Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

download.exe

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Lonely Girl
Návštěvník
Návštěvník
Příspěvky: 31
Registrován: 01 úno 2015 20:14

download.exe

#1 Příspěvek od Lonely Girl »

Dobrý den,dnes jsem na nějakých stránkách omylem stáhla soubor download.exe..Antivir mi ho sice během instalace nejspíš odstranil,ale s spolu s tím zmizel i Google chrome,PhotoFiltre,RealWorld Paint a další věci..Chrome se mi povedlo dostat zpět,ale nevím jak stáhnout Photofiltre..Po instalaci se mi otevře v aplikaci WordPad..Nevíte co s tím?
A rovnou bych poprosila o kontrolu,jestli tam není ještě něco někde špatně..

Logfile of random's system information tool 1.10 (written by random/random)
Run by Monika at 2015-03-21 20:16:37
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 132 GB (69%) free of 191 GB
Total RAM: 3983 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:58, on 21. 3. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\WebcamMax\wcmmon.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Monika.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... 45M19H45MX
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... 45M19H45MX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... 45M19H45MX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... 45M19H45MX
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe,
O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.1.0.411\AVG Web TuneUp.dll
O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
O4 - HKCU\..\Run: [WebcamMaxAutoRun] "C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: Asus WebStorage Windows Service - ASUS Cloud Corporation - C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @oem25.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.4.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 9456 bytes

======Listing Processes======




c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-9890-0472c3a82d5f /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"


wininit.exe
winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 1006230201680
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe"
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
dashost.exe {2d3f13b5-7f26-4589-90ea6ec6f58f2bfb}
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
taskhostex.exe
C:\Windows\Explorer.EXE
KBFiltr.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
"C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
ctfmon.exe
"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe" --type=renderer --no-sandbox --user-agent="Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" --lang=en-US --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --lang=en-US --uncaught-exception-stack-size=1024 --disable-pepper-3d --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --disable-pepper-3d --channel="3896.1.897271755\834118203" /prefetch:673131151
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"

"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
/S
"C:\Windows\System32\WWAHost.exe" -ServerName:Windows.Store
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --profile-directory=Default
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6236.0.1042421578\864956554" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3408 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=6236 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="6236.8.624328385\793452278" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=6236 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="6236.18.1592370271\1923825516" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=6236 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="6236.20.1792757942\376397928" /prefetch:673131151
"C:\Program Files\Windows NT\Accessories\WORDPAD.EXE" "C:\Users\Monika\AppData\Local\Temp\Temp1_StudioEN (1).zip\StudioEN.plg"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=6236 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="6236.25.1180806206\1799992781" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 580 584 592 65536 588

"C:\Users\Monika\Downloads\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Web TuneUp - C:\Program Files\AVG Web TuneUp\4.1.0.411\AVG Web TuneUp.dll [2015-03-04 2467864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Web TuneUp - C:\Program Files (x86)\AVG Web TuneUp\4.1.0.411\AVG Web TuneUp.dll [2015-03-04 2424856]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-02-19 391152]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-02-19 771568]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WebcamMaxAutoRun"=C:\Program Files (x86)\WebcamMax\wcmmon.exe [2011-07-17 1038848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WebStorage"=C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [2014-08-20 63296]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-02-19 3710416]
"ApnTBMon"=C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2014-12-19 1949080]
"vProt"=C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2015-03-04 3033112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-01-16 624640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-21 20:16:37 ----D---- C:\rsit
2015-03-21 20:16:37 ----D---- C:\Program Files\trend micro
2015-03-21 18:50:05 ----D---- C:\Program Files (x86)\Crosswords
2015-03-21 18:49:34 ----D---- C:\Program Files (x86)\youtubeadblocker
2015-03-21 18:49:25 ----D---- C:\Program Files (x86)\VoaudiX
2015-03-21 18:49:18 ----D---- C:\Program Files (x86)\Vauduixx
2015-03-21 18:48:44 ----D---- C:\ProgramData\213968718550338235
2015-03-21 18:48:44 ----D---- C:\Program Files (x86)\Vaoudiixu
2015-03-21 18:47:25 ----D---- C:\ProgramData\jfgbcckgkalgnhmehkljjnbakoooljid
2015-03-21 18:46:46 ----D---- C:\ProgramData\{3615ae50-83eb-dee8-3615-5ae5083eb942}
2015-03-21 18:46:17 ----D---- C:\ProgramData\{188db186-6f5b-e2e0-188d-db1866f5c619}
2015-03-10 21:56:22 ----A---- C:\Windows\system32\calc.exe
2015-03-10 21:56:21 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-03-10 21:55:35 ----A---- C:\Windows\system32\drivers\WdFilter.sys
2015-03-10 21:55:35 ----A---- C:\Windows\system32\drivers\WdBoot.sys
2015-03-10 21:55:34 ----A---- C:\Windows\system32\drivers\WdNisDrv.sys
2015-03-10 21:55:33 ----A---- C:\Windows\SYSWOW64\winshfhc.dll
2015-03-10 21:55:33 ----A---- C:\Windows\system32\winshfhc.dll
2015-03-10 21:54:39 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2015-03-10 21:54:39 ----A---- C:\Windows\system32\photowiz.dll
2015-03-10 21:54:35 ----A---- C:\Windows\system32\msftedit.dll
2015-03-10 21:54:34 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-03-10 21:54:30 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-03-10 21:54:24 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\win32spl.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\puiobj.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\localspl.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\DafPrintProvider.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\puiapi.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\prnntfy.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\printui.exe
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\findnetprinters.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\compstui.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\puiapi.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\prnntfy.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\printui.exe
2015-03-10 21:54:23 ----A---- C:\Windows\system32\findnetprinters.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\compstui.dll
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\fsquirt.exe
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\drivers\hidbth.sys
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\drivers\bthport.sys
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\rfcomm.sys
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\bthenum.sys
2015-03-10 21:54:15 ----A---- C:\Windows\system32\dwmcore.dll
2015-03-10 21:54:14 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-03-10 21:54:11 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2015-03-10 21:54:11 ----A---- C:\Windows\system32\atlthunk.dll
2015-03-10 21:54:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_47.dll
2015-03-10 21:54:10 ----A---- C:\Windows\SYSWOW64\atlthunk.dll
2015-03-10 21:54:10 ----A---- C:\Windows\system32\mfc42u.dll
2015-03-10 21:54:09 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2015-03-10 21:54:09 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2015-03-10 21:54:08 ----A---- C:\Windows\system32\mfc42.dll
2015-03-10 21:53:58 ----A---- C:\Windows\system32\WSShared.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-03-10 21:53:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 21:53:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-03-10 21:53:56 ----A---- C:\Windows\system32\WSReset.exe
2015-03-10 21:53:56 ----A---- C:\Windows\system32\WSCollect.exe
2015-03-10 21:53:46 ----A---- C:\Windows\SYSWOW64\StorageContextHandler.dll
2015-03-10 21:53:46 ----A---- C:\Windows\system32\StorageContextHandler.dll
2015-03-10 21:53:43 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-03-10 21:53:43 ----A---- C:\Windows\system32\authui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappprxy.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappcfg.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappprxy.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eapphost.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappgnui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappcfg.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eapp3hst.dll
2015-03-10 21:53:37 ----A---- C:\Windows\system32\LockScreenContentServer.exe
2015-03-10 21:53:34 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-03-10 21:53:34 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-03-10 21:53:29 ----A---- C:\Windows\explorer.exe
2015-03-10 21:53:28 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-03-10 21:53:09 ----A---- C:\Windows\system32\SHCore.dll
2015-03-10 21:53:08 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2015-03-10 20:38:41 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-10 20:38:41 ----A---- C:\Windows\system32\schannel.dll
2015-03-10 20:38:40 ----A---- C:\Windows\system32\win32k.sys
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-10 20:38:39 ----A---- C:\Windows\system32\fontsub.dll
2015-03-10 20:38:39 ----A---- C:\Windows\system32\atmfd.dll
2015-03-10 20:38:38 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-10 20:38:38 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-10 20:38:38 ----A---- C:\Windows\system32\lpk.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\dciman32.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\atmlib.dll
2015-03-10 20:38:37 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-03-10 20:38:37 ----A---- C:\Windows\system32\ntdll.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\ubpm.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rfxvmt.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2015-03-10 20:37:59 ----A---- C:\Windows\system32\mshtml.dll
2015-03-10 20:37:57 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-10 20:37:54 ----A---- C:\Windows\system32\jscript9.dll
2015-03-10 20:37:53 ----A---- C:\Windows\system32\ieframe.dll
2015-03-10 20:37:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-10 20:37:50 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-10 20:37:50 ----A---- C:\Windows\system32\wininet.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\urlmon.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\inetcomm.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\iertutil.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\vbscript.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\iepeers.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\webcheck.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\jscript.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\actxprxy.dll
2015-03-10 20:37:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-10 20:37:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-10 20:37:25 ----A---- C:\Windows\system32\shell32.dll
2015-03-10 20:37:24 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-10 20:37:00 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-10 20:37:00 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-10 20:36:59 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-10 20:36:59 ----A---- C:\Windows\system32\msctf.dll
2015-03-07 12:27:37 ----D---- C:\Users\Monika\AppData\Roaming\SYSTEMAX Software Development
2015-03-07 12:27:37 ----D---- C:\ProgramData\SYSTEMAX Software Development
2015-02-25 20:38:47 ----D---- C:\Users\Monika\AppData\Roaming\BANDISOFT
2015-02-25 20:38:04 ----D---- C:\Program Files (x86)\Bandicam
2015-02-25 20:38:01 ----D---- C:\Program Files (x86)\BandiMPEG1
2015-02-24 23:30:47 ----D---- C:\ProgramData\AVG Security Toolbar
2015-02-24 23:30:16 ----D---- C:\ProgramData\AVG Secure Search
2015-02-24 23:30:13 ----D---- C:\ProgramData\AVG Web TuneUp
2015-02-24 23:30:13 ----D---- C:\Program Files\AVG Web TuneUp
2015-02-24 23:30:03 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-02-24 22:48:29 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-02-24 22:48:29 ----D---- C:\Program Files (x86)\Star Stable Entertainment AB
2015-02-24 21:29:14 ----A---- C:\Windows\SYSWOW64\Windows.Globalization.dll
2015-02-24 21:29:14 ----A---- C:\Windows\system32\Windows.Globalization.dll
2015-02-24 21:29:13 ----A---- C:\Windows\SYSWOW64\GlobCollationHost.dll
2015-02-24 21:29:12 ----A---- C:\Windows\system32\GlobCollationHost.dll
2015-02-24 15:16:11 ----D---- C:\Users\Monika\AppData\Roaming\RealWorld
2015-02-24 15:15:47 ----D---- C:\Program Files (x86)\RealWorld Paint.COM

======List of files/folders modified in the last 1 month======

2015-03-21 20:16:44 ----D---- C:\Windows\Prefetch
2015-03-21 20:16:37 ----RD---- C:\Program Files
2015-03-21 20:14:11 ----D---- C:\Windows\Temp
2015-03-21 20:00:01 ----D---- C:\Windows\system32\sru
2015-03-21 19:59:01 ----SHD---- C:\Windows\Installer
2015-03-21 19:54:50 ----RD---- C:\Program Files (x86)
2015-03-21 19:54:34 ----D---- C:\Program Files (x86)\Google
2015-03-21 19:54:26 ----D---- C:\Windows\system32\Tasks
2015-03-21 19:54:01 ----D---- C:\Windows\Tasks
2015-03-21 18:59:01 ----D---- C:\ProgramData\MFAData
2015-03-21 18:50:16 ----D---- C:\ProgramData\AVG2015
2015-03-21 18:48:44 ----HD---- C:\ProgramData
2015-03-21 17:08:42 ----D---- C:\Windows\System32
2015-03-21 17:08:42 ----D---- C:\Windows\Inf
2015-03-21 17:08:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-21 10:50:26 ----D---- C:\Windows\AppReadiness
2015-03-21 10:50:25 ----HD---- C:\Program Files\WindowsApps
2015-03-16 16:24:55 ----D---- C:\Windows\system32\config
2015-03-15 14:25:55 ----D---- C:\Windows\Microsoft.NET
2015-03-15 13:11:03 ----D---- C:\Windows\system32\DriverStore
2015-03-15 13:10:49 ----D---- C:\Windows\WinSxS
2015-03-15 12:19:47 ----D---- C:\Windows\system32\drivers
2015-03-15 12:17:18 ----RD---- C:\Windows\ToastData
2015-03-15 12:17:17 ----D---- C:\Windows\SysWOW64
2015-03-15 12:17:16 ----D---- C:\Windows\WinStore
2015-03-15 12:16:18 ----AD---- C:\Windows
2015-03-15 12:13:21 ----D---- C:\Program Files\Windows Defender
2015-03-15 12:13:19 ----D---- C:\Program Files (x86)\Windows Defender
2015-03-15 12:13:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-15 12:13:15 ----D---- C:\Windows\system32\cs-CZ
2015-03-14 22:11:11 ----RSD---- C:\Windows\Fonts
2015-03-14 22:03:16 ----D---- C:\Písma
2015-03-14 12:10:48 ----D---- C:\Windows\CbsTemp
2015-03-14 12:08:51 ----D---- C:\Windows\system32\MRT
2015-03-14 12:01:44 ----A---- C:\Windows\system32\MRT.exe
2015-03-14 09:24:40 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-14 09:24:39 ----D---- C:\Program Files\Internet Explorer
2015-03-11 14:18:01 ----SHD---- C:\System Volume Information
2015-03-10 20:36:37 ----D---- C:\Windows\system32\catroot2
2015-03-04 22:24:42 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-01 10:15:26 ----D---- C:\Windows\rescache
2015-03-01 10:06:34 ----SHD---- C:\$RECYCLE.BIN
2015-02-24 23:30:14 ----D---- C:\Program Files (x86)\Common Files
2015-02-24 16:21:32 ----SD---- C:\Users\Monika\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-11-18 203544]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-02-03 341472]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-01-23 133088]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 MBI;@oem8.inf,%MBI.SVCDESC%;Intel(R) Sideband Fabric Device Service; C:\Windows\System32\drivers\MBI.sys [2013-10-28 29464]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
R1 Avgfwfd;@oem29.inf,%AvgfwfdService_Desc%;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2014-12-03 58136]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-02-19 270816]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
R1 Avgwfpa;AVG Firewall Driver; C:\Windows\system32\DRIVERS\avgwfpa.sys [2015-01-23 289248]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-10-28 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 WCMVCAM;@oem30.inf,%VCamDriver.DeviceDesc%;WebcamMax, WDM Video Capture; C:\Windows\system32\DRIVERS\wcmvcam64.sys [2012-04-15 1071032]
R3 AiCharger;ASUS Charger Driver; C:\Windows\system32\DRIVERS\AiCharger.sys [2014-03-27 17152]
R3 ATP;@oem17.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\Windows\System32\drivers\AsusTP.sys [2014-03-31 71952]
R3 bcbtums;@oem25.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM43XX;@oem20.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2014-12-01 7546544]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2014-10-28 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btwampfl;@oem25.inf,%btwampfl.ServiceName%;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2014-02-03 166616]
R3 btwaudio;@oem21.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-03-19 190168]
R3 btwavdt;@oem21.inf,%btwavdt.SvcDesc%;Bluetooth AVDT; C:\Windows\System32\drivers\btwavdt.sys [2014-03-19 229080]
R3 btwl2cap;@oem24.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 GPIO;@oem10.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\Windows\System32\drivers\iaiogpioe.sys [2013-11-11 31232]
R3 HIDSwitch;@oem28.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\Windows\System32\drivers\AsHIDSwitch64.sys [2013-10-08 20280]
R3 iaioi2c;@oem9.inf,%Driver_Service.Desc%;I2C Controller Service; C:\Windows\System32\drivers\iaioi2ce.sys [2013-11-11 67584]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-16 4222976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-01 4002008]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-01-16 450520]
R3 iwdbus;@oem15.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 kbfiltr;@oem27.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\Windows\System32\drivers\kbfiltr.sys [2012-08-06 17280]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RSBASTOR;@oem19.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\Windows\system32\DRIVERS\RtsBaStor.sys [2013-07-12 309976]
R3 RTL8168;@oem18.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-01-08 848088]
R3 TXEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-10-28 38912]
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\Windows\system32\DRIVERS\avgboota.sys [2013-09-04 20496]
S0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-06-26 670056]
S3 AgereSoftModem;@mdmags64.inf,%FullProductName%;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2013-06-18 1146880]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 btwrchid;btwrchid; C:\Windows\System32\drivers\btwrchid.sys [2014-03-19 38616]
S3 dg_ssudbus;@oem33.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\Windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem14.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 NETwNs64;@netwsw00.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2013-06-18 11518976]
S3 ssudmdm;@oem34.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 APNMCP;Ask Update Service; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2014-12-19 177560]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [2014-03-26 115512]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [2014-08-20 71168]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-02-19 1508656]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-02-19 3411408]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-02-19 308720]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2014-03-18 976600]
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2014-04-24 227904]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
R2 vToolbarUpdater18.4.0;vToolbarUpdater18.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.4.0\ToolbarUpdater.exe [2015-02-24 1883672]
S2 BcmBtRSupport;@oem25.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\Windows\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-02-19 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-04-24 203344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21 107848]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]

-----------------EOF-----------------

Lonely Girl
Návštěvník
Návštěvník
Příspěvky: 31
Registrován: 01 úno 2015 20:14

Re: download.exe

#2 Příspěvek od Lonely Girl »

Tak vše co se smazalo,už se mi podařilo vrátit zpět..Tak prosím jen o tu kontrolu ^^ :)
Be sad → Be mad... →Be mad → Be free..

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: download.exe

#3 Příspěvek od Rudy »

Zdravím!
Koukneme se, zda tam něco nezbylo. Spusťte tuto v utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lonely Girl
Návštěvník
Návštěvník
Příspěvky: 31
Registrován: 01 úno 2015 20:14

Re: download.exe

#4 Příspěvek od Lonely Girl »

# AdwCleaner v4.112 - Logfile created 21/03/2015 at 20:45:41
# Updated 09/03/2015 by Xplode
# Database : 2015-03-21.2 [Server]
# Operating system : Windows 8.1 Connected (x64)
# Username : Monika - CHICKY
# Running from : C:\Users\Monika\Downloads\adwcleaner_4.112.exe
# Option : Cleaning

***** [ Services ] *****

Service Deleted : APNMCP
Service Deleted : vToolbarUpdater18.4.0

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
Folder Deleted : C:\Program Files (x86)\Vaoudiixu
Folder Deleted : C:\Program Files (x86)\Vauduixx
Folder Deleted : C:\Program Files (x86)\VoaudiX
Folder Deleted : C:\Program Files (x86)\youtubeadblocker
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Monika\AppData\Local\Temp\apn
Folder Deleted : C:\Users\Monika\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\ProgramData\jfgbcckgkalgnhmehkljjnbakoooljid
File Deleted : C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage
File Deleted : C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal
File Deleted : C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage
File Deleted : C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaadgepjkdffhjbkfjgnnffnfcffbg
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaadgepjkdffhjbkfjgnnffnfcffbg
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\HomeTab
Key Deleted : HKCU\Software\simplytech
Key Deleted : HKCU\Software\TNT2
Key Deleted : HKCU\Software\WajIntEnhance
Key Deleted : HKCU\Software\SearchProtectWS
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\SearchProtect
Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
Key Deleted : HKLM\SOFTWARE\WajIntEnhance
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Deleted : [x64] HKLM\SOFTWARE\AVG Secure Search
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v41.0.2272.101


-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [8577 bytes] - [21/03/2015 20:42:51]
AdwCleaner[S0].txt - [6700 bytes] - [21/03/2015 20:45:41]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6759 bytes] ##########
Be sad → Be mad... →Be mad → Be free..

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: download.exe

#5 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lonely Girl
Návštěvník
Návštěvník
Příspěvky: 31
Registrován: 01 úno 2015 20:14

Re: download.exe

#6 Příspěvek od Lonely Girl »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Monika at 2015-03-21 21:15:20
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 132 GB (69%) free of 191 GB
Total RAM: 3983 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:15:23, on 21. 3. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\WebcamMax\wcmmon.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Monika.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe,
O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [WebcamMaxAutoRun] "C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: Asus WebStorage Windows Service - ASUS Cloud Corporation - C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @oem25.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 7092 bytes

======Listing Processes======




c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-1d22-7846d8841438 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"

wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
C:\Windows\system32\WLANExt.exe 96540355392
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
dashost.exe {77eaff3a-e9bf-47de-9cadabc5aa676b7c}
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\Explorer.EXE
KBFiltr.exe
taskhostex.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Windows\system32\NOTEPAD.EXE" C:\AdwCleaner\AdwCleaner[S0].txt
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --profile-directory=Default
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4804.0.820744061\1046336890" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3408 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
ctfmon.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"

"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4804 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4804.7.1397675840\1303557374" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4804.8.1510476032\420689575" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Windows\System32\WWAHost.exe" -ServerName:Windows.Store
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
/S
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4804 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4804.19.248831696\202378450" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 580 584 592 65536 588

"C:\Users\Monika\Downloads\RSITx64 (1).exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-02-19 391152]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-02-19 771568]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WebcamMaxAutoRun"=C:\Program Files (x86)\WebcamMax\wcmmon.exe [2011-07-17 1038848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WebStorage"=C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [2014-08-20 63296]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-02-19 3710416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-01-16 624640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-21 20:42:47 ----D---- C:\AdwCleaner
2015-03-21 20:32:32 ----D---- C:\Users\Monika\AppData\Roaming\PhotoFiltre 7
2015-03-21 20:32:25 ----D---- C:\Program Files (x86)\PhotoFiltre 7
2015-03-21 20:16:37 ----D---- C:\rsit
2015-03-21 20:16:37 ----D---- C:\Program Files\trend micro
2015-03-21 18:50:05 ----D---- C:\Program Files (x86)\Crosswords
2015-03-21 18:48:44 ----D---- C:\ProgramData\213968718550338235
2015-03-21 18:46:46 ----D---- C:\ProgramData\{3615ae50-83eb-dee8-3615-5ae5083eb942}
2015-03-21 18:46:17 ----D---- C:\ProgramData\{188db186-6f5b-e2e0-188d-db1866f5c619}
2015-03-10 21:56:22 ----A---- C:\Windows\system32\calc.exe
2015-03-10 21:56:21 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-03-10 21:55:35 ----A---- C:\Windows\system32\drivers\WdFilter.sys
2015-03-10 21:55:35 ----A---- C:\Windows\system32\drivers\WdBoot.sys
2015-03-10 21:55:34 ----A---- C:\Windows\system32\drivers\WdNisDrv.sys
2015-03-10 21:55:33 ----A---- C:\Windows\SYSWOW64\winshfhc.dll
2015-03-10 21:55:33 ----A---- C:\Windows\system32\winshfhc.dll
2015-03-10 21:54:39 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2015-03-10 21:54:39 ----A---- C:\Windows\system32\photowiz.dll
2015-03-10 21:54:35 ----A---- C:\Windows\system32\msftedit.dll
2015-03-10 21:54:34 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-03-10 21:54:30 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-03-10 21:54:24 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\win32spl.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\puiobj.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\localspl.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\DafPrintProvider.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\puiapi.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\prnntfy.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\printui.exe
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\findnetprinters.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\compstui.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\puiapi.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\prnntfy.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\printui.exe
2015-03-10 21:54:23 ----A---- C:\Windows\system32\findnetprinters.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\compstui.dll
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\fsquirt.exe
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\drivers\hidbth.sys
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\drivers\bthport.sys
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\rfcomm.sys
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\bthenum.sys
2015-03-10 21:54:15 ----A---- C:\Windows\system32\dwmcore.dll
2015-03-10 21:54:14 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-03-10 21:54:11 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2015-03-10 21:54:11 ----A---- C:\Windows\system32\atlthunk.dll
2015-03-10 21:54:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_47.dll
2015-03-10 21:54:10 ----A---- C:\Windows\SYSWOW64\atlthunk.dll
2015-03-10 21:54:10 ----A---- C:\Windows\system32\mfc42u.dll
2015-03-10 21:54:09 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2015-03-10 21:54:09 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2015-03-10 21:54:08 ----A---- C:\Windows\system32\mfc42.dll
2015-03-10 21:53:58 ----A---- C:\Windows\system32\WSShared.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-03-10 21:53:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 21:53:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-03-10 21:53:56 ----A---- C:\Windows\system32\WSReset.exe
2015-03-10 21:53:56 ----A---- C:\Windows\system32\WSCollect.exe
2015-03-10 21:53:46 ----A---- C:\Windows\SYSWOW64\StorageContextHandler.dll
2015-03-10 21:53:46 ----A---- C:\Windows\system32\StorageContextHandler.dll
2015-03-10 21:53:43 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-03-10 21:53:43 ----A---- C:\Windows\system32\authui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappprxy.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappcfg.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappprxy.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eapphost.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappgnui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappcfg.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eapp3hst.dll
2015-03-10 21:53:37 ----A---- C:\Windows\system32\LockScreenContentServer.exe
2015-03-10 21:53:34 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-03-10 21:53:34 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-03-10 21:53:29 ----A---- C:\Windows\explorer.exe
2015-03-10 21:53:28 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-03-10 21:53:09 ----A---- C:\Windows\system32\SHCore.dll
2015-03-10 21:53:08 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2015-03-10 20:38:41 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-10 20:38:41 ----A---- C:\Windows\system32\schannel.dll
2015-03-10 20:38:40 ----A---- C:\Windows\system32\win32k.sys
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-10 20:38:39 ----A---- C:\Windows\system32\fontsub.dll
2015-03-10 20:38:39 ----A---- C:\Windows\system32\atmfd.dll
2015-03-10 20:38:38 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-10 20:38:38 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-10 20:38:38 ----A---- C:\Windows\system32\lpk.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\dciman32.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\atmlib.dll
2015-03-10 20:38:37 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-03-10 20:38:37 ----A---- C:\Windows\system32\ntdll.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\ubpm.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rfxvmt.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2015-03-10 20:37:59 ----A---- C:\Windows\system32\mshtml.dll
2015-03-10 20:37:57 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-10 20:37:54 ----A---- C:\Windows\system32\jscript9.dll
2015-03-10 20:37:53 ----A---- C:\Windows\system32\ieframe.dll
2015-03-10 20:37:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-10 20:37:50 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-10 20:37:50 ----A---- C:\Windows\system32\wininet.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\urlmon.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\inetcomm.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\iertutil.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\vbscript.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\iepeers.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\webcheck.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\jscript.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\actxprxy.dll
2015-03-10 20:37:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-10 20:37:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-10 20:37:25 ----A---- C:\Windows\system32\shell32.dll
2015-03-10 20:37:24 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-10 20:37:00 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-10 20:37:00 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-10 20:36:59 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-10 20:36:59 ----A---- C:\Windows\system32\msctf.dll
2015-03-07 12:27:37 ----D---- C:\Users\Monika\AppData\Roaming\SYSTEMAX Software Development
2015-03-07 12:27:37 ----D---- C:\ProgramData\SYSTEMAX Software Development
2015-02-25 20:38:47 ----D---- C:\Users\Monika\AppData\Roaming\BANDISOFT
2015-02-25 20:38:04 ----D---- C:\Program Files (x86)\Bandicam
2015-02-25 20:38:01 ----D---- C:\Program Files (x86)\BandiMPEG1
2015-02-24 23:30:13 ----D---- C:\ProgramData\AVG Web TuneUp
2015-02-24 23:30:13 ----D---- C:\Program Files\AVG Web TuneUp
2015-02-24 23:30:03 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-02-24 22:48:29 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-02-24 22:48:29 ----D---- C:\Program Files (x86)\Star Stable Entertainment AB
2015-02-24 21:29:14 ----A---- C:\Windows\SYSWOW64\Windows.Globalization.dll
2015-02-24 21:29:14 ----A---- C:\Windows\system32\Windows.Globalization.dll
2015-02-24 21:29:13 ----A---- C:\Windows\SYSWOW64\GlobCollationHost.dll
2015-02-24 21:29:12 ----A---- C:\Windows\system32\GlobCollationHost.dll
2015-02-24 15:16:11 ----D---- C:\Users\Monika\AppData\Roaming\RealWorld
2015-02-24 15:15:47 ----D---- C:\Program Files (x86)\RealWorld Paint.COM

======List of files/folders modified in the last 1 month======

2015-03-21 21:07:29 ----D---- C:\Windows\Temp
2015-03-21 21:00:01 ----D---- C:\Windows\system32\sru
2015-03-21 20:59:18 ----D---- C:\ProgramData\MFAData
2015-03-21 20:52:11 ----D---- C:\Windows\System32
2015-03-21 20:52:11 ----D---- C:\Windows\Inf
2015-03-21 20:52:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-21 20:48:18 ----D---- C:\Windows\Prefetch
2015-03-21 20:45:43 ----HD---- C:\ProgramData
2015-03-21 20:45:42 ----RD---- C:\Program Files (x86)
2015-03-21 20:32:00 ----SHD---- C:\System Volume Information
2015-03-21 20:16:37 ----RD---- C:\Program Files
2015-03-21 19:59:01 ----SHD---- C:\Windows\Installer
2015-03-21 19:54:34 ----D---- C:\Program Files (x86)\Google
2015-03-21 19:54:26 ----D---- C:\Windows\system32\Tasks
2015-03-21 19:54:01 ----D---- C:\Windows\Tasks
2015-03-21 18:50:16 ----D---- C:\ProgramData\AVG2015
2015-03-21 10:50:26 ----D---- C:\Windows\AppReadiness
2015-03-21 10:50:25 ----HD---- C:\Program Files\WindowsApps
2015-03-16 16:24:55 ----D---- C:\Windows\system32\config
2015-03-15 14:25:55 ----D---- C:\Windows\Microsoft.NET
2015-03-15 13:11:03 ----D---- C:\Windows\system32\DriverStore
2015-03-15 13:10:49 ----D---- C:\Windows\WinSxS
2015-03-15 12:19:47 ----D---- C:\Windows\system32\drivers
2015-03-15 12:17:18 ----RD---- C:\Windows\ToastData
2015-03-15 12:17:17 ----D---- C:\Windows\SysWOW64
2015-03-15 12:17:16 ----D---- C:\Windows\WinStore
2015-03-15 12:16:18 ----AD---- C:\Windows
2015-03-15 12:13:21 ----D---- C:\Program Files\Windows Defender
2015-03-15 12:13:19 ----D---- C:\Program Files (x86)\Windows Defender
2015-03-15 12:13:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-15 12:13:15 ----D---- C:\Windows\system32\cs-CZ
2015-03-14 22:11:11 ----RSD---- C:\Windows\Fonts
2015-03-14 22:03:16 ----D---- C:\Písma
2015-03-14 12:10:48 ----D---- C:\Windows\CbsTemp
2015-03-14 12:08:51 ----D---- C:\Windows\system32\MRT
2015-03-14 12:01:44 ----A---- C:\Windows\system32\MRT.exe
2015-03-14 09:24:40 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-14 09:24:39 ----D---- C:\Program Files\Internet Explorer
2015-03-10 20:36:37 ----D---- C:\Windows\system32\catroot2
2015-03-04 22:24:42 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-01 10:15:26 ----D---- C:\Windows\rescache
2015-03-01 10:06:34 ----SHD---- C:\$RECYCLE.BIN
2015-02-24 23:30:14 ----D---- C:\Program Files (x86)\Common Files
2015-02-24 16:21:32 ----SD---- C:\Users\Monika\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-11-18 203544]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-02-03 341472]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-01-23 133088]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 MBI;@oem8.inf,%MBI.SVCDESC%;Intel(R) Sideband Fabric Device Service; C:\Windows\System32\drivers\MBI.sys [2013-10-28 29464]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
R1 Avgfwfd;@oem29.inf,%AvgfwfdService_Desc%;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2014-12-03 58136]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-02-19 270816]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
R1 Avgwfpa;AVG Firewall Driver; C:\Windows\system32\DRIVERS\avgwfpa.sys [2015-01-23 289248]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-10-28 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 WCMVCAM;@oem30.inf,%VCamDriver.DeviceDesc%;WebcamMax, WDM Video Capture; C:\Windows\system32\DRIVERS\wcmvcam64.sys [2012-04-15 1071032]
R3 AiCharger;ASUS Charger Driver; C:\Windows\system32\DRIVERS\AiCharger.sys [2014-03-27 17152]
R3 ATP;@oem17.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\Windows\System32\drivers\AsusTP.sys [2014-03-31 71952]
R3 bcbtums;@oem25.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM43XX;@oem20.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2014-12-01 7546544]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2014-10-28 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btwampfl;@oem25.inf,%btwampfl.ServiceName%;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2014-02-03 166616]
R3 btwaudio;@oem21.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-03-19 190168]
R3 btwavdt;@oem21.inf,%btwavdt.SvcDesc%;Bluetooth AVDT; C:\Windows\System32\drivers\btwavdt.sys [2014-03-19 229080]
R3 btwl2cap;@oem24.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 GPIO;@oem10.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\Windows\System32\drivers\iaiogpioe.sys [2013-11-11 31232]
R3 HIDSwitch;@oem28.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\Windows\System32\drivers\AsHIDSwitch64.sys [2013-10-08 20280]
R3 iaioi2c;@oem9.inf,%Driver_Service.Desc%;I2C Controller Service; C:\Windows\System32\drivers\iaioi2ce.sys [2013-11-11 67584]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-16 4222976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-01 4002008]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-01-16 450520]
R3 iwdbus;@oem15.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 kbfiltr;@oem27.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\Windows\System32\drivers\kbfiltr.sys [2012-08-06 17280]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RSBASTOR;@oem19.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\Windows\system32\DRIVERS\RtsBaStor.sys [2013-07-12 309976]
R3 RTL8168;@oem18.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-01-08 848088]
R3 TXEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-10-28 38912]
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\Windows\system32\DRIVERS\avgboota.sys [2013-09-04 20496]
S0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-06-26 670056]
S3 AgereSoftModem;@mdmags64.inf,%FullProductName%;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2013-06-18 1146880]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 btwrchid;btwrchid; C:\Windows\System32\drivers\btwrchid.sys [2014-03-19 38616]
S3 dg_ssudbus;@oem33.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\Windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem14.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 NETwNs64;@netwsw00.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2013-06-18 11518976]
S3 ssudmdm;@oem34.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [2014-03-26 115512]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [2014-08-20 71168]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-02-19 1508656]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-02-19 3411408]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-02-19 308720]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2014-03-18 976600]
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2014-04-24 227904]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
S2 BcmBtRSupport;@oem25.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\Windows\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-02-19 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-04-24 203344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21 107848]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]

-----------------EOF-----------------
Be sad → Be mad... →Be mad → Be free..

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: download.exe

#7 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lonely Girl
Návštěvník
Návštěvník
Příspěvky: 31
Registrován: 01 úno 2015 20:14

Re: download.exe

#8 Příspěvek od Lonely Girl »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Monika at 2015-03-21 22:23:25
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 132 GB (69%) free of 191 GB
Total RAM: 3983 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:23:30, on 21. 3. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\WebcamMax\wcmmon.exe
C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Monika.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe,
O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [WebcamMaxAutoRun] "C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: Asus WebStorage Windows Service - ASUS Cloud Corporation - C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @oem25.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 7465 bytes

======Listing Processes======




C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-daf4-d36eab80b753 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"

wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
C:\Windows\system32\WLANExt.exe 156644853184
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
dashost.exe {462f3f85-18d6-4522-98d59d70036e821e}
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\Explorer.EXE
taskeng.exe {33585679-6E50-4C96-A97C-8D15EC4E1268}
taskhostex.exe
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
KBFiltr.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --profile-directory=Default
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4428.0.965020830\1219558535" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3408 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\WebcamMax\wcmmon.exe" -a
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
C:\Windows\System32\RuntimeBroker.exe -Embedding
ctfmon.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.4.180575344\58743562" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.5.664898446\735641556" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.6.640632970\932019289" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.7.917162179\120980700" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.8.1461876086\2114126957" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.9.1512936578\462720147" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/PasswordGeneration/Disabled/QUIC/EnabledForLargePopulation/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_97/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4428 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --channel="4428.10.1314534273\1602188912" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4428.11.779981671\1590460928" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe -Embedding

C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe

"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Users\Monika\Downloads\RSITx64 (2).exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-02-19 391152]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-02-19 771568]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WebcamMaxAutoRun"=C:\Program Files (x86)\WebcamMax\wcmmon.exe [2011-07-17 1038848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WebStorage"=C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [2014-08-20 63296]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-02-19 3710416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-01-16 624640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-21 22:18:11 ----D---- C:\_OTM
2015-03-21 20:42:47 ----D---- C:\AdwCleaner
2015-03-21 20:32:32 ----D---- C:\Users\Monika\AppData\Roaming\PhotoFiltre 7
2015-03-21 20:32:25 ----D---- C:\Program Files (x86)\PhotoFiltre 7
2015-03-21 20:16:37 ----D---- C:\rsit
2015-03-21 20:16:37 ----D---- C:\Program Files\trend micro
2015-03-21 18:50:05 ----D---- C:\Program Files (x86)\Crosswords
2015-03-21 18:48:44 ----D---- C:\ProgramData\213968718550338235
2015-03-21 18:46:46 ----D---- C:\ProgramData\{3615ae50-83eb-dee8-3615-5ae5083eb942}
2015-03-21 18:46:17 ----D---- C:\ProgramData\{188db186-6f5b-e2e0-188d-db1866f5c619}
2015-03-10 21:56:22 ----A---- C:\Windows\system32\calc.exe
2015-03-10 21:56:21 ----A---- C:\Windows\SYSWOW64\calc.exe
2015-03-10 21:55:35 ----A---- C:\Windows\system32\drivers\WdFilter.sys
2015-03-10 21:55:35 ----A---- C:\Windows\system32\drivers\WdBoot.sys
2015-03-10 21:55:34 ----A---- C:\Windows\system32\drivers\WdNisDrv.sys
2015-03-10 21:55:33 ----A---- C:\Windows\SYSWOW64\winshfhc.dll
2015-03-10 21:55:33 ----A---- C:\Windows\system32\winshfhc.dll
2015-03-10 21:54:39 ----A---- C:\Windows\SYSWOW64\photowiz.dll
2015-03-10 21:54:39 ----A---- C:\Windows\system32\photowiz.dll
2015-03-10 21:54:35 ----A---- C:\Windows\system32\msftedit.dll
2015-03-10 21:54:34 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-03-10 21:54:30 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-03-10 21:54:24 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\win32spl.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\puiobj.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\localspl.dll
2015-03-10 21:54:24 ----A---- C:\Windows\system32\DafPrintProvider.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\puiapi.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\prnntfy.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\printui.exe
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\findnetprinters.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2015-03-10 21:54:23 ----A---- C:\Windows\SYSWOW64\compstui.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\puiapi.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\prnntfy.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\printui.exe
2015-03-10 21:54:23 ----A---- C:\Windows\system32\findnetprinters.dll
2015-03-10 21:54:23 ----A---- C:\Windows\system32\compstui.dll
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\fsquirt.exe
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\drivers\hidbth.sys
2015-03-10 21:54:19 ----AC---- C:\Windows\system32\drivers\bthport.sys
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\rfcomm.sys
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-03-10 21:54:18 ----AC---- C:\Windows\system32\drivers\bthenum.sys
2015-03-10 21:54:15 ----A---- C:\Windows\system32\dwmcore.dll
2015-03-10 21:54:14 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-03-10 21:54:11 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2015-03-10 21:54:11 ----A---- C:\Windows\system32\atlthunk.dll
2015-03-10 21:54:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_47.dll
2015-03-10 21:54:10 ----A---- C:\Windows\SYSWOW64\atlthunk.dll
2015-03-10 21:54:10 ----A---- C:\Windows\system32\mfc42u.dll
2015-03-10 21:54:09 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2015-03-10 21:54:09 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2015-03-10 21:54:08 ----A---- C:\Windows\system32\mfc42.dll
2015-03-10 21:53:58 ----A---- C:\Windows\system32\WSShared.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 21:53:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-03-10 21:53:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-10 21:53:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-03-10 21:53:56 ----A---- C:\Windows\system32\WSReset.exe
2015-03-10 21:53:56 ----A---- C:\Windows\system32\WSCollect.exe
2015-03-10 21:53:46 ----A---- C:\Windows\SYSWOW64\StorageContextHandler.dll
2015-03-10 21:53:46 ----A---- C:\Windows\system32\StorageContextHandler.dll
2015-03-10 21:53:43 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-03-10 21:53:43 ----A---- C:\Windows\system32\authui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappprxy.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eappcfg.dll
2015-03-10 21:53:40 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappprxy.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eapphost.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappgnui.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eappcfg.dll
2015-03-10 21:53:40 ----A---- C:\Windows\system32\eapp3hst.dll
2015-03-10 21:53:37 ----A---- C:\Windows\system32\LockScreenContentServer.exe
2015-03-10 21:53:34 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-03-10 21:53:34 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-03-10 21:53:29 ----A---- C:\Windows\explorer.exe
2015-03-10 21:53:28 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-03-10 21:53:09 ----A---- C:\Windows\system32\SHCore.dll
2015-03-10 21:53:08 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2015-03-10 20:38:41 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-10 20:38:41 ----A---- C:\Windows\system32\schannel.dll
2015-03-10 20:38:40 ----A---- C:\Windows\system32\win32k.sys
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-10 20:38:39 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-10 20:38:39 ----A---- C:\Windows\system32\fontsub.dll
2015-03-10 20:38:39 ----A---- C:\Windows\system32\atmfd.dll
2015-03-10 20:38:38 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-10 20:38:38 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-10 20:38:38 ----A---- C:\Windows\system32\lpk.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\dciman32.dll
2015-03-10 20:38:38 ----A---- C:\Windows\system32\atmlib.dll
2015-03-10 20:38:37 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-03-10 20:38:37 ----A---- C:\Windows\system32\ntdll.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\ubpm.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rfxvmt.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-10 20:38:29 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2015-03-10 20:37:59 ----A---- C:\Windows\system32\mshtml.dll
2015-03-10 20:37:57 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-10 20:37:54 ----A---- C:\Windows\system32\jscript9.dll
2015-03-10 20:37:53 ----A---- C:\Windows\system32\ieframe.dll
2015-03-10 20:37:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-10 20:37:50 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-10 20:37:50 ----A---- C:\Windows\system32\wininet.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-10 20:37:49 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\urlmon.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\inetcomm.dll
2015-03-10 20:37:49 ----A---- C:\Windows\system32\iertutil.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-03-10 20:37:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\vbscript.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\iepeers.dll
2015-03-10 20:37:48 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-03-10 20:37:47 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\webcheck.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\jscript.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-10 20:37:47 ----A---- C:\Windows\system32\actxprxy.dll
2015-03-10 20:37:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-10 20:37:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-10 20:37:25 ----A---- C:\Windows\system32\shell32.dll
2015-03-10 20:37:24 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-10 20:37:00 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-10 20:37:00 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-10 20:36:59 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-10 20:36:59 ----A---- C:\Windows\system32\msctf.dll
2015-03-07 12:27:37 ----D---- C:\Users\Monika\AppData\Roaming\SYSTEMAX Software Development
2015-03-07 12:27:37 ----D---- C:\ProgramData\SYSTEMAX Software Development
2015-02-25 20:38:47 ----D---- C:\Users\Monika\AppData\Roaming\BANDISOFT
2015-02-25 20:38:04 ----D---- C:\Program Files (x86)\Bandicam
2015-02-25 20:38:01 ----D---- C:\Program Files (x86)\BandiMPEG1
2015-02-24 23:30:13 ----D---- C:\ProgramData\AVG Web TuneUp
2015-02-24 23:30:13 ----D---- C:\Program Files\AVG Web TuneUp
2015-02-24 23:30:03 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-02-24 22:48:29 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-02-24 22:48:29 ----D---- C:\Program Files (x86)\Star Stable Entertainment AB
2015-02-24 21:29:14 ----A---- C:\Windows\SYSWOW64\Windows.Globalization.dll
2015-02-24 21:29:14 ----A---- C:\Windows\system32\Windows.Globalization.dll
2015-02-24 21:29:13 ----A---- C:\Windows\SYSWOW64\GlobCollationHost.dll
2015-02-24 21:29:12 ----A---- C:\Windows\system32\GlobCollationHost.dll
2015-02-24 15:16:11 ----D---- C:\Users\Monika\AppData\Roaming\RealWorld
2015-02-24 15:15:47 ----D---- C:\Program Files (x86)\RealWorld Paint.COM

======List of files/folders modified in the last 1 month======

2015-03-21 22:22:11 ----D---- C:\Windows\Temp
2015-03-21 22:18:12 ----D---- C:\Windows\Tasks
2015-03-21 22:18:05 ----D---- C:\Windows\Prefetch
2015-03-21 22:14:06 ----D---- C:\Windows\system32\NDF
2015-03-21 22:12:44 ----D---- C:\ProgramData\MFAData
2015-03-21 22:00:00 ----D---- C:\Windows\system32\sru
2015-03-21 21:18:52 ----SHD---- C:\Windows\Installer
2015-03-21 20:52:11 ----D---- C:\Windows\System32
2015-03-21 20:52:11 ----D---- C:\Windows\Inf
2015-03-21 20:52:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-21 20:45:43 ----HD---- C:\ProgramData
2015-03-21 20:45:42 ----RD---- C:\Program Files (x86)
2015-03-21 20:32:00 ----SHD---- C:\System Volume Information
2015-03-21 20:16:37 ----RD---- C:\Program Files
2015-03-21 19:54:34 ----D---- C:\Program Files (x86)\Google
2015-03-21 19:54:26 ----D---- C:\Windows\system32\Tasks
2015-03-21 18:50:16 ----D---- C:\ProgramData\AVG2015
2015-03-21 10:50:26 ----D---- C:\Windows\AppReadiness
2015-03-21 10:50:25 ----HD---- C:\Program Files\WindowsApps
2015-03-16 16:24:55 ----D---- C:\Windows\system32\config
2015-03-15 14:25:55 ----D---- C:\Windows\Microsoft.NET
2015-03-15 13:11:03 ----D---- C:\Windows\system32\DriverStore
2015-03-15 13:10:49 ----D---- C:\Windows\WinSxS
2015-03-15 12:19:47 ----D---- C:\Windows\system32\drivers
2015-03-15 12:17:18 ----RD---- C:\Windows\ToastData
2015-03-15 12:17:17 ----D---- C:\Windows\SysWOW64
2015-03-15 12:17:16 ----D---- C:\Windows\WinStore
2015-03-15 12:16:18 ----AD---- C:\Windows
2015-03-15 12:13:21 ----D---- C:\Program Files\Windows Defender
2015-03-15 12:13:19 ----D---- C:\Program Files (x86)\Windows Defender
2015-03-15 12:13:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-15 12:13:15 ----D---- C:\Windows\system32\cs-CZ
2015-03-14 22:11:11 ----RSD---- C:\Windows\Fonts
2015-03-14 22:03:16 ----D---- C:\Písma
2015-03-14 12:10:48 ----D---- C:\Windows\CbsTemp
2015-03-14 12:08:51 ----D---- C:\Windows\system32\MRT
2015-03-14 12:01:44 ----A---- C:\Windows\system32\MRT.exe
2015-03-14 09:24:40 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-14 09:24:39 ----D---- C:\Program Files\Internet Explorer
2015-03-10 20:36:37 ----D---- C:\Windows\system32\catroot2
2015-03-04 22:24:42 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-01 10:15:26 ----D---- C:\Windows\rescache
2015-03-01 10:06:34 ----SHD---- C:\$RECYCLE.BIN
2015-02-24 23:30:14 ----D---- C:\Program Files (x86)\Common Files
2015-02-24 16:21:32 ----SD---- C:\Users\Monika\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-11-18 203544]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2015-02-03 341472]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2015-01-23 133088]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 MBI;@oem8.inf,%MBI.SVCDESC%;Intel(R) Sideband Fabric Device Service; C:\Windows\System32\drivers\MBI.sys [2013-10-28 29464]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
R1 Avgfwfd;@oem29.inf,%AvgfwfdService_Desc%;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2014-12-03 58136]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2015-02-19 270816]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
R1 Avgwfpa;AVG Firewall Driver; C:\Windows\system32\DRIVERS\avgwfpa.sys [2015-01-23 289248]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-10-28 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 WCMVCAM;@oem30.inf,%VCamDriver.DeviceDesc%;WebcamMax, WDM Video Capture; C:\Windows\system32\DRIVERS\wcmvcam64.sys [2012-04-15 1071032]
R3 AiCharger;ASUS Charger Driver; C:\Windows\system32\DRIVERS\AiCharger.sys [2014-03-27 17152]
R3 ATP;@oem17.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\Windows\System32\drivers\AsusTP.sys [2014-03-31 71952]
R3 bcbtums;@oem25.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM43XX;@oem20.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2014-12-01 7546544]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2014-10-28 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btwampfl;@oem25.inf,%btwampfl.ServiceName%;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2014-02-03 166616]
R3 btwaudio;@oem21.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-03-19 190168]
R3 btwavdt;@oem21.inf,%btwavdt.SvcDesc%;Bluetooth AVDT; C:\Windows\System32\drivers\btwavdt.sys [2014-03-19 229080]
R3 btwl2cap;@oem24.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 GPIO;@oem10.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\Windows\System32\drivers\iaiogpioe.sys [2013-11-11 31232]
R3 HIDSwitch;@oem28.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\Windows\System32\drivers\AsHIDSwitch64.sys [2013-10-08 20280]
R3 iaioi2c;@oem9.inf,%Driver_Service.Desc%;I2C Controller Service; C:\Windows\System32\drivers\iaioi2ce.sys [2013-11-11 67584]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-16 4222976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-01 4002008]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-01-16 450520]
R3 iwdbus;@oem15.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 kbfiltr;@oem27.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\Windows\System32\drivers\kbfiltr.sys [2012-08-06 17280]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RSBASTOR;@oem19.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\Windows\system32\DRIVERS\RtsBaStor.sys [2013-07-12 309976]
R3 RTL8168;@oem18.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-01-08 848088]
R3 TXEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-10-28 38912]
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\Windows\system32\DRIVERS\avgboota.sys [2013-09-04 20496]
S0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-06-26 670056]
S3 AgereSoftModem;@mdmags64.inf,%FullProductName%;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2013-06-18 1146880]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 btwrchid;btwrchid; C:\Windows\System32\drivers\btwrchid.sys [2014-03-19 38616]
S3 dg_ssudbus;@oem33.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\Windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem14.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 NETwNs64;@netwsw00.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2013-06-18 11518976]
S3 ssudmdm;@oem34.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [2014-03-26 115512]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [2014-08-20 71168]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-02-19 1508656]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-02-19 3411408]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-02-19 308720]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2014-03-18 976600]
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2014-04-24 227904]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
S2 BcmBtRSupport;@oem25.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\Windows\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-02-19 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-04-24 203344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-21 107848]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]

-----------------EOF-----------------
Be sad → Be mad... →Be mad → Be free..

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119677
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: download.exe

#9 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět