Nákaza - wuaudit.exe a rundll32.exe
Napsal: 28 srp 2013 18:43
Dobrý den,
Prosím,mám takový problém.Pročítal jsem vaše řešení s minulých témat, ale moc se v tom nevyznám, proto vás žádám o radu.
Do PC mi nalítl nějaký nabořitel, a Avast mi to co 5 minut hlásí, ale neodstranil to ani online Eset, který prý dokáže nemožné.
Můžete ni s tím nějak pomoci:
Avast hlásí toto.
Objekt: C:\Users\xxx\AppData\Local\Temp\iswizard\wuaudit.exe
Proces: C:\Windows\System32\rundll32.exe
Přikládám Log dle návodu, který jsem zde našel. :
Logfile of random's system information tool 1.09 (written by random/random)
Run by xxx at 2013-08-28 19:14:18
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 8 GB (15%) free of 52 GB
Total RAM: 3070 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:14:33, on 28.8.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Users\xxx\AppData\Roaming\Search Protection\SearchProtection.exe
C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\xxx\Downloads\RSIT.exe
C:\Program Files\trend micro\xxx.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT3303217
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.apsolo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {5BFEFF94-6411-4B74-A947-4969134B24DE} - (no file)
R3 - URLSearchHook: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Speed - {48A789BF-F6D6-4930-9C8B-77855A63EDE1} - C:\PROGRA~1\SECURE~1\IE\SPEEDD~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\ADVANC~2\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
O3 - Toolbar: (no name) - {5BFEFF94-6411-4B74-A947-4969134B24DE} - (no file)
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKLM\..\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" -s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKCU\..\Run: [SearchProtection] "C:\Users\xxx\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
O4 - HKCU\..\Run: [Advanced SystemCare Ultimate] "C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [ConduitFloatingPlugin_ghgmnfeamobhjmillnanbfhmkoeodooi] "C:\Windows\system32\Rundll32.exe" "C:\Program Files\Conduit\CT3303217\plugins\TBVerifier.dll",RunConduitFloatingPlugin ghgmnfeamobhjmillnanbfhmkoeodooi
O4 - HKCU\..\Run: [tsiVideo] rundll32.exe C:\Users\xxx\AppData\Local\Temp\\tsiVi432.dll,start
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4EB6F412-01C8-1B58-4AD6-4B242C0EE614}: NameServer = 93.153.117.1 93.153.117.33
O17 - HKLM\System\CCS\Services\Tcpip\..\{59CCCE1F-7DBA-45BC-B65C-6DE8A2A0C4B6}: NameServer =
O17 - HKLM\System\CS1\Services\Tcpip\..\{4EB6F412-01C8-1B58-4AD6-4B242C0EE614}: NameServer = 93.153.117.1 93.153.117.33
O17 - HKLM\System\CS2\Services\Tcpip\..\{4EB6F412-01C8-1B58-4AD6-4B242C0EE614}: NameServer = 93.153.117.1 93.153.117.33
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files\IObit\Advanced SystemCare Ultimate\ascsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) - IOBit - C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Alcohol Virtual Drive Auto-mount Service (AxAutoMntSrv) - Alcohol Soft Development Team - C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files\SearchProtect\bin\CltMngSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: SecureUpdate (SecureUpdateSvc) - Unknown owner - C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
O23 - Service: WTService - Unknown owner - C:\Windows\system32\atwtusb.exe
--
End of file - 9627 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\Driver Booster Startup.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\RegClean Pro_DEFAULT.job
C:\Windows\tasks\RegClean Pro_UPDATES.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-03-06 540328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}]
AccelerateTab - C:\PROGRA~1\SECURE~1\IE\SPEEDD~1.DLL [2013-08-16 991056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-15 463272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\ADVANC~2\BROWER~1\ASCPLU~1.DLL [2012-12-10 655744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-15 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
{5BFEFF94-6411-4B74-A947-4969134B24DE}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WrtMon.exe"=C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [2006-09-20 20480]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]
"IObit Malware Fighter"=C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [2013-08-16 1549120]
"SearchSettings"=C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2013-07-05 1303360]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2013-05-21 11947080]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SearchProtection"=C:\Users\xxx\AppData\Roaming\Search Protection\SearchProtection.EXE [2013-05-22 740712]
"Advanced SystemCare Ultimate"=C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"ConduitFloatingPlugin_ghgmnfeamobhjmillnanbfhmkoeodooi"=C:\Program Files\Conduit\CT3303217\plugins\TBVerifier.dll [1617-11-28 287008]
"tsiVideo"=C:\Users\xxx\AppData\Local\Temp\\tsiVi432.dll,start []
"T-Mobile CManager"=C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [2012-07-14 1841264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]
C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\asc.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverbooster.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\offdiag.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realconverter.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realplay.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realtrimmer.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rnxproc.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartdefrag.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\suc10_uninstal.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\transformer.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"msacm.l3pacm"=l3codecp.acm
"msacm.aacacm"=AACACM.acm
"msacm.lameacm"=lameACM.acm
"msacm.ac3acm"=ac3acm.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
"VIDC.X264"=x264vfw.dll
"msacm.ac3filter"=ac3filter.acm
"VIDC.MLCY"=mlc.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.iv50"=ir50_32.dll
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux9"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"vidc.tsc2"=C:\Windows\system32\tsc2_codec32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open -
======List of files/folders created in the last 1 month======
2013-08-28 19:14:18 ----D---- C:\rsit
2013-08-28 19:14:18 ----D---- C:\Program Files\trend micro
2013-08-28 12:23:40 ----D---- C:\ProgramData\{CC71B1CB-A2E4-4CF7-8EDB-A0E290BA1604}
2013-08-28 11:42:33 ----D---- C:\Program Files\T-Mobile
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\mod7700.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ewusbwwan.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ewusbmdm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ewdcsc.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_usbenumfilter.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_juwwanecm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_juextctrl.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_jucdcecm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_jucdcacm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_jubusenum.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_hwusbdev.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_hwupgrade.sys
2013-08-27 13:47:37 ----D---- C:\Program Files\Freedom Download Manager
2013-08-27 12:41:50 ----D---- C:\Users\xxx\AppData\Roaming\GHISLER
2013-08-27 12:41:50 ----D---- C:\totalcmd
2013-08-25 12:58:23 ----D---- C:\Users\xxx\AppData\Roaming\PSpad
2013-08-25 11:00:27 ----D---- C:\ProgramData\IsolatedStorage
2013-08-25 11:00:26 ----D---- C:\Users\xxx\AppData\Roaming\IsolatedStorage
2013-08-25 10:59:11 ----D---- C:\Users\xxx\AppData\Roaming\Solvusoft
2013-08-25 10:59:08 ----A---- C:\Windows\system32\roboot.exe
2013-08-25 10:58:08 ----D---- C:\Spacekace
2013-08-22 10:39:05 ----D---- C:\Users\xxx\AppData\Roaming\TechSmith
2013-08-22 10:36:49 ----D---- C:\ProgramData\regid.1995-08.com.techsmith
2013-08-22 10:36:47 ----D---- C:\Program Files\QuickTime
2013-08-22 10:36:34 ----D---- C:\Program Files\Common Files\TechSmith Shared
2013-08-22 10:36:15 ----D---- C:\ProgramData\TechSmith
2013-08-22 10:36:15 ----D---- C:\Program Files\TechSmith
2013-08-21 21:20:43 ----D---- C:\Program Files\FreeTime
2013-08-21 20:56:23 ----D---- C:\ProgramData\Freemake
2013-08-21 20:55:56 ----D---- C:\Program Files\Freemake
2013-08-19 22:19:21 ----D---- C:\Users\xxx\AppData\Roaming\T-Mobile
2013-08-19 09:49:52 ----D---- C:\ProgramData\Gemfor
2013-08-19 09:45:29 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2013-08-19 09:45:29 ----A---- C:\Windows\system32\drivers\WdfCoInstaller01007.dll
2013-08-19 09:45:08 ----D---- C:\Program Files\Huawei
2013-08-17 07:12:09 ----D---- C:\Users\xxx\AppData\Roaming\stetic
2013-08-17 07:11:59 ----D---- C:\Users\xxx\AppData\Roaming\MonoDevelop-Unity-2.8
2013-08-17 07:00:36 ----D---- C:\Program Files\qwined.org
2013-08-14 23:54:51 ----A---- C:\Windows\system32\jscript.dll
2013-08-14 23:54:49 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-14 23:54:49 ----A---- C:\Windows\system32\jscript9.dll
2013-08-14 23:54:48 ----A---- C:\Windows\system32\ieui.dll
2013-08-14 23:54:48 ----A---- C:\Windows\system32\iesetup.dll
2013-08-14 23:54:47 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-14 23:54:47 ----A---- C:\Windows\system32\iernonce.dll
2013-08-14 23:54:47 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-14 23:54:46 ----A---- C:\Windows\system32\urlmon.dll
2013-08-14 23:54:46 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 23:54:46 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-14 23:54:45 ----A---- C:\Windows\system32\iertutil.dll
2013-08-14 23:54:43 ----A---- C:\Windows\system32\wininet.dll
2013-08-14 23:54:40 ----A---- C:\Windows\system32\ieframe.dll
2013-08-14 23:54:38 ----A---- C:\Windows\system32\mshtml.dll
2013-08-14 19:46:32 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-14 19:46:21 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\wintrust.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\crypt32.dll
2013-08-14 19:46:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-14 19:46:14 ----A---- C:\Windows\system32\ntkrnlpa.exe
2013-08-14 19:46:14 ----A---- C:\Windows\system32\ntdll.dll
2013-08-14 19:46:04 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-08-14 19:43:57 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-14 19:40:24 ----A---- C:\Windows\system32\tzres.dll
2013-08-14 18:42:01 ----D---- C:\Users\xxx\AppData\Roaming\Fighters
2013-08-14 18:41:12 ----D---- C:\ProgramData\Fighters
2013-08-14 17:35:02 ----D---- C:\Users\xxx\AppData\Roaming\Blueberry
2013-08-14 17:34:45 ----D---- C:\Users\xxx\AppData\Roaming\LogSys
2013-08-14 17:34:43 ----D---- C:\ProgramData\LogSys
2013-08-14 07:34:53 ----D---- C:\Program Files\Seznam.cz
2013-08-14 07:31:22 ----D---- C:\Users\xxx\AppData\Roaming\SMRecorder
2013-08-14 07:29:30 ----A---- C:\Users\xxx\AppData\Roaming\CamShapes.ini
2013-08-14 07:29:30 ----A---- C:\Users\xxx\AppData\Roaming\CamLayout.ini
2013-08-14 07:29:30 ----A---- C:\Users\xxx\AppData\Roaming\Camdata.ini
2013-08-12 21:21:26 ----D---- C:\Program Files\Common Files\Apple
2013-08-12 21:21:16 ----D---- C:\ProgramData\Apple
2013-08-12 21:21:16 ----D---- C:\Program Files\Apple Software Update
2013-08-10 17:22:38 ----D---- C:\ProgramData\MetaQuotes
2013-08-09 22:59:46 ----D---- C:\Windows\system32\MRT
2013-08-07 20:51:44 ----D---- C:\ProgramData\MGS
2013-08-07 20:51:44 ----D---- C:\Microgaming
2013-08-07 12:53:54 ----D---- C:\Windows\system32\Adobe
2013-08-06 13:05:25 ----D---- C:\Program Files\MAXON
2013-08-06 10:10:54 ----D---- C:\Program Files\Unity
2013-08-02 10:56:33 ----D---- C:\ProgramData\Bitstream
2013-07-31 21:40:20 ----D---- C:\ProgramData\Stardock
2013-07-31 19:50:17 ----D---- C:\Users\xxx\AppData\Roaming\Rainmeter
2013-07-31 19:50:13 ----D---- C:\Program Files\Rainmeter
2013-07-31 17:36:48 ----D---- C:\ProgramData\Package Cache
2013-07-31 16:07:35 ----D---- C:\Program Files\Regino v5.0
2013-07-30 18:19:38 ----D---- C:\Users\xxx\AppData\Roaming\Unity
2013-07-30 17:32:55 ----D---- C:\ProgramData\Unity
2013-07-30 14:34:02 ----D---- C:\Users\xxx\AppData\Roaming\NewSoft
======List of files/folders modified in the last 1 month======
2013-08-28 19:14:31 ----D---- C:\Windows\Prefetch
2013-08-28 19:14:23 ----D---- C:\Windows\Temp
2013-08-28 19:14:18 ----RD---- C:\Program Files
2013-08-28 17:46:03 ----D---- C:\ProgramData\SEarch-NNewiTeaub
2013-08-28 17:46:03 ----D---- C:\ProgramData\BrOwwsae2saevEe
2013-08-28 16:30:02 ----D---- C:\Windows\system32\config
2013-08-28 13:10:25 ----D---- C:\Users\xxx\AppData\Roaming\MAXON
2013-08-28 12:23:43 ----A---- C:\Windows\win.ini
2013-08-28 12:23:40 ----HD---- C:\ProgramData
2013-08-28 12:23:18 ----D---- C:\Windows
2013-08-28 11:53:01 ----D---- C:\Windows\system32\NDF
2013-08-28 11:44:07 ----D---- C:\Windows\System32
2013-08-28 11:44:07 ----D---- C:\Windows\inf
2013-08-28 11:44:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-28 11:42:12 ----D---- C:\Windows\system32\DriverStore
2013-08-28 11:42:12 ----D---- C:\Windows\system32\drivers
2013-08-28 11:42:12 ----D---- C:\Windows\system32\catroot
2013-08-28 08:00:11 ----D---- C:\Windows\system32\RTCOM
2013-08-28 07:58:26 ----D---- C:\Users\xxx\AppData\Roaming\uTorrent
2013-08-28 07:57:18 ----D---- C:\Windows\debug
2013-08-27 13:46:42 ----D---- C:\Users\xxx\AppData\Roaming\SearchProtect
2013-08-27 13:46:37 ----D---- C:\Program Files\Conduit
2013-08-27 11:41:14 ----D---- C:\Users\xxx\AppData\Roaming\Seznam.cz
2013-08-27 11:31:34 ----SHD---- C:\System Volume Information
2013-08-27 11:10:30 ----D---- C:\Program Files\Secure Speed Dial
2013-08-27 11:02:09 ----SHD---- C:\Windows\Installer
2013-08-26 06:59:09 ----D---- C:\Windows\system32\catroot2
2013-08-25 13:17:23 ----D---- C:\Windows\system32\Tasks
2013-08-25 13:17:21 ----D---- C:\Windows\Tasks
2013-08-22 10:56:42 ----D---- C:\Windows\system32\wdi
2013-08-22 10:36:34 ----D---- C:\Program Files\Common Files
2013-08-21 20:55:56 ----D---- C:\Users\xxx\AppData\Roaming\OpenCandy
2013-08-21 20:49:32 ----SD---- C:\Users\xxx\AppData\Roaming\Microsoft
2013-08-21 10:03:10 ----A---- C:\Windows\system32\sqlite3.dll
2013-08-19 09:47:10 ----D---- C:\Windows\ModemLogs
2013-08-17 07:00:52 ----D---- C:\Windows\winsxs
2013-08-17 06:59:40 ----D---- C:\Windows\Downloaded Installations
2013-08-16 20:27:00 ----D---- C:\Windows\Microsoft.NET
2013-08-16 20:26:18 ----RSD---- C:\Windows\assembly
2013-08-15 21:45:54 ----SD---- C:\ProgramData\Microsoft
2013-08-15 12:44:44 ----D---- C:\Windows\rescache
2013-08-15 10:38:27 ----D---- C:\ProgramData\Google
2013-08-15 10:38:27 ----D---- C:\Program Files\Google
2013-08-15 06:17:49 ----D---- C:\Windows\system32\cs-CZ
2013-08-15 06:17:47 ----D---- C:\Program Files\Internet Explorer
2013-08-15 00:00:29 ----A---- C:\Windows\system32\MRT.exe
2013-08-15 00:00:09 ----D---- C:\ProgramData\Microsoft Help
2013-08-14 19:27:56 ----RSD---- C:\Windows\Fonts
2013-08-14 17:34:43 ----D---- C:\Windows\Help
2013-08-13 08:48:34 ----D---- C:\Users\xxx\AppData\Roaming\Apple Computer
2013-08-12 10:24:41 ----D---- C:\Users\xxx\AppData\Roaming\Systweak
2013-08-11 14:01:24 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-08-10 16:04:37 ----D---- C:\Users\xxx\AppData\Roaming\Canon
2013-08-10 16:03:31 ----D---- C:\Windows\system32\FxsTmp
2013-08-06 12:59:21 ----D---- C:\Users\xxx\AppData\Roaming\DAEMON Tools Lite
2013-08-05 22:31:03 ----D---- C:\Users\xxx\AppData\Roaming\vlc
2013-08-02 17:19:06 ----D---- C:\Users\xxx\AppData\Roaming\Audacity
2013-08-02 14:11:31 ----D---- C:\Program Files\Smith Micro
2013-08-02 14:08:14 ----D---- C:\Users\xxx\AppData\Roaming\Poser Pro
2013-07-31 16:07:48 ----A---- C:\Windows\system.ini
2013-07-30 14:47:56 ----D---- C:\Windows\Logs
2013-07-30 09:05:12 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-07-29 22:04:05 ----D---- C:\Users\xxx\AppData\Roaming\dvdcss
2013-07-29 11:27:10 ----D---- C:\ProgramData\Razer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-05-09 49376]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-07-15 175176]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 15672]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-05-02 466008]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-05-09 61680]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-07-15 770344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-07-15 369584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-05-09 56080]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05-09 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 290304]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2012-02-23 86544]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-03-11 242240]
R3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2010-03-20 11136]
R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\fetnd6v.sys [2008-09-22 43520]
R3 FileMonitor;FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2013-03-23 21480]
R3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2012-04-23 95616]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2012-04-23 76544]
R3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2012-04-23 27520]
R3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2012-04-23 202752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2013-05-21 2666248]
R3 moufiltr;Tablet Mouse Filter Driver; C:\Windows\system32\DRIVERS\moufiltr.sys [2009-03-08 6144]
R3 RegFilter;RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2013-03-26 31752]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-11-16 10088]
R3 UrlFilter;UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2013-03-26 20944]
R3 vhidmini;Generic Virtual HID Driver; C:\Windows\system32\DRIVERS\walvhid.sys [2009-08-20 6144]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 DFX11_1;DFX Audio Enhancer 11.1; C:\Windows\system32\drivers\dfx11_1.sys [2012-12-13 24424]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 102784]
S3 FETNDIS;VIA Rhine-Family Fast Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\fetnd6.sys [2009-07-14 44032]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-07-21 14848]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-07-21 49664]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\drivers\usb8023x.sys [2013-02-12 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinRing0_1_2_0;WinRing0_1_2_0; C:\Windows\system32\drivers\WinRing0_1_2_0.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2013-07-08 623936]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 CltMngSvc;Search Protect by Conduit Updater; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [2013-05-08 97056]
R2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2013-08-22 101888]
R2 IMFservice;IMF Service; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [2013-04-25 335168]
R2 MbnExt;Mobile Broadband Extension Service; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-03-06 39056]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2013-01-31 1724192]
R2 WTService;WTService; C:\Windows\system32\atwtusb.exe [2010-04-13 519912]
S2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-01-05 75624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-12 136176]
S2 SecureUpdateSvc;SecureUpdate; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [2013-08-21 2460496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-30 257416]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2013-04-13 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-12 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-03-06 1343400]
S4 ABBYY.Licensing.PDFTransformer.Classic.3.0;Aktivace aplikace ABBYY PDF Transformer 3.0 – Licenční služba; C:\Program Files\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [2009-05-14 759048]
S4 AppHostSvc;Pomocná služba hostitele aplikace; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2013-07-05 807800]
S4 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 97432]
S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 W3SVC;Služba Publikování na webu; C:\Windows\system32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Prosím,mám takový problém.Pročítal jsem vaše řešení s minulých témat, ale moc se v tom nevyznám, proto vás žádám o radu.
Do PC mi nalítl nějaký nabořitel, a Avast mi to co 5 minut hlásí, ale neodstranil to ani online Eset, který prý dokáže nemožné.
Můžete ni s tím nějak pomoci:
Avast hlásí toto.
Objekt: C:\Users\xxx\AppData\Local\Temp\iswizard\wuaudit.exe
Proces: C:\Windows\System32\rundll32.exe
Přikládám Log dle návodu, který jsem zde našel. :
Logfile of random's system information tool 1.09 (written by random/random)
Run by xxx at 2013-08-28 19:14:18
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 8 GB (15%) free of 52 GB
Total RAM: 3070 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:14:33, on 28.8.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Users\xxx\AppData\Roaming\Search Protection\SearchProtection.exe
C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\xxx\Downloads\RSIT.exe
C:\Program Files\trend micro\xxx.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT3303217
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.apsolo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {5BFEFF94-6411-4B74-A947-4969134B24DE} - (no file)
R3 - URLSearchHook: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Speed - {48A789BF-F6D6-4930-9C8B-77855A63EDE1} - C:\PROGRA~1\SECURE~1\IE\SPEEDD~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\ADVANC~2\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
O3 - Toolbar: (no name) - {5BFEFF94-6411-4B74-A947-4969134B24DE} - (no file)
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKLM\..\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" -s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKCU\..\Run: [SearchProtection] "C:\Users\xxx\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
O4 - HKCU\..\Run: [Advanced SystemCare Ultimate] "C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [ConduitFloatingPlugin_ghgmnfeamobhjmillnanbfhmkoeodooi] "C:\Windows\system32\Rundll32.exe" "C:\Program Files\Conduit\CT3303217\plugins\TBVerifier.dll",RunConduitFloatingPlugin ghgmnfeamobhjmillnanbfhmkoeodooi
O4 - HKCU\..\Run: [tsiVideo] rundll32.exe C:\Users\xxx\AppData\Local\Temp\\tsiVi432.dll,start
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4EB6F412-01C8-1B58-4AD6-4B242C0EE614}: NameServer = 93.153.117.1 93.153.117.33
O17 - HKLM\System\CCS\Services\Tcpip\..\{59CCCE1F-7DBA-45BC-B65C-6DE8A2A0C4B6}: NameServer =
O17 - HKLM\System\CS1\Services\Tcpip\..\{4EB6F412-01C8-1B58-4AD6-4B242C0EE614}: NameServer = 93.153.117.1 93.153.117.33
O17 - HKLM\System\CS2\Services\Tcpip\..\{4EB6F412-01C8-1B58-4AD6-4B242C0EE614}: NameServer = 93.153.117.1 93.153.117.33
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files\IObit\Advanced SystemCare Ultimate\ascsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) - IOBit - C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Alcohol Virtual Drive Auto-mount Service (AxAutoMntSrv) - Alcohol Soft Development Team - C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files\SearchProtect\bin\CltMngSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: SecureUpdate (SecureUpdateSvc) - Unknown owner - C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
O23 - Service: WTService - Unknown owner - C:\Windows\system32\atwtusb.exe
--
End of file - 9627 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\Driver Booster Startup.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\RegClean Pro_DEFAULT.job
C:\Windows\tasks\RegClean Pro_UPDATES.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-03-06 540328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}]
AccelerateTab - C:\PROGRA~1\SECURE~1\IE\SPEEDD~1.DLL [2013-08-16 991056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-15 463272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\ADVANC~2\BROWER~1\ASCPLU~1.DLL [2012-12-10 655744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-15 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
{5BFEFF94-6411-4B74-A947-4969134B24DE}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WrtMon.exe"=C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe [2006-09-20 20480]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]
"IObit Malware Fighter"=C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [2013-08-16 1549120]
"SearchSettings"=C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2013-07-05 1303360]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2013-05-21 11947080]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SearchProtection"=C:\Users\xxx\AppData\Roaming\Search Protection\SearchProtection.EXE [2013-05-22 740712]
"Advanced SystemCare Ultimate"=C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"ConduitFloatingPlugin_ghgmnfeamobhjmillnanbfhmkoeodooi"=C:\Program Files\Conduit\CT3303217\plugins\TBVerifier.dll [1617-11-28 287008]
"tsiVideo"=C:\Users\xxx\AppData\Local\Temp\\tsiVi432.dll,start []
"T-Mobile CManager"=C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [2012-07-14 1841264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]
C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\asc.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverbooster.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\offdiag.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realconverter.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realplay.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realtrimmer.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rnxproc.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartdefrag.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\suc10_uninstal.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\transformer.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2013\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"msacm.l3pacm"=l3codecp.acm
"msacm.aacacm"=AACACM.acm
"msacm.lameacm"=lameACM.acm
"msacm.ac3acm"=ac3acm.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
"VIDC.X264"=x264vfw.dll
"msacm.ac3filter"=ac3filter.acm
"VIDC.MLCY"=mlc.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.iv50"=ir50_32.dll
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux9"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"vidc.tsc2"=C:\Windows\system32\tsc2_codec32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open -
======List of files/folders created in the last 1 month======
2013-08-28 19:14:18 ----D---- C:\rsit
2013-08-28 19:14:18 ----D---- C:\Program Files\trend micro
2013-08-28 12:23:40 ----D---- C:\ProgramData\{CC71B1CB-A2E4-4CF7-8EDB-A0E290BA1604}
2013-08-28 11:42:33 ----D---- C:\Program Files\T-Mobile
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\mod7700.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ewusbwwan.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ewusbmdm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ewdcsc.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_usbenumfilter.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_juwwanecm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_juextctrl.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_jucdcecm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_jucdcacm.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_jubusenum.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_hwusbdev.sys
2013-08-28 11:42:12 ----A---- C:\Windows\system32\drivers\ew_hwupgrade.sys
2013-08-27 13:47:37 ----D---- C:\Program Files\Freedom Download Manager
2013-08-27 12:41:50 ----D---- C:\Users\xxx\AppData\Roaming\GHISLER
2013-08-27 12:41:50 ----D---- C:\totalcmd
2013-08-25 12:58:23 ----D---- C:\Users\xxx\AppData\Roaming\PSpad
2013-08-25 11:00:27 ----D---- C:\ProgramData\IsolatedStorage
2013-08-25 11:00:26 ----D---- C:\Users\xxx\AppData\Roaming\IsolatedStorage
2013-08-25 10:59:11 ----D---- C:\Users\xxx\AppData\Roaming\Solvusoft
2013-08-25 10:59:08 ----A---- C:\Windows\system32\roboot.exe
2013-08-25 10:58:08 ----D---- C:\Spacekace
2013-08-22 10:39:05 ----D---- C:\Users\xxx\AppData\Roaming\TechSmith
2013-08-22 10:36:49 ----D---- C:\ProgramData\regid.1995-08.com.techsmith
2013-08-22 10:36:47 ----D---- C:\Program Files\QuickTime
2013-08-22 10:36:34 ----D---- C:\Program Files\Common Files\TechSmith Shared
2013-08-22 10:36:15 ----D---- C:\ProgramData\TechSmith
2013-08-22 10:36:15 ----D---- C:\Program Files\TechSmith
2013-08-21 21:20:43 ----D---- C:\Program Files\FreeTime
2013-08-21 20:56:23 ----D---- C:\ProgramData\Freemake
2013-08-21 20:55:56 ----D---- C:\Program Files\Freemake
2013-08-19 22:19:21 ----D---- C:\Users\xxx\AppData\Roaming\T-Mobile
2013-08-19 09:49:52 ----D---- C:\ProgramData\Gemfor
2013-08-19 09:45:29 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2013-08-19 09:45:29 ----A---- C:\Windows\system32\drivers\WdfCoInstaller01007.dll
2013-08-19 09:45:08 ----D---- C:\Program Files\Huawei
2013-08-17 07:12:09 ----D---- C:\Users\xxx\AppData\Roaming\stetic
2013-08-17 07:11:59 ----D---- C:\Users\xxx\AppData\Roaming\MonoDevelop-Unity-2.8
2013-08-17 07:00:36 ----D---- C:\Program Files\qwined.org
2013-08-14 23:54:51 ----A---- C:\Windows\system32\jscript.dll
2013-08-14 23:54:49 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-14 23:54:49 ----A---- C:\Windows\system32\jscript9.dll
2013-08-14 23:54:48 ----A---- C:\Windows\system32\ieui.dll
2013-08-14 23:54:48 ----A---- C:\Windows\system32\iesetup.dll
2013-08-14 23:54:47 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-14 23:54:47 ----A---- C:\Windows\system32\iernonce.dll
2013-08-14 23:54:47 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-14 23:54:46 ----A---- C:\Windows\system32\urlmon.dll
2013-08-14 23:54:46 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 23:54:46 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-14 23:54:45 ----A---- C:\Windows\system32\iertutil.dll
2013-08-14 23:54:43 ----A---- C:\Windows\system32\wininet.dll
2013-08-14 23:54:40 ----A---- C:\Windows\system32\ieframe.dll
2013-08-14 23:54:38 ----A---- C:\Windows\system32\mshtml.dll
2013-08-14 19:46:32 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-14 19:46:21 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\wintrust.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-14 19:46:19 ----A---- C:\Windows\system32\crypt32.dll
2013-08-14 19:46:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-14 19:46:14 ----A---- C:\Windows\system32\ntkrnlpa.exe
2013-08-14 19:46:14 ----A---- C:\Windows\system32\ntdll.dll
2013-08-14 19:46:04 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-08-14 19:43:57 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-14 19:40:24 ----A---- C:\Windows\system32\tzres.dll
2013-08-14 18:42:01 ----D---- C:\Users\xxx\AppData\Roaming\Fighters
2013-08-14 18:41:12 ----D---- C:\ProgramData\Fighters
2013-08-14 17:35:02 ----D---- C:\Users\xxx\AppData\Roaming\Blueberry
2013-08-14 17:34:45 ----D---- C:\Users\xxx\AppData\Roaming\LogSys
2013-08-14 17:34:43 ----D---- C:\ProgramData\LogSys
2013-08-14 07:34:53 ----D---- C:\Program Files\Seznam.cz
2013-08-14 07:31:22 ----D---- C:\Users\xxx\AppData\Roaming\SMRecorder
2013-08-14 07:29:30 ----A---- C:\Users\xxx\AppData\Roaming\CamShapes.ini
2013-08-14 07:29:30 ----A---- C:\Users\xxx\AppData\Roaming\CamLayout.ini
2013-08-14 07:29:30 ----A---- C:\Users\xxx\AppData\Roaming\Camdata.ini
2013-08-12 21:21:26 ----D---- C:\Program Files\Common Files\Apple
2013-08-12 21:21:16 ----D---- C:\ProgramData\Apple
2013-08-12 21:21:16 ----D---- C:\Program Files\Apple Software Update
2013-08-10 17:22:38 ----D---- C:\ProgramData\MetaQuotes
2013-08-09 22:59:46 ----D---- C:\Windows\system32\MRT
2013-08-07 20:51:44 ----D---- C:\ProgramData\MGS
2013-08-07 20:51:44 ----D---- C:\Microgaming
2013-08-07 12:53:54 ----D---- C:\Windows\system32\Adobe
2013-08-06 13:05:25 ----D---- C:\Program Files\MAXON
2013-08-06 10:10:54 ----D---- C:\Program Files\Unity
2013-08-02 10:56:33 ----D---- C:\ProgramData\Bitstream
2013-07-31 21:40:20 ----D---- C:\ProgramData\Stardock
2013-07-31 19:50:17 ----D---- C:\Users\xxx\AppData\Roaming\Rainmeter
2013-07-31 19:50:13 ----D---- C:\Program Files\Rainmeter
2013-07-31 17:36:48 ----D---- C:\ProgramData\Package Cache
2013-07-31 16:07:35 ----D---- C:\Program Files\Regino v5.0
2013-07-30 18:19:38 ----D---- C:\Users\xxx\AppData\Roaming\Unity
2013-07-30 17:32:55 ----D---- C:\ProgramData\Unity
2013-07-30 14:34:02 ----D---- C:\Users\xxx\AppData\Roaming\NewSoft
======List of files/folders modified in the last 1 month======
2013-08-28 19:14:31 ----D---- C:\Windows\Prefetch
2013-08-28 19:14:23 ----D---- C:\Windows\Temp
2013-08-28 19:14:18 ----RD---- C:\Program Files
2013-08-28 17:46:03 ----D---- C:\ProgramData\SEarch-NNewiTeaub
2013-08-28 17:46:03 ----D---- C:\ProgramData\BrOwwsae2saevEe
2013-08-28 16:30:02 ----D---- C:\Windows\system32\config
2013-08-28 13:10:25 ----D---- C:\Users\xxx\AppData\Roaming\MAXON
2013-08-28 12:23:43 ----A---- C:\Windows\win.ini
2013-08-28 12:23:40 ----HD---- C:\ProgramData
2013-08-28 12:23:18 ----D---- C:\Windows
2013-08-28 11:53:01 ----D---- C:\Windows\system32\NDF
2013-08-28 11:44:07 ----D---- C:\Windows\System32
2013-08-28 11:44:07 ----D---- C:\Windows\inf
2013-08-28 11:44:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-28 11:42:12 ----D---- C:\Windows\system32\DriverStore
2013-08-28 11:42:12 ----D---- C:\Windows\system32\drivers
2013-08-28 11:42:12 ----D---- C:\Windows\system32\catroot
2013-08-28 08:00:11 ----D---- C:\Windows\system32\RTCOM
2013-08-28 07:58:26 ----D---- C:\Users\xxx\AppData\Roaming\uTorrent
2013-08-28 07:57:18 ----D---- C:\Windows\debug
2013-08-27 13:46:42 ----D---- C:\Users\xxx\AppData\Roaming\SearchProtect
2013-08-27 13:46:37 ----D---- C:\Program Files\Conduit
2013-08-27 11:41:14 ----D---- C:\Users\xxx\AppData\Roaming\Seznam.cz
2013-08-27 11:31:34 ----SHD---- C:\System Volume Information
2013-08-27 11:10:30 ----D---- C:\Program Files\Secure Speed Dial
2013-08-27 11:02:09 ----SHD---- C:\Windows\Installer
2013-08-26 06:59:09 ----D---- C:\Windows\system32\catroot2
2013-08-25 13:17:23 ----D---- C:\Windows\system32\Tasks
2013-08-25 13:17:21 ----D---- C:\Windows\Tasks
2013-08-22 10:56:42 ----D---- C:\Windows\system32\wdi
2013-08-22 10:36:34 ----D---- C:\Program Files\Common Files
2013-08-21 20:55:56 ----D---- C:\Users\xxx\AppData\Roaming\OpenCandy
2013-08-21 20:49:32 ----SD---- C:\Users\xxx\AppData\Roaming\Microsoft
2013-08-21 10:03:10 ----A---- C:\Windows\system32\sqlite3.dll
2013-08-19 09:47:10 ----D---- C:\Windows\ModemLogs
2013-08-17 07:00:52 ----D---- C:\Windows\winsxs
2013-08-17 06:59:40 ----D---- C:\Windows\Downloaded Installations
2013-08-16 20:27:00 ----D---- C:\Windows\Microsoft.NET
2013-08-16 20:26:18 ----RSD---- C:\Windows\assembly
2013-08-15 21:45:54 ----SD---- C:\ProgramData\Microsoft
2013-08-15 12:44:44 ----D---- C:\Windows\rescache
2013-08-15 10:38:27 ----D---- C:\ProgramData\Google
2013-08-15 10:38:27 ----D---- C:\Program Files\Google
2013-08-15 06:17:49 ----D---- C:\Windows\system32\cs-CZ
2013-08-15 06:17:47 ----D---- C:\Program Files\Internet Explorer
2013-08-15 00:00:29 ----A---- C:\Windows\system32\MRT.exe
2013-08-15 00:00:09 ----D---- C:\ProgramData\Microsoft Help
2013-08-14 19:27:56 ----RSD---- C:\Windows\Fonts
2013-08-14 17:34:43 ----D---- C:\Windows\Help
2013-08-13 08:48:34 ----D---- C:\Users\xxx\AppData\Roaming\Apple Computer
2013-08-12 10:24:41 ----D---- C:\Users\xxx\AppData\Roaming\Systweak
2013-08-11 14:01:24 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-08-10 16:04:37 ----D---- C:\Users\xxx\AppData\Roaming\Canon
2013-08-10 16:03:31 ----D---- C:\Windows\system32\FxsTmp
2013-08-06 12:59:21 ----D---- C:\Users\xxx\AppData\Roaming\DAEMON Tools Lite
2013-08-05 22:31:03 ----D---- C:\Users\xxx\AppData\Roaming\vlc
2013-08-02 17:19:06 ----D---- C:\Users\xxx\AppData\Roaming\Audacity
2013-08-02 14:11:31 ----D---- C:\Program Files\Smith Micro
2013-08-02 14:08:14 ----D---- C:\Users\xxx\AppData\Roaming\Poser Pro
2013-07-31 16:07:48 ----A---- C:\Windows\system.ini
2013-07-30 14:47:56 ----D---- C:\Windows\Logs
2013-07-30 09:05:12 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-07-29 22:04:05 ----D---- C:\Users\xxx\AppData\Roaming\dvdcss
2013-07-29 11:27:10 ----D---- C:\ProgramData\Razer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-05-09 49376]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-07-15 175176]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 15672]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-05-02 466008]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-05-09 61680]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-07-15 770344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-07-15 369584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-05-09 56080]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05-09 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 290304]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2012-02-23 86544]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-03-11 242240]
R3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2010-03-20 11136]
R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\fetnd6v.sys [2008-09-22 43520]
R3 FileMonitor;FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2013-03-23 21480]
R3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2012-04-23 95616]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2012-04-23 76544]
R3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2012-04-23 27520]
R3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2012-04-23 202752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2013-05-21 2666248]
R3 moufiltr;Tablet Mouse Filter Driver; C:\Windows\system32\DRIVERS\moufiltr.sys [2009-03-08 6144]
R3 RegFilter;RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2013-03-26 31752]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-11-16 10088]
R3 UrlFilter;UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2013-03-26 20944]
R3 vhidmini;Generic Virtual HID Driver; C:\Windows\system32\DRIVERS\walvhid.sys [2009-08-20 6144]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 DFX11_1;DFX Audio Enhancer 11.1; C:\Windows\system32\drivers\dfx11_1.sys [2012-12-13 24424]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 102784]
S3 FETNDIS;VIA Rhine-Family Fast Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\fetnd6.sys [2009-07-14 44032]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-07-21 14848]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-07-21 49664]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\drivers\usb8023x.sys [2013-02-12 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinRing0_1_2_0;WinRing0_1_2_0; C:\Windows\system32\drivers\WinRing0_1_2_0.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2013-07-08 623936]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 CltMngSvc;Search Protect by Conduit Updater; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [2013-05-08 97056]
R2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2013-08-22 101888]
R2 IMFservice;IMF Service; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [2013-04-25 335168]
R2 MbnExt;Mobile Broadband Extension Service; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-03-06 39056]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2013-01-31 1724192]
R2 WTService;WTService; C:\Windows\system32\atwtusb.exe [2010-04-13 519912]
S2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-01-05 75624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-12 136176]
S2 SecureUpdateSvc;SecureUpdate; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [2013-08-21 2460496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-30 257416]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2013-04-13 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-12 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-03-06 1343400]
S4 ABBYY.Licensing.PDFTransformer.Classic.3.0;Aktivace aplikace ABBYY PDF Transformer 3.0 – Licenční služba; C:\Program Files\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [2009-05-14 759048]
S4 AppHostSvc;Pomocná služba hostitele aplikace; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2013-07-05 807800]
S4 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 97432]
S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 W3SVC;Služba Publikování na webu; C:\Windows\system32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------