Stránka 1 z 1

Prosím o kontrolu logu po nalezení malware

Napsal: 12 bře 2015 20:37
od DarkMan_X
Zdravim,
omylem jsem kliknul na jeden odkaz, a Avira mi nasla Adware. To zapricinilo, ze mi zmizela slozka Mobogenie. Adware bylo nalezeno vzdy v ceste k mobogenii.
Provedl jsem kompletni sken Avirou, SuperantiSpyware + SpywareTerminator. Bylo nalezeno 5x Adware, z toho 3x se dalo do karanteny, a zbyle 2 jsem odstranil rucne + vycistil registry + CCleaner.

I tak prosim o kontrolu logu zda nejaka havěť v PC nezustala. Díky


Logfile of random's system information tool 1.10 (written by random/random)
Run by Lucas at 2015-03-12 20:17:35
Microsoft Windows 8.1
System drive C: has 343 GB (79%) free of 434 GB
Total RAM: 3962 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:17:36, on 12. 3. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\Lucas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com/?pc=lcjb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [NextLive] C:\windows\SysWOW64\rundll32.exe ",EntryPoint -m l
O4 - Global Startup: ING eKalkulačka.lnk = Lucas\ING_eKalkulacka_OVB_CZ\jettyStarter.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Architect 2 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\ws.exe
O23 - Service: pdfforge CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 11490 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\windows\system32\CxAudMsg64.exe
dashost.exe {18bc7984-3890-4d27-8fa8c67405b35ce8}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000604
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-450fc534-adcf-4e12-bd4f-8310ca756d0e -SystemEventPortName:HostProcess-e4789676-a8b6-4561-8ae9-eabab15ee50e -IoCancelEventPortName:HostProcess-431269f8-c9ff-4468-a881-3e43c42be97a -NonStateChangingEventPortName:HostProcess-369a99c5-c9a2-40df-817c-0b80ec455b07 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2332b132-849f-4ae2-b069-bfd9b0670093 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
taskeng.exe {4264F4E3-B7A7-40CA-AAA2-0BD966F51C99}
taskhostex.exe
C:\WINDOWS\Explorer.EXE
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" /ELEVATED
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
taskhost.exe
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe22_ Global\UsGthrCtrlFltPipeMssGthrPipe22 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 584 588 596 65536 592

C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Lucas\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-03-21 6270336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-04-24 6339656]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2014-10-01 448912]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-08-24 17097200]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-08-24 193008]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-02-04 899680]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2013-03-05 1647616]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2014-11-04 2774904]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2014-11-04 3681656]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"=C:\windows\SysWOW64\rundll32.exe [2013-08-22 49664]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2015-01-19 126712]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2015-02-25 703280]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ING eKalkulačka.lnk - C:\Users\Lucas\ING_eKalkulacka_OVB_CZ\jettyStarter.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SMR430]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-11 09:11:47 ----A---- C:\WINDOWS\ntbtlog.txt
2015-03-11 09:11:42 ----D---- C:\Users\Lucas\AppData\Roaming\Spyware Terminator
2015-03-11 09:11:42 ----D---- C:\ProgramData\Spyware Terminator
2015-03-11 09:11:42 ----A---- C:\WINDOWS\system32\drivers\stflt.sys
2015-03-11 09:11:13 ----D---- C:\Program Files (x86)\Spyware Terminator
2015-03-11 08:27:28 ----D---- C:\NPE
2015-03-11 07:28:20 ----A---- C:\WINDOWS\system32\calc.exe
2015-03-11 07:28:19 ----A---- C:\WINDOWS\SYSWOW64\calc.exe
2015-03-11 07:28:15 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2015-03-11 07:28:15 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2015-03-11 07:28:14 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2015-03-11 07:28:13 ----A---- C:\WINDOWS\SYSWOW64\winshfhc.dll
2015-03-11 07:28:13 ----A---- C:\WINDOWS\system32\winshfhc.dll
2015-03-11 07:28:00 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2015-03-11 07:28:00 ----A---- C:\WINDOWS\system32\SHCore.dll
2015-03-11 07:27:51 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-03-11 07:27:51 ----A---- C:\WINDOWS\system32\win32k.sys
2015-03-11 07:27:51 ----A---- C:\WINDOWS\system32\schannel.dll
2015-03-11 07:27:50 ----A---- C:\WINDOWS\SYSWOW64\photowiz.dll
2015-03-11 07:27:50 ----A---- C:\WINDOWS\system32\photowiz.dll
2015-03-11 07:27:49 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-03-11 07:27:49 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\lpk.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-03-11 07:27:43 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\printui.exe
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\win32spl.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\puiobj.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\puiapi.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\prnntfy.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\printui.exe
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\localspl.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\findnetprinters.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\compstui.dll
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\fsquirt.exe
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\rfcomm.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\hidbth.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\bthenum.sys
2015-03-11 07:27:39 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2015-03-11 07:27:39 ----A---- C:\WINDOWS\system32\dwmcore.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\mfc42u.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\mfc42.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\atlthunk.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\mfc42u.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\atlthunk.dll
2015-03-11 07:27:37 ----A---- C:\WINDOWS\system32\mfc42.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSReset.exe
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSCollect.exe
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\SYSWOW64\StorageContextHandler.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\system32\authui.dll
2015-03-11 07:27:28 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-03-11 07:27:28 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-03-11 07:27:27 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-03-11 07:27:22 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\SYSWOW64\eappcfg.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\ubpm.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\rfxvmt.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\rdpudd.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eapphost.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eappcfg.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\drivers\rdpvideominiport.sys
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eappprxy.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eapphost.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eappgnui.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eapp3hst.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\system32\eappprxy.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\system32\eappgnui.dll
2015-03-11 07:27:06 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-03-11 07:27:05 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-03-11 07:27:02 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-03-11 07:27:01 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-03-11 07:26:59 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-03-11 07:26:58 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\jscript.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-03-11 07:26:43 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-03-11 07:26:43 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-11 07:26:38 ----A---- C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-11 07:26:37 ----A---- C:\WINDOWS\system32\shell32.dll
2015-03-11 07:26:36 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-03-11 07:26:24 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2015-03-11 07:26:24 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2015-03-11 07:26:22 ----A---- C:\WINDOWS\SYSWOW64\WMPhoto.dll
2015-03-11 07:26:22 ----A---- C:\WINDOWS\system32\WMPhoto.dll
2015-03-11 07:26:21 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2015-03-11 07:26:21 ----A---- C:\WINDOWS\explorer.exe
2015-03-11 07:26:19 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2015-03-11 07:26:19 ----A---- C:\WINDOWS\system32\msctf.dll
2015-03-10 08:45:48 ----A---- C:\WINDOWS\system32\drivers\avnetflt.sys
2015-03-10 08:44:16 ----D---- C:\Users\Lucas\AppData\Roaming\Avira
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2015-03-10 08:39:37 ----D---- C:\ProgramData\Avira
2015-03-10 08:39:37 ----D---- C:\Program Files (x86)\Avira
2015-03-10 08:39:34 ----D---- C:\ProgramData\Package Cache
2015-03-10 08:38:27 ----D---- C:\OETemp
2015-03-06 12:23:00 ----D---- C:\CPSkla
2015-03-06 12:12:14 ----D---- C:\DATA_CPC
2015-03-06 12:10:37 ----D---- C:\Program Files (x86)\CPC
2015-02-26 21:14:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2015-02-26 21:14:23 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-26 21:14:22 ----A---- C:\WINDOWS\SYSWOW64\GlobCollationHost.dll
2015-02-26 21:14:22 ----A---- C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-17 15:26:28 ----A---- C:\WINDOWS\SYSWOW64\FM20.DLL

======List of files/folders modified in the last 1 month======

2015-03-12 20:17:35 ----D---- C:\WINDOWS\Temp
2015-03-12 20:17:35 ----D---- C:\rsit
2015-03-12 20:17:35 ----D---- C:\Program Files\trend micro
2015-03-12 20:17:07 ----D---- C:\WINDOWS\Prefetch
2015-03-12 20:03:26 ----D---- C:\WINDOWS\system32\sru
2015-03-12 17:20:27 ----HD---- C:\ProgramData
2015-03-12 15:53:20 ----D---- C:\WINDOWS\system32\config
2015-03-12 15:41:05 ----D---- C:\WINDOWS\system32\DriverStore
2015-03-12 15:38:52 ----D---- C:\WINDOWS\WinSxS
2015-03-12 15:29:27 ----D---- C:\WINDOWS\Microsoft.NET
2015-03-12 09:21:21 ----RD---- C:\WINDOWS\System32
2015-03-12 09:21:12 ----D---- C:\WINDOWS\Inf
2015-03-12 09:21:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-12 09:17:53 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-03-12 09:15:15 ----D---- C:\Windows
2015-03-12 09:13:55 ----D---- C:\WINDOWS\system32\drivers
2015-03-12 09:12:06 ----D---- C:\WINDOWS\SysWOW64
2015-03-12 09:12:05 ----RD---- C:\WINDOWS\ToastData
2015-03-12 09:12:04 ----D---- C:\WINDOWS\WinStore
2015-03-12 09:12:03 ----D---- C:\Program Files\Windows Defender
2015-03-12 09:12:02 ----D---- C:\Program Files (x86)\Windows Defender
2015-03-11 18:37:22 ----D---- C:\ProgramData\CPC
2015-03-11 17:34:08 ----D---- C:\WINDOWS\CbsTemp
2015-03-11 17:33:45 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-03-11 17:33:45 ----D---- C:\WINDOWS\system32\cs-CZ
2015-03-11 15:46:06 ----D---- C:\Users\Lucas\AppData\Roaming\vlc
2015-03-11 10:26:47 ----D---- C:\WINDOWS\rescache
2015-03-11 09:55:39 ----D---- C:\WINDOWS\debug
2015-03-11 09:11:13 ----RD---- C:\Program Files (x86)
2015-03-11 09:02:15 ----D---- C:\WINDOWS\SoftwareDistribution
2015-03-11 08:54:10 ----D---- C:\Program Files\CCleaner
2015-03-11 08:39:29 ----HD---- C:\Program Files\WindowsApps
2015-03-11 08:39:29 ----D---- C:\WINDOWS\AppReadiness
2015-03-11 07:52:43 ----D---- C:\WINDOWS\system32\catroot
2015-03-11 07:45:02 ----D---- C:\Program Files\Internet Explorer
2015-03-11 07:45:02 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 07:44:51 ----SHD---- C:\WINDOWS\Installer
2015-03-11 07:44:50 ----D---- C:\ProgramData\Microsoft Help
2015-03-11 07:44:39 ----A---- C:\WINDOWS\win.ini
2015-03-11 07:43:27 ----D---- C:\WINDOWS\system32\MRT
2015-03-11 07:37:01 ----A---- C:\WINDOWS\system32\MRT.exe
2015-03-11 07:23:36 ----D---- C:\WINDOWS\system32\catroot2
2015-03-10 17:18:11 ----SHD---- C:\System Volume Information
2015-03-10 17:01:03 ----D---- C:\Program Files\SUPERAntiSpyware
2015-03-10 08:24:39 ----D---- C:\WINDOWS\Logs
2015-03-06 12:11:46 ----D---- C:\Users\Lucas\AppData\Roaming\CPC
2015-03-06 10:10:56 ----D---- C:\Program Files (x86)\KA15
2015-03-04 22:24:42 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-22 16:48:33 ----D---- C:\WINDOWS\twain_32
2015-02-19 20:51:51 ----D---- C:\Users\Lucas\AppData\Roaming\newnext.me
2015-02-17 20:42:33 ----D---- C:\WZP2010
2015-02-16 16:08:03 ----RSD---- C:\WINDOWS\assembly
2015-02-14 19:04:14 ----SD---- C:\WINDOWS\system32\CompatTel
2015-02-14 19:04:14 ----D---- C:\WINDOWS\system32\appraiser
2015-02-14 19:04:11 ----D---- C:\WINDOWS\apppatch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-01-31 652784]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-08-24 39008]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2015-02-25 132120]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2015-02-25 28600]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2015-02-25 128536]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\WINDOWS\system32\DRIVERS\stflt.sys [2015-03-11 51496]
R2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [2011-03-21 11576]
R3 ACPIVPC;@oem56.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-08-24 33560]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-04-28 599240]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 CnxtHdAudService;@oem93.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2013-03-05 1680992]
R3 ETD;@oem54.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-02-27 355664]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcDAud;@oem60.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-04-22 342528]
R3 iwdbus;@oem106.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MEIx64;@oem27.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RSUSBVSTOR;@oem82.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2013-01-15 327240]
R3 rtsuvc;@oem40.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-04-24 8243144]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 AthBTPort;@oem53.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2013-06-13 89800]
S3 BTATH_A2DP;@oem52.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2013-06-13 347336]
S3 btath_avdt;@oem52.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2013-06-13 115912]
S3 BTATH_HCRP;@oem55.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-06-13 179432]
S3 BTATH_LWFLT;@oem57.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2013-06-13 77464]
S3 BTATH_RCP;@oem59.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-06-13 136784]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-09-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2015-03-09 172344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2015-02-25 432888]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2015-02-25 432888]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2013-06-13 312448]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2015-01-19 182520]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
R2 CxAudMsg;Conexant Audio Message Service; C:\windows\system32\CxAudMsg64.exe [2013-03-05 202400]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-08-21 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-09-11 277792]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2014-11-04 1146272]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-09-11 365344]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-08-24 68368]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-02-01 150600]
S3 PDF Architect 2;PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [2014-04-30 1716264]
S3 pdfforge CrashHandler;pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [2014-04-30 861736]
S3 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

-----------------EOF-----------------

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 12 bře 2015 20:57
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 12 bře 2015 21:21
od DarkMan_X
Tu je LOG, akorat jsem nevypnul rezidentni stit Antiviru, snad to nevadi...

# AdwCleaner v4.112 - Logfile created 12/03/2015 at 21:15:15
# Updated 09/03/2015 by Xplode
# Database : 2015-03-05.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Lucas - DB2013
# Running from : C:\Users\Lucas\Desktop\adwcleaner_4.112.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\GreenTree Applications
Folder Deleted : C:\Users\Lucas\AppData\Local\genienext
Folder Deleted : C:\Users\Lucas\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Lucas\AppData\Roaming\pdfforge
File Deleted : C:\Users\Bajinka\daemonprocess.txt
File Deleted : C:\Users\Lucas\daemonprocess.txt

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v


-\\ Google Chrome v41.0.2272.89


*************************

AdwCleaner[R0].txt - [1155 bytes] - [12/03/2015 21:11:43]
AdwCleaner[S0].txt - [1096 bytes] - [12/03/2015 21:15:15]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1155 bytes] ##########

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 12 bře 2015 22:31
od Rudy
Dejte nový log RSIT.

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 13 bře 2015 09:18
od DarkMan_X
Logfile of random's system information tool 1.10 (written by random/random)
Run by Lucas at 2015-03-13 09:17:20
Microsoft Windows 8.1
System drive C: has 343 GB (79%) free of 434 GB
Total RAM: 3962 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:17:22, on 13. 3. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\Lucas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com/?pc=lcjb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - Global Startup: ING eKalkulačka.lnk = Lucas\ING_eKalkulacka_OVB_CZ\jettyStarter.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Architect 2 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\ws.exe
O23 - Service: pdfforge CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 11408 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\windows\system32\CxAudMsg64.exe
dashost.exe {9e46bbd7-26d5-4c2d-a538b11392bd1d82}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000005cc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-eb77d5c4-8a27-4e47-b64d-cad75b19e93b -SystemEventPortName:HostProcess-eb881f5b-fe4f-47a5-976b-02dff5ca056d -IoCancelEventPortName:HostProcess-47df6eb5-482e-4c21-adba-2115ca47f713 -NonStateChangingEventPortName:HostProcess-5afc9ac0-3589-499c-b05b-3bdfc25c1a67 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2db8900d-433f-4210-825c-4c18b841643b -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
taskeng.exe {9B8EF554-72B3-49D2-B448-C152A3189E70}
taskhostex.exe
igfxHK.exe
igfxTray.exe
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\system32\igfxEM.exe" -Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" /ELEVATED
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding

"C:\Users\Lucas\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-03-21 6270336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-04-24 6339656]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2014-10-01 448912]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-08-24 17097200]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-08-24 193008]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-02-04 899680]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2013-03-05 1647616]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2014-11-04 2774904]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2014-11-04 3681656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2015-01-19 126712]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2015-02-25 703280]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ING eKalkulačka.lnk - C:\Users\Lucas\ING_eKalkulacka_OVB_CZ\jettyStarter.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SMR430]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-12 21:11:33 ----D---- C:\AdwCleaner
2015-03-11 09:11:47 ----A---- C:\WINDOWS\ntbtlog.txt
2015-03-11 09:11:42 ----D---- C:\Users\Lucas\AppData\Roaming\Spyware Terminator
2015-03-11 09:11:42 ----D---- C:\ProgramData\Spyware Terminator
2015-03-11 09:11:42 ----A---- C:\WINDOWS\system32\drivers\stflt.sys
2015-03-11 09:11:13 ----D---- C:\Program Files (x86)\Spyware Terminator
2015-03-11 08:27:28 ----D---- C:\NPE
2015-03-11 07:28:20 ----A---- C:\WINDOWS\system32\calc.exe
2015-03-11 07:28:19 ----A---- C:\WINDOWS\SYSWOW64\calc.exe
2015-03-11 07:28:15 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2015-03-11 07:28:15 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2015-03-11 07:28:14 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2015-03-11 07:28:13 ----A---- C:\WINDOWS\SYSWOW64\winshfhc.dll
2015-03-11 07:28:13 ----A---- C:\WINDOWS\system32\winshfhc.dll
2015-03-11 07:28:00 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2015-03-11 07:28:00 ----A---- C:\WINDOWS\system32\SHCore.dll
2015-03-11 07:27:51 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-03-11 07:27:51 ----A---- C:\WINDOWS\system32\win32k.sys
2015-03-11 07:27:51 ----A---- C:\WINDOWS\system32\schannel.dll
2015-03-11 07:27:50 ----A---- C:\WINDOWS\SYSWOW64\photowiz.dll
2015-03-11 07:27:50 ----A---- C:\WINDOWS\system32\photowiz.dll
2015-03-11 07:27:49 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-03-11 07:27:49 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\lpk.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-03-11 07:27:43 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\printui.exe
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\win32spl.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\puiobj.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\puiapi.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\prnntfy.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\printui.exe
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\localspl.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\findnetprinters.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\compstui.dll
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\fsquirt.exe
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\rfcomm.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\hidbth.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\bthenum.sys
2015-03-11 07:27:39 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2015-03-11 07:27:39 ----A---- C:\WINDOWS\system32\dwmcore.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\mfc42u.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\mfc42.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\atlthunk.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\mfc42u.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\atlthunk.dll
2015-03-11 07:27:37 ----A---- C:\WINDOWS\system32\mfc42.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSReset.exe
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSCollect.exe
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\SYSWOW64\StorageContextHandler.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\system32\authui.dll
2015-03-11 07:27:28 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-03-11 07:27:28 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-03-11 07:27:27 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-03-11 07:27:22 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\SYSWOW64\eappcfg.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\ubpm.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\rfxvmt.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\rdpudd.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eapphost.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eappcfg.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\drivers\rdpvideominiport.sys
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eappprxy.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eapphost.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eappgnui.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eapp3hst.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\system32\eappprxy.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\system32\eappgnui.dll
2015-03-11 07:27:06 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-03-11 07:27:05 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-03-11 07:27:02 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-03-11 07:27:01 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-03-11 07:26:59 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-03-11 07:26:58 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\jscript.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-03-11 07:26:43 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-03-11 07:26:43 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-11 07:26:38 ----A---- C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-11 07:26:37 ----A---- C:\WINDOWS\system32\shell32.dll
2015-03-11 07:26:36 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-03-11 07:26:24 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2015-03-11 07:26:24 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2015-03-11 07:26:22 ----A---- C:\WINDOWS\SYSWOW64\WMPhoto.dll
2015-03-11 07:26:22 ----A---- C:\WINDOWS\system32\WMPhoto.dll
2015-03-11 07:26:21 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2015-03-11 07:26:21 ----A---- C:\WINDOWS\explorer.exe
2015-03-11 07:26:19 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2015-03-11 07:26:19 ----A---- C:\WINDOWS\system32\msctf.dll
2015-03-10 08:45:48 ----A---- C:\WINDOWS\system32\drivers\avnetflt.sys
2015-03-10 08:44:16 ----D---- C:\Users\Lucas\AppData\Roaming\Avira
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2015-03-10 08:39:37 ----D---- C:\ProgramData\Avira
2015-03-10 08:39:37 ----D---- C:\Program Files (x86)\Avira
2015-03-10 08:39:34 ----D---- C:\ProgramData\Package Cache
2015-03-10 08:38:27 ----D---- C:\OETemp
2015-03-06 12:23:00 ----D---- C:\CPSkla
2015-03-06 12:12:14 ----D---- C:\DATA_CPC
2015-03-06 12:10:37 ----D---- C:\Program Files (x86)\CPC
2015-02-26 21:14:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2015-02-26 21:14:23 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-26 21:14:22 ----A---- C:\WINDOWS\SYSWOW64\GlobCollationHost.dll
2015-02-26 21:14:22 ----A---- C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-17 15:26:28 ----A---- C:\WINDOWS\SYSWOW64\FM20.DLL

======List of files/folders modified in the last 1 month======

2015-03-13 09:17:21 ----D---- C:\WINDOWS\Temp
2015-03-13 09:17:21 ----D---- C:\Program Files\trend micro
2015-03-13 09:08:28 ----D---- C:\WINDOWS\Prefetch
2015-03-13 09:06:51 ----D---- C:\WINDOWS\system32\sru
2015-03-12 21:25:21 ----D---- C:\WINDOWS\system32\config
2015-03-12 21:22:29 ----RD---- C:\WINDOWS\System32
2015-03-12 21:22:29 ----D---- C:\WINDOWS\Inf
2015-03-12 21:22:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-12 21:19:17 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-03-12 20:17:40 ----D---- C:\rsit
2015-03-12 17:20:27 ----HD---- C:\ProgramData
2015-03-12 15:41:05 ----D---- C:\WINDOWS\system32\DriverStore
2015-03-12 15:38:52 ----D---- C:\WINDOWS\WinSxS
2015-03-12 15:29:27 ----D---- C:\WINDOWS\Microsoft.NET
2015-03-12 09:15:15 ----D---- C:\Windows
2015-03-12 09:13:55 ----D---- C:\WINDOWS\system32\drivers
2015-03-12 09:12:06 ----D---- C:\WINDOWS\SysWOW64
2015-03-12 09:12:05 ----RD---- C:\WINDOWS\ToastData
2015-03-12 09:12:04 ----D---- C:\WINDOWS\WinStore
2015-03-12 09:12:03 ----D---- C:\Program Files\Windows Defender
2015-03-12 09:12:02 ----D---- C:\Program Files (x86)\Windows Defender
2015-03-11 18:37:22 ----D---- C:\ProgramData\CPC
2015-03-11 17:34:08 ----D---- C:\WINDOWS\CbsTemp
2015-03-11 17:33:45 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-03-11 17:33:45 ----D---- C:\WINDOWS\system32\cs-CZ
2015-03-11 15:46:06 ----D---- C:\Users\Lucas\AppData\Roaming\vlc
2015-03-11 10:26:47 ----D---- C:\WINDOWS\rescache
2015-03-11 09:55:39 ----D---- C:\WINDOWS\debug
2015-03-11 09:11:13 ----RD---- C:\Program Files (x86)
2015-03-11 09:02:15 ----D---- C:\WINDOWS\SoftwareDistribution
2015-03-11 08:54:10 ----D---- C:\Program Files\CCleaner
2015-03-11 08:39:29 ----HD---- C:\Program Files\WindowsApps
2015-03-11 08:39:29 ----D---- C:\WINDOWS\AppReadiness
2015-03-11 07:52:43 ----D---- C:\WINDOWS\system32\catroot
2015-03-11 07:45:02 ----D---- C:\Program Files\Internet Explorer
2015-03-11 07:45:02 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 07:44:51 ----SHD---- C:\WINDOWS\Installer
2015-03-11 07:44:50 ----D---- C:\ProgramData\Microsoft Help
2015-03-11 07:44:39 ----A---- C:\WINDOWS\win.ini
2015-03-11 07:43:27 ----D---- C:\WINDOWS\system32\MRT
2015-03-11 07:37:01 ----A---- C:\WINDOWS\system32\MRT.exe
2015-03-11 07:23:36 ----D---- C:\WINDOWS\system32\catroot2
2015-03-10 17:18:11 ----SHD---- C:\System Volume Information
2015-03-10 17:01:03 ----D---- C:\Program Files\SUPERAntiSpyware
2015-03-10 08:24:39 ----D---- C:\WINDOWS\Logs
2015-03-06 12:11:46 ----D---- C:\Users\Lucas\AppData\Roaming\CPC
2015-03-06 10:10:56 ----D---- C:\Program Files (x86)\KA15
2015-03-04 22:24:42 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-22 16:48:33 ----D---- C:\WINDOWS\twain_32
2015-02-17 20:42:33 ----D---- C:\WZP2010
2015-02-16 16:08:03 ----RSD---- C:\WINDOWS\assembly
2015-02-14 19:04:14 ----SD---- C:\WINDOWS\system32\CompatTel
2015-02-14 19:04:14 ----D---- C:\WINDOWS\system32\appraiser
2015-02-14 19:04:11 ----D---- C:\WINDOWS\apppatch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-01-31 652784]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-08-24 39008]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2015-02-25 132120]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2015-02-25 28600]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2015-02-25 128536]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\WINDOWS\system32\DRIVERS\stflt.sys [2015-03-11 51496]
R2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [2011-03-21 11576]
R3 ACPIVPC;@oem56.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-08-24 33560]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-04-28 599240]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 CnxtHdAudService;@oem93.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2013-03-05 1680992]
R3 ETD;@oem54.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-02-27 355664]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcDAud;@oem60.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-04-22 342528]
R3 iwdbus;@oem106.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MEIx64;@oem27.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RSUSBVSTOR;@oem82.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2013-01-15 327240]
R3 rtsuvc;@oem40.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-04-24 8243144]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 AthBTPort;@oem53.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2013-06-13 89800]
S3 BTATH_A2DP;@oem52.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2013-06-13 347336]
S3 btath_avdt;@oem52.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2013-06-13 115912]
S3 BTATH_HCRP;@oem55.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-06-13 179432]
S3 BTATH_LWFLT;@oem57.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2013-06-13 77464]
S3 BTATH_RCP;@oem59.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-06-13 136784]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-09-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2015-03-09 172344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2015-02-25 432888]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2015-02-25 432888]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2013-06-13 312448]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2015-01-19 182520]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
R2 CxAudMsg;Conexant Audio Message Service; C:\windows\system32\CxAudMsg64.exe [2013-03-05 202400]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-08-21 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-09-11 277792]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2014-11-04 1146272]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-09-11 365344]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-08-24 68368]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-02-01 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PDF Architect 2;PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [2014-04-30 1716264]
S3 pdfforge CrashHandler;pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [2014-04-30 861736]
S3 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

-----------------EOF-----------------

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 13 bře 2015 18:08
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\Skype\Toolbars
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64

:services
c2cpnrsvc
c2cautoupdatesvc

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 14 bře 2015 17:05
od DarkMan_X
Logfile of random's system information tool 1.10 (written by random/random)
Run by Lucas at 2015-03-14 17:04:49
Microsoft Windows 8.1
System drive C: has 343 GB (79%) free of 434 GB
Total RAM: 3962 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:04:52, on 14. 3. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\Lucas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com/?pc=lcjb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - Global Startup: ING eKalkulačka.lnk = Lucas\ING_eKalkulacka_OVB_CZ\jettyStarter.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Architect 2 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\ws.exe
O23 - Service: pdfforge CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 11294 bytes

======Listing Processes======





wininit.exe


C:\WINDOWS\system32\lsass.exe
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
C:\windows\system32\CxAudMsg64.exe
dashost.exe {bf9afcbd-83de-43f8-9a4fc5404a1f464d}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000594
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ba37d3f8-dd46-463d-b1d0-8b21ca5ebbb5 -SystemEventPortName:HostProcess-72a5ff37-e8ad-41ad-9366-9805f7e365f8 -IoCancelEventPortName:HostProcess-871e4515-d3a7-4042-b269-d1088700c5b5 -NonStateChangingEventPortName:HostProcess-3f9d895d-0a69-478f-befe-c7bf02a04bd4 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e7cc6ae8-b193-45c4-bee7-6a3c635b73e5 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe -Embedding
taskeng.exe {E076D998-69C9-4FC8-BDC4-C371302DD133}
taskhostex.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 584 588 596 65536 592
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" /ELEVATED
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min


"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"

"C:\Users\Lucas\Desktop\RSITx64.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-04-24 6339656]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-01-31 36352]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2014-10-01 448912]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-08-24 17097200]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-08-24 193008]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-02-04 899680]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2013-03-05 1647616]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2014-11-04 2774904]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2014-11-04 3681656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2015-01-19 126712]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2015-02-25 703280]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ING eKalkulačka.lnk - C:\Users\Lucas\ING_eKalkulacka_OVB_CZ\jettyStarter.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SMR430]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-14 16:59:36 ----D---- C:\_OTM
2015-03-12 21:11:33 ----D---- C:\AdwCleaner
2015-03-11 09:11:47 ----A---- C:\WINDOWS\ntbtlog.txt
2015-03-11 09:11:42 ----D---- C:\Users\Lucas\AppData\Roaming\Spyware Terminator
2015-03-11 09:11:42 ----D---- C:\ProgramData\Spyware Terminator
2015-03-11 09:11:42 ----A---- C:\WINDOWS\system32\drivers\stflt.sys
2015-03-11 09:11:13 ----D---- C:\Program Files (x86)\Spyware Terminator
2015-03-11 08:27:28 ----D---- C:\NPE
2015-03-11 07:28:20 ----A---- C:\WINDOWS\system32\calc.exe
2015-03-11 07:28:19 ----A---- C:\WINDOWS\SYSWOW64\calc.exe
2015-03-11 07:28:15 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2015-03-11 07:28:15 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2015-03-11 07:28:14 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2015-03-11 07:28:13 ----A---- C:\WINDOWS\SYSWOW64\winshfhc.dll
2015-03-11 07:28:13 ----A---- C:\WINDOWS\system32\winshfhc.dll
2015-03-11 07:28:00 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2015-03-11 07:28:00 ----A---- C:\WINDOWS\system32\SHCore.dll
2015-03-11 07:27:51 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-03-11 07:27:51 ----A---- C:\WINDOWS\system32\win32k.sys
2015-03-11 07:27:51 ----A---- C:\WINDOWS\system32\schannel.dll
2015-03-11 07:27:50 ----A---- C:\WINDOWS\SYSWOW64\photowiz.dll
2015-03-11 07:27:50 ----A---- C:\WINDOWS\system32\photowiz.dll
2015-03-11 07:27:49 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-03-11 07:27:49 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\lpk.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-03-11 07:27:44 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-03-11 07:27:43 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\printui.exe
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\win32spl.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\puiobj.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\puiapi.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\prnntfy.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\printui.exe
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\localspl.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\findnetprinters.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2015-03-11 07:27:41 ----A---- C:\WINDOWS\system32\compstui.dll
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\fsquirt.exe
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\rfcomm.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\hidbth.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2015-03-11 07:27:40 ----AC---- C:\WINDOWS\system32\drivers\bthenum.sys
2015-03-11 07:27:39 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2015-03-11 07:27:39 ----A---- C:\WINDOWS\system32\dwmcore.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\mfc42u.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\mfc42.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\SYSWOW64\atlthunk.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\mfc42u.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-11 07:27:38 ----A---- C:\WINDOWS\system32\atlthunk.dll
2015-03-11 07:27:37 ----A---- C:\WINDOWS\system32\mfc42.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSReset.exe
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\WSCollect.exe
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-11 07:27:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\SYSWOW64\StorageContextHandler.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-11 07:27:29 ----A---- C:\WINDOWS\system32\authui.dll
2015-03-11 07:27:28 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-03-11 07:27:28 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-03-11 07:27:27 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-03-11 07:27:22 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\SYSWOW64\eappcfg.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\ubpm.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\rfxvmt.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\rdpudd.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eapphost.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eappcfg.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2015-03-11 07:27:21 ----A---- C:\WINDOWS\system32\drivers\rdpvideominiport.sys
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eappprxy.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eapphost.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eappgnui.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\SYSWOW64\eapp3hst.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\system32\eappprxy.dll
2015-03-11 07:27:20 ----A---- C:\WINDOWS\system32\eappgnui.dll
2015-03-11 07:27:06 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-03-11 07:27:05 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-03-11 07:27:02 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-03-11 07:27:01 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-03-11 07:26:59 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-03-11 07:26:58 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-03-11 07:26:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\jscript.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-03-11 07:26:56 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-03-11 07:26:43 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-03-11 07:26:43 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-11 07:26:38 ----A---- C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-11 07:26:37 ----A---- C:\WINDOWS\system32\shell32.dll
2015-03-11 07:26:36 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-03-11 07:26:24 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2015-03-11 07:26:24 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2015-03-11 07:26:22 ----A---- C:\WINDOWS\SYSWOW64\WMPhoto.dll
2015-03-11 07:26:22 ----A---- C:\WINDOWS\system32\WMPhoto.dll
2015-03-11 07:26:21 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2015-03-11 07:26:21 ----A---- C:\WINDOWS\explorer.exe
2015-03-11 07:26:19 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2015-03-11 07:26:19 ----A---- C:\WINDOWS\system32\msctf.dll
2015-03-10 08:45:48 ----A---- C:\WINDOWS\system32\drivers\avnetflt.sys
2015-03-10 08:44:16 ----D---- C:\Users\Lucas\AppData\Roaming\Avira
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2015-03-10 08:42:12 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2015-03-10 08:39:37 ----D---- C:\ProgramData\Avira
2015-03-10 08:39:37 ----D---- C:\Program Files (x86)\Avira
2015-03-10 08:39:34 ----D---- C:\ProgramData\Package Cache
2015-03-10 08:38:27 ----D---- C:\OETemp
2015-03-06 12:23:00 ----D---- C:\CPSkla
2015-03-06 12:12:14 ----D---- C:\DATA_CPC
2015-03-06 12:10:37 ----D---- C:\Program Files (x86)\CPC
2015-02-26 21:14:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2015-02-26 21:14:23 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2015-02-26 21:14:22 ----A---- C:\WINDOWS\SYSWOW64\GlobCollationHost.dll
2015-02-26 21:14:22 ----A---- C:\WINDOWS\system32\GlobCollationHost.dll
2015-02-17 15:26:28 ----A---- C:\WINDOWS\SYSWOW64\FM20.DLL

======List of files/folders modified in the last 1 month======

2015-03-14 17:04:53 ----D---- C:\WINDOWS\Temp
2015-03-14 17:04:51 ----D---- C:\Program Files\trend micro
2015-03-14 17:04:48 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-03-14 17:03:41 ----D---- C:\WINDOWS\Prefetch
2015-03-14 17:00:00 ----D---- C:\WINDOWS\system32\sru
2015-03-14 16:59:37 ----RD---- C:\Program Files (x86)\Skype
2015-03-14 16:59:37 ----D---- C:\WINDOWS\Tasks
2015-03-14 16:32:24 ----HD---- C:\ProgramData
2015-03-14 16:08:58 ----D---- C:\WINDOWS\AppReadiness
2015-03-14 16:08:57 ----HD---- C:\Program Files\WindowsApps
2015-03-13 17:53:04 ----D---- C:\Users\Lucas\AppData\Roaming\vlc
2015-03-13 14:44:38 ----D---- C:\WINDOWS\rescache
2015-03-13 14:39:25 ----D---- C:\WINDOWS\Inf
2015-03-13 14:37:44 ----D---- C:\WINDOWS\Microsoft.NET
2015-03-13 14:24:24 ----D---- C:\WINDOWS\system32\config
2015-03-12 21:22:29 ----RD---- C:\WINDOWS\System32
2015-03-12 21:22:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-12 20:17:40 ----D---- C:\rsit
2015-03-12 15:41:05 ----D---- C:\WINDOWS\system32\DriverStore
2015-03-12 15:38:52 ----D---- C:\WINDOWS\WinSxS
2015-03-12 09:15:15 ----D---- C:\Windows
2015-03-12 09:13:55 ----D---- C:\WINDOWS\system32\drivers
2015-03-12 09:12:06 ----D---- C:\WINDOWS\SysWOW64
2015-03-12 09:12:05 ----RD---- C:\WINDOWS\ToastData
2015-03-12 09:12:04 ----D---- C:\WINDOWS\WinStore
2015-03-12 09:12:03 ----D---- C:\Program Files\Windows Defender
2015-03-12 09:12:02 ----D---- C:\Program Files (x86)\Windows Defender
2015-03-11 18:37:22 ----D---- C:\ProgramData\CPC
2015-03-11 17:34:08 ----D---- C:\WINDOWS\CbsTemp
2015-03-11 17:33:45 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-03-11 17:33:45 ----D---- C:\WINDOWS\system32\cs-CZ
2015-03-11 09:55:39 ----D---- C:\WINDOWS\debug
2015-03-11 09:11:13 ----RD---- C:\Program Files (x86)
2015-03-11 09:02:15 ----D---- C:\WINDOWS\SoftwareDistribution
2015-03-11 08:54:10 ----D---- C:\Program Files\CCleaner
2015-03-11 07:52:43 ----D---- C:\WINDOWS\system32\catroot
2015-03-11 07:45:02 ----D---- C:\Program Files\Internet Explorer
2015-03-11 07:45:02 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-11 07:44:51 ----SHD---- C:\WINDOWS\Installer
2015-03-11 07:44:50 ----D---- C:\ProgramData\Microsoft Help
2015-03-11 07:44:39 ----A---- C:\WINDOWS\win.ini
2015-03-11 07:43:27 ----D---- C:\WINDOWS\system32\MRT
2015-03-11 07:37:01 ----A---- C:\WINDOWS\system32\MRT.exe
2015-03-11 07:23:36 ----D---- C:\WINDOWS\system32\catroot2
2015-03-10 17:18:11 ----SHD---- C:\System Volume Information
2015-03-10 17:01:03 ----D---- C:\Program Files\SUPERAntiSpyware
2015-03-10 08:24:39 ----D---- C:\WINDOWS\Logs
2015-03-06 12:11:46 ----D---- C:\Users\Lucas\AppData\Roaming\CPC
2015-03-06 10:10:56 ----D---- C:\Program Files (x86)\KA15
2015-03-04 22:24:42 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-22 16:48:33 ----D---- C:\WINDOWS\twain_32
2015-02-17 20:42:33 ----D---- C:\WZP2010
2015-02-16 16:08:03 ----RSD---- C:\WINDOWS\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-01-31 652784]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-08-24 39008]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2015-02-25 132120]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2015-02-25 28600]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2015-02-25 128536]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\WINDOWS\system32\DRIVERS\stflt.sys [2015-03-11 51496]
R2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [2011-03-21 11576]
R3 ACPIVPC;@oem56.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-08-24 33560]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-04-28 599240]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 CnxtHdAudService;@oem93.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2013-03-05 1680992]
R3 ETD;@oem54.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-02-27 355664]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcDAud;@oem60.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-04-22 342528]
R3 iwdbus;@oem106.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MEIx64;@oem27.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RSUSBVSTOR;@oem82.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2013-01-15 327240]
R3 rtsuvc;@oem40.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-04-24 8243144]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 AthBTPort;@oem53.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2013-06-13 89800]
S3 BTATH_A2DP;@oem52.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2013-06-13 347336]
S3 btath_avdt;@oem52.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2013-06-13 115912]
S3 BTATH_HCRP;@oem55.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-06-13 179432]
S3 BTATH_LWFLT;@oem57.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2013-06-13 77464]
S3 BTATH_RCP;@oem59.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-06-13 136784]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-09-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2015-03-09 172344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2015-02-25 432888]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2015-02-25 432888]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2013-06-13 312448]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2015-01-19 182520]
R2 CxAudMsg;Conexant Audio Message Service; C:\windows\system32\CxAudMsg64.exe [2013-03-05 202400]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-01-31 15344]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-08-21 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-09-11 277792]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2014-11-04 1146272]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-09-11 365344]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-08-24 68368]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-02-01 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PDF Architect 2;PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [2014-04-30 1716264]
S3 pdfforge CrashHandler;pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [2014-04-30 861736]
S3 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

-----------------EOF-----------------

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 14 bře 2015 17:44
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Lucas.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 15 bře 2015 19:04
od DarkMan_X
Hotovo... akorat po kliknuti na FixChecked vyskocila nejaka chybova hlaska, ale snad je to OK? :) díky
Rudy píše:Dvouklikem na soubor C:\Program Files\trend micro\Lucas.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 15 bře 2015 19:12
od Rudy
Ono nemusí být možné všechno fixovat. Jde ale jen o nefunkční zbytky, takže budou pouze zabírat místo. Mělo by to být už čisté.

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 17 bře 2015 18:17
od DarkMan_X
díky za rychlost a ochotu :)

Re: Prosím o kontrolu logu po nalezení malware

Napsal: 17 bře 2015 19:04
od Rudy
Rádo se stalo! :)