Možné zašifrování dat
Napsal: 29 bře 2015 19:17
Zdravím,
Při brouzdání po internetu na mě vyskočilo vyskakovací okno z hláškou že mi prej zašifrovali data a ať jim zaplatím a odpočítával se čas a zobrazovala se tam i moje Ip adresa ňijak jsem nelenil a rychle restartoval počítač. Prosím o zjištění jestli je to mu opravdu tak že mám infikovanej počítač nebo to byla podvodná informace.Díky za pomoc.
Přikládám log RSIT
Logfile of random's system information tool 1.10 (written by random/random)
Run by Administrátor at 2015-03-29 20:16:53
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 1029 GB (54%) free of 1908 GB
Total RAM: 8175 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:58, on 29.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Administrátor.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.cz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll
O4 - HKUS\S-1-5-18\..\Run: [AviraSpeedup] "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AviraSpeedup] "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - http://assets.photobox.com/assets/v/ra3 ... _0fSS8.cab
O16 - DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - https://carina.cd.cz/dwa85W.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - https://carina.cd.cz/dwa7W.cab
O18 - Protocol: linkscanner - (no CLSID) - (no file)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton Security (NS) - Symantec Corporation - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 6457 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe" /s "NS" /m "C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe" /c /a /s UserSession2
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss b58d72f4-5579-456b-8212-6a6ca03df70d 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-682509082-533512337-1267490790-920949865325587282021111928-21222567721869578300
\??\C:\Windows\system32\conhost.exe "1483144758-168598702618759391441129384444-39845194720661951561761209907-1602324035
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\Administrátor\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Acrobat Update Task.job - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d0408ca3c18acf.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d042c2adf2cc5.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
=========Mozilla firefox=========
ProfilePath - C:\Users\Administrátor\AppData\Roaming\Mozilla\Firefox\Profiles\aoprsa0j.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.75.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.75.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Security\Engine64\22.1.0.9\coIEPlg.dll [2014-12-05 886584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2015-02-13 553896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-02-13 211880]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll [2014-12-05 664888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Security\Engine64\22.1.0.9\coIEPlg.dll [2014-12-05 886584]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll [2014-12-05 664888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-05-09 13672152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\*WerKernelReporting]
C:\Windows\SYSTEM32\WerFault.exe [2009-07-14 415232]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=60
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.FPS1"=frapsv64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-03-29 20:16:53 ----D---- C:\rsit
2015-03-29 20:16:53 ----D---- C:\Program Files\trend micro
2015-03-29 19:48:49 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-03-29 19:47:04 ----D---- C:\Windows\LastGood
2015-03-29 19:46:02 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-03-29 19:46:02 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-03-29 19:46:02 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvopencl.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvoglv64.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvinitx.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\NvIFR64.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-03-29 19:46:00 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\NvFBC64.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\nvdispgenco6434788.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\nvdispco6434788.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-03-29 19:45:59 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-03-29 19:45:59 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-03-29 19:45:59 ----A---- C:\Windows\system32\nvcuvid.dll
2015-03-29 19:45:59 ----A---- C:\Windows\system32\nvcuda.dll
2015-03-29 19:45:55 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-03-29 19:45:55 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-03-29 19:45:55 ----A---- C:\Windows\system32\nvcompiler.dll
2015-03-29 19:10:55 ----A---- C:\Windows\ntbtlog.txt
2015-03-22 17:05:22 ----D---- C:\ProgramData\WarThunder
2015-03-17 14:48:50 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-16 16:31:34 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\wextract.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\url.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msls31.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshta.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\inseng.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\icardie.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\wininet.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\urlmon.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2015-03-16 16:31:32 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msrating.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msls31.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\mshtmler.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msfeedssync.exe
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jsIntl.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jscript9.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\ieui.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\iesysprep.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\iertutil.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\ieframe.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\IEAdvpack.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\elshyph.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\wextract.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\webcheck.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\vbscript.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\url.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\pngfilt.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\occache.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshtml.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshta.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\licmgr10.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\jscript.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\inseng.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\imgutil.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iexpress.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iesetup.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iernonce.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iepeers.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieapfltr.dat
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\icardie.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-15 22:07:47 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-03-11 19:04:21 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-11 18:13:00 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 18:13:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 18:12:59 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 18:12:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 18:12:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 18:12:57 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 18:12:57 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 18:12:56 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 18:12:56 ----A---- C:\Windows\system32\mf.dll
2015-03-11 18:12:56 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 18:12:55 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 18:12:54 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 18:12:54 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 18:12:53 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 18:12:51 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 18:12:51 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 18:12:51 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\winload.exe
2015-03-11 18:12:51 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\smss.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\evr.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 18:12:50 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 18:12:50 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 18:12:49 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 18:12:03 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 18:11:49 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 18:11:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 18:11:49 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 18:11:49 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 18:11:49 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 18:11:30 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 18:11:30 ----A---- C:\Windows\system32\shell32.dll
2015-03-11 18:11:29 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 18:11:29 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 18:11:29 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 18:11:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 18:11:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 18:11:10 ----D---- C:\ProgramData\Malwarebytes
2015-03-11 18:11:10 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-11 18:11:10 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-03-11 18:11:10 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-03-11 18:11:10 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-03-11 18:09:34 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 18:09:34 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 18:09:01 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 18:09:01 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 18:08:59 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 18:08:39 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-11 18:08:39 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-11 17:35:41 ----D---- C:\AdwCleaner
2015-03-11 17:35:06 ----D---- C:\Program Files\Common Files\Symantec Shared
2015-03-11 17:35:06 ----A---- C:\Windows\system32\drivers\SYMEVENT64x86.SYS
2015-03-11 17:34:20 ----D---- C:\Windows\system32\drivers\NSx64
2015-03-11 17:34:20 ----D---- C:\Program Files (x86)\Norton Security
2015-03-11 17:34:19 ----D---- C:\ProgramData\Norton
2015-03-11 17:34:04 ----D---- C:\ProgramData\NortonInstaller
2015-03-11 17:34:04 ----D---- C:\Program Files (x86)\NortonInstaller
2015-03-11 17:09:42 ----SHD---- C:\Config.Msi
2015-03-10 22:25:44 ----D---- C:\Program Files\TeamSpeak 3 Client
======List of files/folders modified in the last 1 month======
2015-03-29 20:16:58 ----D---- C:\Windows\Prefetch
2015-03-29 20:16:53 ----RD---- C:\Program Files
2015-03-29 19:50:30 ----D---- C:\Windows\System32
2015-03-29 19:50:30 ----D---- C:\Windows\inf
2015-03-29 19:50:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-29 19:49:30 ----D---- C:\ProgramData\NVIDIA
2015-03-29 19:49:17 ----D---- C:\Windows\SysWOW64
2015-03-29 19:49:12 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-03-29 19:48:47 ----D---- C:\Windows\system32\DriverStore
2015-03-29 19:47:19 ----D---- C:\Windows\temp
2015-03-29 19:47:06 ----D---- C:\Windows\system32\drivers
2015-03-29 19:47:06 ----D---- C:\Program Files\NVIDIA Corporation
2015-03-29 19:47:04 ----D---- C:\Windows
2015-03-29 19:43:22 ----D---- C:\Windows\system32\config
2015-03-29 19:29:16 ----A---- C:\Windows\SYSWOW64\log.txt
2015-03-29 19:27:55 ----SD---- C:\System Volume Information
2015-03-29 12:22:07 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-28 14:11:35 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-27 22:36:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-03-26 16:37:54 ----D---- C:\Windows\system32\catroot2
2015-03-22 17:05:22 ----D---- C:\ProgramData
2015-03-20 21:47:22 ----D---- C:\Windows\SYSWOW64\directx
2015-03-20 21:47:14 ----HD---- C:\Windows\msdownld.tmp
2015-03-20 21:47:11 ----D---- C:\Windows\Logs
2015-03-20 16:22:05 ----D---- C:\Windows\rescache
2015-03-18 22:21:36 ----RD---- C:\Program Files (x86)
2015-03-18 09:19:03 ----D---- C:\Windows\winsxs
2015-03-18 00:24:07 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-18 00:24:07 ----D---- C:\Windows\system32\cs-CZ
2015-03-16 16:36:18 ----D---- C:\Program Files\Internet Explorer
2015-03-16 16:36:14 ----D---- C:\Windows\SYSWOW64\migration
2015-03-16 16:36:13 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-16 16:36:11 ----D---- C:\Windows\system32\migration
2015-03-16 16:36:11 ----D---- C:\Windows\PolicyDefinitions
2015-03-16 16:36:10 ----D---- C:\Windows\system32\en-US
2015-03-15 22:27:50 ----D---- C:\Windows\servicing
2015-03-15 22:10:01 ----D---- C:\Windows\Panther
2015-03-15 22:02:34 ----D---- C:\Windows\debug
2015-03-13 21:41:47 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2015-03-13 21:41:47 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-03-13 21:41:47 ----A---- C:\Windows\system32\OpenCL.dll
2015-03-13 21:41:47 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-03-13 21:41:47 ----A---- C:\Windows\system32\nvapi64.dll
2015-03-13 18:16:47 ----A---- C:\Windows\system32\nvsvc64.dll
2015-03-13 18:16:47 ----A---- C:\Windows\system32\nvcpl.dll
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvvsvc.exe
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvsvcr.dll
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvshext.dll
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvmctray.dll
2015-03-13 13:34:50 ----D---- C:\Windows\system32\Tasks
2015-03-11 19:13:11 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-11 19:13:11 ----D---- C:\Windows\system32\Dism
2015-03-11 19:13:11 ----D---- C:\Program Files\Windows Media Player
2015-03-11 19:13:11 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-11 19:13:02 ----D---- C:\Windows\system32\Boot
2015-03-11 19:03:39 ----D---- C:\Program Files (x86)\Common Files
2015-03-11 18:28:50 ----SHD---- C:\Windows\Installer
2015-03-11 18:28:45 ----D---- C:\ProgramData\Microsoft Help
2015-03-11 18:22:20 ----D---- C:\Windows\system32\MRT
2015-03-11 18:18:19 ----A---- C:\Windows\system32\MRT.exe
2015-03-11 18:12:31 ----D---- C:\Programy
2015-03-11 17:35:06 ----D---- C:\Program Files\Common Files
2015-03-11 17:27:23 ----D---- C:\Program Files (x86)\Steam
2015-03-11 17:10:04 ----DC---- C:\Windows\system32\DRVSTORE
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-02-06 564824]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NSx64\1601000.009\SYMDS64.SYS [2014-09-09 490712]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NSx64\1601000.009\SYMEFA64.SYS [2014-09-09 1151704]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 BHDrvx64;BHDrvx64; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\BASHDefs\20150321.001\BHDrvx64.sys [2015-03-09 1622744]
R1 ccSet_NS;NS Settings Manager; C:\Windows\system32\drivers\NSx64\1601000.009\ccSetx64.sys [2014-09-09 165080]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-06 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2015-03-11 487216]
R1 IDSVia64;IDSVia64; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\IPSDefs\20150327.001\IDSvia64.sys [2015-03-27 671448]
R1 mbamchameleon;mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [2015-03-17 107736]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NSx64\1601000.009\SRTSPX64.SYS [2014-09-09 42200]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NSx64\1601000.009\Ironx64.SYS [2014-09-09 271576]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NSx64\1601000.009\SYMNETS.SYS [2014-09-09 565464]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2015-01-02 42696]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2015-03-11 142640]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-03-17 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-03-29 136408]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-03-17 63704]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-12-08 64624]
R3 NAVENG;NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\VirusDefs\20150329.001\ENG64.SYS [2015-03-11 129752]
R3 NAVEX15;NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\VirusDefs\20150329.001\EX64.SYS [2015-03-11 2137304]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-02-05 195728]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-01-20 888536]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NSx64\1601000.009\SRTSP64.SYS [2014-12-02 914648]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2015-03-11 102616]
S1 FldSafe;FldSafe; C:\Windows\system32\DRIVERS\FldSafe.sys []
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2015-01-02 310728]
S3 agvkhi1n;agvkhi1n; C:\Windows\system32\drivers\agvkhi1n.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 gdrv;gdrv; C:\Windows\system32\drivers\gdrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 ivusb;Initio Driver for USB Default Controller; C:\Windows\system32\DRIVERS\ivusb.sys [2010-07-29 29720]
S3 Prot6Flt;Prot6Flt; C:\Windows\system32\DRIVERS\Prot6Flt.sys []
S3 PSKMAD;PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [2013-04-29 47632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [2007-05-14 27520]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbser;Nokia USB Serial Port Driver ; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-10-05 325656]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-03-17 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-03-17 1871160]
R2 NS;Norton Security; C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe [2014-12-10 282528]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-03-13 935056]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-03-13 410768]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-03-16 114688]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-14 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-04 107912]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-04 107912]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-27 148080]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-25 1903472]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S4 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-11-18 833728]
-----------------EOF-----------------
Při brouzdání po internetu na mě vyskočilo vyskakovací okno z hláškou že mi prej zašifrovali data a ať jim zaplatím a odpočítával se čas a zobrazovala se tam i moje Ip adresa ňijak jsem nelenil a rychle restartoval počítač. Prosím o zjištění jestli je to mu opravdu tak že mám infikovanej počítač nebo to byla podvodná informace.Díky za pomoc.
Přikládám log RSIT
Logfile of random's system information tool 1.10 (written by random/random)
Run by Administrátor at 2015-03-29 20:16:53
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 1029 GB (54%) free of 1908 GB
Total RAM: 8175 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:58, on 29.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17689)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Administrátor.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.cz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll
O4 - HKUS\S-1-5-18\..\Run: [AviraSpeedup] "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AviraSpeedup] "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} - http://assets.photobox.com/assets/v/ra3 ... _0fSS8.cab
O16 - DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - https://carina.cd.cz/dwa85W.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - https://carina.cd.cz/dwa7W.cab
O18 - Protocol: linkscanner - (no CLSID) - (no file)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton Security (NS) - Symantec Corporation - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 6457 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe" /s "NS" /m "C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe" /c /a /s UserSession2
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss b58d72f4-5579-456b-8212-6a6ca03df70d 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-682509082-533512337-1267490790-920949865325587282021111928-21222567721869578300
\??\C:\Windows\system32\conhost.exe "1483144758-168598702618759391441129384444-39845194720661951561761209907-1602324035
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
"C:\Users\Administrátor\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Acrobat Update Task.job - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d0408ca3c18acf.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineCore1d042c2adf2cc5.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
=========Mozilla firefox=========
ProfilePath - C:\Users\Administrátor\AppData\Roaming\Mozilla\Firefox\Profiles\aoprsa0j.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.75.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.75.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Security\Engine64\22.1.0.9\coIEPlg.dll [2014-12-05 886584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2015-02-13 553896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-02-13 211880]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll [2014-12-05 664888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Security\Engine64\22.1.0.9\coIEPlg.dll [2014-12-05 886584]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\coIEPlg.dll [2014-12-05 664888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-05-09 13672152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\*WerKernelReporting]
C:\Windows\SYSTEM32\WerFault.exe [2009-07-14 415232]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=60
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.FPS1"=frapsv64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2015-03-29 20:16:53 ----D---- C:\rsit
2015-03-29 20:16:53 ----D---- C:\Program Files\trend micro
2015-03-29 19:48:49 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-03-29 19:47:04 ----D---- C:\Windows\LastGood
2015-03-29 19:46:02 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-03-29 19:46:02 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-03-29 19:46:02 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-03-29 19:46:01 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvopencl.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvoglv64.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\nvinitx.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\NvIFR64.dll
2015-03-29 19:46:01 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-03-29 19:46:00 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\NvFBC64.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\nvdispgenco6434788.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\nvdispco6434788.dll
2015-03-29 19:46:00 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-03-29 19:45:59 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-03-29 19:45:59 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-03-29 19:45:59 ----A---- C:\Windows\system32\nvcuvid.dll
2015-03-29 19:45:59 ----A---- C:\Windows\system32\nvcuda.dll
2015-03-29 19:45:55 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-03-29 19:45:55 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-03-29 19:45:55 ----A---- C:\Windows\system32\nvcompiler.dll
2015-03-29 19:10:55 ----A---- C:\Windows\ntbtlog.txt
2015-03-22 17:05:22 ----D---- C:\ProgramData\WarThunder
2015-03-17 14:48:50 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-16 16:31:34 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\wextract.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\url.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msls31.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\mshta.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\inseng.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\icardie.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-03-16 16:31:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\wininet.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\urlmon.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2015-03-16 16:31:32 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msrating.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msls31.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\mshtmler.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msfeedssync.exe
2015-03-16 16:31:32 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jsproxy.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jsIntl.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jscript9diag.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\jscript9.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\ieui.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\iesysprep.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\iertutil.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\ieframe.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\IEAdvpack.dll
2015-03-16 16:31:32 ----A---- C:\Windows\system32\elshyph.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\wextract.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\webcheck.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\vbscript.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\url.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\pngfilt.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\occache.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshtmled.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshtml.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\mshta.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\msfeeds.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\licmgr10.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\jscript.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\inseng.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\imgutil.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iexpress.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieUnatt.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iesetup.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iernonce.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iepeers.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\iedkcs32.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieapfltr.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ieapfltr.dat
2015-03-16 16:31:31 ----A---- C:\Windows\system32\ie4uinit.exe
2015-03-16 16:31:31 ----A---- C:\Windows\system32\icardie.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\dxtrans.dll
2015-03-16 16:31:31 ----A---- C:\Windows\system32\dxtmsft.dll
2015-03-15 22:07:47 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-03-11 19:04:21 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-03-11 18:13:00 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-03-11 18:13:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-03-11 18:12:59 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-03-11 18:12:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-03-11 18:12:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-03-11 18:12:57 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-03-11 18:12:57 ----A---- C:\Windows\system32\crypt32.dll
2015-03-11 18:12:56 ----A---- C:\Windows\system32\wmp.dll
2015-03-11 18:12:56 ----A---- C:\Windows\system32\mf.dll
2015-03-11 18:12:56 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-03-11 18:12:55 ----A---- C:\Windows\system32\drmv2clt.dll
2015-03-11 18:12:54 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-03-11 18:12:54 ----A---- C:\Windows\system32\quartz.dll
2015-03-11 18:12:53 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-03-11 18:12:51 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-03-11 18:12:51 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-03-11 18:12:51 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\winload.exe
2015-03-11 18:12:51 ----A---- C:\Windows\system32\msscp.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\cryptui.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\cryptnet.dll
2015-03-11 18:12:51 ----A---- C:\Windows\system32\audiosrv.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-03-11 18:12:50 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\wintrust.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\srcore.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\srclient.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\smss.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\rstrui.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\rrinstaller.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\qdvd.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcawrk.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcasvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcalua.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\pcadm.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\msnetobj.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\msmmsp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\mfps.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\mfpmp.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\mfplat.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\evr.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\EncDump.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-03-11 18:12:50 ----A---- C:\Windows\system32\drivers\appid.sys
2015-03-11 18:12:50 ----A---- C:\Windows\system32\csrsrv.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\cryptsvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\cryptsp.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\blackbox.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\AudioSes.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\AudioEng.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\audiodg.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidsvc.dll
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 18:12:50 ----A---- C:\Windows\system32\appidapi.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-03-11 18:12:49 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\wmploc.DLL
2015-03-11 18:12:49 ----A---- C:\Windows\system32\spwmp.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\pcaevts.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\mferror.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\dxmasf.dll
2015-03-11 18:12:49 ----A---- C:\Windows\system32\apisetschema.dll
2015-03-11 18:12:03 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-03-11 18:11:49 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\wdigest.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\TSpkg.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\sspisrv.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\sspicli.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\schannel.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\secur32.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\ncrypt.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\msv1_0.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\msobjs.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\msaudite.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\lsass.exe
2015-03-11 18:11:49 ----A---- C:\Windows\system32\lsasrv.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\kerberos.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-03-11 18:11:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-03-11 18:11:49 ----A---- C:\Windows\system32\drivers\cng.sys
2015-03-11 18:11:49 ----A---- C:\Windows\system32\credssp.dll
2015-03-11 18:11:49 ----A---- C:\Windows\system32\auditpol.exe
2015-03-11 18:11:49 ----A---- C:\Windows\system32\adtschema.dll
2015-03-11 18:11:30 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-03-11 18:11:30 ----A---- C:\Windows\system32\shell32.dll
2015-03-11 18:11:29 ----A---- C:\Windows\system32\rdpudd.dll
2015-03-11 18:11:29 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 18:11:29 ----A---- C:\Windows\system32\rdpcorets.dll
2015-03-11 18:11:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-03-11 18:11:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-03-11 18:11:10 ----D---- C:\ProgramData\Malwarebytes
2015-03-11 18:11:10 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-11 18:11:10 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-03-11 18:11:10 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-03-11 18:11:10 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-03-11 18:09:34 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-03-11 18:09:34 ----A---- C:\Windows\system32\ubpm.dll
2015-03-11 18:09:01 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-03-11 18:09:01 ----A---- C:\Windows\system32\msctf.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-03-11 18:09:00 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\lpk.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\fontsub.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\dciman32.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\atmlib.dll
2015-03-11 18:09:00 ----A---- C:\Windows\system32\atmfd.dll
2015-03-11 18:08:59 ----A---- C:\Windows\system32\win32k.sys
2015-03-11 18:08:39 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-03-11 18:08:39 ----A---- C:\Windows\system32\WMPhoto.dll
2015-03-11 17:35:41 ----D---- C:\AdwCleaner
2015-03-11 17:35:06 ----D---- C:\Program Files\Common Files\Symantec Shared
2015-03-11 17:35:06 ----A---- C:\Windows\system32\drivers\SYMEVENT64x86.SYS
2015-03-11 17:34:20 ----D---- C:\Windows\system32\drivers\NSx64
2015-03-11 17:34:20 ----D---- C:\Program Files (x86)\Norton Security
2015-03-11 17:34:19 ----D---- C:\ProgramData\Norton
2015-03-11 17:34:04 ----D---- C:\ProgramData\NortonInstaller
2015-03-11 17:34:04 ----D---- C:\Program Files (x86)\NortonInstaller
2015-03-11 17:09:42 ----SHD---- C:\Config.Msi
2015-03-10 22:25:44 ----D---- C:\Program Files\TeamSpeak 3 Client
======List of files/folders modified in the last 1 month======
2015-03-29 20:16:58 ----D---- C:\Windows\Prefetch
2015-03-29 20:16:53 ----RD---- C:\Program Files
2015-03-29 19:50:30 ----D---- C:\Windows\System32
2015-03-29 19:50:30 ----D---- C:\Windows\inf
2015-03-29 19:50:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-03-29 19:49:30 ----D---- C:\ProgramData\NVIDIA
2015-03-29 19:49:17 ----D---- C:\Windows\SysWOW64
2015-03-29 19:49:12 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2015-03-29 19:48:47 ----D---- C:\Windows\system32\DriverStore
2015-03-29 19:47:19 ----D---- C:\Windows\temp
2015-03-29 19:47:06 ----D---- C:\Windows\system32\drivers
2015-03-29 19:47:06 ----D---- C:\Program Files\NVIDIA Corporation
2015-03-29 19:47:04 ----D---- C:\Windows
2015-03-29 19:43:22 ----D---- C:\Windows\system32\config
2015-03-29 19:29:16 ----A---- C:\Windows\SYSWOW64\log.txt
2015-03-29 19:27:55 ----SD---- C:\System Volume Information
2015-03-29 12:22:07 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-28 14:11:35 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-27 22:36:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-03-26 16:37:54 ----D---- C:\Windows\system32\catroot2
2015-03-22 17:05:22 ----D---- C:\ProgramData
2015-03-20 21:47:22 ----D---- C:\Windows\SYSWOW64\directx
2015-03-20 21:47:14 ----HD---- C:\Windows\msdownld.tmp
2015-03-20 21:47:11 ----D---- C:\Windows\Logs
2015-03-20 16:22:05 ----D---- C:\Windows\rescache
2015-03-18 22:21:36 ----RD---- C:\Program Files (x86)
2015-03-18 09:19:03 ----D---- C:\Windows\winsxs
2015-03-18 00:24:07 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-03-18 00:24:07 ----D---- C:\Windows\system32\cs-CZ
2015-03-16 16:36:18 ----D---- C:\Program Files\Internet Explorer
2015-03-16 16:36:14 ----D---- C:\Windows\SYSWOW64\migration
2015-03-16 16:36:13 ----D---- C:\Windows\SYSWOW64\en-US
2015-03-16 16:36:11 ----D---- C:\Windows\system32\migration
2015-03-16 16:36:11 ----D---- C:\Windows\PolicyDefinitions
2015-03-16 16:36:10 ----D---- C:\Windows\system32\en-US
2015-03-15 22:27:50 ----D---- C:\Windows\servicing
2015-03-15 22:10:01 ----D---- C:\Windows\Panther
2015-03-15 22:02:34 ----D---- C:\Windows\debug
2015-03-13 21:41:47 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2015-03-13 21:41:47 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-03-13 21:41:47 ----A---- C:\Windows\system32\OpenCL.dll
2015-03-13 21:41:47 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-03-13 21:41:47 ----A---- C:\Windows\system32\nvapi64.dll
2015-03-13 18:16:47 ----A---- C:\Windows\system32\nvsvc64.dll
2015-03-13 18:16:47 ----A---- C:\Windows\system32\nvcpl.dll
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvvsvc.exe
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvsvcr.dll
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvshext.dll
2015-03-13 18:16:45 ----A---- C:\Windows\system32\nvmctray.dll
2015-03-13 13:34:50 ----D---- C:\Windows\system32\Tasks
2015-03-11 19:13:11 ----D---- C:\Windows\SYSWOW64\Dism
2015-03-11 19:13:11 ----D---- C:\Windows\system32\Dism
2015-03-11 19:13:11 ----D---- C:\Program Files\Windows Media Player
2015-03-11 19:13:11 ----D---- C:\Program Files (x86)\Windows Media Player
2015-03-11 19:13:02 ----D---- C:\Windows\system32\Boot
2015-03-11 19:03:39 ----D---- C:\Program Files (x86)\Common Files
2015-03-11 18:28:50 ----SHD---- C:\Windows\Installer
2015-03-11 18:28:45 ----D---- C:\ProgramData\Microsoft Help
2015-03-11 18:22:20 ----D---- C:\Windows\system32\MRT
2015-03-11 18:18:19 ----A---- C:\Windows\system32\MRT.exe
2015-03-11 18:12:31 ----D---- C:\Programy
2015-03-11 17:35:06 ----D---- C:\Program Files\Common Files
2015-03-11 17:27:23 ----D---- C:\Program Files (x86)\Steam
2015-03-11 17:10:04 ----DC---- C:\Windows\system32\DRVSTORE
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-02-06 564824]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NSx64\1601000.009\SYMDS64.SYS [2014-09-09 490712]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NSx64\1601000.009\SYMEFA64.SYS [2014-09-09 1151704]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 BHDrvx64;BHDrvx64; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\BASHDefs\20150321.001\BHDrvx64.sys [2015-03-09 1622744]
R1 ccSet_NS;NS Settings Manager; C:\Windows\system32\drivers\NSx64\1601000.009\ccSetx64.sys [2014-09-09 165080]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-06 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2015-03-11 487216]
R1 IDSVia64;IDSVia64; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\IPSDefs\20150327.001\IDSvia64.sys [2015-03-27 671448]
R1 mbamchameleon;mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [2015-03-17 107736]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NSx64\1601000.009\SRTSPX64.SYS [2014-09-09 42200]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NSx64\1601000.009\Ironx64.SYS [2014-09-09 271576]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NSx64\1601000.009\SYMNETS.SYS [2014-09-09 565464]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2015-01-02 42696]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2015-03-11 142640]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-03-17 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-03-29 136408]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-03-17 63704]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-12-08 64624]
R3 NAVENG;NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\VirusDefs\20150329.001\ENG64.SYS [2015-03-11 129752]
R3 NAVEX15;NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.0.0.110\Definitions\VirusDefs\20150329.001\EX64.SYS [2015-03-11 2137304]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-02-05 195728]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-01-20 888536]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NSx64\1601000.009\SRTSP64.SYS [2014-12-02 914648]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2015-03-11 102616]
S1 FldSafe;FldSafe; C:\Windows\system32\DRIVERS\FldSafe.sys []
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2015-01-02 310728]
S3 agvkhi1n;agvkhi1n; C:\Windows\system32\drivers\agvkhi1n.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 gdrv;gdrv; C:\Windows\system32\drivers\gdrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 ivusb;Initio Driver for USB Default Controller; C:\Windows\system32\DRIVERS\ivusb.sys [2010-07-29 29720]
S3 Prot6Flt;Prot6Flt; C:\Windows\system32\DRIVERS\Prot6Flt.sys []
S3 PSKMAD;PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [2013-04-29 47632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [2007-05-14 27520]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbser;Nokia USB Serial Port Driver ; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-10-05 325656]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-03-17 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-03-17 1871160]
R2 NS;Norton Security; C:\Program Files (x86)\Norton Security\Engine\22.1.0.9\NS.exe [2014-12-10 282528]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-03-13 935056]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-03-13 410768]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-03-16 114688]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-14 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-04 107912]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-04 107912]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-27 148080]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-25 1903472]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S4 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-11-18 833728]
-----------------EOF-----------------