\Program Files\NDAS\System\ndassvc.exe [2007-11-27 377832]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-08-27 382568]
R2 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2015-07-30 5132888]
R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-09-11 5702416]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-20 154440]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2016-06-14 2960672]
S2 PCNetSoftware RAC Server;PCNetSoftware RAC Server; C:\Program Files (x86)\PCNetSoftware\RAC Server\RACs.exe [2008-11-24 3186688]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
S3 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2016-02-24 1145928]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08 270016]
S3 Autodesk Content Service;Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [2015-02-05 31160]
S3 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
S3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2016-03-23 1369856]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2016-03-21 651720]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-20 154440]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2016-03-20 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-09-30 114688]
S3 IGBASVC;EgisTec Service; C:\Program Files (x86)\Acer Bio Protection\BASVC.exe [2009-08-28 3450368]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-10-21 172488]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S3 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-22 62720]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-06-18 50432]
S3 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-06-18 144640]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 242864]
S3 Partner Service;Partner Service; C:\ProgramData\Partner\Partner.exe [2009-09-08 332272]
S3 SystemExplorerHelpService;System Explorer Service; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [2014-12-20 820960]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-03-23 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119672
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý NB

#3 Příspěvek od Rudy »

Zdravím!
1. Doporučuji odinstalovat Advanced system care. Tento optimalizátor vidí problémy i tam, kde nejsou a laik si jím snadno může poškodit systém.
2. Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

tominaxx
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 20 zář 2006 00:03
Kontaktovat uživatele:

Re: Pomalý NB

#4 Příspěvek od tominaxx »

# AdwCleaner v6.030 - Log soubor vytvořen 08/11/2016 na 22:44:22
# Aktualizováno dne 19/10/2016 z Malwarebytes
# Databáze : 2016-11-08.1 [Server]
# Operační systém : Windows 7 Home Premium Service Pack 1 (X64)
# Uživatelské jméno : TOMASHEK - TOMASHEK
# Beží od : C:\Users\TOMASHEK\Desktop\adwcleaner_6.030.exe
# Mod: Čištění
# Podpora : hxxps://www.malwarebytes.com/support



***** [ Služby ] *****

[-] Služby smazány:Partner Service


***** [ Adresáře ] *****

[-] Adresář smazán:C:\Users\TOMASHEK\Documents\ppt
[-] Adresář smazán:C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\FoxTab
[-] Adresář smazán:C:\ProgramData\Partner
[#] Adresář nelze smazat:C:\ProgramData\Application Data\Partner


***** [ Soubory ] *****

[-] Soubor smazán:C:\Users\TOMASHEK\AppData\Roaming\Mozilla\Firefox\Profiles\p8fjacgh.default-1458592961249\searchplugins\mystartsearch.xml


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKLM\SOFTWARE\Classes\kt_bho.KettleBho.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Klíč smazán:HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Klíč smazán:HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\kt_bho.KettleBho.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\protector_dll.Protector
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AppID\{28A88B70-D874-4F73-BBBA-9B2B222FB7D6}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Klíč smazán:HKLM\SOFTWARE\master
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AppID\kt_bho_dll.dll


***** [ Prohlížeče ] *****

[-] Firefox nastavení vyčištěno:"browser.newtab.url" - "chrome://quick_start/content/index.html"
[-] Firefox nastavení vyčištěno:"browser.search.searchengine.alias" - "mystartsearch"
[-] Firefox nastavení vyčištěno:"browser.search.searchengine.iconURL" - "hxxp://www.mystartsearch.com/web/favicon.ico"
[-] Firefox nastavení vyčištěno:"browser.search.searchengine.name" - "mystartsearch"
[-] Firefox nastavení vyčištěno:"browser.search.searchengine.url" - "hxxp://www.mystartsearch.com/web/?type=dspp&ts ... earchTerms}"
[-] Firefox nastavení vyčištěno:
[-] Firefox nastavení vyčištěno:"extensions.quick_start.enable_search1" - false
[-] Firefox nastavení vyčištěno:"extensions.quick_start.sd.closeWindowWithLastTab_prev_state" - false


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [3927 Bajtů] - [08/11/2016 22:44:22]
C:\AdwCleaner\AdwCleaner[S0].txt - [4847 Bajtů] - [08/11/2016 22:43:24]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4075 Bajtů] ##########

tominaxx
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 20 zář 2006 00:03
Kontaktovat uživatele:

Re: Pomalý NB

#5 Příspěvek od tominaxx »

Zdravim ! .. po zasahu AdwCleaneru to najizdelo 30min, paxe to jen a jen sekalo, kdyz pustim Firefox, tak je to mnohem horsi .. 10 min to nacita domovskou stranku .. projel jsem to znovu AdwCleanerem, tady je log

# AdwCleaner v6.030 - Log soubor vytvořen 09/11/2016 na 10:20:13
# Aktualizováno dne 19/10/2016 z Malwarebytes
# Databáze : 2016-11-08.1 [Server]
# Operační systém : Windows 7 Home Premium Service Pack 1 (X64)
# Uživatelské jméno : TOMASHEK - TOMASHEK
# Beží od : C:\Users\TOMASHEK\Desktop\adwcleaner_6.030.exe
# Mod: Čištění
# Podpora : hxxps://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Adresáře ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}


***** [ Prohlížeče ] *****

[-] Firefox nastavení vyčištěno:


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [4175 Bajtů] - [08/11/2016 22:44:22]
C:\AdwCleaner\AdwCleaner[C2].txt - [1165 Bajtů] - [09/11/2016 10:20:13]
C:\AdwCleaner\AdwCleaner[S0].txt - [4847 Bajtů] - [08/11/2016 22:43:24]
C:\AdwCleaner\AdwCleaner[S1].txt - [1892 Bajtů] - [09/11/2016 10:19:32]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1387 Bajtů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119672
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý NB

#6 Příspěvek od Rudy »

ADWCleaner čistí PC od Adwaru. Takže by se to mělo spíše zlepšit. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

tominaxx
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 20 zář 2006 00:03
Kontaktovat uživatele:

Re: Pomalý NB

#7 Příspěvek od tominaxx »

Díky moc, ale už jsem to psychicky nevydržel a celé jsem to přeinstaloval celé W7.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119672
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý NB

#8 Příspěvek od Rudy »

Také řešení. Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno