Stránka 1 z 2

kontrola logu po odstranění viru

Napsal: 30 říj 2014 20:15
od roman4791
Dobrý den,
prosím o kontrolu logu, minulý týden jsem tam měl vir (zablokovaný počítač policií české republiky), dle návodu na webu jsem sám laicky odstranil - roguekiller - eset online scaner - ccleaner. PC funguje, ale zdá se mi, že to pořád není v pořádku nějak se zpomalil.
Děkuji
zde log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:59:14, on 30.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Roman\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "D:\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-21-2284442310-3605169074-2699344400-1000\..\Run: [CCleaner Monitoring] "D:\CCleaner\CCleaner64.exe" /MONITOR (User '?')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11042 bytes

Re: kontrola logu po odstranění viru

Napsal: 30 říj 2014 20:19
od Rudy
Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: kontrola logu po odstranění viru

Napsal: 30 říj 2014 20:41
od roman4791
tak, provedeno:

# AdwCleaner v3.311 - Report created 30/10/2014 at 20:37:44
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Roman - ROMAN-PC
# Running from : C:\Users\Roman\Desktop\adwcleaner_3.311.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\BitGuard
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files (x86)\TornTV.com
Folder Deleted : C:\Users\Roman\AppData\Local\onlysearch
Folder Deleted : C:\Users\Roman\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Roman\AppData\Roaming\Yontoo
Folder Deleted : C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
File Deleted : C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS
Key Deleted : HKCU\Software\f2dc8ae768b946
Key Deleted : HKLM\SOFTWARE\f2dc8ae768b946
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\filescout
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17344


-\\ Mozilla Firefox v33.0.2 (x86 cs)

[ File : C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yu5b02o1.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://www2.delta-search.com/?q={searchTerms}&affID=119776&tt=gc_&babsrc=SP_ss&mntrId=D42C1A4BD677F884
Deleted [Extension] : aidbbndgjnlaclnmhkdimcdjiebjpdel
Deleted [Extension] : bfcpnihmbfoaeoakalclfalkdepgiaje
Deleted [Extension] : cfcbmgbfdbijmjgjihagbomfbjfjmgon
Deleted [Extension] : hgojaaaiddhmiiakpejiklijbalpckih
Deleted [Extension] : mocblcnaofikinigmceddfghppkkjbog

*************************

AdwCleaner[R0].txt - [3799 octets] - [30/10/2014 20:35:25]
AdwCleaner[S0].txt - [3369 octets] - [30/10/2014 20:37:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3429 octets] ##########

Re: kontrola logu po odstranění viru

Napsal: 30 říj 2014 21:49
od Rudy

Re: kontrola logu po odstranění viru

Napsal: 30 říj 2014 22:05
od roman4791
tu je:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Roman at 2014-10-30 21:59:08
WIN_7 Service Pack 1
System drive C: has 14 GB (19%) free of 76 GB
Total RAM: 2925 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:02:11, on 30.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Roman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "D:\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-21-2284442310-3605169074-2699344400-1000\..\Run: [CCleaner Monitoring] "D:\CCleaner\CCleaner64.exe" /MONITOR (User '?')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11596 bytes

======Listing Processes======


======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yu5b02o1.default

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"Description"=Office Live Update v1.5
"Path"=C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-08-05 132448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-10-01 5595336]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-01-10 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-01-10 392984]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-01-10 417560]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=D:\CCleaner\CCleaner64.exe [2014-09-26 6482200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-02-21 3054136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
D:\CCleaner\CCleaner64.exe [2014-09-26 6482200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant]
C:\Windows\System32\LogiLDA.dll [2012-09-20 1832760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS Premium Sound.lnk]
C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-02-21 156952]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-01-13 7109248]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-01-05 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2011-10-31 1058400]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-01-10 390656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-30 21:59:38 ----D---- C:\Program Files\trend micro
2014-10-30 21:59:08 ----D---- C:\rsit
2014-10-30 20:36:29 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-10-30 20:35:16 ----D---- C:\AdwCleaner
2014-10-29 20:10:23 ----D---- C:\Users\Roman\AppData\Roaming\vlc
2014-10-29 19:48:49 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-10-29 18:40:23 ----D---- C:\Users\Roman\AppData\Roaming\Mozilla
2014-10-29 18:40:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-22 20:10:07 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-10-22 18:05:03 ----D---- C:\ProgramData\Intel
2014-10-21 22:52:41 ----SD---- C:\Windows\system32\CompatTel
2014-10-21 22:40:50 ----A---- C:\Windows\system32\wmploc.DLL
2014-10-21 22:40:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-10-21 22:40:49 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-10-21 22:40:48 ----A---- C:\Windows\system32\wmp.dll
2014-10-21 22:31:30 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-10-21 22:24:11 ----D---- C:\Windows\Migration
2014-10-21 20:15:11 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-10-21 20:15:10 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-10-21 20:15:10 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-10-21 20:15:10 ----A---- C:\Windows\system32\infocardapi.dll
2014-10-21 20:15:10 ----A---- C:\Windows\system32\icardres.dll
2014-10-21 20:15:10 ----A---- C:\Windows\system32\icardagt.exe
2014-10-21 20:14:59 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-10-21 20:14:59 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-10-21 20:11:17 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-21 20:11:17 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-10-21 20:11:07 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate.exe
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc_isv.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\msdrm.dll
2014-10-21 20:11:05 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-10-21 20:11:05 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-10-21 20:10:12 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-10-21 20:10:12 ----A---- C:\Windows\system32\certutil.exe
2014-10-21 20:10:11 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-10-21 20:10:11 ----A---- C:\Windows\system32\certenc.dll
2014-10-21 20:09:59 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-10-21 20:09:59 ----A---- C:\Windows\system32\WMPhoto.dll
2014-10-21 20:09:55 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-10-21 20:09:55 ----A---- C:\Windows\system32\shdocvw.dll
2014-10-21 20:09:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-10-21 20:09:47 ----A---- C:\Windows\system32\wintrust.dll
2014-10-21 20:09:34 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-10-21 20:09:34 ----A---- C:\Windows\system32\crypt32.dll
2014-10-21 20:09:33 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-10-21 20:09:33 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-10-21 20:09:33 ----A---- C:\Windows\system32\cryptsvc.dll
2014-10-21 20:09:33 ----A---- C:\Windows\system32\cryptnet.dll
2014-10-21 20:09:14 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-10-21 20:09:14 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-10-21 20:09:14 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-10-21 20:09:14 ----A---- C:\Windows\system32\credui.dll
2014-10-21 20:09:08 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-10-21 20:09:08 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-10-21 20:09:08 ----A---- C:\Windows\system32\wscript.exe
2014-10-21 20:09:08 ----A---- C:\Windows\system32\scrrun.dll
2014-10-21 20:09:08 ----A---- C:\Windows\system32\cscript.exe
2014-10-21 20:09:07 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-10-21 20:08:56 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\iernonce.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\ie4uinit.exe
2014-10-21 20:08:54 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-10-21 20:08:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-10-21 20:08:53 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-10-21 20:08:53 ----A---- C:\Windows\system32\urlmon.dll
2014-10-21 20:08:53 ----A---- C:\Windows\system32\iedkcs32.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-10-21 20:08:52 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-21 20:08:52 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-10-21 20:08:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-10-21 20:08:52 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-21 20:08:51 ----A---- C:\Windows\system32\iesetup.dll
2014-10-21 20:08:44 ----A---- C:\Windows\system32\iertutil.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-10-21 20:08:43 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-21 20:08:42 ----A---- C:\Windows\system32\ieui.dll
2014-10-21 20:08:42 ----A---- C:\Windows\system32\ieframe.dll
2014-10-21 20:08:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\jscript9diag.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\jscript9.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-21 20:08:40 ----A---- C:\Windows\system32\wininet.dll
2014-10-21 20:08:40 ----A---- C:\Windows\system32\vbscript.dll
2014-10-21 20:08:40 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-10-21 20:08:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-10-21 20:08:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-21 20:08:39 ----A---- C:\Windows\system32\msrating.dll
2014-10-21 20:08:39 ----A---- C:\Windows\system32\mshtml.dll
2014-10-21 20:08:32 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-10-21 20:08:32 ----A---- C:\Windows\system32\d2d1.dll
2014-10-21 20:08:13 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-10-21 20:08:13 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-10-21 20:08:12 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-10-21 20:08:12 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-10-21 20:08:12 ----A---- C:\Windows\system32\smss.exe
2014-10-21 20:08:12 ----A---- C:\Windows\system32\objsel.dll
2014-10-21 20:08:12 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-10-21 20:08:12 ----A---- C:\Windows\system32\KernelBase.dll
2014-10-21 20:08:12 ----A---- C:\Windows\system32\dimsroam.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\wincredprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\csrsrv.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\cngprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\capiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\adprovider.dll
2014-10-21 20:08:10 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-10-21 20:08:10 ----A---- C:\Windows\system32\apisetschema.dll
2014-10-21 20:07:32 ----A---- C:\Windows\system32\winlogon.exe
2014-10-21 20:07:31 ----A---- C:\Windows\system32\termsrv.dll
2014-10-21 20:07:31 ----A---- C:\Windows\system32\schannel.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\winsta.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\winsta.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\wdigest.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\ncrypt.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\msv1_0.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-21 20:07:30 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-21 20:07:30 ----A---- C:\Windows\system32\credssp.dll
2014-10-21 20:07:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-10-21 20:07:11 ----A---- C:\Windows\system32\DWrite.dll
2014-10-21 20:06:01 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-10-21 20:06:01 ----A---- C:\Windows\system32\msi.dll
2014-10-21 20:06:01 ----A---- C:\Windows\system32\authui.dll
2014-10-21 20:06:00 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-10-21 20:06:00 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-10-21 20:06:00 ----A---- C:\Windows\system32\msihnd.dll
2014-10-21 20:06:00 ----A---- C:\Windows\system32\consent.exe
2014-10-21 20:05:51 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-10-21 20:05:51 ----A---- C:\Windows\system32\osk.exe
2014-10-21 20:05:46 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-10-21 20:05:46 ----A---- C:\Windows\system32\tzres.dll
2014-10-21 20:05:23 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-10-21 20:05:23 ----A---- C:\Windows\system32\drivers\netio.sys
2014-10-21 20:05:23 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-10-21 20:05:21 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-10-21 20:05:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-10-21 20:05:19 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-10-21 20:05:19 ----A---- C:\Windows\system32\usp10.dll
2014-10-21 20:05:18 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2014-10-21 20:05:18 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-10-21 20:05:18 ----A---- C:\Windows\system32\mscorier.dll
2014-10-21 20:05:18 ----A---- C:\Windows\system32\dfshim.dll
2014-10-21 20:05:17 ----A---- C:\Windows\SYSWOW64\mscories.dll
2014-10-21 20:05:17 ----A---- C:\Windows\system32\mscories.dll
2014-10-21 20:05:12 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-10-21 20:05:12 ----A---- C:\Windows\system32\comctl32.dll
2014-10-21 20:05:09 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-10-21 20:05:08 ----A---- C:\Windows\system32\wwansvc.dll
2014-10-21 20:05:08 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-10-21 20:05:07 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-10-21 20:05:07 ----A---- C:\Windows\system32\wer.dll
2014-10-21 20:05:03 ----A---- C:\Windows\system32\msieftp.dll
2014-10-21 20:05:02 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-10-21 20:05:00 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-10-21 20:04:59 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-10-21 20:04:59 ----A---- C:\Windows\system32\atmfd.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\lpk.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\lpk.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\fontsub.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\dciman32.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\atmlib.dll
2014-10-21 20:04:55 ----A---- C:\Windows\system32\drivers\usbscan.sys
2014-10-21 20:04:55 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-10-21 20:04:54 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-10-21 20:04:52 ----A---- C:\Windows\system32\qedit.dll
2014-10-21 20:04:51 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-10-21 20:04:49 ----A---- C:\Windows\system32\drivers\afd.sys
2014-10-21 20:04:47 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-10-21 20:04:44 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-10-21 20:04:44 ----A---- C:\Windows\system32\drivers\usbcir.sys
2014-10-21 20:04:39 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-10-21 20:04:39 ----A---- C:\Windows\system32\win32spl.dll
2014-10-21 20:04:36 ----A---- C:\Windows\system32\generaltel.dll
2014-10-21 20:04:36 ----A---- C:\Windows\system32\aepdu.dll
2014-10-21 20:04:36 ----A---- C:\Windows\system32\aeinv.dll
2014-10-21 20:04:34 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-10-21 20:04:34 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-10-21 20:04:31 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-10-21 20:04:30 ----A---- C:\Windows\system32\mstscax.dll
2014-10-21 20:04:27 ----A---- C:\Windows\system32\msxml6.dll
2014-10-21 20:04:27 ----A---- C:\Windows\system32\msxml3.dll
2014-10-21 20:04:26 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-10-21 20:04:25 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-10-21 20:04:25 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-10-21 20:04:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-10-21 20:04:25 ----A---- C:\Windows\system32\msxml6r.dll
2014-10-21 20:04:25 ----A---- C:\Windows\system32\msxml3r.dll
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDRU.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-10-21 20:03:54 ----A---- C:\Windows\system32\shell32.dll
2014-10-21 20:03:52 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-10-21 20:03:50 ----A---- C:\Windows\system32\imagehlp.dll
2014-10-21 20:03:49 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-10-21 20:03:49 ----A---- C:\Windows\system32\win32k.sys
2014-10-21 20:03:44 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-10-21 20:03:43 ----A---- C:\Windows\SYSWOW64\rastls.dll
2014-10-21 20:03:43 ----A---- C:\Windows\system32\rastls.dll
2014-10-21 20:03:42 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-10-21 20:03:42 ----A---- C:\Windows\system32\packager.dll
2014-10-21 19:49:19 ----A---- C:\Windows\system32\scavengeui.dll
2014-10-21 19:48:53 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-10-21 19:48:53 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-10-21 19:48:53 ----A---- C:\Windows\system32\nshwfp.dll
2014-10-21 19:48:53 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-10-21 19:48:53 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-10-21 19:48:15 ----A---- C:\Windows\system32\rpcrt4.dll
2014-10-21 19:48:14 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-10-21 15:55:31 ----D---- C:\Users\Roman\AppData\Roaming\ESET
2014-10-21 15:51:00 ----D---- C:\ProgramData\ESET
2014-10-21 15:51:00 ----D---- C:\Program Files\ESET
2014-10-21 15:28:09 ----D---- C:\Program Files\WinRAR
2014-10-21 15:21:09 ----D---- C:\Windows\pss
2014-10-21 15:06:42 ----SD---- C:\Windows\SYSWOW64\Microsoft
2014-10-21 15:00:49 ----A---- C:\Windows\system32\OGACheckControl.dll
2014-10-21 14:47:29 ----D---- C:\Program Files (x86)\VideoLAN
2014-10-21 14:42:12 ----D---- C:\ProgramData\Mozilla
2014-10-21 10:48:32 ----A---- C:\Windows\system32\drivers\TrueSight.sys
2014-10-21 10:48:30 ----D---- C:\ProgramData\RogueKiller
2014-10-19 21:09:29 ----D---- C:\Windows\Minidump
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\epfwwfp.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\EpfwLWF.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\epfw.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\edevmon.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\eamonm.sys
2014-10-05 19:12:42 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-10-05 19:12:42 ----A---- C:\Windows\system32\qdvd.dll

======List of files/folders modified in the last 1 month======

2014-10-30 21:59:41 ----D---- C:\Windows\Temp
2014-10-30 21:59:38 ----D---- C:\Program Files
2014-10-30 21:47:07 ----D---- C:\Windows\system32\config
2014-10-30 20:40:08 ----D---- C:\Windows\system32\Tasks
2014-10-30 20:39:19 ----A---- C:\Windows\SYSWOW64\log.txt
2014-10-30 20:37:45 ----RD---- C:\Program Files (x86)
2014-10-30 20:37:45 ----HD---- C:\ProgramData
2014-10-30 20:36:29 ----D---- C:\Windows\SysWOW64
2014-10-30 19:39:31 ----D---- C:\Windows\inf
2014-10-29 18:31:43 ----D---- C:\Windows
2014-10-24 20:54:09 ----D---- C:\Windows\Microsoft.NET
2014-10-24 20:01:43 ----D---- C:\Windows\debug
2014-10-24 18:53:45 ----D---- C:\Windows\system32\catroot2
2014-10-22 20:10:29 ----RSD---- C:\Windows\assembly
2014-10-22 20:10:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-10-22 19:20:15 ----D---- C:\Windows\Tasks
2014-10-22 18:50:29 ----SHD---- C:\Windows\Installer
2014-10-22 18:31:36 ----D---- C:\Windows\System32
2014-10-22 18:31:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-22 18:12:58 ----SHD---- C:\System Volume Information
2014-10-22 18:00:13 ----D---- C:\Program Files (x86)\Intel
2014-10-22 17:59:34 ----D---- C:\Windows\system32\drivers
2014-10-22 17:59:24 ----D---- C:\Windows\system32\catroot
2014-10-22 17:59:10 ----D---- C:\Windows\system32\DriverStore
2014-10-21 22:59:27 ----D---- C:\Windows\winsxs
2014-10-21 22:57:22 ----D---- C:\Program Files\Microsoft Silverlight
2014-10-21 22:57:19 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-10-21 22:53:12 ----D---- C:\Windows\ehome
2014-10-21 22:53:12 ----D---- C:\Program Files\Windows Media Player
2014-10-21 22:53:12 ----D---- C:\Program Files (x86)\Windows Media Player
2014-10-21 22:53:11 ----D---- C:\Windows\AppPatch
2014-10-21 22:53:10 ----D---- C:\Program Files\Windows Journal
2014-10-21 22:52:56 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-21 22:52:56 ----D---- C:\Windows\system32\cs-CZ
2014-10-21 22:52:51 ----D---- C:\Windows\SYSWOW64\Dism
2014-10-21 22:52:50 ----D---- C:\Windows\system32\Dism
2014-10-21 22:52:46 ----RSD---- C:\Windows\Fonts
2014-10-21 22:52:45 ----D---- C:\Program Files\Windows Defender
2014-10-21 22:52:45 ----D---- C:\Program Files (x86)\Windows Defender
2014-10-21 22:52:40 ----D---- C:\Program Files\Internet Explorer
2014-10-21 22:52:39 ----D---- C:\Windows\SYSWOW64\en-US
2014-10-21 22:52:37 ----D---- C:\Windows\system32\en-US
2014-10-21 22:52:36 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-21 22:42:30 ----D---- C:\ProgramData\Microsoft Help
2014-10-21 22:24:11 ----SD---- C:\ProgramData\Microsoft
2014-10-21 21:08:58 ----D---- C:\Program Files (x86)\Microsoft Office
2014-10-21 21:00:53 ----D---- C:\Program Files (x86)\Common Files
2014-10-21 20:24:27 ----D---- C:\Windows\system32\MRT
2014-10-21 20:18:00 ----A---- C:\Windows\system32\MRT.exe
2014-10-21 16:14:25 ----D---- C:\Program Files (x86)\Nokia
2014-10-21 16:02:45 ----A---- C:\Windows\system32\ServiceFilter.ini
2014-10-21 16:02:37 ----A---- C:\Windows\system32\AutoRunFilter.ini
2014-10-21 15:30:54 ----D---- C:\Program Files (x86)\WinRAR
2014-10-21 15:24:33 ----D---- C:\Users\Roman\AppData\Roaming\WinRAR
2014-10-21 15:24:18 ----D---- C:\Program Files (x86)\Microsoft
2014-10-21 15:21:56 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-21 15:21:56 ----D---- C:\Program Files (x86)\ASUS
2014-10-21 15:00:43 ----D---- C:\Windows\system
2014-10-21 14:38:46 ----D---- C:\Windows\SoftwareDistribution
2014-10-21 14:31:59 ----D---- C:\Users\Roman\AppData\Roaming\TeamViewer
2014-10-21 14:31:55 ----D---- C:\Users\Roman\AppData\Roaming\uTorrent
2014-10-21 14:31:53 ----D---- C:\Windows\Panther
2014-10-21 14:31:53 ----D---- C:\Windows\ModemLogs
2014-10-21 14:31:52 ----D---- C:\Windows\Logs
2014-10-21 10:37:49 ----D---- C:\Windows\Prefetch
2014-10-02 14:53:02 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2014-10-10 63160]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-06 408600]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2014-10-10 243440]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2014-10-10 169280]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2014-10-10 44632]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2014-10-10 222280]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2009-10-30 704512]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-01-10 12311904]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2009-11-26 244736]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2009-08-18 143472]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits); C:\Windows\system32\DRIVERS\JME.sys [2009-12-04 107120]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-03-29 82816]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [2013-04-18 29184]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [2013-06-28 36352]
S3 AVerFx2hbtv64;AVerMedia USB SW Hybrid Tuner; C:\Windows\system32\drivers\AVerFx2hbtv64.sys [2009-05-05 508672]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 61280]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-05-18 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-05-18 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2011-05-18 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-05-18 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TrueSight;TrueSight; \??\C:\Windows\System32\drivers\TrueSight.sys [2014-10-21 34808]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-05-18 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-05-18 9216]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-12-08 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 AVerRemote;AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2008-09-10 352256]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-07-15 409600]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-02 864032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-10-01 1349576]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-11-02 179296]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2011-11-02 151648]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [2006-12-19 94208]
R2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2011-12-12 135824]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-10-01 262144]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-22 267440]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 111616]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-29 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-04 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: kontrola logu po odstranění viru

Napsal: 30 říj 2014 22:15
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]


:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: kontrola logu po odstranění viru

Napsal: 30 říj 2014 22:40
od roman4791
hotovo:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Roman at 2014-10-30 22:33:05
WIN_7 Service Pack 1
System drive C: has 15 GB (19%) free of 76 GB
Total RAM: 2925 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:38:40, on 30.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Roman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "D:\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-21-2284442310-3605169074-2699344400-1000\..\Run: [CCleaner Monitoring] "D:\CCleaner\CCleaner64.exe" /MONITOR (User '?')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11527 bytes

======Listing Processes======


======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yu5b02o1.default

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"Description"=Office Live Update v1.5
"Path"=C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-08-05 132448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-10-01 5595336]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-01-10 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-01-10 392984]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-01-10 417560]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=D:\CCleaner\CCleaner64.exe [2014-09-26 6482200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-02-21 3054136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
D:\CCleaner\CCleaner64.exe [2014-09-26 6482200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant]
C:\Windows\System32\LogiLDA.dll [2012-09-20 1832760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SRS Premium Sound.lnk]
C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-02-21 156952]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-01-13 7109248]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-01-05 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2011-10-31 1058400]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-01-10 390656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-30 22:23:11 ----D---- C:\_OTM
2014-10-30 21:59:38 ----D---- C:\Program Files\trend micro
2014-10-30 21:59:08 ----D---- C:\rsit
2014-10-30 20:36:29 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-10-30 20:35:16 ----D---- C:\AdwCleaner
2014-10-29 20:10:23 ----D---- C:\Users\Roman\AppData\Roaming\vlc
2014-10-29 19:48:49 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-10-29 18:40:23 ----D---- C:\Users\Roman\AppData\Roaming\Mozilla
2014-10-29 18:40:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-22 20:10:07 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-10-22 18:05:03 ----D---- C:\ProgramData\Intel
2014-10-21 22:52:41 ----SD---- C:\Windows\system32\CompatTel
2014-10-21 22:40:50 ----A---- C:\Windows\system32\wmploc.DLL
2014-10-21 22:40:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-10-21 22:40:49 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-10-21 22:40:48 ----A---- C:\Windows\system32\wmp.dll
2014-10-21 22:31:30 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-10-21 22:24:11 ----D---- C:\Windows\Migration
2014-10-21 20:15:11 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-10-21 20:15:10 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-10-21 20:15:10 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-10-21 20:15:10 ----A---- C:\Windows\system32\infocardapi.dll
2014-10-21 20:15:10 ----A---- C:\Windows\system32\icardres.dll
2014-10-21 20:15:10 ----A---- C:\Windows\system32\icardagt.exe
2014-10-21 20:14:59 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-10-21 20:14:59 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-10-21 20:11:17 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-21 20:11:17 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-10-21 20:11:07 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-10-21 20:11:07 ----A---- C:\Windows\system32\RMActivate.exe
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-10-21 20:11:06 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc_isv.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\secproc.dll
2014-10-21 20:11:06 ----A---- C:\Windows\system32\msdrm.dll
2014-10-21 20:11:05 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-10-21 20:11:05 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-10-21 20:10:12 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-10-21 20:10:12 ----A---- C:\Windows\system32\certutil.exe
2014-10-21 20:10:11 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-10-21 20:10:11 ----A---- C:\Windows\system32\certenc.dll
2014-10-21 20:09:59 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-10-21 20:09:59 ----A---- C:\Windows\system32\WMPhoto.dll
2014-10-21 20:09:55 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-10-21 20:09:55 ----A---- C:\Windows\system32\shdocvw.dll
2014-10-21 20:09:47 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-10-21 20:09:47 ----A---- C:\Windows\system32\wintrust.dll
2014-10-21 20:09:34 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-10-21 20:09:34 ----A---- C:\Windows\system32\crypt32.dll
2014-10-21 20:09:33 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-10-21 20:09:33 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-10-21 20:09:33 ----A---- C:\Windows\system32\cryptsvc.dll
2014-10-21 20:09:33 ----A---- C:\Windows\system32\cryptnet.dll
2014-10-21 20:09:14 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-10-21 20:09:14 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-10-21 20:09:14 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-10-21 20:09:14 ----A---- C:\Windows\system32\credui.dll
2014-10-21 20:09:08 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-10-21 20:09:08 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-10-21 20:09:08 ----A---- C:\Windows\system32\wscript.exe
2014-10-21 20:09:08 ----A---- C:\Windows\system32\scrrun.dll
2014-10-21 20:09:08 ----A---- C:\Windows\system32\cscript.exe
2014-10-21 20:09:07 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-10-21 20:08:56 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-10-21 20:08:55 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\iernonce.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-10-21 20:08:55 ----A---- C:\Windows\system32\ie4uinit.exe
2014-10-21 20:08:54 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-10-21 20:08:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-10-21 20:08:53 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-10-21 20:08:53 ----A---- C:\Windows\system32\urlmon.dll
2014-10-21 20:08:53 ----A---- C:\Windows\system32\iedkcs32.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-10-21 20:08:52 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-10-21 20:08:52 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-21 20:08:52 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-10-21 20:08:52 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-10-21 20:08:52 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-21 20:08:51 ----A---- C:\Windows\system32\iesetup.dll
2014-10-21 20:08:44 ----A---- C:\Windows\system32\iertutil.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-10-21 20:08:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-10-21 20:08:43 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-21 20:08:42 ----A---- C:\Windows\system32\ieui.dll
2014-10-21 20:08:42 ----A---- C:\Windows\system32\ieframe.dll
2014-10-21 20:08:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\jscript9diag.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\jscript9.dll
2014-10-21 20:08:41 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-21 20:08:40 ----A---- C:\Windows\system32\wininet.dll
2014-10-21 20:08:40 ----A---- C:\Windows\system32\vbscript.dll
2014-10-21 20:08:40 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-10-21 20:08:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-10-21 20:08:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-21 20:08:39 ----A---- C:\Windows\system32\msrating.dll
2014-10-21 20:08:39 ----A---- C:\Windows\system32\mshtml.dll
2014-10-21 20:08:32 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-10-21 20:08:32 ----A---- C:\Windows\system32\d2d1.dll
2014-10-21 20:08:13 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-10-21 20:08:13 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-10-21 20:08:12 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-10-21 20:08:12 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-10-21 20:08:12 ----A---- C:\Windows\system32\smss.exe
2014-10-21 20:08:12 ----A---- C:\Windows\system32\objsel.dll
2014-10-21 20:08:12 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-10-21 20:08:12 ----A---- C:\Windows\system32\KernelBase.dll
2014-10-21 20:08:12 ----A---- C:\Windows\system32\dimsroam.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\wincredprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\csrsrv.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\cngprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\capiprovider.dll
2014-10-21 20:08:11 ----A---- C:\Windows\system32\adprovider.dll
2014-10-21 20:08:10 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-10-21 20:08:10 ----A---- C:\Windows\system32\apisetschema.dll
2014-10-21 20:07:32 ----A---- C:\Windows\system32\winlogon.exe
2014-10-21 20:07:31 ----A---- C:\Windows\system32\termsrv.dll
2014-10-21 20:07:31 ----A---- C:\Windows\system32\schannel.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\winsta.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-10-21 20:07:30 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\winsta.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\wdigest.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\ncrypt.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\msv1_0.dll
2014-10-21 20:07:30 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-21 20:07:30 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-21 20:07:30 ----A---- C:\Windows\system32\credssp.dll
2014-10-21 20:07:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-10-21 20:07:11 ----A---- C:\Windows\system32\DWrite.dll
2014-10-21 20:06:01 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-10-21 20:06:01 ----A---- C:\Windows\system32\msi.dll
2014-10-21 20:06:01 ----A---- C:\Windows\system32\authui.dll
2014-10-21 20:06:00 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-10-21 20:06:00 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-10-21 20:06:00 ----A---- C:\Windows\system32\msihnd.dll
2014-10-21 20:06:00 ----A---- C:\Windows\system32\consent.exe
2014-10-21 20:05:51 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-10-21 20:05:51 ----A---- C:\Windows\system32\osk.exe
2014-10-21 20:05:46 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-10-21 20:05:46 ----A---- C:\Windows\system32\tzres.dll
2014-10-21 20:05:23 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-10-21 20:05:23 ----A---- C:\Windows\system32\drivers\netio.sys
2014-10-21 20:05:23 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-10-21 20:05:21 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-10-21 20:05:20 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-10-21 20:05:19 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-10-21 20:05:19 ----A---- C:\Windows\system32\usp10.dll
2014-10-21 20:05:18 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2014-10-21 20:05:18 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-10-21 20:05:18 ----A---- C:\Windows\system32\mscorier.dll
2014-10-21 20:05:18 ----A---- C:\Windows\system32\dfshim.dll
2014-10-21 20:05:17 ----A---- C:\Windows\SYSWOW64\mscories.dll
2014-10-21 20:05:17 ----A---- C:\Windows\system32\mscories.dll
2014-10-21 20:05:12 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2014-10-21 20:05:12 ----A---- C:\Windows\system32\comctl32.dll
2014-10-21 20:05:09 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-10-21 20:05:08 ----A---- C:\Windows\system32\wwansvc.dll
2014-10-21 20:05:08 ----A---- C:\Windows\system32\wwanprotdim.dll
2014-10-21 20:05:07 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-10-21 20:05:07 ----A---- C:\Windows\system32\wer.dll
2014-10-21 20:05:03 ----A---- C:\Windows\system32\msieftp.dll
2014-10-21 20:05:02 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-10-21 20:05:00 ----A---- C:\Windows\system32\drivers\ataport.sys
2014-10-21 20:04:59 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2014-10-21 20:04:59 ----A---- C:\Windows\system32\atmfd.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\lpk.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2014-10-21 20:04:58 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\lpk.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\fontsub.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\dciman32.dll
2014-10-21 20:04:58 ----A---- C:\Windows\system32\atmlib.dll
2014-10-21 20:04:55 ----A---- C:\Windows\system32\drivers\usbscan.sys
2014-10-21 20:04:55 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-10-21 20:04:54 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-10-21 20:04:53 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2014-10-21 20:04:52 ----A---- C:\Windows\system32\qedit.dll
2014-10-21 20:04:51 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-10-21 20:04:49 ----A---- C:\Windows\system32\drivers\afd.sys
2014-10-21 20:04:47 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-10-21 20:04:44 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-10-21 20:04:44 ----A---- C:\Windows\system32\drivers\usbcir.sys
2014-10-21 20:04:39 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-10-21 20:04:39 ----A---- C:\Windows\system32\win32spl.dll
2014-10-21 20:04:36 ----A---- C:\Windows\system32\generaltel.dll
2014-10-21 20:04:36 ----A---- C:\Windows\system32\aepdu.dll
2014-10-21 20:04:36 ----A---- C:\Windows\system32\aeinv.dll
2014-10-21 20:04:34 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-10-21 20:04:34 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-10-21 20:04:31 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-10-21 20:04:30 ----A---- C:\Windows\system32\mstscax.dll
2014-10-21 20:04:27 ----A---- C:\Windows\system32\msxml6.dll
2014-10-21 20:04:27 ----A---- C:\Windows\system32\msxml3.dll
2014-10-21 20:04:26 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-10-21 20:04:25 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-10-21 20:04:25 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-10-21 20:04:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-10-21 20:04:25 ----A---- C:\Windows\system32\msxml6r.dll
2014-10-21 20:04:25 ----A---- C:\Windows\system32\msxml3r.dll
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDRU.DLL
2014-10-21 20:03:59 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-10-21 20:03:54 ----A---- C:\Windows\system32\shell32.dll
2014-10-21 20:03:52 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-10-21 20:03:50 ----A---- C:\Windows\system32\imagehlp.dll
2014-10-21 20:03:49 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-10-21 20:03:49 ----A---- C:\Windows\system32\win32k.sys
2014-10-21 20:03:44 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-10-21 20:03:43 ----A---- C:\Windows\SYSWOW64\rastls.dll
2014-10-21 20:03:43 ----A---- C:\Windows\system32\rastls.dll
2014-10-21 20:03:42 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-10-21 20:03:42 ----A---- C:\Windows\system32\packager.dll
2014-10-21 19:49:19 ----A---- C:\Windows\system32\scavengeui.dll
2014-10-21 19:48:53 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-10-21 19:48:53 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-10-21 19:48:53 ----A---- C:\Windows\system32\nshwfp.dll
2014-10-21 19:48:53 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-10-21 19:48:53 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-10-21 19:48:15 ----A---- C:\Windows\system32\rpcrt4.dll
2014-10-21 19:48:14 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-10-21 15:55:31 ----D---- C:\Users\Roman\AppData\Roaming\ESET
2014-10-21 15:51:00 ----D---- C:\ProgramData\ESET
2014-10-21 15:51:00 ----D---- C:\Program Files\ESET
2014-10-21 15:28:09 ----D---- C:\Program Files\WinRAR
2014-10-21 15:21:09 ----D---- C:\Windows\pss
2014-10-21 15:06:42 ----SD---- C:\Windows\SYSWOW64\Microsoft
2014-10-21 15:00:49 ----A---- C:\Windows\system32\OGACheckControl.dll
2014-10-21 14:47:29 ----D---- C:\Program Files (x86)\VideoLAN
2014-10-21 14:42:12 ----D---- C:\ProgramData\Mozilla
2014-10-21 10:48:32 ----A---- C:\Windows\system32\drivers\TrueSight.sys
2014-10-21 10:48:30 ----D---- C:\ProgramData\RogueKiller
2014-10-19 21:09:29 ----D---- C:\Windows\Minidump
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\epfwwfp.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\EpfwLWF.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\epfw.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\ehdrv.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\edevmon.sys
2014-10-10 07:59:12 ----A---- C:\Windows\system32\drivers\eamonm.sys
2014-10-05 19:12:42 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-10-05 19:12:42 ----A---- C:\Windows\system32\qdvd.dll

======List of files/folders modified in the last 1 month======

2014-10-30 22:37:47 ----D---- C:\Windows\system32\config
2014-10-30 22:34:42 ----D---- C:\Windows\Temp
2014-10-30 22:28:10 ----D---- C:\Windows\system32\Tasks
2014-10-30 22:27:22 ----A---- C:\Windows\SYSWOW64\log.txt
2014-10-30 21:59:38 ----D---- C:\Program Files
2014-10-30 20:37:45 ----RD---- C:\Program Files (x86)
2014-10-30 20:37:45 ----HD---- C:\ProgramData
2014-10-30 20:36:29 ----D---- C:\Windows\SysWOW64
2014-10-30 19:39:31 ----D---- C:\Windows\inf
2014-10-29 18:31:43 ----D---- C:\Windows
2014-10-24 20:54:09 ----D---- C:\Windows\Microsoft.NET
2014-10-24 20:01:43 ----D---- C:\Windows\debug
2014-10-24 18:53:45 ----D---- C:\Windows\system32\catroot2
2014-10-22 20:10:29 ----RSD---- C:\Windows\assembly
2014-10-22 20:10:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-10-22 19:20:15 ----D---- C:\Windows\Tasks
2014-10-22 18:50:29 ----SHD---- C:\Windows\Installer
2014-10-22 18:31:36 ----D---- C:\Windows\System32
2014-10-22 18:31:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-22 18:12:58 ----SHD---- C:\System Volume Information
2014-10-22 18:00:13 ----D---- C:\Program Files (x86)\Intel
2014-10-22 17:59:34 ----D---- C:\Windows\system32\drivers
2014-10-22 17:59:24 ----D---- C:\Windows\system32\catroot
2014-10-22 17:59:10 ----D---- C:\Windows\system32\DriverStore
2014-10-21 22:59:27 ----D---- C:\Windows\winsxs
2014-10-21 22:57:22 ----D---- C:\Program Files\Microsoft Silverlight
2014-10-21 22:57:19 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-10-21 22:53:12 ----D---- C:\Windows\ehome
2014-10-21 22:53:12 ----D---- C:\Program Files\Windows Media Player
2014-10-21 22:53:12 ----D---- C:\Program Files (x86)\Windows Media Player
2014-10-21 22:53:11 ----D---- C:\Windows\AppPatch
2014-10-21 22:53:10 ----D---- C:\Program Files\Windows Journal
2014-10-21 22:52:56 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-21 22:52:56 ----D---- C:\Windows\system32\cs-CZ
2014-10-21 22:52:51 ----D---- C:\Windows\SYSWOW64\Dism
2014-10-21 22:52:50 ----D---- C:\Windows\system32\Dism
2014-10-21 22:52:46 ----RSD---- C:\Windows\Fonts
2014-10-21 22:52:45 ----D---- C:\Program Files\Windows Defender
2014-10-21 22:52:45 ----D---- C:\Program Files (x86)\Windows Defender
2014-10-21 22:52:40 ----D---- C:\Program Files\Internet Explorer
2014-10-21 22:52:39 ----D---- C:\Windows\SYSWOW64\en-US
2014-10-21 22:52:37 ----D---- C:\Windows\system32\en-US
2014-10-21 22:52:36 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-21 22:42:30 ----D---- C:\ProgramData\Microsoft Help
2014-10-21 22:24:11 ----SD---- C:\ProgramData\Microsoft
2014-10-21 21:08:58 ----D---- C:\Program Files (x86)\Microsoft Office
2014-10-21 21:00:53 ----D---- C:\Program Files (x86)\Common Files
2014-10-21 20:24:27 ----D---- C:\Windows\system32\MRT
2014-10-21 20:18:00 ----A---- C:\Windows\system32\MRT.exe
2014-10-21 16:14:25 ----D---- C:\Program Files (x86)\Nokia
2014-10-21 16:02:45 ----A---- C:\Windows\system32\ServiceFilter.ini
2014-10-21 16:02:37 ----A---- C:\Windows\system32\AutoRunFilter.ini
2014-10-21 15:30:54 ----D---- C:\Program Files (x86)\WinRAR
2014-10-21 15:24:33 ----D---- C:\Users\Roman\AppData\Roaming\WinRAR
2014-10-21 15:24:18 ----D---- C:\Program Files (x86)\Microsoft
2014-10-21 15:21:56 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-21 15:21:56 ----D---- C:\Program Files (x86)\ASUS
2014-10-21 15:00:43 ----D---- C:\Windows\system
2014-10-21 14:38:46 ----D---- C:\Windows\SoftwareDistribution
2014-10-21 14:31:59 ----D---- C:\Users\Roman\AppData\Roaming\TeamViewer
2014-10-21 14:31:55 ----D---- C:\Users\Roman\AppData\Roaming\uTorrent
2014-10-21 14:31:53 ----D---- C:\Windows\Panther
2014-10-21 14:31:53 ----D---- C:\Windows\ModemLogs
2014-10-21 14:31:52 ----D---- C:\Windows\Logs
2014-10-21 10:37:49 ----D---- C:\Windows\Prefetch
2014-10-02 14:53:02 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2014-10-10 63160]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-06 408600]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2014-10-10 243440]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2014-10-10 169280]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2014-10-10 44632]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2014-10-10 222280]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2009-10-30 704512]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-01-10 12311904]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2009-11-26 244736]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2009-08-18 143472]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits); C:\Windows\system32\DRIVERS\JME.sys [2009-12-04 107120]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-03-29 82816]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [2013-04-18 29184]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [2013-06-28 36352]
S3 AVerFx2hbtv64;AVerMedia USB SW Hybrid Tuner; C:\Windows\system32\drivers\AVerFx2hbtv64.sys [2009-05-05 508672]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 61280]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-05-18 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-05-18 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2011-05-18 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-05-18 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TrueSight;TrueSight; \??\C:\Windows\System32\drivers\TrueSight.sys [2014-10-21 34808]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-05-18 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-05-18 9216]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-12-08 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 AVerRemote;AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2008-09-10 352256]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-07-15 409600]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-02 864032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-10-01 1349576]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-11-02 179296]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2011-11-02 151648]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [2006-12-19 94208]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-10-01 262144]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2011-12-12 135824]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-22 267440]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 111616]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-29 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-04 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: kontrola logu po odstranění viru

Napsal: 31 říj 2014 18:12
od Rudy
Log je již OK. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: kontrola logu po odstranění viru

Napsal: 31 říj 2014 20:12
od roman4791
Ok, to je dobrá zpráva.
Děkuji

Akorát ještě dotaz, myslel jsem, že to je kvůli nějaké havěti v PC, ale asi to bude jiný problém.
Bylo to před i teď po zásahu všech čističů.
- v mozille mi nezobrazí google mapa satelitní, místo toho je pouze černé pozadí s cestami
- opět v mozille, když dám Seznam tak na konci stránky když sjedu na konec stránky tak se mi vysune reklama přes půl monitoru
- v centum akci mi to hlásí zapnout službu zabezpečení systému, ale když to chci zapnout tak to nejde.

Re: kontrola logu po odstranění viru

Napsal: 31 říj 2014 21:21
od Rudy
Ještě dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.

Re: kontrola logu po odstranění viru

Napsal: 31 říj 2014 22:36
od roman4791
zde:
ComboFix 14-10-29.01 - Roman 31.10.2014 22:06:44.1.4 - x64
Spuštěný z: c:\users\Roman\Desktop\ComboFix.exe
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\users\Roman\AppData\Roaming\.#
c:\users\Roman\AppData\Roaming\inst.exe
c:\windows\iun6002.exe
c:\windows\msvcr71.dll
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system\OGACheckControl.dll
.
Nakažená kopie c:\windows\SysWow64\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\combofix\HarddiskVolumeShadowCopy4_!Windows!SysWOW64!userinit.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-09-28 do 2014-10-31 )))))))))))))))))))))))))))))))
.
.
2014-10-31 21:16 . 2014-10-31 21:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-30 20:59 . 2014-10-30 21:34 -------- d-----w- c:\program files\trend micro
2014-10-30 19:36 . 2010-08-30 07:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-10-30 19:35 . 2014-10-30 19:37 -------- d-----w- C:\AdwCleaner
2014-10-29 19:10 . 2014-10-29 19:10 -------- d-----w- c:\users\Roman\AppData\Roaming\vlc
2014-10-29 17:40 . 2014-10-30 18:12 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-10-22 19:10 . 2014-10-22 19:10 17323696 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-10-22 18:20 . 2014-10-22 18:20 -------- d-----w- c:\users\Roman\AppData\Local\Macromedia
2014-10-22 17:05 . 2014-10-22 17:05 -------- d-----w- c:\programdata\Intel
2014-10-21 21:52 . 2014-10-21 21:52 -------- d-s---w- c:\windows\system32\CompatTel
2014-10-21 21:40 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-10-21 21:40 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-10-21 21:40 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-10-21 21:40 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-10-21 21:40 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-10-21 21:24 . 2014-10-21 21:24 -------- d-----w- c:\windows\Migration
2014-10-21 20:34 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4F1F9D8B-3559-4B9E-989C-3EE64BE41B4A}\mpengine.dll
2014-10-21 19:15 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-10-21 19:15 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-10-21 19:15 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-10-21 19:15 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-10-21 19:15 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-10-21 19:15 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-10-21 19:14 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-10-21 19:14 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-10-21 19:10 . 2014-06-03 10:02 1719296 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-10-21 19:10 . 2014-06-03 10:02 1389568 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-10-21 19:10 . 2014-06-03 10:02 1380864 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-10-21 19:10 . 2014-06-03 10:02 1354240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-10-21 19:10 . 2014-06-03 09:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-10-21 19:10 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2014-10-21 19:10 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2014-10-21 19:10 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2014-10-21 19:10 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2014-10-21 19:07 . 2014-07-17 02:07 455168 ----a-w- c:\windows\system32\winlogon.exe
2014-10-21 19:06 . 2014-09-18 02:00 3241472 ----a-w- c:\windows\system32\msi.dll
2014-10-21 19:06 . 2014-09-18 01:32 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-10-21 19:06 . 2014-06-03 10:02 1941504 ----a-w- c:\windows\system32\authui.dll
2014-10-21 19:06 . 2014-06-03 10:02 112064 ----a-w- c:\windows\system32\consent.exe
2014-10-21 19:06 . 2014-06-03 10:02 504320 ----a-w- c:\windows\system32\msihnd.dll
2014-10-21 19:06 . 2014-06-03 09:29 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2014-10-21 19:06 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2014-10-21 19:04 . 2013-06-06 03:30 368128 ----a-w- c:\windows\system32\atmfd.dll
2014-10-21 19:03 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-10-21 18:49 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2014-10-21 18:48 . 2013-10-12 02:30 830464 ----a-w- c:\windows\system32\nshwfp.dll
2014-10-21 18:48 . 2013-10-12 02:29 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-10-21 18:48 . 2013-10-12 02:29 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-10-21 18:48 . 2013-10-12 02:03 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2014-10-21 18:48 . 2013-10-12 02:01 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2014-10-21 18:48 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-10-21 18:48 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-10-21 14:55 . 2014-10-21 14:55 -------- d-----w- c:\users\Roman\AppData\Local\ESET
2014-10-21 14:51 . 2014-10-21 14:51 -------- d-----w- c:\program files\ESET
2014-10-21 14:28 . 2014-10-21 14:28 -------- d-----w- c:\program files\WinRAR
2014-10-21 14:06 . 2014-10-21 14:06 -------- d-s---w- c:\windows\SysWow64\Microsoft
2014-10-21 14:00 . 2009-08-27 06:50 667136 ----a-w- c:\windows\system32\OGACheckControl.dll
2014-10-21 13:47 . 2014-10-21 13:47 -------- d-----w- c:\program files (x86)\VideoLAN
2014-10-21 09:48 . 2014-10-21 09:48 34808 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-10-21 09:48 . 2014-10-21 09:48 -------- d-----w- c:\programdata\RogueKiller
2014-10-10 06:59 . 2014-10-10 06:59 63160 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2014-10-10 06:59 . 2014-10-10 06:59 44632 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys
2014-10-10 06:59 . 2014-10-10 06:59 243440 ----a-w- c:\windows\system32\drivers\eamonm.sys
2014-10-10 06:59 . 2014-10-10 06:59 241368 ----a-w- c:\windows\system32\drivers\edevmon.sys
2014-10-10 06:59 . 2014-10-10 06:59 222280 ----a-w- c:\windows\system32\drivers\epfw.sys
2014-10-10 06:59 . 2014-10-10 06:59 169280 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2014-10-05 18:12 . 2014-09-25 02:08 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-10-05 18:12 . 2014-09-25 01:40 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-22 19:10 . 2013-01-04 18:12 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-10-22 19:10 . 2011-10-18 18:37 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-10-21 19:18 . 2010-03-29 15:56 103265616 ----a-w- c:\windows\system32\MRT.exe
2014-10-02 13:53 . 2010-03-25 20:26 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-08-23 02:07 . 2014-09-10 19:10 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 01:45 . 2014-09-10 19:10 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2009-04-08 18:31 . 2009-04-08 18:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 . 2008-08-12 05:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="d:\ccleaner\CCleaner64.exe" [2014-09-26 6482200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-01-13 7109248]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-01-05 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2011-10-31 1058400]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AVer HID Receiver.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2010-3-28 159744]
AVerQuick.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-3-28 663552]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 AVerFx2hbtv64;AVerMedia USB SW Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv64.sys;c:\windows\SYSNATIVE\drivers\AVerFx2hbtv64.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsucx64.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 AVerRemote;AVerRemote;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [x]
S2 AVerScheduleService;AVerScheduleService;c:\program files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe;c:\program files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2014-10-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-26 19:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-10-01 5595336]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 392984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 417560]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yu5b02o1.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2284442310-3605169074-2699344400-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
@DACL=(02 0000)
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,3b,1b,21,82,15,
ee,69,9b,45,01,a0,31,d4,a9,2a,93,10,1a
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,c2,fa,
ac,56,95,bb,5e,a3,e7,42,e0,ca,4f,f0,16
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,3b,1b,71,2d,95,
63,f6,67,49,02,a8,f3,49,fc,1e,7d,e6,67
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,c8,20,
81,31,1b,d4,05,91,c6,13,24,75,4d,26,df
"{9421DD08-935F-4701-A9CA-22DF90AC4EA6}"=hex:51,66,7a,6c,4c,1d,3b,1b,18,c1,31,
85,6c,c4,6a,08,b6,c0,60,9f,93,e9,0b,bf
"{4D2D3B0F-69BE-477A-90F5-FDDB05357975}"=hex:51,66,7a,6c,4c,1d,3b,1b,1f,27,3d,
5c,8d,3e,11,08,8f,ff,bf,9b,06,70,3c,6c
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,3b,1b,01,84,98,
89,1e,13,b6,06,86,dd,9e,c6,68,ad,38,a5
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2014-10-31 22:33:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-10-31 21:33
.
Před spuštěním: Volných bajtů: 15 078 670 336
Po spuštění: Volných bajtů: 15 165 579 264
.
- - End Of File - - 27985EED05B7457F14A8DD40FE7E87F5
5C616939100B85E558DA92B899A0FC36

Re: kontrola logu po odstranění viru

Napsal: 01 lis 2014 11:09
od Rudy
Příště vypínejte rez štít antiviru. Ta hláška tam není pro legraci.Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
RegLock::
[HKEY_USERS\S-1-5-21-2284442310-3605169074-2699344400-1000\Software\Microsoft\Internet Explorer\Approved Extensions]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: kontrola logu po odstranění viru

Napsal: 01 lis 2014 19:21
od roman4791
za ten antivir se omlouvám, ale nějak jsem to nepochopil. Kdyby jste rovnou napsal vypnout antivir tak by mi to došlo lépe.
Tak snad se to nyní povedlo.
zde log:

ComboFix 14-10-29.01 - Roman 01.11.2014 18:58:47.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.2925.1666 [GMT 1:00]
Spuštěný z: c:\users\Roman\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Roman\Desktop\CFScript.txt
AV: ESET Smart Security 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-10-01 do 2014-11-01 )))))))))))))))))))))))))))))))
.
.
2014-11-01 18:06 . 2014-11-01 18:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-30 20:59 . 2014-10-30 21:34 -------- d-----w- c:\program files\trend micro
2014-10-30 19:36 . 2010-08-30 07:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-10-30 19:35 . 2014-10-30 19:37 -------- d-----w- C:\AdwCleaner
2014-10-29 19:10 . 2014-10-29 19:10 -------- d-----w- c:\users\Roman\AppData\Roaming\vlc
2014-10-29 17:40 . 2014-10-30 18:12 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-10-22 19:10 . 2014-10-22 19:10 17323696 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-10-22 18:20 . 2014-10-22 18:20 -------- d-----w- c:\users\Roman\AppData\Local\Macromedia
2014-10-22 17:05 . 2014-10-22 17:05 -------- d-----w- c:\programdata\Intel
2014-10-21 21:52 . 2014-10-21 21:52 -------- d-s---w- c:\windows\system32\CompatTel
2014-10-21 21:40 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-10-21 21:40 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-10-21 21:40 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-10-21 21:40 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-10-21 21:40 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-10-21 21:24 . 2014-10-21 21:24 -------- d-----w- c:\windows\Migration
2014-10-21 20:34 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4F1F9D8B-3559-4B9E-989C-3EE64BE41B4A}\mpengine.dll
2014-10-21 19:15 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-10-21 19:15 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-10-21 19:15 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-10-21 19:15 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-10-21 19:15 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-10-21 19:15 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-10-21 19:14 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-10-21 19:14 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-10-21 19:10 . 2014-06-03 10:02 1719296 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-10-21 19:10 . 2014-06-03 10:02 1389568 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-10-21 19:10 . 2014-06-03 10:02 1380864 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-10-21 19:10 . 2014-06-03 10:02 1354240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-10-21 19:10 . 2014-06-03 09:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-10-21 19:10 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2014-10-21 19:10 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2014-10-21 19:10 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2014-10-21 19:10 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2014-10-21 19:07 . 2014-07-17 02:07 455168 ----a-w- c:\windows\system32\winlogon.exe
2014-10-21 19:06 . 2014-09-18 02:00 3241472 ----a-w- c:\windows\system32\msi.dll
2014-10-21 19:06 . 2014-09-18 01:32 2363904 ----a-w- c:\windows\SysWow64\msi.dll
2014-10-21 19:06 . 2014-06-03 10:02 1941504 ----a-w- c:\windows\system32\authui.dll
2014-10-21 19:06 . 2014-06-03 10:02 112064 ----a-w- c:\windows\system32\consent.exe
2014-10-21 19:06 . 2014-06-03 10:02 504320 ----a-w- c:\windows\system32\msihnd.dll
2014-10-21 19:06 . 2014-06-03 09:29 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2014-10-21 19:06 . 2014-06-03 09:29 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2014-10-21 19:04 . 2013-06-06 03:30 368128 ----a-w- c:\windows\system32\atmfd.dll
2014-10-21 19:03 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-10-21 18:49 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2014-10-21 18:48 . 2013-10-12 02:30 830464 ----a-w- c:\windows\system32\nshwfp.dll
2014-10-21 18:48 . 2013-10-12 02:29 859648 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-10-21 18:48 . 2013-10-12 02:29 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-10-21 18:48 . 2013-10-12 02:03 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll
2014-10-21 18:48 . 2013-10-12 02:01 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL
2014-10-21 18:48 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-10-21 18:48 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-10-21 14:55 . 2014-10-21 14:55 -------- d-----w- c:\users\Roman\AppData\Local\ESET
2014-10-21 14:51 . 2014-10-21 14:51 -------- d-----w- c:\program files\ESET
2014-10-21 14:28 . 2014-10-21 14:28 -------- d-----w- c:\program files\WinRAR
2014-10-21 14:06 . 2014-10-21 14:06 -------- d-s---w- c:\windows\SysWow64\Microsoft
2014-10-21 14:00 . 2009-08-27 06:50 667136 ----a-w- c:\windows\system32\OGACheckControl.dll
2014-10-21 13:47 . 2014-10-21 13:47 -------- d-----w- c:\program files (x86)\VideoLAN
2014-10-21 09:48 . 2014-10-21 09:48 34808 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-10-21 09:48 . 2014-10-21 09:48 -------- d-----w- c:\programdata\RogueKiller
2014-10-10 06:59 . 2014-10-10 06:59 63160 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2014-10-10 06:59 . 2014-10-10 06:59 44632 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys
2014-10-10 06:59 . 2014-10-10 06:59 243440 ----a-w- c:\windows\system32\drivers\eamonm.sys
2014-10-10 06:59 . 2014-10-10 06:59 241368 ----a-w- c:\windows\system32\drivers\edevmon.sys
2014-10-10 06:59 . 2014-10-10 06:59 222280 ----a-w- c:\windows\system32\drivers\epfw.sys
2014-10-10 06:59 . 2014-10-10 06:59 169280 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2014-10-05 18:12 . 2014-09-25 02:08 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-10-05 18:12 . 2014-09-25 01:40 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-22 19:10 . 2013-01-04 18:12 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-10-22 19:10 . 2011-10-18 18:37 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-10-21 19:18 . 2010-03-29 15:56 103265616 ----a-w- c:\windows\system32\MRT.exe
2014-10-02 13:53 . 2010-03-25 20:26 278152 ------w- c:\windows\system32\MpSigStub.exe
2014-08-23 02:07 . 2014-09-10 19:10 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-23 01:45 . 2014-09-10 19:10 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2009-04-08 18:31 . 2009-04-08 18:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 . 2008-08-12 05:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="d:\ccleaner\CCleaner64.exe" [2014-09-26 6482200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-01-13 7109248]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-01-05 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2011-10-31 1058400]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AVer HID Receiver.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2010-3-28 159744]
AVerQuick.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-3-28 663552]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 AVerFx2hbtv64;AVerMedia USB SW Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv64.sys;c:\windows\SYSNATIVE\drivers\AVerFx2hbtv64.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsucx64.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 AVerRemote;AVerRemote;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [x]
S2 AVerScheduleService;AVerScheduleService;c:\program files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe;c:\program files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-11-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-26 19:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-10-01 5595336]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-10 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-10 392984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-10 417560]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yu5b02o1.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Celkový čas: 2014-11-01 19:14:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-11-01 18:14
ComboFix2.txt 2014-10-31 21:33
.
Před spuštěním: Volných bajtů: 15 479 660 544
Po spuštění: Volných bajtů: 15 289 368 576
.
- - End Of File - - 34EFAC1CD3FC73E002DE6B4DADB8075F
5C616939100B85E558DA92B899A0FC36

Re: kontrola logu po odstranění viru

Napsal: 01 lis 2014 20:22
od Rudy
roman4791 píše:za ten antivir se omlouvám, ale nějak jsem to nepochopil. Kdyby jste rovnou napsal vypnout antivir tak by mi to došlo lépe.
CF vás v jednom okamžiku sám vyzve k vypnutí antiviru, tak jsem myslel, že to není třeba zdůrazňovat. Je to nutné, některé položky nejdou bez vypnutí odstranit. Log je již OK.

Re: kontrola logu po odstranění viru

Napsal: 01 lis 2014 20:47
od roman4791
Super, děkuji.
Hláška zapnout službu zabezpečení systému již zmizela, ale problém s mozillou a google mapy přetrvává. To asi bude nějaký jiný problém, zkusím vygooglovat.
Takže jsem tam měl ještě nejaký neodstraněný vir ? Vůbec totiž netuším co jsem dělal.