Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

URL:Mal - Virus

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

URL:Mal - Virus

#1 Příspěvek od Zemos »

Dobrý večer, do počítače se mi dostal mojí chybou virus URL:Mal, který jsem se nejdříve pokoušel odstranit sám. Avast po restartu, MBAM a ADWCleaner nepomohli. Proto se už obracím na vás.
Předem děkuji za nervy strávené se mnou :happy:
Přikládám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Péťa at 2017-04-29 22:36:57
Microsoft Windows 8.1
System drive C: has 269 GB (57%) free of 467 GB
Total RAM: 8114 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:37:01, on 29. 4. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe
D:\Programy\Steam\Steam.exe
D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe
D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Péťa.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 159.203.24.28:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [Overwolf] "D:\Programy\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Péťa\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "D:\Programy\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\Run: [World of Tanks] "D:\Hry\World_of_Tanks\WargamingGameUpdater.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [WallpaperEngine] "D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe" -silent
O4 - HKCU\..\Run: [Steam] "D:\Programy\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [EvolveClient] D:\Programy\evolveo\EvolveClient.exe -autorun
O4 - Startup: Dropbox.lnk = ?
O4 - Startup: MEGAsync.lnk = ?
O4 - Startup: Trust.Zone VPN Client.lnk = C:\Program Files\Trust.Zone VPN Client\trustzone_x64.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{47B75A97-BFE7-49CC-84D3-78AAF20B4CB7}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E9227A9-8C09-4C6E-87B3-80E27532210B}: NameServer = 8.8.8.8
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AODService - Unknown owner - D:\Programy\AMD-OverDrive\AODAssist.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Evolve Service (EvoSvc) - Echobit LLC - D:\Programy\evolveo\EvoSvc.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IObit Uninstaller Service (IObitUnSvr) - IObit - C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - D:\Programy\origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Programy\origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: scinfo - Unknown owner - C:\Users\PA010B~1\AppData\Local\scinfo\scinfo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Intel(R) Common Connectivity Framework (STCServ) - Intel Corporation - C:\Program Files\Intel\STCServ\STCServ.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: Trust.Zone VPN Client (TZVPNCLIENT) - Trust.Zone VPN Project - C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12383 bytes

======Listing Processes======





wininit.exe

winlogon.exe


C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
dashost.exe {07bdb87a-015a-47c6-9fe64f0b3275d82b}
"D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
"C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe"
C:\Users\PA010B~1\AppData\Local\scinfo\scinfo.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe" /service
"C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe" -s
C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-237ddbbb-c7d4-4d58-8e4a-9c358c439e0f -SystemEventPortName:HostProcess-63a01ac2-eee2-4bd4-94ac-9d90c6fa744b -IoCancelEventPortName:HostProcess-7549dfa2-ce51-47cd-b68d-6953588aef9a -NonStateChangingEventPortName:HostProcess-d61e59f0-43ba-4d6b-87e1-0a33388e3dd2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5e16bd10-8c31-486e-a3fb-65ba28b54a40 -DeviceGroupId:WudfDefaultDevicePool
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3eaa7151-cd25-4d72-a8b4-7fb8a1b91e73 -SystemEventPortName:HostProcess-2de95007-cc32-45e5-93d6-a26b6b55b3dd -IoCancelEventPortName:HostProcess-845a608c-e459-4979-9a3a-5bf0fb4ca47a -NonStateChangingEventPortName:HostProcess-1563298b-a854-42a4-8ff2-e108c92d0a82 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ba38a0c7-d93b-42c3-b7c8-0a80736be0b5 -DeviceGroupId:WpdFsGroup
taskhostex.exe
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe atlogon
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
AvastUI.exe /nogui
"C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe" /uihelp
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe" -silent
webwallpaper32.exe -parentprocess 1108 -messagehandler WPEWebIpcHandler0 -parenthwnd 66246

/tasktrayonly
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Intel\STCServ\STCServ.exe"
"D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe" --type=gpu-process --no-sandbox --disable-d3d11 --lang=en-US --log-file="D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\debug.log" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,18,19,20,23,26,40,71 --gpu-vendor-id=0x1002 --gpu-device-id=0x6611 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=22.19.157.3 --gpu-driver-date=4-10-2017 --lang=en-US --log-file="D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\debug.log" --service-request-channel-token=396E1A1C9804C7A172ACC8A6B49F5D4B --mojo-platform-channel-handle=1256 /prefetch:2
"D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe" --type=renderer --force-device-scale-factor=1 --no-sandbox --primordial-pipe-token=963AE5217AD4DB29A92A82C59B4723CB --lang=en-US --lang=en-US --log-file="D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\debug.log" --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=963AE5217AD4DB29A92A82C59B4723CB --renderer-client-id=3 --mojo-platform-channel-handle=1472 /prefetch:1
D:\Programy\Steam\Steam.exe
D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe "-cachedir=C:\Users\Péťa\AppData\Local\Steam\htmlcache" "-steampid=1188" "-buildid=1493162727" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --disable-spell-checking --disable-out-of-process-pac --disable-smooth-scrolling --enable-direct-write "--log-file=D:\Programy\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --disable-smooth-scrolling --enable-pinch --primordial-pipe-token=E6922B848C447CB76D3D486E2550306F --lang=en-US --lang=cs-CZ --log-file="D:\Programy\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --disable-spell-checking --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --service-request-channel-token=E6922B848C447CB76D3D486E2550306F --renderer-client-id=2 --mojo-platform-channel-handle=1568 /prefetch:1
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\LiveUpdate.exe"
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe" /Set
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
taskhost.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Péťa\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Péťa\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=58.0.3029.81 --initial-client-data=0x134,0x138,0x13c,0x130,0x140,0x5ed77de4,0x5ed77dd0,0x5ed77df0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1148 --on-initialized-event-handle=472 --parent-handle=484 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1276 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,18,19,20,23,26,41,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x6611 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=22.19.157.3 --gpu-driver-date=4-10-2017 --service-request-channel-token=CEF4FCB58E925BF2C0E09A82B5EFE07D --mojo-platform-channel-handle=1288 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1276 --primordial-pipe-token=AB91085179F2668A174316E30AAD8434 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=AB91085179F2668A174316E30AAD8434 --renderer-client-id=4 --mojo-platform-channel-handle=2904 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1276 --primordial-pipe-token=0F773A2FC2558A37387942FCE967069D --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=0F773A2FC2558A37387942FCE967069D --renderer-client-id=5 --mojo-platform-channel-handle=2904 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1276 --primordial-pipe-token=901B87B2B78DD094DCD42A0B8CECB860 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=901B87B2B78DD094DCD42A0B8CECB860 --renderer-client-id=8 --mojo-platform-channel-handle=5228 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1276 --primordial-pipe-token=19699A6C532E680D82D2451508A02076 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=19699A6C532E680D82D2451508A02076 --renderer-client-id=14 --mojo-platform-channel-handle=6064 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1276 --primordial-pipe-token=5EF4FAEF6E772F8AAADA270C357F6EF9 --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=5EF4FAEF6E772F8AAADA270C357F6EF9 --renderer-client-id=20 --mojo-platform-channel-handle=7956 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1276 --primordial-pipe-token=662D0382D4273D2D6CE85FFDA2F9B288 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=662D0382D4273D2D6CE85FFDA2F9B288 --renderer-client-id=21 --mojo-platform-channel-handle=1880 /prefetch:1
taskeng.exe {68AFB8D3-5CC6-4397-AEBE-CE6A42A72FA1}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
taskeng.exe {B9A99ACA-0004-4B83-8F41-B6A56E878819}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Péťa\Desktop\Programy\čistící programy\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-621929646-1206955908-3885600500-1001Core.job - C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-621929646-1206955908-3885600500-1001UA.job - C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Uninstaller_SkipUac_Péťa.job - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-27 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-07 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-27 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-27 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-07 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-27 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-01-07 13663448]
"IntelConnectCenter"=C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [2015-03-16 90112]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-04-07 213824]
"Trust.Zone VPN Client UI Helper"=C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe [2017-04-29 4617200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Dropbox Update"=C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05 143144]
"Overwolf"=D:\Programy\Overwolf\OverwolfLauncher.exe [2016-11-07 247344]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-09-28 8944344]
"Spotify Web Helper"=C:\Users\Péťa\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2017-04-16 1446000]
"DAEMON Tools Lite Automount"=D:\Programy\DAEMON Tools Lite\DTAgent.exe [2015-06-18 4468056]
"SpybotPostWindows10UpgradeReInstall"=C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [2015-07-28 1011200]
"World of Tanks"=D:\Hry\World_of_Tanks\WargamingGameUpdater.exe [2017-02-28 3135752]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]
"WallpaperEngine"=D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe [2017-04-10 731136]
"Steam"=D:\Programy\Steam\steam.exe [2017-04-26 3019552]
"EvolveClient"=D:\Programy\evolveo\EvolveClient.exe [2017-03-31 3334528]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2017-03-02 5883912]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]

C:\Users\Péťa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Péťa\AppData\Roaming\Dropbox\bin\Dropbox.exe
MEGAsync.lnk - C:\Users\Péťa\AppData\Local\MEGAsync\MEGAsync.exe
Trust.Zone VPN Client.lnk - C:\Program Files\Trust.Zone VPN Client\trustzone_x64.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2017-04-29 22:32:12 ----D---- C:\rsit
2017-04-29 12:13:03 ----A---- C:\Windows\system32\drivers\neo_vpn.sys
2017-04-29 12:12:50 ----D---- C:\Program Files\Trust.Zone VPN Client
2017-04-22 20:56:03 ----D---- C:\Program Files (x86)\1C Company
2017-04-17 17:35:42 ----D---- C:\Users\Péťa\AppData\Roaming\SpinTires
2017-04-15 10:27:40 ----D---- C:\Program Files (x86)\Prime95
2017-04-15 09:35:12 ----D---- C:\Program Files\CPUID
2017-04-14 17:38:27 ----D---- C:\Program Files (x86)\SpeedFan
2017-04-10 19:32:02 ----A---- C:\Windows\system32\GameManager64.dll
2017-04-10 19:32:00 ----A---- C:\Windows\system32\dgtrayicon.exe
2017-04-10 19:31:58 ----A---- C:\Windows\system32\detoured.dll
2017-04-10 19:31:52 ----A---- C:\Windows\system32\atitmm64.dll
2017-04-10 19:31:50 ----A---- C:\Windows\system32\atimuixx.dll
2017-04-10 19:31:48 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2017-04-10 19:31:48 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2017-04-10 19:31:48 ----A---- C:\Windows\system32\atiglpxx.dll
2017-04-10 19:31:46 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2017-04-10 19:31:42 ----A---- C:\Windows\system32\atiesrxx.exe
2017-04-10 19:31:38 ----A---- C:\Windows\system32\atieclxx.exe
2017-04-10 19:31:36 ----A---- C:\Windows\system32\atieah64.exe
2017-04-10 19:31:34 ----A---- C:\Windows\SYSWOW64\atieah32.exe
2017-04-10 19:31:32 ----A---- C:\Windows\system32\atidemgy.dll
2017-04-10 19:31:28 ----A---- C:\Windows\system32\aticalrt64.dll
2017-04-10 19:31:26 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2017-04-10 19:31:22 ----A---- C:\Windows\system32\aticaldd64.dll
2017-04-10 19:31:16 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2017-04-10 19:31:14 ----A---- C:\Windows\SYSWOW64\RapidFireServer.dll
2017-04-10 19:31:14 ----A---- C:\Windows\system32\RapidFireServer64.dll
2017-04-10 19:31:14 ----A---- C:\Windows\system32\aticalcl64.dll
2017-04-10 19:31:12 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2017-04-10 19:31:12 ----A---- C:\Windows\system32\Rapidfire64.dll
2017-04-10 19:31:10 ----A---- C:\Windows\SYSWOW64\Rapidfire.dll
2017-04-10 19:31:10 ----A---- C:\Windows\system32\atiapfxx.exe
2017-04-10 19:31:08 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
2017-04-10 19:31:08 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2017-04-10 19:31:08 ----A---- C:\Windows\SYSWOW64\atiadlxx.dll
2017-04-10 19:31:08 ----A---- C:\Windows\system32\mantleaxl64.dll
2017-04-10 19:31:06 ----A---- C:\Windows\system32\mantle64.dll
2017-04-10 19:31:06 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2017-04-10 19:31:04 ----A---- C:\Windows\SYSWOW64\mantle32.dll
2017-04-10 19:31:02 ----A---- C:\Windows\system32\ATIODE.exe
2017-04-10 19:31:02 ----A---- C:\Windows\system32\ATIODCLI.exe
2017-04-10 19:30:48 ----A---- C:\Windows\system32\OpenCL.dll
2017-04-10 19:30:48 ----A---- C:\Windows\system32\clinfo.exe
2017-04-10 19:30:48 ----A---- C:\Windows\system32\amdgfxinfo64.dll
2017-04-10 19:30:46 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2017-04-10 19:30:46 ----A---- C:\Windows\SYSWOW64\amdgfxinfo32.dll
2017-04-10 19:30:44 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2017-04-10 19:30:44 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
2017-04-10 19:30:44 ----A---- C:\Windows\system32\atimpc64.dll
2017-04-10 19:30:42 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2017-04-10 19:30:42 ----A---- C:\Windows\system32\amdpcom64.dll
2017-04-10 19:30:40 ----A---- C:\Windows\system32\amdmiracast.dll
2017-04-10 19:30:40 ----A---- C:\Windows\system32\amdhcp64.dll
2017-04-10 19:30:38 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
2017-04-10 19:30:38 ----A---- C:\Windows\system32\amdmantle64.dll
2017-04-10 19:30:34 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
2017-04-10 19:30:34 ----A---- C:\Windows\SYSWOW64\amdave32.dll
2017-04-10 19:30:34 ----A---- C:\Windows\system32\amdocl64.dll
2017-04-10 19:30:34 ----A---- C:\Windows\system32\amdave64.dll
2017-04-10 19:30:30 ----A---- C:\Windows\SYSWOW64\amdlvr32.dll
2017-04-10 19:30:30 ----A---- C:\Windows\system32\coinst_17.10.dll
2017-04-10 19:30:30 ----A---- C:\Windows\system32\amdlvr64.dll
2017-04-10 19:30:28 ----A---- C:\Windows\system32\amdocl12cl64.dll
2017-04-10 19:30:24 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2017-04-10 19:30:20 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2017-04-10 19:30:20 ----A---- C:\Windows\system32\atisamu64.dll
2017-04-10 19:30:18 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
2017-04-10 19:30:08 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2017-04-10 19:30:02 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2017-04-10 19:30:02 ----A---- C:\Windows\system32\amfrt64.dll
2017-04-10 19:29:56 ----A---- C:\Windows\system32\amdvlk64.dll
2017-04-10 19:29:52 ----A---- C:\Windows\SYSWOW64\amdvlk32.dll
2017-04-10 19:29:48 ----A---- C:\Windows\system32\amduve64.dll
2017-04-10 19:29:46 ----A---- C:\Windows\SYSWOW64\amduve32.dll
2017-04-10 19:29:42 ----A---- C:\Windows\system32\amdmmcl6.dll
2017-04-10 19:29:40 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
2017-04-10 19:29:40 ----A---- C:\Windows\system32\amdmcl64.dll
2017-04-10 19:29:38 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2017-04-10 19:29:36 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2017-04-10 19:29:16 ----A---- C:\Windows\system32\amdhdl64.dll
2017-04-10 19:29:14 ----A---- C:\Windows\SYSWOW64\amdhdl32.dll
2017-04-09 17:01:39 ----D---- C:\ProgramData\RealVNC-Service
2017-04-09 17:01:27 ----D---- C:\Program Files\RealVNC
2017-04-08 22:25:19 ----D---- C:\Users\Péťa\AppData\Roaming\Warner Bros. Interactive Entertainment
2017-04-07 16:37:34 ----A---- C:\Windows\system32\aswBoot.exe
2017-04-04 19:42:59 ----D---- C:\ProgramData\FLEXnet
2017-04-04 19:20:51 ----D---- C:\Program Files\Common Files\Macrovision Shared
2017-04-04 19:19:22 ----D---- C:\Program Files\Common Files\Autodesk Shared
2017-04-03 21:01:27 ----D---- C:\ProgramData\Protexis
2017-04-03 21:01:25 ----D---- C:\Users\Péťa\AppData\Roaming\Corel
2017-04-03 20:07:26 ----D---- C:\ProgramData\Corel
2017-03-30 21:56:34 ----D---- C:\Program Files (x86)\Mr DJ
2017-03-30 21:56:01 ----HD---- C:\Windows\msdownld.tmp

======List of files/folders modified in the last 1 month======

2017-04-29 22:37:00 ----D---- C:\Program Files\trend micro
2017-04-29 22:34:34 ----D---- C:\Windows\Temp
2017-04-29 22:32:25 ----D---- C:\Windows\Prefetch
2017-04-29 22:27:59 ----D---- C:\Users\Péťa\AppData\Roaming\Skype
2017-04-29 22:00:01 ----D---- C:\Windows\system32\sru
2017-04-29 21:53:04 ----D---- C:\Windows\system32\config
2017-04-29 21:51:04 ----D---- C:\Windows\CbsTemp
2017-04-29 21:31:39 ----SHD---- C:\System Volume Information
2017-04-29 21:30:23 ----HD---- C:\ProgramData
2017-04-29 21:04:12 ----D---- C:\ProgramData\ASUS Smart Gesture
2017-04-29 21:00:22 ----D---- C:\AdwCleaner
2017-04-29 21:00:11 ----D---- C:\Program Files (x86)
2017-04-29 20:53:37 ----D---- C:\Windows\system32\Tasks
2017-04-29 16:51:42 ----SHD---- C:\Windows\Installer
2017-04-29 16:51:42 ----SHD---- C:\Config.Msi
2017-04-29 13:54:07 ----D---- C:\Windows\system32\drivers
2017-04-29 13:54:07 ----D---- C:\Windows\IObit
2017-04-29 13:50:55 ----D---- C:\Windows\SYSWOW64\drivers
2017-04-29 12:38:25 ----D---- C:\Windows\Microsoft.NET
2017-04-29 12:13:08 ----D---- C:\Windows\system32\DriverStore
2017-04-29 12:13:08 ----D---- C:\Windows\Inf
2017-04-29 12:12:50 ----RD---- C:\Program Files
2017-04-29 11:59:01 ----HD---- C:\Windows\system32\GroupPolicy
2017-04-29 11:58:58 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2017-04-28 22:56:46 ----D---- C:\ProgramData\ProductData
2017-04-28 18:02:53 ----D---- C:\Users\Péťa\AppData\Roaming\TS3Client
2017-04-27 16:36:41 ----D---- C:\Users\Péťa\AppData\Roaming\Dropbox
2017-04-26 21:35:25 ----D---- C:\Windows\system32\catroot2
2017-04-26 17:09:10 ----D---- C:\Windows\system32\Macromed
2017-04-26 17:09:06 ----D---- C:\Windows\SYSWOW64\Macromed
2017-04-24 18:27:57 ----D---- C:\Users\Péťa\AppData\Roaming\Origin
2017-04-24 18:27:36 ----D---- C:\ProgramData\Origin
2017-04-20 17:14:41 ----RD---- C:\Windows\System32
2017-04-20 17:13:05 ----D---- C:\Windows
2017-04-20 16:54:19 ----D---- C:\Program Files\AMD
2017-04-20 16:52:04 ----D---- C:\Windows\SysWOW64
2017-04-20 16:51:01 ----D---- C:\Windows\system32\catroot
2017-04-20 16:50:16 ----D---- C:\Program Files (x86)\VulkanRT
2017-04-20 16:45:45 ----D---- C:\AMD
2017-04-18 18:34:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-17 17:43:16 ----D---- C:\Users\Péťa\AppData\Roaming\SmartSteamEmu
2017-04-16 16:54:29 ----D---- C:\Users\Péťa\AppData\Roaming\Spotify
2017-04-16 10:10:59 ----D---- C:\Users\Péťa\AppData\Roaming\Autodesk
2017-04-16 10:10:59 ----D---- C:\ProgramData\Autodesk
2017-04-15 10:31:19 ----D---- C:\Windows\SYSWOW64\directx
2017-04-15 09:49:54 ----D---- C:\Windows\WinSxS
2017-04-14 19:52:56 ----D---- C:\Windows\AppReadiness
2017-04-13 10:35:46 ----RSD---- C:\Windows\assembly
2017-04-11 22:23:21 ----RSD---- C:\Windows\Fonts
2017-04-11 22:23:21 ----D---- C:\Program Files (x86)\Common Files
2017-04-11 22:23:14 ----SD---- C:\Windows\Downloaded Program Files
2017-04-11 22:14:14 ----D---- C:\Windows\Help
2017-04-11 21:50:26 ----D---- C:\ProgramData\Microsoft Help
2017-04-11 21:09:00 ----D---- C:\Windows\system32\MRT
2017-04-11 21:05:52 ----AC---- C:\Windows\system32\MRT.exe
2017-04-10 19:32:32 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2017-04-10 19:32:30 ----A---- C:\Windows\system32\atiuxp64.dll
2017-04-10 19:32:26 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2017-04-10 19:32:22 ----A---- C:\Windows\system32\atiumd64.dll
2017-04-10 19:32:20 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2017-04-10 19:32:18 ----A---- C:\Windows\system32\atiu9p64.dll
2017-04-10 19:32:02 ----A---- C:\Windows\SYSWOW64\GameManager32.dll
2017-04-10 19:31:56 ----A---- C:\Windows\SYSWOW64\detoured.dll
2017-04-10 19:31:44 ----A---- C:\Windows\system32\atig6txx.dll
2017-04-10 19:31:44 ----A---- C:\Windows\system32\atig6pxx.dll
2017-04-10 19:31:34 ----A---- C:\Windows\system32\atidxx64.dll
2017-04-10 19:31:30 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2017-04-10 19:31:26 ----A---- C:\Windows\system32\aticfx64.dll
2017-04-10 19:31:24 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2017-04-10 19:31:06 ----A---- C:\Windows\system32\atiadlxx.dll
2017-04-10 19:30:52 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2017-04-10 19:30:46 ----A---- C:\Windows\system32\atiumd6a.dll
2017-04-10 19:29:22 ----A---- C:\Windows\system32\atio6axx.dll
2017-04-09 20:40:51 ----D---- C:\ProgramData\IObit
2017-04-09 20:40:50 ----D---- C:\Users\Péťa\AppData\Roaming\IObit
2017-04-04 19:20:51 ----D---- C:\Program Files\Common Files
2017-04-03 20:11:18 ----D---- C:\Program Files\Common Files\microsoft shared
2017-04-03 20:10:55 ----D---- C:\ProgramData\Package Cache
2017-04-02 16:10:50 ----D---- C:\Program Files (x86)\Adobe
2017-04-02 15:18:42 ----D---- C:\Users\Péťa\AppData\Roaming\DAEMON Tools Lite
2017-04-01 10:29:43 ----HD---- C:\Program Files\WindowsApps
2017-04-01 03:12:21 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-03-31 18:30:40 ----D---- C:\Windows\Logs
2017-03-30 16:07:34 ----D---- C:\ProgramData\AVAST Software
2017-03-30 16:06:10 ----D---- C:\Windows\Minidump

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\System32\drivers\amd_sata.sys [2016-10-23 83656]
R0 amd_xata;amd_xata; C:\Windows\System32\drivers\amd_xata.sys [2016-10-23 23752]
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-04-07 189768]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-04-07 334088]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-04-07 48528]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-04-07 75704]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-04-07 339696]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-04-07 307736]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-04-07 32600]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-04-07 101152]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-04-07 1005048]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-04-28 556784]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-10-23 27552]
R2 AODDriver4.3.0;AODDriver4.3.0; \??\D:\Programy\AMD-OverDrive\amd64\AODDriver2.sys [2014-09-19 60104]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-04-28 128648]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-04-07 164064]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2017-04-10 36547976]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2017-04-10 520072]
R3 AsusVBus;AsusVBus; C:\Windows\System32\drivers\AsusVBus.sys [2016-11-03 39704]
R3 AtiHDAudioService;@oem38.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWB6.sys [2016-08-09 118848]
R3 dtlitescsibus;@oem23.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2015-08-22 30264]
R3 EvolveVirtualAdapter;@oem33.inf,%EvolveVirtualAdapter.Service.DispName%;Evolve Virtual Miniport Driver; C:\Windows\system32\DRIVERS\evolve.sys [2016-11-03 21656]
R3 Hamachi;LogMeIn Hamachi Virtual Miniport); C:\Windows\system32\DRIVERS\Hamdrv.sys [2017-02-27 45680]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-11-22 5310472]
R3 Neo_VPN;@oem37.inf,%Neo.Service.DispName%;VPN Client Device Driver - VPN; C:\Windows\system32\DRIVERS\neo_vpn.sys [2017-04-29 22784]
R3 RTL8168;@oem50.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2017-01-17 954368]
R3 RTSUER;@oem46.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\Windows\system32\Drivers\RtsUer.sys [2016-11-22 418784]
R3 SensorsSimulatorDriver;@oem16.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-10-29 226304]
R3 tap0901t;@oem35.inf,%DeviceDescription%;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2016-04-27 39464]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
S0 amdkmafd;@oem14.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S1 ndisrd;@oem3.inf,%ndisrfl_Desc%;Intel(R) Technology Access Filter Driver; C:\Windows\system32\DRIVERS\ndisrfl.sys [2015-04-30 41688]
S3 ALSysIO;ALSysIO; \??\C:\Users\PA010B~1\AppData\Local\Temp\ALSysIO64.sys []
S3 AODDriver2;AODDriver2; \??\D:\Programy\overdrive-amd\amd64\AODDriver2.sys []
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-04-07 38296]
S3 aswTap;@oem36.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2015-01-08 44640]
S3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
S3 dg_ssudbus;@oem29.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 NetTap630;@oem15.inf,%NetTap.Service.DispName%;Intel(R) Technology Access TAP Driver (NDIS 6.30); C:\Windows\system32\DRIVERS\nettap630.sys [2014-10-30 67800]
S3 ptun0901;@oem44.inf,%DeviceDescription%;TAP Adapter V9 for Private Tunnel; C:\Windows\system32\DRIVERS\ptun0901.sys [2016-06-15 27136]
S3 RSUSBVSTOR;@oem2.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2013-12-16 330968]
S3 ssudmdm;@oem31.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 ssudserd;@oem32.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudserd.sys [2014-01-22 206080]
S3 tap0901;@oem51.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2016-04-21 27136]
S3 taphss6;@oem52.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2016-12-29 42064]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2014-03-18 121088]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-02-02 82640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2017-04-10 543112]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-04-07 261712]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2017-03-02 3416584]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2017-02-24 9728]
R2 IObitUnSvr;IObit Uninstaller Service; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [2016-10-28 360736]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc); C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [2014-10-15 22744]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [2017-02-27 419248]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2016-09-14 805752]
R2 scinfo;scinfo; C:\Users\PA010B~1\AppData\Local\scinfo\scinfo.exe [2017-04-29 96768]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2014-02-21 134336]
R2 STCServ;Intel(R) Common Connectivity Framework; C:\Program Files\Intel\STCServ\STCServ.exe [2015-03-16 8095456]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-09-20 7500048]
R2 TZVPNCLIENT;Trust.Zone VPN Client; C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe [2017-04-29 4617200]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-04-07 7398336]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-04-26 1590048]
S2 AODService;AODService; D:\Programy\AMD-OverDrive\AODAssist.exe [2014-09-19 137584]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-30 107848]
S2 Origin Web Helper Service;Origin Web Helper Service; D:\Programy\origin\OriginWebHelperService.exe [2017-04-24 3115928]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-01-16 317400]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-12-25 1447944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1268568]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2016-12-25 395536]
S3 EvoSvc;Evolve Service; D:\Programy\evolveo\EvoSvc.exe [2017-03-31 1583488]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2017-04-04 1030600]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-20 142336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-30 107848]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; D:\Programy\origin\OriginClientService.exe [2017-04-24 2146704]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2016-12-15 838128]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-26 271448]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-08-04 344064]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 Intel(R) TechnologyAccessService;Intel(R) Technology Access Service; C:\Program Files\Intel Corporation\Intel(R) Technology Access\IntelTechnologyAccessService.exe [2015-03-17 93408]
S4 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-06-09 174368]
S4 OverwolfUpdater;Overwolf Updater Windows SCM; D:\Programy\Overwolf\OverwolfUpdater.exe [2016-11-07 1316080]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2012-04-24 254512]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#2 Příspěvek od Rudy »

Zdravím!

1. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:reg
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

2. Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#3 Příspěvek od Zemos »

V příloze jsou logy z MBAM, jedne z 29.4., kde to nalezlo PUP a dalo do karantény a z dneška, který nenalezl nic.
Přikládám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Péťa at 2017-04-30 12:40:24
Microsoft Windows 8.1
System drive C: has 269 GB (58%) free of 467 GB
Total RAM: 8114 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:40:28, on 30. 4. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe
D:\Programy\Steam\Steam.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe
D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe
D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files\trend micro\Péťa.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 159.203.24.28:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [Overwolf] "D:\Programy\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Péťa\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "D:\Programy\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\Run: [World of Tanks] "D:\Hry\World_of_Tanks\WargamingGameUpdater.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [WallpaperEngine] "D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe" -silent
O4 - HKCU\..\Run: [Steam] "D:\Programy\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [EvolveClient] D:\Programy\evolveo\EvolveClient.exe -autorun
O4 - Startup: Dropbox.lnk = ?
O4 - Startup: MEGAsync.lnk = ?
O4 - Startup: Trust.Zone VPN Client.lnk = C:\Program Files\Trust.Zone VPN Client\trustzone_x64.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{47B75A97-BFE7-49CC-84D3-78AAF20B4CB7}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E9227A9-8C09-4C6E-87B3-80E27532210B}: NameServer = 8.8.8.8
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AODService - Unknown owner - D:\Programy\AMD-OverDrive\AODAssist.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Evolve Service (EvoSvc) - Echobit LLC - D:\Programy\evolveo\EvoSvc.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IObit Uninstaller Service (IObitUnSvr) - IObit - C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - D:\Programy\origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Programy\origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: scinfo - Unknown owner - C:\Users\PA010B~1\AppData\Local\scinfo\scinfo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Intel(R) Common Connectivity Framework (STCServ) - Intel Corporation - C:\Program Files\Intel\STCServ\STCServ.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: Trust.Zone VPN Client (TZVPNCLIENT) - Trust.Zone VPN Project - C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11413 bytes

======Listing Processes======





wininit.exe

winlogon.exe


C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
dashost.exe {449a026e-9f55-4369-8916287e10810c63}
"C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe"
C:\Users\PA010B~1\AppData\Local\scinfo\scinfo.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe" /service
"C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe" -s
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-23d235ef-5c2a-4b7c-a83d-0840f481bfca -SystemEventPortName:HostProcess-5a235333-07c4-415d-b69b-612d530f3fde -IoCancelEventPortName:HostProcess-9aea92b9-6236-495d-9aef-aa1535a5791a -NonStateChangingEventPortName:HostProcess-3cb8e9ef-32b3-42f2-9027-47c132ced06a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bf0bf7f0-c09c-4bf9-8bbe-6445f7ec60eb -DeviceGroupId:WpdFsGroup
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-7bf19d2d-ab4f-4246-a940-6bdafb9f84c0 -SystemEventPortName:HostProcess-19a27067-30b4-439d-b384-bd62f266f02a -IoCancelEventPortName:HostProcess-107fde06-d672-4656-b82a-30ae067626a7 -NonStateChangingEventPortName:HostProcess-8a4aba97-c7a6-4a0e-9316-58c7ca4c53e1 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7694d8b9-4b4f-4a96-ad6b-940b3c3c8144 -DeviceGroupId:WudfDefaultDevicePool
taskhostex.exe
C:\Windows\Explorer.EXE
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe atlogon
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe" /uihelp
AvastUI.exe /nogui
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe" -silent
/tasktrayonly
"D:\Programy\Steam\Steam.exe" -silent
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
webwallpaper32.exe -parentprocess 5184 -messagehandler WPEWebIpcHandler0 -parenthwnd 3277644

"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe "-cachedir=C:\Users\Péťa\AppData\Local\Steam\htmlcache" "-steampid=5432" "-buildid=1493162727" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --disable-spell-checking --disable-out-of-process-pac --disable-smooth-scrolling --enable-direct-write "--log-file=D:\Programy\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files\Intel\STCServ\STCServ.exe"
"D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe" --type=gpu-process --no-sandbox --disable-d3d11 --lang=en-US --log-file="D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\debug.log" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,18,19,20,23,26,40,71 --gpu-vendor-id=0x1002 --gpu-device-id=0x6611 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=22.19.157.3 --gpu-driver-date=4-10-2017 --lang=en-US --log-file="D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\debug.log" --service-request-channel-token=8065C4DD44489A7E992A2131913D85A3 --mojo-platform-channel-handle=1264 /prefetch:2
"D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\webwallpaper32.exe" --type=renderer --force-device-scale-factor=1 --no-sandbox --primordial-pipe-token=8833589021770F239FC81B5EA1033BE9 --lang=en-US --lang=en-US --log-file="D:\Programy\Steam\steamapps\common\wallpaper_engine\bin\debug.log" --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=8833589021770F239FC81B5EA1033BE9 --renderer-client-id=3 --mojo-platform-channel-handle=1512 /prefetch:1
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Windows\system32\wuauclt.exe"

C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\LiveUpdate.exe"
"D:\Programy\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --disable-smooth-scrolling --enable-pinch --primordial-pipe-token=068CB4598BE33D8075DB48FCA6C71BED --lang=en-US --lang=cs-CZ --log-file="D:\Programy\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --disable-spell-checking --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --service-request-channel-token=068CB4598BE33D8075DB48FCA6C71BED --renderer-client-id=2 --mojo-platform-channel-handle=1696 /prefetch:1
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe" /Set

"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}
"C:\Users\Péťa\Desktop\Programy\čistící programy\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-621929646-1206955908-3885600500-1001Core.job - C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-621929646-1206955908-3885600500-1001UA.job - C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Uninstaller_SkipUac_Péťa.job - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-27 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-07 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-27 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-27 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-07 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-27 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-01-07 13663448]
"IntelConnectCenter"=C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [2015-03-16 90112]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-04-07 213824]
"Trust.Zone VPN Client UI Helper"=C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe [2017-04-29 4617200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Dropbox Update"=C:\Users\Péťa\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05 143144]
"Overwolf"=D:\Programy\Overwolf\OverwolfLauncher.exe [2016-11-07 247344]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-09-28 8944344]
"Spotify Web Helper"=C:\Users\Péťa\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2017-04-16 1446000]
"DAEMON Tools Lite Automount"=D:\Programy\DAEMON Tools Lite\DTAgent.exe [2015-06-18 4468056]
"SpybotPostWindows10UpgradeReInstall"=C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [2015-07-28 1011200]
"World of Tanks"=D:\Hry\World_of_Tanks\WargamingGameUpdater.exe [2017-02-28 3135752]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]
"WallpaperEngine"=D:\Programy\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe [2017-04-10 731136]
"Steam"=D:\Programy\Steam\steam.exe [2017-04-26 3019552]
"EvolveClient"=D:\Programy\evolveo\EvolveClient.exe [2017-03-31 3334528]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2017-03-02 5883912]

C:\Users\Péťa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Péťa\AppData\Roaming\Dropbox\bin\Dropbox.exe
MEGAsync.lnk - C:\Users\Péťa\AppData\Local\MEGAsync\MEGAsync.exe
Trust.Zone VPN Client.lnk - C:\Program Files\Trust.Zone VPN Client\trustzone_x64.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2017-04-30 12:10:09 ----D---- C:\ProgramData\SWCUTemp
2017-04-30 11:47:36 ----D---- C:\_OTM
2017-04-29 22:32:12 ----D---- C:\rsit
2017-04-29 12:13:03 ----A---- C:\Windows\system32\drivers\neo_vpn.sys
2017-04-29 12:12:50 ----D---- C:\Program Files\Trust.Zone VPN Client
2017-04-22 20:56:03 ----D---- C:\Program Files (x86)\1C Company
2017-04-17 17:35:42 ----D---- C:\Users\Péťa\AppData\Roaming\SpinTires
2017-04-15 10:27:40 ----D---- C:\Program Files (x86)\Prime95
2017-04-15 09:35:12 ----D---- C:\Program Files\CPUID
2017-04-14 17:38:27 ----D---- C:\Program Files (x86)\SpeedFan
2017-04-10 19:32:02 ----A---- C:\Windows\system32\GameManager64.dll
2017-04-10 19:32:00 ----A---- C:\Windows\system32\dgtrayicon.exe
2017-04-10 19:31:58 ----A---- C:\Windows\system32\detoured.dll
2017-04-10 19:31:52 ----A---- C:\Windows\system32\atitmm64.dll
2017-04-10 19:31:50 ----A---- C:\Windows\system32\atimuixx.dll
2017-04-10 19:31:48 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2017-04-10 19:31:48 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2017-04-10 19:31:48 ----A---- C:\Windows\system32\atiglpxx.dll
2017-04-10 19:31:46 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2017-04-10 19:31:42 ----A---- C:\Windows\system32\atiesrxx.exe
2017-04-10 19:31:38 ----A---- C:\Windows\system32\atieclxx.exe
2017-04-10 19:31:36 ----A---- C:\Windows\system32\atieah64.exe
2017-04-10 19:31:34 ----A---- C:\Windows\SYSWOW64\atieah32.exe
2017-04-10 19:31:32 ----A---- C:\Windows\system32\atidemgy.dll
2017-04-10 19:31:28 ----A---- C:\Windows\system32\aticalrt64.dll
2017-04-10 19:31:26 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2017-04-10 19:31:22 ----A---- C:\Windows\system32\aticaldd64.dll
2017-04-10 19:31:16 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2017-04-10 19:31:14 ----A---- C:\Windows\SYSWOW64\RapidFireServer.dll
2017-04-10 19:31:14 ----A---- C:\Windows\system32\RapidFireServer64.dll
2017-04-10 19:31:14 ----A---- C:\Windows\system32\aticalcl64.dll
2017-04-10 19:31:12 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2017-04-10 19:31:12 ----A---- C:\Windows\system32\Rapidfire64.dll
2017-04-10 19:31:10 ----A---- C:\Windows\SYSWOW64\Rapidfire.dll
2017-04-10 19:31:10 ----A---- C:\Windows\system32\atiapfxx.exe
2017-04-10 19:31:08 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
2017-04-10 19:31:08 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2017-04-10 19:31:08 ----A---- C:\Windows\SYSWOW64\atiadlxx.dll
2017-04-10 19:31:08 ----A---- C:\Windows\system32\mantleaxl64.dll
2017-04-10 19:31:06 ----A---- C:\Windows\system32\mantle64.dll
2017-04-10 19:31:06 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2017-04-10 19:31:04 ----A---- C:\Windows\SYSWOW64\mantle32.dll
2017-04-10 19:31:02 ----A---- C:\Windows\system32\ATIODE.exe
2017-04-10 19:31:02 ----A---- C:\Windows\system32\ATIODCLI.exe
2017-04-10 19:30:48 ----A---- C:\Windows\system32\OpenCL.dll
2017-04-10 19:30:48 ----A---- C:\Windows\system32\clinfo.exe
2017-04-10 19:30:48 ----A---- C:\Windows\system32\amdgfxinfo64.dll
2017-04-10 19:30:46 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2017-04-10 19:30:46 ----A---- C:\Windows\SYSWOW64\amdgfxinfo32.dll
2017-04-10 19:30:44 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2017-04-10 19:30:44 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
2017-04-10 19:30:44 ----A---- C:\Windows\system32\atimpc64.dll
2017-04-10 19:30:42 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2017-04-10 19:30:42 ----A---- C:\Windows\system32\amdpcom64.dll
2017-04-10 19:30:40 ----A---- C:\Windows\system32\amdmiracast.dll
2017-04-10 19:30:40 ----A---- C:\Windows\system32\amdhcp64.dll
2017-04-10 19:30:38 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
2017-04-10 19:30:38 ----A---- C:\Windows\system32\amdmantle64.dll
2017-04-10 19:30:34 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
2017-04-10 19:30:34 ----A---- C:\Windows\SYSWOW64\amdave32.dll
2017-04-10 19:30:34 ----A---- C:\Windows\system32\amdocl64.dll
2017-04-10 19:30:34 ----A---- C:\Windows\system32\amdave64.dll
2017-04-10 19:30:30 ----A---- C:\Windows\SYSWOW64\amdlvr32.dll
2017-04-10 19:30:30 ----A---- C:\Windows\system32\coinst_17.10.dll
2017-04-10 19:30:30 ----A---- C:\Windows\system32\amdlvr64.dll
2017-04-10 19:30:28 ----A---- C:\Windows\system32\amdocl12cl64.dll
2017-04-10 19:30:24 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2017-04-10 19:30:20 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2017-04-10 19:30:20 ----A---- C:\Windows\system32\atisamu64.dll
2017-04-10 19:30:18 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
2017-04-10 19:30:08 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2017-04-10 19:30:02 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2017-04-10 19:30:02 ----A---- C:\Windows\system32\amfrt64.dll
2017-04-10 19:29:56 ----A---- C:\Windows\system32\amdvlk64.dll
2017-04-10 19:29:52 ----A---- C:\Windows\SYSWOW64\amdvlk32.dll
2017-04-10 19:29:48 ----A---- C:\Windows\system32\amduve64.dll
2017-04-10 19:29:46 ----A---- C:\Windows\SYSWOW64\amduve32.dll
2017-04-10 19:29:42 ----A---- C:\Windows\system32\amdmmcl6.dll
2017-04-10 19:29:40 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
2017-04-10 19:29:40 ----A---- C:\Windows\system32\amdmcl64.dll
2017-04-10 19:29:38 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2017-04-10 19:29:36 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2017-04-10 19:29:16 ----A---- C:\Windows\system32\amdhdl64.dll
2017-04-10 19:29:14 ----A---- C:\Windows\SYSWOW64\amdhdl32.dll
2017-04-09 17:01:39 ----D---- C:\ProgramData\RealVNC-Service
2017-04-09 17:01:27 ----D---- C:\Program Files\RealVNC
2017-04-08 22:25:19 ----D---- C:\Users\Péťa\AppData\Roaming\Warner Bros. Interactive Entertainment
2017-04-07 16:37:34 ----A---- C:\Windows\system32\aswBoot.exe
2017-04-04 19:42:59 ----D---- C:\ProgramData\FLEXnet
2017-04-04 19:20:51 ----D---- C:\Program Files\Common Files\Macrovision Shared
2017-04-04 19:19:22 ----D---- C:\Program Files\Common Files\Autodesk Shared
2017-04-03 21:01:27 ----D---- C:\ProgramData\Protexis
2017-04-03 21:01:25 ----D---- C:\Users\Péťa\AppData\Roaming\Corel
2017-04-03 20:07:26 ----D---- C:\ProgramData\Corel

======List of files/folders modified in the last 1 month======

2017-04-30 12:40:26 ----D---- C:\Program Files\trend micro
2017-04-30 12:36:41 ----D---- C:\Windows\Temp
2017-04-30 12:28:25 ----D---- C:\Windows\system32\drivers
2017-04-30 12:28:09 ----D---- C:\Users\Péťa\AppData\Roaming\Skype
2017-04-30 12:10:09 ----HD---- C:\ProgramData
2017-04-30 12:09:34 ----D---- C:\Program Files (x86)
2017-04-30 12:07:56 ----A---- C:\Windows\wininit.ini
2017-04-30 12:04:25 ----RD---- C:\Windows\System32
2017-04-30 12:04:24 ----SD---- C:\ProgramData\Microsoft
2017-04-30 12:04:23 ----D---- C:\Windows\Prefetch
2017-04-30 12:00:02 ----D---- C:\Windows\system32\sru
2017-04-30 11:48:33 ----D---- C:\Windows\SysWOW64
2017-04-30 11:48:31 ----D---- C:\Windows
2017-04-30 08:01:21 ----D---- C:\AdwCleaner
2017-04-30 06:54:41 ----D---- C:\ProgramData\ASUS Smart Gesture
2017-04-29 21:53:04 ----D---- C:\Windows\system32\config
2017-04-29 21:51:04 ----D---- C:\Windows\CbsTemp
2017-04-29 21:31:39 ----SHD---- C:\System Volume Information
2017-04-29 20:53:37 ----D---- C:\Windows\system32\Tasks
2017-04-29 16:51:42 ----SHD---- C:\Windows\Installer
2017-04-29 16:51:42 ----SHD---- C:\Config.Msi
2017-04-29 13:54:07 ----D---- C:\Windows\IObit
2017-04-29 13:50:55 ----D---- C:\Windows\SYSWOW64\drivers
2017-04-29 12:38:25 ----D---- C:\Windows\Microsoft.NET
2017-04-29 12:13:08 ----D---- C:\Windows\system32\DriverStore
2017-04-29 12:13:08 ----D---- C:\Windows\Inf
2017-04-29 12:12:50 ----RD---- C:\Program Files
2017-04-29 11:59:01 ----HD---- C:\Windows\system32\GroupPolicy
2017-04-29 11:58:58 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2017-04-28 22:56:46 ----D---- C:\ProgramData\ProductData
2017-04-28 18:02:53 ----D---- C:\Users\Péťa\AppData\Roaming\TS3Client
2017-04-27 16:36:41 ----D---- C:\Users\Péťa\AppData\Roaming\Dropbox
2017-04-26 21:35:25 ----D---- C:\Windows\system32\catroot2
2017-04-26 17:09:10 ----D---- C:\Windows\system32\Macromed
2017-04-26 17:09:06 ----D---- C:\Windows\SYSWOW64\Macromed
2017-04-24 18:27:57 ----D---- C:\Users\Péťa\AppData\Roaming\Origin
2017-04-24 18:27:36 ----D---- C:\ProgramData\Origin
2017-04-20 16:54:19 ----D---- C:\Program Files\AMD
2017-04-20 16:51:01 ----D---- C:\Windows\system32\catroot
2017-04-20 16:50:16 ----D---- C:\Program Files (x86)\VulkanRT
2017-04-20 16:45:45 ----D---- C:\AMD
2017-04-18 18:34:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-17 17:43:16 ----D---- C:\Users\Péťa\AppData\Roaming\SmartSteamEmu
2017-04-16 16:54:29 ----D---- C:\Users\Péťa\AppData\Roaming\Spotify
2017-04-16 10:10:59 ----D---- C:\Users\Péťa\AppData\Roaming\Autodesk
2017-04-16 10:10:59 ----D---- C:\ProgramData\Autodesk
2017-04-15 10:31:19 ----D---- C:\Windows\SYSWOW64\directx
2017-04-15 09:49:54 ----D---- C:\Windows\WinSxS
2017-04-14 19:52:56 ----D---- C:\Windows\AppReadiness
2017-04-13 10:35:46 ----RSD---- C:\Windows\assembly
2017-04-11 22:23:21 ----RSD---- C:\Windows\Fonts
2017-04-11 22:23:21 ----D---- C:\Program Files (x86)\Common Files
2017-04-11 22:23:14 ----SD---- C:\Windows\Downloaded Program Files
2017-04-11 22:14:14 ----D---- C:\Windows\Help
2017-04-11 21:50:26 ----D---- C:\ProgramData\Microsoft Help
2017-04-11 21:09:00 ----D---- C:\Windows\system32\MRT
2017-04-11 21:05:52 ----AC---- C:\Windows\system32\MRT.exe
2017-04-10 19:32:32 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2017-04-10 19:32:30 ----A---- C:\Windows\system32\atiuxp64.dll
2017-04-10 19:32:26 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2017-04-10 19:32:22 ----A---- C:\Windows\system32\atiumd64.dll
2017-04-10 19:32:20 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2017-04-10 19:32:18 ----A---- C:\Windows\system32\atiu9p64.dll
2017-04-10 19:32:02 ----A---- C:\Windows\SYSWOW64\GameManager32.dll
2017-04-10 19:31:56 ----A---- C:\Windows\SYSWOW64\detoured.dll
2017-04-10 19:31:44 ----A---- C:\Windows\system32\atig6txx.dll
2017-04-10 19:31:44 ----A---- C:\Windows\system32\atig6pxx.dll
2017-04-10 19:31:34 ----A---- C:\Windows\system32\atidxx64.dll
2017-04-10 19:31:30 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2017-04-10 19:31:26 ----A---- C:\Windows\system32\aticfx64.dll
2017-04-10 19:31:24 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2017-04-10 19:31:06 ----A---- C:\Windows\system32\atiadlxx.dll
2017-04-10 19:30:52 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2017-04-10 19:30:46 ----A---- C:\Windows\system32\atiumd6a.dll
2017-04-10 19:29:22 ----A---- C:\Windows\system32\atio6axx.dll
2017-04-09 20:40:51 ----D---- C:\ProgramData\IObit
2017-04-09 20:40:50 ----D---- C:\Users\Péťa\AppData\Roaming\IObit
2017-04-04 19:20:51 ----D---- C:\Program Files\Common Files
2017-04-03 20:11:18 ----D---- C:\Program Files\Common Files\microsoft shared
2017-04-03 20:10:55 ----D---- C:\ProgramData\Package Cache
2017-04-02 16:10:50 ----D---- C:\Program Files (x86)\Adobe
2017-04-02 15:18:42 ----D---- C:\Users\Péťa\AppData\Roaming\DAEMON Tools Lite
2017-04-01 10:29:43 ----HD---- C:\Program Files\WindowsApps
2017-04-01 03:12:21 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-03-31 18:30:40 ----D---- C:\Windows\Logs

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\System32\drivers\amd_sata.sys [2016-10-23 83656]
R0 amd_xata;amd_xata; C:\Windows\System32\drivers\amd_xata.sys [2016-10-23 23752]
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-04-07 189768]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-04-07 334088]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-04-07 48528]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-04-07 75704]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-04-07 339696]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-04-07 307736]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-04-07 32600]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-04-07 101152]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-04-07 1005048]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-04-28 556784]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-10-23 27552]
R2 AODDriver4.3.0;AODDriver4.3.0; \??\D:\Programy\AMD-OverDrive\amd64\AODDriver2.sys [2014-09-19 60104]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-04-28 128648]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-04-07 164064]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2017-04-10 36547976]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2017-04-10 520072]
R3 AsusVBus;AsusVBus; C:\Windows\System32\drivers\AsusVBus.sys [2016-11-03 39704]
R3 AtiHDAudioService;@oem38.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWB6.sys [2016-08-09 118848]
R3 dtlitescsibus;@oem23.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2015-08-22 30264]
R3 EvolveVirtualAdapter;@oem33.inf,%EvolveVirtualAdapter.Service.DispName%;Evolve Virtual Miniport Driver; C:\Windows\system32\DRIVERS\evolve.sys [2016-11-03 21656]
R3 Hamachi;LogMeIn Hamachi Virtual Miniport); C:\Windows\system32\DRIVERS\Hamdrv.sys [2017-02-27 45680]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-11-22 5310472]
R3 Neo_VPN;@oem37.inf,%Neo.Service.DispName%;VPN Client Device Driver - VPN; C:\Windows\system32\DRIVERS\neo_vpn.sys [2017-04-29 22784]
R3 RTL8168;@oem50.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2017-01-17 954368]
R3 RTSUER;@oem46.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\Windows\system32\Drivers\RtsUer.sys [2016-11-22 418784]
R3 SensorsSimulatorDriver;@oem16.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-10-29 226304]
R3 tap0901t;@oem35.inf,%DeviceDescription%;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2016-04-27 39464]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
S0 amdkmafd;@oem14.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S1 ndisrd;@oem3.inf,%ndisrfl_Desc%;Intel(R) Technology Access Filter Driver; C:\Windows\system32\DRIVERS\ndisrfl.sys [2015-04-30 41688]
S3 ALSysIO;ALSysIO; \??\C:\Users\PA010B~1\AppData\Local\Temp\ALSysIO64.sys []
S3 AODDriver2;AODDriver2; \??\D:\Programy\overdrive-amd\amd64\AODDriver2.sys []
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-04-07 38296]
S3 aswTap;@oem36.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2015-01-08 44640]
S3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
S3 dg_ssudbus;@oem29.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 NetTap630;@oem15.inf,%NetTap.Service.DispName%;Intel(R) Technology Access TAP Driver (NDIS 6.30); C:\Windows\system32\DRIVERS\nettap630.sys [2014-10-30 67800]
S3 ptun0901;@oem44.inf,%DeviceDescription%;TAP Adapter V9 for Private Tunnel; C:\Windows\system32\DRIVERS\ptun0901.sys [2016-06-15 27136]
S3 RSUSBVSTOR;@oem2.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2013-12-16 330968]
S3 ssudmdm;@oem31.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 ssudserd;@oem32.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudserd.sys [2014-01-22 206080]
S3 tap0901;@oem51.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2016-04-21 27136]
S3 taphss6;@oem52.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2016-12-29 42064]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2014-03-18 121088]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-02-02 82640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2017-04-10 543112]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-04-07 261712]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2017-03-02 3416584]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2017-02-24 9728]
R2 IObitUnSvr;IObit Uninstaller Service; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [2016-10-28 360736]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc); C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [2014-10-15 22744]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [2017-02-27 419248]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2016-09-14 805752]
R2 scinfo;scinfo; C:\Users\PA010B~1\AppData\Local\scinfo\scinfo.exe [2017-04-29 96768]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2014-02-21 134336]
R2 STCServ;Intel(R) Common Connectivity Framework; C:\Program Files\Intel\STCServ\STCServ.exe [2015-03-16 8095456]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-09-20 7500048]
R2 TZVPNCLIENT;Trust.Zone VPN Client; C:\Program Files\Trust.Zone VPN Client\tzclient_x64.exe [2017-04-29 4617200]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-04-07 7398336]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-04-26 1590048]
S2 AODService;AODService; D:\Programy\AMD-OverDrive\AODAssist.exe [2014-09-19 137584]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-30 107848]
S2 Origin Web Helper Service;Origin Web Helper Service; D:\Programy\origin\OriginWebHelperService.exe [2017-04-24 3115928]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-01-16 317400]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-12-25 1447944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; D:\Programy\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1268568]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2016-12-25 395536]
S3 EvoSvc;Evolve Service; D:\Programy\evolveo\EvoSvc.exe [2017-03-31 1583488]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2017-04-04 1030600]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-20 142336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-30 107848]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; D:\Programy\origin\OriginClientService.exe [2017-04-24 2146704]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2016-12-15 838128]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-26 271448]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-08-04 344064]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 Intel(R) TechnologyAccessService;Intel(R) Technology Access Service; C:\Program Files\Intel Corporation\Intel(R) Technology Access\IntelTechnologyAccessService.exe [2015-03-17 93408]
S4 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-06-09 174368]
S4 OverwolfUpdater;Overwolf Updater Windows SCM; D:\Programy\Overwolf\OverwolfUpdater.exe [2016-11-07 1316080]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2012-04-24 254512]

-----------------EOF-----------------
Přílohy
mbam-log.rar
(2.53 KiB) Staženo 105 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#4 Příspěvek od Rudy »

Říkal jsem, předem nemazat. MBAM je vynikající skener, mívá ale občas falešné detekce. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#5 Příspěvek od Zemos »

Furt vybíhá avast s tou chybou, z MBAM jsem nic nemazal, vše to zůstalo v karanténě.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#6 Příspěvek od Rudy »

V karanténě je to, jako by to bylo smazané. Zkuste vyčistit prohlížeče těmito skeny:

1. Stahnete Zoek.exe http://download.bleepingcomputer.com/smeenk/zoek.exe a ulozte jej na plochu

Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
Do okna vlozte skript nize




autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;





Nasledne kliknete na Run Script
PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem.

a

2. Junkware removal tool: http://thisisudax.org/downloads/JRT.exe
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#7 Příspěvek od Zemos »

Problém stále přetrvává. Náhodně si to otevře okno s reklamou, jindy to blokne avast.
Zde je Zoek Log:

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by P‚śa on ne 30. 04. 2017 at 17:31:44,54.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\PA010B~1\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

30. 4. 2017 17:36:04 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~2\R.G. Mechanics deleted successfully
C:\PROGRA~2\Rockstar Games deleted successfully
C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully
C:\Program Files\RealVNC deleted successfully
C:\Users\PA010B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\GIF Viewer deleted successfully
C:\Users\PA010B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Hammer & Chisel, Inc deleted successfully
C:\Users\PA010B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Prime95 deleted successfully
C:\Users\PA010B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\San Andreas Multiplayer deleted successfully
C:\Users\PA010B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\TrainCraft.cz v1.0 deleted successfully
C:\PROGRA~3\CorelDRAW Graphics Suite X7 x64 deleted successfully
C:\PROGRA~3\RealVNC-Service deleted successfully
C:\PROGRA~3\{74E9F814-C737-42CC-B721-DBBC4059367A} deleted successfully
C:\PROGRA~3\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} deleted successfully
C:\Users\Guest\AppData\Local\VirtualStore deleted successfully
C:\Users\PA010B~1\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\PA010B~1\AppData\Local\EmieSiteList deleted successfully
C:\Users\PA010B~1\AppData\Local\EmieUserList deleted successfully
C:\Users\PA010B~1\AppData\Local\MediaShow deleted successfully
C:\Users\PA010B~1\AppData\Local\Opera Software deleted successfully
C:\Users\PA010B~1\AppData\Local\RealVNC deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2ABC2EBE-0228-4CC6-8C9B-FDA659964B0D} deleted successfully
HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{329C1586-57AD-4EB9-A2B6-277900A0727A} deleted successfully
HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5673E4A3-F3D0-4812-8471-77375340B761} deleted successfully
HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{755569DD-BA38-4C08-AB52-6E1D8F217EED} deleted successfully
HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7AEFE841-DCA1-4A95-80CB-BE935D020602} deleted successfully
HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AEFE841-DCA1-4A95-80CB-BE935D020602} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AEFE841-DCA1-4A95-80CB-BE935D020602} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-621929646-1206955908-3885600500-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{8E8F97CD-60B5-456F-A201-73065652D099} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\asdpfanz.default\prefs.js:

Added to C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\asdpfanz.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\PA010B~1\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\prefs.js:
user_pref("browser.startup.homepage", "http://mail.ru/cnt/10445?gp=811040");
user_pref("browser.search.defaultenginename", "Поиск@Mail.Ru");
user_pref("browser.search.selectedEngine", "Поиск@Mail.Ru");
user_pref("keyword.URL", "http://go.mail.ru/distib/ep/?product_id ... &gp=811041");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", false);

Added to C:\Users\PA010B~1\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\AGEIA Technologies not found
C:\PROGRA~2\Origin Games not found
C:\PROGRA~2\R.G. Mechanics not found
C:\PROGRA~2\Rockstar Games not found
C:\PROGRA~3\CorelDRAW Graphics Suite X7 x64 not found
C:\PROGRA~3\{74E9F814-C737-42CC-B721-DBBC4059367A} not found
C:\PROGRA~3\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98} not found
C:\PROGRA~2\BandiMPEG1 deleted
C:\PROGRA~2\TalkHelper Call Recorder for Skype deleted
C:\found.000 deleted
C:\found.001 deleted
C:\PROGRA~3\ProductData deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\PA010B~1\AppData\Local\Unity deleted
C:\Users\PA010B~1\AppData\Local\CrashRpt deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\CrashRpt deleted
C:\Windows\wininit.ini deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\PA010B~1\AppData\Local\MSGBOX.EXE deleted
C:\Users\PA010B~1\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\extensions\homepage@mail.ru deleted
C:\Users\PA010B~1\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\extensions\search@mail.ru deleted
"C:\Users\PA010B~1\AppData\Local\LumaEmu" deleted
"C:\Users\PA010B~1\AppData\Local???????????????????" not deleted
"C:\ProgramData\mntemp" deleted
"C:\Users\PA010B~1\AppData\LocalLow\Unity" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\asdpfanz.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\PA010B~1\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [08. 12. 2016 17:19]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [08. 12. 2016 17:19]

==== Firefox Extensions ======================

ProfilePath: C:\Users\PA010B~1\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default
- @Mail.Ru - %ProfilePath%\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}

==== Firefox Plugins ======================


==== Chromium Look ======================

Google Chrome Version: 46.0.2490.86

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
efaidnbmnnnibpcajpcglclefindmkaj - No path found[]
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[]

Avast SafePrice - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
TwitchAlerts Stream Labels - PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg
Chrome Media Router - PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Chromium Fix ======================

C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_shoppingcart.aliexpress.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_shoppingcart.aliexpress.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mystartab.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mystartab.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mystartabsearch.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mystartabsearch.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_battlefield-1942.en.softonic.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_battlefield-1942.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_hide-and-shriek.en.softonic.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_hide-and-shriek.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mcskinsearch.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mcskinsearch.com_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vovographics.webnode.cz_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vovographics.webnode.cz_0.localstorage-journal deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.coreldraw.com_0.localstorage deleted successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.coreldraw.com_0.localstorage-journal deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{FFEBBF0A-C22C-4172-89FF-45215A135AC7}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IESR02"

==== Reset Google Chrome ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\PA010B~1\AppData\Local\Chromium\User Data\Default\Preferences was reset successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\PA010B~1\AppData\Local\vpnsecure-gui\User Data\Default\Preferences was reset successfully
C:\Users\PA010B~1\AppData\Local\vpnsecure-gui\User Data\Default\Secure Preferences was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\PA010B~1\AppData\Local\Chromium\User Data\Default\Web Data was reset successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Web Data will be reset at reboot
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\PA010B~1\AppData\Local\vpnsecure-gui\User Data\Default\Web Data was reset successfully
C:\Users\PA010B~1\AppData\Local\vpnsecure-gui\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\PA010B~1\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\PA010B~1\AppData\Local\Microsoft\Windows\INetCache\IE\4HQ27ZOB will be deleted at reboot
C:\Users\PA010B~1\AppData\Local\Microsoft\Windows\INetCache\IE\6XKTR820 will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\PA010B~1\AppData\Local\Chromium\User Data\Default\Cache emptied successfully
C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\PA010B~1\AppData\Local\vpnsecure-gui\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=396 folders=248 295465617 bytes)

==== Empty Temp Folders ======================

C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\PA010B~1\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\PA010B~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\PA010B~1\AppData\Local???????????????????" not deleted
"C:\Users\PA010B~1\AppData\Local\Google\Chrome\User Data\Default\Web Data" not found
"C:\Users\PA010B~1\AppData\Local\Microsoft\Windows\INetCache\IE\4HQ27ZOB" not found
"C:\Users\PA010B~1\AppData\Local\Microsoft\Windows\INetCache\IE\6XKTR820" not found

==== EOF on ne 30. 04. 2017 at 22:22:34,82 ======================


A zde jrt:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 8.1 x64
Ran by P‚śa (Administrator) on ne 30. 04. 2017 at 22:26:18,34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 7

Successfully deleted: C:\ProgramData\productdata (Folder)
Successfully deleted: C:\Users\P‚śa\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7} (Folder)
Successfully deleted: C:\Users\P‚śa\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\searchplugins\mailru.xml (File)
Successfully deleted: C:\Users\P‚śa\AppData\Roaming\productdata (Folder)
Successfully deleted: C:\Windows\system32\Tasks\Driver Booster SkipUAC (P‚śa) (Task)
Successfully deleted: C:\Windows\system32\Tasks\Uninstaller_SkipUac_P‚śa (Task)
Successfully deleted: C:\Windows\Tasks\Uninstaller_SkipUac_P‚śa.job (Task)

Deleted the following from C:\Users\P‚śa\AppData\Roaming\Mozilla\Firefox\Profiles\t4rih17k.default\prefs.js
user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7BF7B8AC81-3936-44CF-8505-9DB0265E0178%7D&install_id=%
user_pref(extensions.{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7BF7B8AC81-3936
user_pref(extensions.homepage@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B0DB16FB2-0F56-4445-AC1E-D5277D63501F%7D&install_id=%7BAB38851D-F7DD-4776-9
user_pref(extensions.homepage@mail.ru.install_id, {AB38851D-F7DD-4776-9065-14976D432155});
user_pref(extensions.homepage@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B0DB16FB2-0F56-4445-AC1E-D5277D63501
user_pref(extensions.homepage@mail.ru.partner_product_online_url, hxxp://ec2-54-171-243-238.eu-west-1.compute.amazonaws.com/affect?guid={guid}&sid=16045&homesearch=1&label=
user_pref(extensions.homepage@mail.ru.product_id, {0DB16FB2-0F56-4445-AC1E-D5277D63501F});
user_pref(extensions.homepage@mail.ru.product_type, ff_xtnhp);
user_pref(extensions.homepage@mail.ru.rfr, 811040);
user_pref(extensions.search@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7B8D02CD6F-5414-491B-9AA0-0B77937F9FDD%7D&install_id=%7BAB38851D-F7DD-4776-906
user_pref(extensions.search@mail.ru.install_id, {AB38851D-F7DD-4776-9065-14976D432155});
user_pref(extensions.search@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7B8D02CD6F-5414-491B-9AA0-0B77937F9FDD%
user_pref(extensions.search@mail.ru.partner_product_online_url, hxxp://ec2-54-171-243-238.eu-west-1.compute.amazonaws.com/affect?guid={guid}&sid=16045&homesearch=1&label=81
user_pref(extensions.search@mail.ru.product_id, {8D02CD6F-5414-491B-9AA0-0B77937F9FDD});
user_pref(extensions.search@mail.ru.product_type, ff_xtndse);
user_pref(extensions.search@mail.ru.rfr, 811041);



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 30. 04. 2017 at 22:30:49,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#8 Příspěvek od Rudy »

Smazáno, PC je čistý. Zde: https://forum.avast.com/index.php?topic=151096.0 je o tom něco přímo od Avastu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#9 Příspěvek od Zemos »

Ale furt se mi otevře sám od sebe googl s nějakou reklamou, ať už na podivuhodné soutěže s penny, tak na další blbosti.
Viz.

Kód: Vybrat vše

http://winner.zmobio.com/cz/6/?device_name=Desktop&device_brand=Desktop&device_model=Desktop&os_name=Windows&isp=METRONET%20s.r.o.&city=Milovice&country=Czech%20Republic&ip=95.85.240.82&uclick=b42ta71m#
Toto mi to v klidu otevře, že jsem vyhrál.
V čem by mohl být problém? Všechny testy jsem už dělal, pak podle Vás a toto stále nezmizelo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#10 Příspěvek od Rudy »

Zkusíme ještě přeinstalovat Chrome. Chrome zazálohujte pomocí ChromeBackup: http://www.stahuj.centrum.cz/internet_a ... me-backup/ . Pak Chrome kompletně odinstalujte vč. jeho profilu (podadresáře Chrome v c:\users\Péťa\appdata\local, c:\users\Péťa\appdata\roaming, c:\users\Péťa\data aplikací, c:\users\Péťa\local settings a v c:\program data musí být smazány). Pak znovu nainstalujte Chrome a zpět ze zálohy nakopírujte pouze záložky a hesla.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#11 Příspěvek od Zemos »

Ať dělám co dělám, nedaří se mi vytvořit záloha. Nejdříve psalo že googl není nainstalován a po stáhnutí nejnovější verze se záloha nevytvoří.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#12 Příspěvek od Rudy »

Tak to je divné. Zkuste Chrome Cleanup: https://support.google.com/chrome/answer/2765944?hl=cs .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#13 Příspěvek od Zemos »

Avast vypadá že dal klid. Intenzita vybíhání podivuhodných reklam se zmenšila. Asi nevidím jiný způsob, než celý Google odinstalovat.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119357
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: URL:Mal - Virus

#14 Příspěvek od Rudy »

Hlavně se musí smazat ty podadresáře. V těch je to uloženo. Bez zálohy ale přijdete o hesla a záložky.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zemos
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 15 bře 2015 13:17

Re: URL:Mal - Virus

#15 Příspěvek od Zemos »

Zdravím, tak jsem odinstaloval Google a už to nic nehlásí.
Děkuji za pomoc.
S pozdravem,
Zemos :fez:

Odpovědět