Stránka 1 z 2

Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 21:26
od cm_L_da
Dobrý den. Můžet mi prosím pomoci odstranit viry v systému, které obtěžují při využívání prohlížečů? Děkuji.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Ultimate x64
Ran by INDI on so 14.12.2013 at 18:43:32,97
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-4113872694-1721576408-89762151-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\im
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminstaller
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\sprotector
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4113872694-1721576408-89762151-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sp global
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sprotector
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskPIP_FF__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r362-n-bf(1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskPIP_FF__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r362-n-bf(1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25EB66FC-03A7-40AA-A073-EAAF723CDD90}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{25EB66FC-03A7-40AA-A073-EAAF723CDD90}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25EB66FC-03A7-40AA-A073-EAAF723CDD90}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\cloud software ltd"
Successfully deleted: [Folder] "C:\ProgramData\rightclick"
Successfully deleted: [Folder] "C:\ProgramData\softsafe"
Successfully deleted: [Folder] "C:\ProgramData\starapp"
Successfully deleted: [Folder] "C:\Users\INDI\AppData\Roaming\dvdvideosoftiehelpers"
Successfully deleted: [Folder] "C:\Users\INDI\AppData\Roaming\pdfforge"
Successfully deleted: [Folder] "C:\Users\INDI\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Program Files (x86)\continuetosave"
Successfully deleted: [Folder] "C:\Program Files (x86)\simplespeedy"



~~~ FireFox

Successfully deleted: [File] C:\Users\INDI\AppData\Roaming\mozilla\firefox\profiles\u88yrlve.default\user.js
Successfully deleted: [File] C:\Users\INDI\AppData\Roaming\mozilla\firefox\profiles\u88yrlve.default\invalidprefs.js
Successfully deleted the following from C:\Users\INDI\AppData\Roaming\mozilla\firefox\profiles\u88yrlve.default\prefs.js

user_pref("aol_toolbar.default.homepage.check", false);
user_pref("aol_toolbar.default.search.check", false);
user_pref("extensions.BabylonToolbar.prtkDS", 0);
user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
user_pref("sweetim.toolbar.previous.keyword.URL", "");
user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
user_pref("sweetim.toolbar.searchguard.enable", "");
Emptied folder: C:\Users\INDI\AppData\Roaming\mozilla\firefox\profiles\u88yrlve.default\minidumps [8 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 14.12.2013 at 19:25:41,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 21:28
od Rudy
Zdravím!
Zkuste tento postup: http://forum.viry.cz/viewtopic.php?f=24&t=132509 .

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 22:09
od cm_L_da
Děkuji. FRST64 jsem spustil. Logy se bohužel neuložily. Okno z logem bylo vždy prázdné a neuložilo se. První otisk obrazovky přikládám a ostatní dva přiložím v dalších odpovědích.

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 22:09
od cm_L_da
Otisk 2.

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 22:10
od cm_L_da
Otisk 3.

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 22:15
od cm_L_da
HJT přikládám:
Logfile of random's system information tool 1.09 (written by random/random)
Run by INDI at 2013-12-14 22:14:13
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 23 GB (23%) free of 100 GB
Total RAM: 3519 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:14:33, on 14.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\hwevid\hwevid.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\IObit\Advanced SystemCare 7\Homepage.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
C:\Program Files\trend micro\INDI.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?ptr=100&crg=3. ... 5FF443EA76}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: BetterSurf - {6E3C6B04-08FE-43BC-8E50-F90285024DEA} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: BetterSrf - {8271B5D6-76D3-4ABF-AEB3-1721161C76BC} - (no file)
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: (no name) - {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - (no file)
O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O3 - Toolbar: PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
O3 - Toolbar: (no name) - {CF0F43AB-9C23-4D7B-8040-201B82844854} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [hwevid] C:\hwevid\akt.exe hwevid
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\INDI\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [Application Restart #0] D:\Instalace\Remote Control Android\MonectHost.exe /RestartByRestartManager:19312E76-19EC-48f1-8100-D290B5CE3FBF (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Application Restart #0] D:\Instalace\Remote Control Android\MonectHost.exe /RestartByRestartManager:19312E76-19EC-48f1-8100-D290B5CE3FBF (User 'Default user')
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MonectServerService - Monect - D:\Instalace\Remote Control Android\MonectServerService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PDF Architect Helper Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SureThing Labelflash service - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 13441 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
"D:\Instalace\Remote Control Android\MonectServerService.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\PDF Architect\HelperService.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
"C:\Program Files (x86)\PDF Architect\ConversionService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe"
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe"
"C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Program Files\Saitek\SD6\Software\ProfilerU.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\Saitek\SD6\Software\SaiMfd.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\hwevid\hwevid.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\totalcmd\TOTALCMD.EXE"
C:\Windows\explorer.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\Homepage.exe" /popup
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6764.b37bb00.925853683 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 6764 "\\.\pipe\gecko-crash-server-pipe.6764" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe" --proxy-stub-channel=Flash976.67F1DC68.23464 --host-broker-channel=Flash976.67F1DC68.17489 --host-pid=976 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe" --channel=6048.0033F2BC.1019341445 --proxy-stub-channel=Flash976.67F1DC68.23464 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll" --host-npapi-version=27 --type=renderer
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe48_ Global\UsGthrCtrlFltPipeMssGthrPipe48 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 824 828 836 65536 832
taskeng.exe {2CE8526D-FEFD-4A6F-A060-0C8AF5CEBCDC}
"C:\Users\INDI\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4113872694-1721576408-89762151-1001Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4113872694-1721576408-89762151-1001UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://login.szn.cz/?returnURL=https%3a ... ilLogout=1"
prefs.js - "keyword.URL" - ""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\Sony\Media Go\npmediago.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default\extensions\
adsremoval@adsremoval.net
ascsurfingprotection@iobit.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]
SmileysWeLoveToolbar - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
DVDVideoSoft WebPageAdjuster Class - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2013-08-27 336952]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}]
PDF Architect Helper - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2012-11-22 91784]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2013-10-03 583520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-10-17 669504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
DVDVideoSoft WebPageAdjuster Class - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2013-08-27 277560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CF0F43AB-9C23-4D7B-8040-201B82844854} - SmileysWeLove - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{25A3A431-30BB-47C8-AD6A-E1063801134F} - PDF Architect Toolbar - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll [2012-11-22 731784]
{CF0F43AB-9C23-4D7B-8040-201B82844854}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-11-11 1612504]
"ProfilerU"=C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [2010-07-29 310272]
"SaiMfd"=C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [2010-07-29 158208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2012-07-02 2736128]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-05-29 449248]
"Facebook Update"=C:\Users\INDI\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-10-14 138096]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"CloneCDTray"=C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [2009-01-29 57344]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]
"hwevid"=C:\hwevid\akt.exe [2013-08-27 824320]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

C:\Users\INDI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EvernoteClipper.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-12-14 22:14:14 ----D---- C:\Program Files\trend micro
2013-12-14 22:14:13 ----D---- C:\rsit
2013-12-14 21:43:53 ----D---- C:\FRST
2013-12-14 18:43:26 ----D---- C:\Windows\ERUNT
2013-12-14 18:40:11 ----A---- C:\Windows\wininit.ini
2013-12-14 12:37:05 ----D---- C:\ProgramData\Spybot - Search & Destroy
2013-12-14 12:36:58 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-12-14 11:12:43 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2013-12-12 03:03:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-12 03:03:49 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-12 03:03:48 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-12 03:03:46 ----A---- C:\Windows\system32\wmp.dll
2013-12-12 03:02:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:02:13 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-12 03:02:13 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-12 03:02:13 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-12 03:02:13 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-12 03:02:13 ----A---- C:\Windows\system32\ieui.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\mshtml.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\iesetup.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\iernonce.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-12 03:02:11 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-12 03:02:11 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-12 03:02:11 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-12 03:02:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-12 03:02:10 ----A---- C:\Windows\system32\iertutil.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-12 03:02:09 ----A---- C:\Windows\system32\wininet.dll
2013-12-12 03:02:08 ----A---- C:\Windows\system32\urlmon.dll
2013-12-12 03:02:07 ----A---- C:\Windows\system32\ieframe.dll
2013-12-12 03:02:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-12 03:02:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-12 03:02:05 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-12 03:02:04 ----A---- C:\Windows\system32\jscript9.dll
2013-12-11 20:46:35 ----N---- C:\Windows\system32\fppr4-x64.dll
2013-12-11 20:46:35 ----N---- C:\Windows\system32\fppmon4.dll
2013-12-11 13:24:21 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-11 13:24:21 ----A---- C:\Windows\system32\msieftp.dll
2013-12-11 13:24:20 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-11 13:24:20 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-11 13:24:20 ----A---- C:\Windows\system32\win32k.sys
2013-12-11 13:24:19 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-11 13:24:18 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-11 13:24:15 ----A---- C:\Windows\system32\tzres.dll
2013-12-11 13:24:14 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-11 13:24:11 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-11 13:24:11 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-11 13:24:10 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 13:24:10 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 13:24:10 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 13:24:10 ----A---- C:\Windows\system32\cscript.exe
2013-12-11 13:24:09 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 13:24:09 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-10 20:31:14 ----A---- C:\autoexec.bat
2013-12-10 20:30:23 ----D---- C:\Program Files\Enigma Software Group
2013-12-10 20:28:23 ----D---- C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-12-07 14:53:09 ----A---- C:\Windows\system32\RTNUninst64.dll
2013-12-07 14:53:09 ----A---- C:\Windows\system32\RtNicProp64.dll
2013-12-07 14:53:09 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2013-12-07 14:47:13 ----A---- C:\Windows\system32\nvopencl.dll
2013-12-07 14:47:13 ----A---- C:\Windows\system32\nvoglv64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2013-12-07 14:47:12 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\NvIFR64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\NvFBC64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\nvdispgenco6433165.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\nvdispco6433165.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvd3dumx.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuvid.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuvenc.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuda.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcompiler.dll
2013-12-07 13:55:57 ----D---- C:\ProgramData\ProductData
2013-12-07 13:55:38 ----D---- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-29 19:53:10 ----D---- C:\Program Files (x86)\Crux Technologies
2013-11-29 19:36:20 ----D---- C:\Program Files (x86)\Moo0
2013-11-29 19:15:25 ----D---- C:\Users\INDI\AppData\Roaming\AMPSoft
2013-11-26 15:38:22 ----D---- C:\Users\INDI\AppData\Roaming\Dropbox
2013-11-22 18:08:43 ----D---- C:\Program Files\GIMP 2
2013-11-20 03:20:10 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-20 03:06:29 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-20 03:06:29 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-20 03:06:22 ----A---- C:\Windows\system32\elshyph.dll
2013-11-20 03:06:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-20 03:06:11 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\wextract.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\webcheck.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\vbscript.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\url.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\occache.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msrating.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msls31.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshta.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\jscript.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\inseng.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\imgutil.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iexpress.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iepeers.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-20 03:06:10 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\icardie.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-19 18:33:23 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-19 18:33:23 ----A---- C:\Windows\system32\authui.dll
2013-11-19 18:33:22 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-19 18:33:22 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-19 18:33:22 ----A---- C:\Windows\system32\credui.dll
2013-11-19 18:33:21 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-19 18:32:54 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-19 18:32:54 ----A---- C:\Windows\system32\gdi32.dll
2013-11-19 18:32:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-19 18:32:24 ----A---- C:\Windows\system32\crypt32.dll
2013-11-19 18:31:14 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\sspicli.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\schannel.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\secur32.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\lsass.exe
2013-11-19 18:30:34 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-19 18:30:33 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-19 18:30:02 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-19 18:30:01 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-19 18:30:01 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-19 18:30:01 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-19 18:30:01 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-16 01:59:14 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2013-12-14 22:14:26 ----D---- C:\Windows\Prefetch
2013-12-14 22:14:14 ----RD---- C:\Program Files
2013-12-14 18:56:28 ----D---- C:\Program Files (x86)\The KMPlayer
2013-12-14 18:49:37 ----D---- C:\Program Files (x86)
2013-12-14 18:49:29 ----HD---- C:\ProgramData
2013-12-14 18:46:19 ----D---- C:\Program Files (x86)\IObit
2013-12-14 18:46:15 ----D---- C:\Windows\Tasks
2013-12-14 18:46:15 ----D---- C:\Windows\system32\Tasks
2013-12-14 18:43:26 ----AD---- C:\Windows
2013-12-14 18:40:18 ----D---- C:\Windows\System32
2013-12-14 18:40:17 ----SD---- C:\ProgramData\Microsoft
2013-12-14 12:57:22 ----D---- C:\Windows\Temp
2013-12-14 12:49:46 ----D---- C:\Windows\system32\drivers\etc
2013-12-14 11:12:43 ----D---- C:\Windows\system32\drivers
2013-12-14 11:12:43 ----D---- C:\Users\INDI\AppData\Roaming\IObit
2013-12-14 11:12:14 ----D---- C:\ProgramData\IObit
2013-12-12 04:13:42 ----D---- C:\Windows\system32\config
2013-12-12 04:01:26 ----D---- C:\Windows\rescache
2013-12-12 03:28:50 ----D---- C:\Windows\inf
2013-12-12 03:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-12 03:25:43 ----D---- C:\Windows\winsxs
2013-12-12 03:21:13 ----D---- C:\Windows\SysWOW64
2013-12-12 03:21:13 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-12 03:21:09 ----D---- C:\Program Files\Windows Media Player
2013-12-12 03:21:07 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-12 03:21:05 ----D---- C:\Program Files\Internet Explorer
2013-12-12 03:20:56 ----D---- C:\Windows\SYSWOW64\fr-FR
2013-12-12 03:20:56 ----D---- C:\Windows\SYSWOW64\de-DE
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\ar-SA
2013-12-12 03:20:54 ----D---- C:\Windows\system32\sk-SK
2013-12-12 03:20:54 ----D---- C:\Windows\system32\fr-FR
2013-12-12 03:20:54 ----D---- C:\Windows\system32\en-US
2013-12-12 03:20:54 ----D---- C:\Windows\system32\de-DE
2013-12-12 03:20:54 ----D---- C:\Windows\system32\cs-CZ
2013-12-12 03:20:54 ----D---- C:\Windows\system32\ar-SA
2013-12-12 03:20:53 ----D---- C:\Windows\system32\DriverStore
2013-12-12 03:04:04 ----D---- C:\Windows\system32\catroot
2013-12-12 03:02:30 ----D---- C:\Windows\system32\catroot2
2013-12-12 03:01:02 ----SHD---- C:\System Volume Information
2013-12-11 20:56:42 ----RSD---- C:\Windows\Fonts
2013-12-11 16:13:31 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-11 14:39:04 ----D---- C:\Users\INDI\AppData\Roaming\DVDVideoSoft
2013-12-11 10:40:46 ----SHD---- C:\Windows\Installer
2013-12-11 10:40:42 ----SHD---- C:\Config.Msi
2013-12-11 10:37:51 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-10 20:28:12 ----D---- C:\Program Files (x86)\Common Files
2013-12-10 20:09:13 ----D---- C:\Program Files (x86)\SqueakyChocolate
2013-12-10 20:08:21 ----D---- C:\Program Files (x86)\SoftQuick
2013-12-10 14:04:49 ----D---- C:\Windows\system32\NDF
2013-12-07 22:17:35 ----D---- C:\Users\INDI\AppData\Roaming\vlc
2013-12-07 14:57:17 ----D---- C:\Windows\SoftwareDistribution
2013-12-07 14:56:45 ----D---- C:\Windows\debug
2013-12-07 14:50:50 ----D---- C:\ProgramData\NVIDIA
2013-12-07 14:50:07 ----D---- C:\TEMP
2013-12-07 14:49:40 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-12-07 14:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvapi64.dll
2013-12-07 14:47:10 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2013-12-07 14:09:20 ----D---- C:\Windows\Panther
2013-12-07 14:09:20 ----D---- C:\Windows\ModemLogs
2013-12-07 14:09:19 ----D---- C:\Windows\Logs
2013-12-07 14:09:18 ----D---- C:\Windows\Downloaded Program Files
2013-12-07 14:09:16 ----D---- C:\Program Files (x86)\PDFCreator
2013-12-07 14:05:23 ----SHD---- C:\Boot
2013-11-30 15:29:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-22 17:54:45 ----RASHD---- C:\hwevid
2013-11-20 03:36:47 ----D---- C:\Windows\SYSWOW64\migration
2013-11-20 03:36:15 ----D---- C:\Windows\PolicyDefinitions
2013-11-20 03:36:14 ----D---- C:\Windows\system32\migration
2013-11-20 03:03:46 ----D---- C:\Windows\system32\MRT
2013-11-20 03:01:29 ----A---- C:\Windows\system32\MRT.exe
2013-11-18 21:31:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2013-09-24 23168]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2013-11-14 709144]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2013-09-24 48872]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2013-09-24 96800]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2007-04-13 105176]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 monectdevices;Monect Hid Device; C:\Windows\system32\DRIVERS\monectdevices.sys [2013-03-23 10432]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-12-07 883928]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2010-08-10 22792]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2010-08-10 50056]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2012-11-28 35112]
R4 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys []
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthMtpEnum;Modul pro výčet zařízení Bluetooth MTP; C:\Windows\system32\DRIVERS\BthMtpEnum.sys [2009-07-14 64512]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 CrystalSysInfo;CrystalSysInfo; C:\Windows\system32\drivers\CrystalSysInfo.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2013-04-24 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2013-04-24 27760]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 SaiH0464;SaiH0464; C:\Windows\system32\DRIVERS\SaiH0464.sys [2007-05-01 171144]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;tsusbhub; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;Sony sa0104 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-10-20 6254152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2012-06-27 73728]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MonectServerService;MonectServerService; D:\Instalace\Remote Control Android\MonectServerService.exe [2013-04-05 72192]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-10-23 922912]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 PDF Architect Helper Service;PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [2012-11-22 1522312]
R2 PDF Architect Service;PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [2012-11-22 905864]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-10-01 5087584]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-19 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-14 1266464]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-09-24 164056]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-19 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-16 119408]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 SureThing Labelflash service;SureThing Labelflash service; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-10-20 74392]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-20 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 22:48
od Rudy
Nic se neděje, zkusíme to přes vámi přiložený log RSIT. Spusťtě tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Problém s viry (awardhotspot, atd)

Napsal: 14 pro 2013 23:59
od cm_L_da
Zde je log z AdwCleaner:

# AdwCleaner v3.015 - Report created 14/12/2013 at 23:53:45
# Updated 10/12/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : INDI - INDI-PC
# Running from : C:\Users\INDI\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaveByclick
Folder Deleted : C:\Users\INDI\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedmngkbaffkenlfdcbganndoghblmap
Folder Deleted : C:\Users\INDI\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjbbjfdilbioabojmcplalojlmdngbjl
Folder Deleted : C:\Users\INDI\AppData\Local\Google\Chrome\User Data\Default\Extensions\poheodfamflhhhdcmjfeggbgigeefaco

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [12x3q@3244516.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [xz123@ya456.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dedmngkbaffkenlfdcbganndoghblmap
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\poheodfamflhhhdcmjfeggbgigeefaco
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{462862BE-9A5C-49A5-9CBD-A649EAC63645}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKCU\Software\Popajar
Key Deleted : HKCU\Software\SmileysWeLove
Key Deleted : HKLM\Software\BetterSurf
Key Deleted : HKLM\Software\PIP
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default\prefs.js ]


-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\INDI\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage

*************************

AdwCleaner[R0].txt - [4985 octets] - [14/12/2013 23:51:28]
AdwCleaner[S0].txt - [4464 octets] - [14/12/2013 23:53:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4524 octets] ##########

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 11:12
od Rudy
Dejte nový log RSIT.

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 11:32
od cm_L_da
Logfile of random's system information tool 1.09 (written by random/random)
Run by INDI at 2013-12-15 11:30:56
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 23 GB (23%) free of 100 GB
Total RAM: 3519 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:31:13, on 15.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\hwevid\hwevid.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\trend micro\INDI.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?ptr=100&crg=3. ... 5FF443EA76}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: (no name) - {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - (no file)
O3 - Toolbar: (no name) - {CF0F43AB-9C23-4D7B-8040-201B82844854} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [hwevid] C:\hwevid\akt.exe hwevid
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\INDI\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [Application Restart #0] D:\Instalace\Remote Control Android\MonectHost.exe /RestartByRestartManager:19312E76-19EC-48f1-8100-D290B5CE3FBF (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Application Restart #0] D:\Instalace\Remote Control Android\MonectHost.exe /RestartByRestartManager:19312E76-19EC-48f1-8100-D290B5CE3FBF (User 'Default user')
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MonectServerService - Monect - D:\Instalace\Remote Control Android\MonectServerService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PDF Architect Helper Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SureThing Labelflash service - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 12293 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
"D:\Instalace\Remote Control Android\MonectServerService.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\PDF Architect\HelperService.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"C:\Program Files (x86)\PDF Architect\ConversionService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Program Files\Saitek\SD6\Software\ProfilerU.exe"
"C:\Program Files\Saitek\SD6\Software\SaiMfd.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\hwevid\hwevid.exe"
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
taskeng.exe {53EFAA3E-3CA1-4389-B3FA-9F5037967F8C}
"C:\Users\INDI\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4113872694-1721576408-89762151-1001Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4113872694-1721576408-89762151-1001UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://login.szn.cz/?returnURL=https%3a ... ilLogout=1"
prefs.js - "keyword.URL" - ""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\Sony\Media Go\npmediago.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default\extensions\
adsremoval@adsremoval.net
ascsurfingprotection@iobit.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]
SmileysWeLoveToolbar - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}]
PDF Architect Helper - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2012-11-22 91784]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2013-10-03 583520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-10-17 669504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CF0F43AB-9C23-4D7B-8040-201B82844854} - SmileysWeLove - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CF0F43AB-9C23-4D7B-8040-201B82844854}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-11-11 1612504]
"ProfilerU"=C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [2010-07-29 310272]
"SaiMfd"=C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [2010-07-29 158208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2012-07-02 2736128]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-05-29 449248]
"Facebook Update"=C:\Users\INDI\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-10-14 138096]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"CloneCDTray"=C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [2009-01-29 57344]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]
"hwevid"=C:\hwevid\akt.exe [2013-08-27 824320]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

C:\Users\INDI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EvernoteClipper.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-12-14 23:51:25 ----D---- C:\AdwCleaner
2013-12-14 22:14:14 ----D---- C:\Program Files\trend micro
2013-12-14 22:14:13 ----D---- C:\rsit
2013-12-14 21:43:53 ----D---- C:\FRST
2013-12-14 18:43:26 ----D---- C:\Windows\ERUNT
2013-12-14 18:40:11 ----A---- C:\Windows\wininit.ini
2013-12-14 12:37:05 ----D---- C:\ProgramData\Spybot - Search & Destroy
2013-12-14 12:36:58 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-12-14 11:12:43 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2013-12-12 03:03:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-12 03:03:49 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-12 03:03:48 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-12 03:03:46 ----A---- C:\Windows\system32\wmp.dll
2013-12-12 03:02:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:02:13 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-12 03:02:13 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-12 03:02:13 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-12 03:02:13 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-12 03:02:13 ----A---- C:\Windows\system32\ieui.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\mshtml.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\iesetup.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\iernonce.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-12 03:02:11 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-12 03:02:11 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-12 03:02:11 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-12 03:02:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-12 03:02:10 ----A---- C:\Windows\system32\iertutil.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-12 03:02:09 ----A---- C:\Windows\system32\wininet.dll
2013-12-12 03:02:08 ----A---- C:\Windows\system32\urlmon.dll
2013-12-12 03:02:07 ----A---- C:\Windows\system32\ieframe.dll
2013-12-12 03:02:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-12 03:02:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-12 03:02:05 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-12 03:02:04 ----A---- C:\Windows\system32\jscript9.dll
2013-12-11 20:46:35 ----N---- C:\Windows\system32\fppr4-x64.dll
2013-12-11 20:46:35 ----N---- C:\Windows\system32\fppmon4.dll
2013-12-11 13:24:21 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-11 13:24:21 ----A---- C:\Windows\system32\msieftp.dll
2013-12-11 13:24:20 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-11 13:24:20 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-11 13:24:20 ----A---- C:\Windows\system32\win32k.sys
2013-12-11 13:24:19 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-11 13:24:18 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-11 13:24:15 ----A---- C:\Windows\system32\tzres.dll
2013-12-11 13:24:14 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-11 13:24:11 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-11 13:24:11 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-11 13:24:10 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 13:24:10 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 13:24:10 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 13:24:10 ----A---- C:\Windows\system32\cscript.exe
2013-12-11 13:24:09 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 13:24:09 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-10 20:31:14 ----A---- C:\autoexec.bat
2013-12-10 20:30:23 ----D---- C:\Program Files\Enigma Software Group
2013-12-10 20:28:23 ----D---- C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-12-07 14:53:09 ----A---- C:\Windows\system32\RTNUninst64.dll
2013-12-07 14:53:09 ----A---- C:\Windows\system32\RtNicProp64.dll
2013-12-07 14:53:09 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2013-12-07 14:47:13 ----A---- C:\Windows\system32\nvopencl.dll
2013-12-07 14:47:13 ----A---- C:\Windows\system32\nvoglv64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2013-12-07 14:47:12 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\NvIFR64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\NvFBC64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\nvdispgenco6433165.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\nvdispco6433165.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvd3dumx.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuvid.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuvenc.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuda.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcompiler.dll
2013-12-07 13:55:57 ----D---- C:\ProgramData\ProductData
2013-12-07 13:55:38 ----D---- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-29 19:53:10 ----D---- C:\Program Files (x86)\Crux Technologies
2013-11-29 19:36:20 ----D---- C:\Program Files (x86)\Moo0
2013-11-29 19:15:25 ----D---- C:\Users\INDI\AppData\Roaming\AMPSoft
2013-11-26 15:38:22 ----D---- C:\Users\INDI\AppData\Roaming\Dropbox
2013-11-22 18:08:43 ----D---- C:\Program Files\GIMP 2
2013-11-20 03:20:10 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-20 03:06:29 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-20 03:06:29 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-20 03:06:22 ----A---- C:\Windows\system32\elshyph.dll
2013-11-20 03:06:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-20 03:06:11 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\wextract.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\webcheck.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\vbscript.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\url.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\occache.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msrating.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msls31.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshta.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\jscript.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\inseng.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\imgutil.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iexpress.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iepeers.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-20 03:06:10 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\icardie.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-19 18:33:23 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-19 18:33:23 ----A---- C:\Windows\system32\authui.dll
2013-11-19 18:33:22 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-19 18:33:22 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-19 18:33:22 ----A---- C:\Windows\system32\credui.dll
2013-11-19 18:33:21 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-19 18:32:54 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-19 18:32:54 ----A---- C:\Windows\system32\gdi32.dll
2013-11-19 18:32:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-19 18:32:24 ----A---- C:\Windows\system32\crypt32.dll
2013-11-19 18:31:14 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\sspicli.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\schannel.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\secur32.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\lsass.exe
2013-11-19 18:30:34 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-19 18:30:33 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-19 18:30:02 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-19 18:30:01 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-19 18:30:01 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-19 18:30:01 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-19 18:30:01 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-16 01:59:14 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2013-12-15 11:31:09 ----D---- C:\Windows\Prefetch
2013-12-15 01:00:56 ----D---- C:\Windows\Temp
2013-12-14 23:57:39 ----AD---- C:\Windows
2013-12-14 22:14:14 ----RD---- C:\Program Files
2013-12-14 18:56:28 ----D---- C:\Program Files (x86)\The KMPlayer
2013-12-14 18:49:37 ----D---- C:\Program Files (x86)
2013-12-14 18:49:29 ----HD---- C:\ProgramData
2013-12-14 18:46:19 ----D---- C:\Program Files (x86)\IObit
2013-12-14 18:46:15 ----D---- C:\Windows\Tasks
2013-12-14 18:46:15 ----D---- C:\Windows\system32\Tasks
2013-12-14 18:40:18 ----D---- C:\Windows\System32
2013-12-14 18:40:17 ----SD---- C:\ProgramData\Microsoft
2013-12-14 12:49:46 ----D---- C:\Windows\system32\drivers\etc
2013-12-14 11:12:43 ----D---- C:\Windows\system32\drivers
2013-12-14 11:12:43 ----D---- C:\Users\INDI\AppData\Roaming\IObit
2013-12-14 11:12:14 ----D---- C:\ProgramData\IObit
2013-12-12 04:13:42 ----D---- C:\Windows\system32\config
2013-12-12 04:01:26 ----D---- C:\Windows\rescache
2013-12-12 03:28:50 ----D---- C:\Windows\inf
2013-12-12 03:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-12 03:25:43 ----D---- C:\Windows\winsxs
2013-12-12 03:21:13 ----D---- C:\Windows\SysWOW64
2013-12-12 03:21:13 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-12 03:21:09 ----D---- C:\Program Files\Windows Media Player
2013-12-12 03:21:07 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-12 03:21:05 ----D---- C:\Program Files\Internet Explorer
2013-12-12 03:20:56 ----D---- C:\Windows\SYSWOW64\fr-FR
2013-12-12 03:20:56 ----D---- C:\Windows\SYSWOW64\de-DE
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\ar-SA
2013-12-12 03:20:54 ----D---- C:\Windows\system32\sk-SK
2013-12-12 03:20:54 ----D---- C:\Windows\system32\fr-FR
2013-12-12 03:20:54 ----D---- C:\Windows\system32\en-US
2013-12-12 03:20:54 ----D---- C:\Windows\system32\de-DE
2013-12-12 03:20:54 ----D---- C:\Windows\system32\cs-CZ
2013-12-12 03:20:54 ----D---- C:\Windows\system32\ar-SA
2013-12-12 03:20:53 ----D---- C:\Windows\system32\DriverStore
2013-12-12 03:04:04 ----D---- C:\Windows\system32\catroot
2013-12-12 03:02:30 ----D---- C:\Windows\system32\catroot2
2013-12-12 03:01:02 ----SHD---- C:\System Volume Information
2013-12-11 20:56:42 ----RSD---- C:\Windows\Fonts
2013-12-11 16:13:31 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-11 14:39:04 ----D---- C:\Users\INDI\AppData\Roaming\DVDVideoSoft
2013-12-11 10:40:46 ----SHD---- C:\Windows\Installer
2013-12-11 10:40:42 ----SHD---- C:\Config.Msi
2013-12-11 10:37:51 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-10 20:28:12 ----D---- C:\Program Files (x86)\Common Files
2013-12-10 20:09:13 ----D---- C:\Program Files (x86)\SqueakyChocolate
2013-12-10 20:08:21 ----D---- C:\Program Files (x86)\SoftQuick
2013-12-10 14:04:49 ----D---- C:\Windows\system32\NDF
2013-12-07 22:17:35 ----D---- C:\Users\INDI\AppData\Roaming\vlc
2013-12-07 14:57:17 ----D---- C:\Windows\SoftwareDistribution
2013-12-07 14:56:45 ----D---- C:\Windows\debug
2013-12-07 14:50:50 ----D---- C:\ProgramData\NVIDIA
2013-12-07 14:50:07 ----D---- C:\TEMP
2013-12-07 14:49:40 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-12-07 14:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvapi64.dll
2013-12-07 14:47:10 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2013-12-07 14:09:20 ----D---- C:\Windows\Panther
2013-12-07 14:09:20 ----D---- C:\Windows\ModemLogs
2013-12-07 14:09:19 ----D---- C:\Windows\Logs
2013-12-07 14:09:18 ----D---- C:\Windows\Downloaded Program Files
2013-12-07 14:09:16 ----D---- C:\Program Files (x86)\PDFCreator
2013-12-07 14:05:23 ----SHD---- C:\Boot
2013-11-30 15:29:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-22 17:54:45 ----RASHD---- C:\hwevid
2013-11-20 03:36:47 ----D---- C:\Windows\SYSWOW64\migration
2013-11-20 03:36:15 ----D---- C:\Windows\PolicyDefinitions
2013-11-20 03:36:14 ----D---- C:\Windows\system32\migration
2013-11-20 03:03:46 ----D---- C:\Windows\system32\MRT
2013-11-20 03:01:29 ----A---- C:\Windows\system32\MRT.exe
2013-11-18 21:31:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2013-09-24 23168]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2013-11-14 709144]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2013-09-24 48872]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2013-09-24 96800]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2007-04-13 105176]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 monectdevices;Monect Hid Device; C:\Windows\system32\DRIVERS\monectdevices.sys [2013-03-23 10432]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-12-07 883928]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2010-08-10 22792]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2010-08-10 50056]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2012-11-28 35112]
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthMtpEnum;Modul pro výčet zařízení Bluetooth MTP; C:\Windows\system32\DRIVERS\BthMtpEnum.sys [2009-07-14 64512]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 CrystalSysInfo;CrystalSysInfo; C:\Windows\system32\drivers\CrystalSysInfo.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2013-04-24 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2013-04-24 27760]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 SaiH0464;SaiH0464; C:\Windows\system32\DRIVERS\SaiH0464.sys [2007-05-01 171144]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;tsusbhub; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;Sony sa0104 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-10-20 6254152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2012-06-27 73728]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MonectServerService;MonectServerService; D:\Instalace\Remote Control Android\MonectServerService.exe [2013-04-05 72192]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-10-23 922912]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 PDF Architect Helper Service;PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [2012-11-22 1522312]
R2 PDF Architect Service;PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [2012-11-22 905864]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-10-01 5087584]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-19 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-14 1266464]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-09-24 164056]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-19 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-16 119408]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 SureThing Labelflash service;SureThing Labelflash service; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-10-20 74392]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-20 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 12:03
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\hwevid\akt.exe
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4113872694-1721576408-89762151-1001Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4113872694-1721576408-89762151-1001UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Users\INDI\AppData\Local\Facebook\Update
C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"hwevid"=-
"SunJavaUpdateSched"=-

:commands
[Purity]
[Empytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 12:25
od cm_L_da
Zde log po provedení akcí:

Logfile of random's system information tool 1.09 (written by random/random)
Run by INDI at 2013-12-15 12:24:01
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 23 GB (23%) free of 100 GB
Total RAM: 3519 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:24:20, on 15.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\trend micro\INDI.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?ptr=100&crg=3. ... 5FF443EA76}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CF0F43AB-9C23-4D7B-8040-201B82844854} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [Application Restart #0] D:\Instalace\Remote Control Android\MonectHost.exe /RestartByRestartManager:19312E76-19EC-48f1-8100-D290B5CE3FBF (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Application Restart #0] D:\Instalace\Remote Control Android\MonectHost.exe /RestartByRestartManager:19312E76-19EC-48f1-8100-D290B5CE3FBF (User 'Default user')
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O8 - Extra context menu item: Clip Image - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MonectServerService - Monect - D:\Instalace\Remote Control Android\MonectServerService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PDF Architect Helper Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SureThing Labelflash service - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 11851 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
taskeng.exe {F25530C2-E768-40EA-BA6E-3F5DB58AC936}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
taskeng.exe {A5F2E15C-60FF-4197-B992-694932C2B01B}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
"D:\Instalace\Remote Control Android\MonectServerService.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\PDF Architect\HelperService.exe"
"C:\Program Files (x86)\PDF Architect\ConversionService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Program Files\Saitek\SD6\Software\ProfilerU.exe"
"C:\Program Files\Saitek\SD6\Software\SaiMfd.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe"
"C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version8\TeamViewer8_Logfile.log
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
"C:\Users\INDI\Desktop\RSITx64.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\sppsvc.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://login.szn.cz/?returnURL=https%3a ... ilLogout=1"
prefs.js - "keyword.URL" - ""

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\Sony\Media Go\npmediago.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


C:\Users\INDI\AppData\Roaming\Mozilla\Firefox\Profiles\u88yrlve.default\extensions\
adsremoval@adsremoval.net
ascsurfingprotection@iobit.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}]
SmileysWeLoveToolbar - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}]
PDF Architect Helper - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2012-11-22 91784]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2013-10-03 583520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-10-17 669504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CF0F43AB-9C23-4D7B-8040-201B82844854} - SmileysWeLove - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CF0F43AB-9C23-4D7B-8040-201B82844854}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-11-11 1612504]
"ProfilerU"=C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [2010-07-29 310272]
"SaiMfd"=C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [2010-07-29 158208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2012-07-02 2736128]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-05-29 449248]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"CloneCDTray"=C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [2009-01-29 57344]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]

C:\Users\INDI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EvernoteClipper.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter"=ac3filter64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-12-15 12:19:20 ----D---- C:\_OTM
2013-12-14 23:51:25 ----D---- C:\AdwCleaner
2013-12-14 22:14:14 ----D---- C:\Program Files\trend micro
2013-12-14 22:14:13 ----D---- C:\rsit
2013-12-14 21:43:53 ----D---- C:\FRST
2013-12-14 18:43:26 ----D---- C:\Windows\ERUNT
2013-12-14 18:40:11 ----A---- C:\Windows\wininit.ini
2013-12-14 12:37:05 ----D---- C:\ProgramData\Spybot - Search & Destroy
2013-12-14 12:36:58 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-12-14 11:12:43 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2013-12-12 03:03:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-12 03:03:49 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-12 03:03:48 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-12 03:03:46 ----A---- C:\Windows\system32\wmp.dll
2013-12-12 03:02:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:02:13 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-12 03:02:13 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-12 03:02:13 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-12 03:02:13 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-12 03:02:13 ----A---- C:\Windows\system32\ieui.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\mshtml.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\iesetup.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\iernonce.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:02:12 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-12 03:02:11 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-12 03:02:11 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-12 03:02:11 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-12 03:02:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-12 03:02:10 ----A---- C:\Windows\system32\iertutil.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-12 03:02:09 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-12 03:02:09 ----A---- C:\Windows\system32\wininet.dll
2013-12-12 03:02:08 ----A---- C:\Windows\system32\urlmon.dll
2013-12-12 03:02:07 ----A---- C:\Windows\system32\ieframe.dll
2013-12-12 03:02:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-12 03:02:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-12 03:02:05 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-12 03:02:04 ----A---- C:\Windows\system32\jscript9.dll
2013-12-11 20:46:35 ----N---- C:\Windows\system32\fppr4-x64.dll
2013-12-11 20:46:35 ----N---- C:\Windows\system32\fppmon4.dll
2013-12-11 13:24:21 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-11 13:24:21 ----A---- C:\Windows\system32\msieftp.dll
2013-12-11 13:24:20 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-11 13:24:20 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-11 13:24:20 ----A---- C:\Windows\system32\win32k.sys
2013-12-11 13:24:19 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-11 13:24:18 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-11 13:24:15 ----A---- C:\Windows\system32\tzres.dll
2013-12-11 13:24:14 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-11 13:24:11 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-11 13:24:11 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-11 13:24:10 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 13:24:10 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 13:24:10 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 13:24:10 ----A---- C:\Windows\system32\cscript.exe
2013-12-11 13:24:09 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 13:24:09 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-10 20:31:14 ----A---- C:\autoexec.bat
2013-12-10 20:30:23 ----D---- C:\Program Files\Enigma Software Group
2013-12-07 14:53:09 ----A---- C:\Windows\system32\RTNUninst64.dll
2013-12-07 14:53:09 ----A---- C:\Windows\system32\RtNicProp64.dll
2013-12-07 14:53:09 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2013-12-07 14:47:13 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2013-12-07 14:47:13 ----A---- C:\Windows\system32\nvopencl.dll
2013-12-07 14:47:13 ----A---- C:\Windows\system32\nvoglv64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2013-12-07 14:47:12 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\NvIFR64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\NvFBC64.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\nvdispgenco6433165.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\nvdispco6433165.dll
2013-12-07 14:47:12 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvd3dumx.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuvid.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuvenc.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcuda.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvcompiler.dll
2013-12-07 13:55:57 ----D---- C:\ProgramData\ProductData
2013-12-07 13:55:38 ----D---- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-29 19:53:10 ----D---- C:\Program Files (x86)\Crux Technologies
2013-11-29 19:36:20 ----D---- C:\Program Files (x86)\Moo0
2013-11-29 19:15:25 ----D---- C:\Users\INDI\AppData\Roaming\AMPSoft
2013-11-26 15:38:22 ----D---- C:\Users\INDI\AppData\Roaming\Dropbox
2013-11-22 18:08:43 ----D---- C:\Program Files\GIMP 2
2013-11-20 03:20:10 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-11-20 03:06:29 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-11-20 03:06:29 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-11-20 03:06:22 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-11-20 03:06:22 ----A---- C:\Windows\system32\elshyph.dll
2013-11-20 03:06:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-11-20 03:06:20 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\url.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-11-20 03:06:19 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-11-20 03:06:18 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-11-20 03:06:17 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-11-20 03:06:16 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-11-20 03:06:15 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-11-20 03:06:14 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-11-20 03:06:11 ----A---- C:\Windows\system32\jsIntl.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\wextract.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\webcheck.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\vbscript.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\url.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\pngfilt.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\occache.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msrating.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msls31.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmler.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshtmled.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\mshta.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeedssync.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\msfeeds.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\licmgr10.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\jscript.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\inseng.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\imgutil.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iexpress.exe
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iesysprep.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iepeers.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\iedkcs32.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\ieapfltr.dat
2013-11-20 03:06:10 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\icardie.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\dxtrans.dll
2013-11-20 03:06:10 ----A---- C:\Windows\system32\dxtmsft.dll
2013-11-19 18:33:23 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-19 18:33:23 ----A---- C:\Windows\system32\authui.dll
2013-11-19 18:33:22 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-19 18:33:22 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-19 18:33:22 ----A---- C:\Windows\system32\credui.dll
2013-11-19 18:33:21 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-19 18:32:54 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-19 18:32:54 ----A---- C:\Windows\system32\gdi32.dll
2013-11-19 18:32:24 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-19 18:32:24 ----A---- C:\Windows\system32\crypt32.dll
2013-11-19 18:31:14 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-19 18:30:34 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\sspicli.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\schannel.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\secur32.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\lsass.exe
2013-11-19 18:30:34 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-19 18:30:34 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-19 18:30:33 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-19 18:30:02 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-19 18:30:01 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-19 18:30:01 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-19 18:30:01 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-19 18:30:01 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2013-11-16 01:59:14 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2013-12-15 12:24:16 ----D---- C:\Windows\Prefetch
2013-12-15 12:23:21 ----D---- C:\Windows\Temp
2013-12-15 12:22:27 ----AD---- C:\Windows
2013-12-15 12:19:20 ----RASHD---- C:\hwevid
2013-12-15 12:19:20 ----D---- C:\Windows\Tasks
2013-12-14 22:14:14 ----RD---- C:\Program Files
2013-12-14 18:56:28 ----D---- C:\Program Files (x86)\The KMPlayer
2013-12-14 18:49:37 ----D---- C:\Program Files (x86)
2013-12-14 18:49:29 ----HD---- C:\ProgramData
2013-12-14 18:46:19 ----D---- C:\Program Files (x86)\IObit
2013-12-14 18:46:15 ----D---- C:\Windows\system32\Tasks
2013-12-14 18:40:18 ----D---- C:\Windows\System32
2013-12-14 18:40:17 ----SD---- C:\ProgramData\Microsoft
2013-12-14 12:49:46 ----D---- C:\Windows\system32\drivers\etc
2013-12-14 11:12:43 ----D---- C:\Windows\system32\drivers
2013-12-14 11:12:43 ----D---- C:\Users\INDI\AppData\Roaming\IObit
2013-12-14 11:12:14 ----D---- C:\ProgramData\IObit
2013-12-12 04:13:42 ----D---- C:\Windows\system32\config
2013-12-12 04:01:26 ----D---- C:\Windows\rescache
2013-12-12 03:28:50 ----D---- C:\Windows\inf
2013-12-12 03:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-12 03:25:43 ----D---- C:\Windows\winsxs
2013-12-12 03:21:13 ----D---- C:\Windows\SysWOW64
2013-12-12 03:21:13 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-12 03:21:09 ----D---- C:\Program Files\Windows Media Player
2013-12-12 03:21:07 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-12 03:21:05 ----D---- C:\Program Files\Internet Explorer
2013-12-12 03:20:56 ----D---- C:\Windows\SYSWOW64\fr-FR
2013-12-12 03:20:56 ----D---- C:\Windows\SYSWOW64\de-DE
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-12 03:20:55 ----D---- C:\Windows\SYSWOW64\ar-SA
2013-12-12 03:20:54 ----D---- C:\Windows\system32\sk-SK
2013-12-12 03:20:54 ----D---- C:\Windows\system32\fr-FR
2013-12-12 03:20:54 ----D---- C:\Windows\system32\en-US
2013-12-12 03:20:54 ----D---- C:\Windows\system32\de-DE
2013-12-12 03:20:54 ----D---- C:\Windows\system32\cs-CZ
2013-12-12 03:20:54 ----D---- C:\Windows\system32\ar-SA
2013-12-12 03:20:53 ----D---- C:\Windows\system32\DriverStore
2013-12-12 03:04:04 ----D---- C:\Windows\system32\catroot
2013-12-12 03:02:30 ----D---- C:\Windows\system32\catroot2
2013-12-12 03:01:02 ----SHD---- C:\System Volume Information
2013-12-11 20:56:42 ----RSD---- C:\Windows\Fonts
2013-12-11 16:13:31 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-11 14:39:04 ----D---- C:\Users\INDI\AppData\Roaming\DVDVideoSoft
2013-12-11 10:40:46 ----SHD---- C:\Windows\Installer
2013-12-11 10:40:42 ----SHD---- C:\Config.Msi
2013-12-11 10:37:51 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-10 20:28:12 ----D---- C:\Program Files (x86)\Common Files
2013-12-10 20:09:13 ----D---- C:\Program Files (x86)\SqueakyChocolate
2013-12-10 20:08:21 ----D---- C:\Program Files (x86)\SoftQuick
2013-12-10 14:04:49 ----D---- C:\Windows\system32\NDF
2013-12-07 22:17:35 ----D---- C:\Users\INDI\AppData\Roaming\vlc
2013-12-07 14:57:17 ----D---- C:\Windows\SoftwareDistribution
2013-12-07 14:56:45 ----D---- C:\Windows\debug
2013-12-07 14:50:50 ----D---- C:\ProgramData\NVIDIA
2013-12-07 14:50:07 ----D---- C:\TEMP
2013-12-07 14:49:40 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-12-07 14:47:14 ----A---- C:\Windows\system32\nvwgf2umx.dll
2013-12-07 14:47:11 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2013-12-07 14:47:11 ----A---- C:\Windows\system32\nvapi64.dll
2013-12-07 14:47:10 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2013-12-07 14:09:20 ----D---- C:\Windows\Panther
2013-12-07 14:09:20 ----D---- C:\Windows\ModemLogs
2013-12-07 14:09:19 ----D---- C:\Windows\Logs
2013-12-07 14:09:18 ----D---- C:\Windows\Downloaded Program Files
2013-12-07 14:09:16 ----D---- C:\Program Files (x86)\PDFCreator
2013-12-07 14:05:23 ----SHD---- C:\Boot
2013-11-30 15:29:04 ----D---- C:\ProgramData\Microsoft Help
2013-11-20 03:36:47 ----D---- C:\Windows\SYSWOW64\migration
2013-11-20 03:36:15 ----D---- C:\Windows\PolicyDefinitions
2013-11-20 03:36:14 ----D---- C:\Windows\system32\migration
2013-11-20 03:03:46 ----D---- C:\Windows\system32\MRT
2013-11-20 03:01:29 ----A---- C:\Windows\system32\MRT.exe
2013-11-18 21:31:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2013-09-24 23168]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2013-11-14 709144]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2013-09-24 48872]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2013-09-24 96800]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2007-04-13 105176]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 monectdevices;Monect Hid Device; C:\Windows\system32\DRIVERS\monectdevices.sys [2013-03-23 10432]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-12-07 883928]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2010-08-10 22792]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2010-08-10 50056]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2012-11-28 35112]
S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 29184]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthMtpEnum;Modul pro výčet zařízení Bluetooth MTP; C:\Windows\system32\DRIVERS\BthMtpEnum.sys [2009-07-14 64512]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 CrystalSysInfo;CrystalSysInfo; C:\Windows\system32\drivers\CrystalSysInfo.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2013-04-24 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2013-04-24 27760]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 SaiH0464;SaiH0464; C:\Windows\system32\DRIVERS\SaiH0464.sys [2007-05-01 171144]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;tsusbhub; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;Sony sa0104 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-10-20 6254152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2012-06-27 73728]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MonectServerService;MonectServerService; D:\Instalace\Remote Control Android\MonectServerService.exe [2013-04-05 72192]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-10-23 922912]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 PDF Architect Helper Service;PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [2012-11-22 1522312]
R2 PDF Architect Service;PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [2012-11-22 905864]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-10-01 5087584]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-19 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-14 1266464]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-09-24 164056]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-19 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-16 119408]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 SureThing Labelflash service;SureThing Labelflash service; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-10-20 74392]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-20 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 12:28
od cm_L_da
Bohužel stále ještě reklamy awardhotspot.com a public8media.com vyskakují.

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 19:15
od Rudy
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: Problém s viry (awardhotspot, atd)

Napsal: 15 pro 2013 22:42
od cm_L_da
Protokol z MB:

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.12.15.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
INDI :: INDI-PC [administrátor]

Ochrana: Povolena

15.12.2013 19:46:14
mbam-log-2013-12-11 (10-41-38).txt

Typ: Kompletní kontrola (C:\|D:\|E:\|H:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 517764
Uplynulý čas: 2 hodin, 19 minut, 11 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 5
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CF0F43AB-9C23-4D7B-8040-201B82844854} (PUP.Optional.SmileysWeLove.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF0F43AB-9C23-4D7B-8040-201B82844854} (PUP.Optional.SmileysWeLove.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} (PUP.Optional.SmileysWeLove.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} (PUP.Optional.SmileysWeLove.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} (PUP.Optional.SmileysWeLove.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{CF0F43AB-9C23-4D7B-8040-201B82844854} (PUP.Optional.SmileysWeLove.A) -> Data: SmileysWeLoveToolbar.IEModule -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{CF0F43AB-9C23-4D7B-8040-201B82844854} (PUP.Optional.SmileysWeLove.A) -> Data: -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 5
C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-saudi-forf.exe (PUP.Optional.Hao123.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Comodo\Cis\Quarantine\data\{28492B78-350A-4398-B511-B1985883ED3C} (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Comodo\Cis\Quarantine\data\{381F0815-93DF-4A3F-8092-CD4FB8541969} (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Comodo\Cis\Quarantine\data\{DF3E4D45-96F1-40A0-9BEA-B560011807EA} (Adware.BetterSurf) -> Nebyla provedena žádná instrukce.
D:\Instalace\System\Aida\AIDA64 Extreme Edition 2.00.1700.exe (PUP.Optional.Elex.A) -> Nebyla provedena žádná instrukce.

(konec)