Stránka 1 z 4

prosba o kontrolu logu

Napsal: 22 úno 2015 17:35
od alces
poprosím o kontrolu logu.dakujem

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:56:17, on 22.2.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\XTab\cmdshell.exe
C:\Program Files (x86)\XTab\HPNotify.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\Tanica\Pictures\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: a871f777818f47498876c33ff94bea260070121 - {11111111-1111-1111-1111-110711011121} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: Disc Soft Bus Service - Disc Soft Ltd - C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - SysTool PasSame LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - GOOBZO - C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe

--
End of file - 13002 bytes

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 17:41
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 18:14
od alces
urobil som kontrolu a pytalo to reštart,ale po reštarte nejde net.wifi je pripojene ale prehliadač vôbec neraguje a nič nezobrazuje.čo mam robit?

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 18:45
od Rudy
Klikněte na ikonu sítě pravým myšítkem>odstranit potíže. Jen nechápu, jak může ADW, který odstraňuje pouze AdWary, zrušit připojení k internetu.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 19:41
od alces
odstranit potiaže nepomohlo.wifi bolo pripojene a signal vyborny,ale prehlaidač aj ked som napisal ručne adresu nič neurobil a ani nenapisal žiadnu hlašku.nezobrazil absolutne nič,plocha bola biela a okolo len ram prehliadača.dal som bod obnovy a to pomohlo,ale teraz mam obavy znova spustit adwcleaner aby to znova neurobilo.respektivne ho spustim ale nedam clean.
po spusteni adw mi vyhodilo toto
Obrázek
mam to nechat zaškrtnute a dat clean?

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 20:17
od Rudy
Nespouštějte a dejte nový log RSIT. To, co je na screenu, rozhodně vám neshodilo připojení.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 20:28
od alces
Logfile of random's system information tool 1.10 (written by random/random)
Run by Tanica at 2015-02-22 20:24:40
Microsoft Windows 8.1
System drive C: has 376 GB (81%) free of 463 GB
Total RAM: 3993 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:24:50, on 22.2.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\XTab\cmdshell.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Windows\syswow64\wwahost.exe
C:\Program Files\trend micro\Tanica.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: a871f777818f47498876c33ff94bea260070121 - {11111111-1111-1111-1111-110711011121} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: Disc Soft Bus Service - Disc Soft Ltd - C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - SysTool PasSame LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - GOOBZO - C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe

--
End of file - 12993 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SC
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\Windows\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
dashost.exe {60bf6b6c-58c0-4fc3-8f8ab4b3a143aed9}
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files\Common Files\ShopperPro\spbiu.exe" /service
C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe -start -scm
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\Explorer.EXE
taskhostex.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\XTab\cmdshell.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe"
"C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe"
"C:\Windows\system32\igfxsrvc.exe" -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\syswow64\wwahost.exe" -ServerName:App.wwa
taskhostex.exe Idle
taskhost.exe IdleSyncMaintenance
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe -Embedding

"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 568 572 580 65536 576

"C:\Users\Tanica\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\13a8a803-9afb-449a-a365-c3bd7b81e33f-2.job - C:\Program Files (x86)\iWebar\13a8a803-9afb-449a-a365-c3bd7b81e33f-2.exe /rawdata=O3yVGRJbxaESixWJR/jrtoNFIn3WuvDHoKTAaHQFMeJGuGXjVM2L9SqkRJL43jRNyC2pXw0jRsdUQWyeAmuZRyVhnWN4icYIj2WcCXbd/SPkNPoEkmXTvJ8enyBrX/B/XBv6FGr23uRr/eSTMCzGYfAXY8FTmLkrEmuxWI/V6lq3InIfR1hnSVjDXiwA39Hje6lUVDaspMbLrtxYCMXdwwNtekAFtuap2XLuiSilEYXDD+49XTKQxclQrHwKjxXo9gF9XHnHc2FjE80T4T9kz+/j1ERwtUOLj/Wx3WivZL7AyeMBKvqXsIFprRMvnvr3fiUe9W0dxoMpA6BGe4LPULFvGLYM6Zx3KwwqH9Sq9Kr0Jn60EYMy8yKPacTTYMNrpOAt9Ne4jzHDN7k8KNhT7X7Fes+lvWS0+KRH+xNKJkltZIoG6wgLm36kJj6CPtU11UiX9ZGJKRjNRmROdSA5iM7Uoj4pstGArKZWyznsZBtVbR/E8rIk1+CuLMlLmuqTYqf925YTxe/dloADvRQAwDOKhmzBhKMu/SV/3RS3TvFSXXb/9X6xQRsCI1oVPEXQ39RHB4pREE/MfoCbZqZYNb1Wz1gCFYU0xWsW97oaZEnAPkoyOmGV1G8npYcDdfJ1aMyBxFSdEGsties6oG1Coi9VZ1iQlrGRFLCH2Z2tv/9+WK0oyrg9ef8VVeE/1rkGrohDU0AZbiw3DWP4sC/354k2xhJ1ACUOyCHfibbCEm7Mz8jFfn0zTCzkKGjLjxrPievYXWtkZ6pBMQ3oIgec52N0C6srgBsmENytMu5eycAXEwcQoCb1/k5Vb6ZHR2fEzz+gKrRkzh66HW+3gkR9IMHvDLAUAVWsoICLDwz43g9s6SYdr4AFPY1DT/nAjyiTPICfF7CXqIK0ISFqRTPJPDQW7xHZ8m+0thvB2TNAQZYxukDQYFbbew6vPyUfcjHVqPrbLC9uLSuL2H+7+x4uDFPNLWf9CTVCX/olz2dCfsczbxLh1unoXpUfoyK2hcaD
C:\Windows\tasks\13a8a803-9afb-449a-a365-c3bd7b81e33f-5.job - C:\Program Files (x86)\iWebar\13a8a803-9afb-449a-a365-c3bd7b81e33f-5.exe /rawdata=fai+oqquvOa/cubm0mA3BCZrq+TwCUJXbRuI07aI4FF4GFOh4jRA1uLS0BUd0ExyYRC5lYSl61v/vdeBvsEcxJZTLJlgj9KuBMdMJFmrMkdYUmqyVtGZDV9BCH2hs1HlQjnHISFNLocugrLReJJvksNFEZdMV1Yk2DO3vwRvdeIn8PJESyqp6hZoOg5roz2WnNEdPFnAmv76P0LMCfu8D0QaJx0E2/ES1zthbzZeorTcxnK9whrDVJEdUYZL1X6aUZO8TA2ixTSmllAdO8KfcmRYX9X73N50dCv8j8coIWnMaT8SuRG4zFzkEyfGCZkJq8bqmuoUo6CgfF2Lj8nYGjmNpVUNuJLCgiQiSb7OW4WvEYhxc1jZb4jaxtHCkKcWhI1fmn8ChXZN3bYOxrqZCjnX61bm5+77vLPTyOJRQkb3WedmFrMr5UYWN+dtN2D6slTITVC+lHhNIxFaH84AEi/uXcgcCRkrk2rThLO2Zn7tGsbs/8aNQdZvUbGcHbYfxnsc30wed2Ncuua1+duQpclU85Od+wCPGAR5g63KFzdZBwigQ+rIQ+u/lX2SAXf96O6Th5XsNojNzKPnKAU5K/8lYPJmnPyofZRYsdc7xH7ijerM9rYZmvTytjPDdJYKu5BakA1fu2AoNsowqDZ1Afj7sFtLmjv7rE6ybjZY10Ene4ih4+XrV+zsUvcybFDSrnWWElz581w9Z+5kEZOMwHPdRu8nxfyY4c8araoeFFN0PXEKkYeKZD+8vCgt4PqGtm6Z+mpSr/qOww7VpkuQstizSSHCCjs9EmPEyVAQKgCh0Ck7yiAUd5uV+nCIaJPcdgTM28oBkDbGIXmSB2D96LiZwAdXqamDBJjVEcVXK3Q43Lk4DvqEuF0Q0zuCWugBLW8me7a3wPXXL7BMs9jHCuRGsy5l3gSQ/So6mmKsIWYGYBuYD7ljFEwrgQb5f+W2z3c8/o4WkJHb6CBnT/OSyx8Ld6iRUPThZBC8iL6Z/IM0zRks0T8CvLvfHjszM+z8cPe/7H2nrFEVC8U6px8q6T3Ztfiq1vycIah+ZMxNcsKiCYDA6QnVkxd7dQ3XSmWndbcwSibE8uWghL6gpNGsH01u4uFcrASeqUOXVZJERGYdTLJlZS1/b7Gc331oPXFhUKrOndKm6wF9F4MTR5VBzQ9XgaWv7L2k9taHJBWmz98=
C:\Windows\tasks\13a8a803-9afb-449a-a365-c3bd7b81e33f-5_user.job - C:\Program Files (x86)\iWebar\13a8a803-9afb-449a-a365-c3bd7b81e33f-5.exe /rawdata=fai+oqquvOa/cubm0mA3BCZrq+TwCUJXbRuI07aI4FF4GFOh4jRA1uLS0BUd0ExyYRC5lYSl61v/vdeBvsEcxJZTLJlgj9KuBMdMJFmrMkdYUmqyVtGZDV9BCH2hs1HlQjnHISFNLocugrLReJJvksNFEZdMV1Yk2DO3vwRvdeIn8PJESyqp6hZoOg5roz2WnNEdPFnAmv76P0LMCfu8D0QaJx0E2/ES1zthbzZeorTcxnK9whrDVJEdUYZL1X6aUZO8TA2ixTSmllAdO8KfcmRYX9X73N50dCv8j8coIWnMaT8SuRG4zFzkEyfGCZkJq8bqmuoUo6CgfF2Lj8nYGjmNpVUNuJLCgiQiSb7OW4WvEYhxc1jZb4jaxtHCkKcWhI1fmn8ChXZN3bYOxrqZCjnX61bm5+77vLPTyOJRQkb3WedmFrMr5UYWN+dtN2D6slTITVC+lHhNIxFaH84AEi/uXcgcCRkrk2rThLO2Zn7tGsbs/8aNQdZvUbGcHbYfxnsc30wed2Ncuua1+duQpclU85Od+wCPGAR5g63KFzdZBwigQ+rIQ+u/lX2SAXf96O6Th5XsNojNzKPnKAU5K/8lYPJmnPyofZRYsdc7xH7ijerM9rYZmvTytjPDdJYKu5BakA1fu2AoNsowqDZ1Afj7sFtLmjv7rE6ybjZY10Ene4ih4+XrV+zsUvcybFDSrnWWElz581w9Z+5kEZOMwHPdRu8nxfyY4c8araoeFFN0PXEKkYeKZD+8vCgt4PqGtm6Z+mpSr/qOww7VpkuQstizSSHCCjs9EmPEyVAQKgCh0Ck7yiAUd5uV+nCIaJPcdgTM28oBkDbGIXmSB2D96LiZwAdXqamDBJjVEcVXK3Q43Lk4DvqEuF0Q0zuCWugBLW8me7a3wPXXL7BMs9jHCuRGsy5l3gSQ/So6mmKsIWYGYBuYD7ljFEwrgQb5f+W2z3c8/o4WkJHb6CBnT/OSyx8Ld6iRUPThZBC8iL6Z/IM0zRks0T8CvLvfHjszM+z8JetJjvnFsgNtWZ1IA5N57DnTAdTBIcIfwG8NSO2BAuIZcAuKzbBRRqRKowd3mxNarF70l1JRfy4Vqb89xYMf/JJwtp78rn4BlNm3zBs5NHb0/soBxYA8cIWVQ+gbl/9S7GQt2Fhb7JDLov9qTgFJse7FO14FS4BGe4hpsx2nymY=
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681452378-971542548-1818972947-1001Core.job - C:\Users\Tanica\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681452378-971542548-1818972947-1001Core1cf4eafb65853a6.job - C:\Users\Tanica\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Tanica\AppData\Roaming\Mozilla\Firefox\Profiles\zm7fbzoh.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.mystartsearch.com/?type=hppp ... 2_S3P30LHZ"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110711011121}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho64.dll [2015-01-24 890344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-11-04 218784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-11-21 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro64.dll [2015-02-02 502632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-11-12 2334928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper64.dll [2014-06-15 522600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110711011121}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho.dll [2015-01-24 707048]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2014-10-14 153248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\XTab\SupTab.dll [2015-01-16 210096]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-21 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro.dll [2015-02-02 422248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-11-12 1729744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper.dll [2014-06-15 434024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-10-25 391152]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-10-25 771056]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-10-25 769520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-09-02 7199448]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-09-20 2780912]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [2014-11-10 3761424]
"GoobzoYouTubeAccelerator"=C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe [2015-01-24 2227048]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Service"=C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2013-09-02 267224]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2013-10-08 1045304]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-02-03 5227112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-10-25 623104]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-02-22 20:24:41 ----D---- C:\Program Files\trend micro
2015-02-22 20:24:40 ----D---- C:\rsit
2015-02-22 18:45:38 ----A---- C:\Windows\system32\aswBoot.exe
2015-02-22 18:45:03 ----D---- C:\ProgramData\IHProtectUpDate
2015-02-22 17:49:37 ----D---- C:\AdwCleaner
2015-02-16 17:48:11 ----N---- C:\Windows\system32\schannel.dll
2015-02-16 17:48:09 ----N---- C:\Windows\system32\scesrv.dll
2015-02-16 17:48:06 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-02-16 17:48:05 ----N---- C:\Windows\system32\wow64.dll
2015-02-16 17:48:05 ----A---- C:\Windows\system32\ntdll.dll
2015-02-16 17:48:04 ----N---- C:\Windows\system32\wow64cpu.dll
2015-02-16 17:48:01 ----N---- C:\Windows\system32\WindowsCodecs.dll
2015-02-16 17:47:55 ----N---- C:\Windows\system32\lsasrv.dll
2015-02-16 17:47:29 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-16 17:47:28 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-02-16 17:47:07 ----N---- C:\Windows\system32\iertutil.dll
2015-02-16 17:47:05 ----N---- C:\Windows\system32\wininet.dll
2015-02-16 17:46:59 ----N---- C:\Windows\system32\actxprxy.dll
2015-02-16 17:46:58 ----N---- C:\Windows\system32\urlmon.dll
2015-02-16 17:46:33 ----A---- C:\Windows\system32\sppobjs.dll
2015-02-05 14:44:34 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-02-03 14:08:39 ----D---- C:\Program Files\Common Files\ShopperPro
2015-01-25 01:26:25 ----D---- C:\Users\Tanica\AppData\Roaming\The Creative Assembly
2015-01-24 23:51:45 ----D---- C:\Program Files (x86)\Napoleon - Total War
2015-01-24 22:34:20 ----D---- C:\Program Files (x86)\globalUpdate
2015-01-24 22:33:46 ----D---- C:\Program Files (x86)\iWebar
2015-01-24 22:14:13 ----D---- C:\ProgramData\YTAHelper
2015-01-24 22:14:07 ----D---- C:\Program Files (x86)\YTAHelper
2015-01-24 22:13:24 ----D---- C:\ProgramData\ShopperPro
2015-01-24 22:13:14 ----D---- C:\Program Files (x86)\YouTube Accelerator
2015-01-24 22:13:06 ----D---- C:\Program Files (x86)\ShopperPro
2015-01-24 22:12:08 ----D---- C:\Program Files (x86)\XTab
2015-01-24 22:11:33 ----D---- C:\ProgramData\WindowsMangerProtect
2015-01-24 22:10:33 ----D---- C:\Users\Tanica\AppData\Roaming\mystartsearch
2015-01-24 22:07:37 ----A---- C:\Windows\system32\drivers\dtscsibus.sys
2015-01-24 22:07:21 ----D---- C:\Users\Tanica\AppData\Roaming\DAEMON Tools Pro
2015-01-24 22:07:13 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2015-01-24 22:05:41 ----D---- C:\ProgramData\DAEMON Tools Pro
2015-01-24 18:24:40 ----D---- C:\Users\Tanica\AppData\Roaming\Ulozto File Manager
2015-01-24 18:24:35 ----D---- C:\Program Files (x86)\Ulozto File Manager
2015-01-24 18:14:03 ----A---- C:\Windows\system32\profsvc.dll
2015-01-24 18:14:02 ----A---- C:\Windows\system32\nlasvc.dll
2015-01-24 18:14:02 ----A---- C:\Windows\system32\ncsi.dll
2015-01-24 18:14:01 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-01-24 18:14:01 ----A---- C:\Windows\system32\nlaapi.dll
2015-01-24 18:14:00 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-01-24 18:13:58 ----A---- C:\Windows\system32\drivers\ahcache.sys
2015-01-24 18:13:57 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-01-24 18:13:01 ----A---- C:\Windows\SYSWOW64\WerFault.exe
2015-01-24 18:13:01 ----A---- C:\Windows\SYSWOW64\wer.dll
2015-01-24 18:13:01 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2015-01-24 18:13:01 ----A---- C:\Windows\system32\WerFault.exe
2015-01-24 18:13:01 ----A---- C:\Windows\system32\wer.dll
2015-01-24 18:13:00 ----A---- C:\Windows\SYSWOW64\wermgr.exe
2015-01-24 18:13:00 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2015-01-24 18:13:00 ----A---- C:\Windows\system32\wermgr.exe
2015-01-24 18:13:00 ----A---- C:\Windows\system32\WerFaultSecure.exe
2015-01-24 18:13:00 ----A---- C:\Windows\system32\Faultrep.dll
2015-01-24 18:13:00 ----A---- C:\Windows\system32\EncDump.dll
2015-01-24 18:13:00 ----A---- C:\Windows\system32\ci.dll
2015-01-24 18:13:00 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2015-01-24 18:12:59 ----A---- C:\Windows\SYSWOW64\werdiagcontroller.dll
2015-01-24 18:12:59 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-01-24 18:12:59 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-01-24 18:12:59 ----A---- C:\Windows\system32\AudioSes.dll
2015-01-24 18:12:59 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-01-24 18:12:59 ----A---- C:\Windows\system32\AudioEng.dll
2015-01-24 18:12:58 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-01-24 18:12:58 ----A---- C:\Windows\system32\werdiagcontroller.dll
2015-01-24 18:12:58 ----A---- C:\Windows\system32\audiosrv.dll
2015-01-24 18:12:58 ----A---- C:\Windows\system32\audiodg.exe

======List of files/folders modified in the last 1 month======

2015-02-22 20:24:48 ----D---- C:\Windows\Prefetch
2015-02-22 20:24:41 ----D---- C:\Program Files
2015-02-22 20:20:39 ----D---- C:\Windows\system32\config
2015-02-22 20:20:33 ----D---- C:\Windows\Temp
2015-02-22 20:08:42 ----D---- C:\Windows\system32\Tasks
2015-02-22 20:02:00 ----D---- C:\Windows\system32\sru
2015-02-22 19:35:09 ----AD---- C:\ProgramData\Temp
2015-02-22 19:26:45 ----D---- C:\Windows\WinSxS
2015-02-22 19:26:05 ----D---- C:\Windows
2015-02-22 19:23:32 ----RD---- C:\Windows\System32
2015-02-22 19:23:32 ----D---- C:\Windows\SysWOW64
2015-02-22 19:22:06 ----D---- C:\Windows\AppReadiness
2015-02-22 19:18:49 ----D---- C:\Windows\CbsTemp
2015-02-22 19:15:06 ----D---- C:\Windows\system32\MRT
2015-02-22 19:15:01 ----A---- C:\Windows\system32\MRT.exe
2015-02-22 19:05:25 ----D---- C:\Windows\Microsoft.NET
2015-02-22 19:02:08 ----D---- C:\Windows\debug
2015-02-22 18:51:20 ----D---- C:\Windows\system32\catroot2
2015-02-22 18:46:18 ----D---- C:\Windows\Inf
2015-02-22 18:45:11 ----D---- C:\Windows\system32\drivers
2015-02-22 18:45:03 ----HD---- C:\ProgramData
2015-02-22 18:42:02 ----D---- C:\Windows\system32\wbem
2015-02-22 18:38:58 ----RSD---- C:\Windows\Media
2015-02-22 18:38:58 ----D---- C:\Windows\SYSWOW64\wbem
2015-02-22 18:38:58 ----D---- C:\Windows\system32\sk-SK
2015-02-22 18:38:53 ----D---- C:\Windows\Tasks
2015-02-22 18:38:53 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-02-22 18:38:52 ----D---- C:\Windows\SYSWOW64\migration
2015-02-22 18:38:52 ----D---- C:\Windows\SYSWOW64\en-US
2015-02-22 18:38:52 ----D---- C:\Windows\system32\migration
2015-02-22 18:38:52 ----D---- C:\Windows\system32\en-US
2015-02-22 18:38:52 ----D---- C:\Windows\system32\drivers\etc
2015-02-22 18:38:52 ----D---- C:\Windows\PolicyDefinitions
2015-02-22 18:38:52 ----D---- C:\Windows\apppatch
2015-02-22 18:38:52 ----D---- C:\Program Files\Windows Defender
2015-02-22 18:38:52 ----D---- C:\Program Files\Internet Explorer
2015-02-22 18:38:52 ----D---- C:\Program Files (x86)\Internet Explorer
2015-02-22 18:38:37 ----D---- C:\Windows\system32\Sysprep
2015-02-22 18:38:36 ----D---- C:\Windows\system32\CodeIntegrity
2015-02-22 18:38:22 ----D---- C:\Program Files\Common Files\microsoft shared
2015-02-22 18:38:21 ----RD---- C:\Program Files (x86)
2015-02-22 18:35:24 ----HD---- C:\Program Files\WindowsApps
2015-02-22 18:26:02 ----D---- C:\Windows\registration
2015-02-22 18:18:46 ----SHD---- C:\System Volume Information
2015-02-22 18:17:21 ----D---- C:\Windows\Logs
2015-02-22 18:13:06 ----D---- C:\Windows\system32\NDF
2015-02-22 16:22:15 ----D---- C:\Windows\SoftwareDistribution
2015-02-08 19:25:29 ----D---- C:\Windows\system32\DriverStore
2015-02-06 14:22:07 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-05 17:55:38 ----A---- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2015-02-04 15:31:25 ----D---- C:\Windows\rescache
2015-02-04 15:00:56 ----RSD---- C:\Windows\assembly
2015-02-03 20:31:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-02-03 14:08:39 ----D---- C:\Program Files\Common Files
2015-01-25 10:03:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-01-25 01:25:57 ----SHD---- C:\Windows\Installer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-21 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-21 267632]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-21 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-22 1050432]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-21 436624]
R1 CLVirtualDrive;CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [2013-03-05 91712]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-21 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-21 83280]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-21 116728]
R2 SPDRIVER_1481.0.0.0;SPDRIVER_1481.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1481.0.0.0\jsdrv.sys [2015-02-02 52584]
R3 athr;@oem4.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2013-08-23 3860480]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2013-11-15 594632]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 clwvd;@oem19.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2013-03-05 41408]
R3 dtscsibus;DAEMON Tools Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtscsibus.sys [2015-01-24 29864]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-10-25 4177920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-09-03 3630168]
R3 IntcDAud;@oem11.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2013-10-25 449528]
R3 iwdbus;@oem14.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2013-08-22 26008]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@oem16.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-08-15 830680]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2013-09-20 34544]
R3 SPBIUpdd;ShopperPro UpdateD; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys [2015-02-02 41856]
R3 SynTP;@oem2.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-09-20 533232]
R3 TXEIx64;@oem6.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2013-07-01 87568]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 intaud_WaveExtensible;@oem13.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2013-08-22 39320]
S3 RSUSBSTOR;@oem7.inf,%RSUSBSTOR.SvcDesc%;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2013-08-26 263896]
S3 SmbDrv;SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [2013-09-20 30448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-17 98208]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2013-08-22 37768]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2013-08-07 312448]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-21 50344]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 ClickToRunSvc;Služba Klikni a spusti balíka Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-11-12 2449592]
R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2013-09-05 77576]
R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2013-09-05 298760]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-08-29 92160]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2013-10-08 1039160]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2015-01-16 158896]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-08-23 289496]
R2 SPBIUpd;ShopperPro Update; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2015-02-02 2346880]
R3 Disc Soft Bus Service;Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe [2014-11-10 2216208]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-01-24 68608]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05 267440]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-08-10 50784]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-10-25 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-23 43696]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-01-24 68608]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-02-05 114800]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-02-01 150600]
S3 w3logsvc;@%windir%\system32\inetsrv\iisres.dll,-30014; C:\Windows\system32\svchost.exe [2013-08-22 37768]
S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2013-08-22 37768]

-----------------EOF-----------------

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 20:48
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\iWebar
C:\Program Files (x86)\XTab
C:\ProgramData\ShopperPro
C:\ProgramData\YTAHelper
C:\Program Files (x86)\YouTube Accelerator
C:\Windows\tasks\13a8a803-9afb-449a-a365-c3bd7b81e33f-2.job
C:\Windows\tasks\13a8a803-9afb-449a-a365-c3bd7b81e33f-5_user.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681452378-971542548-1818972947-1001Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-681452378-971542548-1818972947-1001Core1cf4eafb65853a6.job
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
C:\Program Files\Common Files\ShopperPro
C:\ProgramData\ShopperPro
C:\Users\Tanica\AppData\Roaming\mystartsearch

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110711011121}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110711011121}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A
5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"=-

:services
SPBIUpdd

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 21:09
od alces
po reštarte zase nejde net.stale mi ukazuje len stranku mystartsearch a explorer nezobrazuje nič...v pripojeniach ukazuje že je pripojeny do siete

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 21:19
od Rudy
Tak to nevím proč. Mé čestné slovo, že jsem nemazal žádné síť. nastavení.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 21:20
od alces
tak čo mam teraz urobit?dat znova bod obnovy?

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 21:23
od Rudy
Asi nic jiného nezbude. Pak zkusíme klasický skener. Opravdu nevím, co se tam smaže.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 22:02
od alces
po obnoveni napisalo že obnovenie neprebehlo v poriadku ale net ide.

Re: prosba o kontrolu logu

Napsal: 22 úno 2015 22:28
od Rudy
OK. Zkusíme tedy skener MBAM: http://www.malwarebytes.org/mbam.php . Stáhněte, neinstalujte, spusťte. Nakonec dejte log, předem nic nemažte.

Re: prosba o kontrolu logu

Napsal: 23 úno 2015 06:17
od alces
ako ho mam spustit bez inštalácie?ked zapnem notbook tak mi vyhodi toto
Obrázek