Stránka 1 z 1

kontrola logu, podozrenie na vírusi

Napsal: 26 črc 2015 11:42
od jardo
Dobrý den, poprosil by som o kontrolu logu. Ide o sestrin notebook ktory pouziva na bezne veci ako pozeranie filmov a surfovanie na internete, no vobec sa on nestara vyskakuju tu vseliake programy ktore chcu stale nieco aktualizovat, 3/4 programov ani nepoznam a tusim tu nema ani antivirus. Chcel by som ten ntb troska precistit pripadne odstranit nejaky ten virus a nepotrebny softver ktory len spomaluje pocitac. Vopred dakujem :)

Logfile of random's system information tool 1.10 (written by random/random)
Run by Jaro at 2015-07-26 12:37:11
Microsoft Windows 8.1
System drive C: has 349 GB (81%) free of 433 GB
Total RAM: 3816 MB (23% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:37:19, on 26.7.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\UMonit64.exe
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Users\Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\WINDOWS\syswow64\wwahost.exe
D:\Program Files (x86)\Steam\Steam.exe
D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jaro.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... XXW3713NNH
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... XXW3713NNH
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkID= ... 6pc%3DLCJB
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Movies Toolbar (Dist. by Bandoo Media, Inc.) - {d1dac034-9fd9-4c13-a388-d2e10e57707f} - C:\Program Files (x86)\ilividmoviestoolbar181\IE\searchresultsDx.dll
O2 - BHO: buenosearch Helper Object - {F1C81E40-2485-4DB6-8C9D-04BD596B281E} - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\bh\buenosearch.dll
O3 - Toolbar: Movies Toolbar (Dist. by Bandoo Media, Inc.) - {d1dac034-9fd9-4c13-a388-d2e10e57707f} - C:\Program Files (x86)\ilividmoviestoolbar181\IE\searchresultsDx.dll
O3 - Toolbar: buenosearch Toolbar - {828DC97A-2277-4E10-92A9-4907FA0922A9} - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\buenosearchTlbr.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-21-1687900140-1392591902-1605008389-1006\..\Run: [Dropbox Update] "C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c (User 'Miriam')
O4 - S-1-5-21-1687900140-1392591902-1605008389-1006 Startup: Dropbox.lnk = Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Miriam')
O4 - S-1-5-21-1687900140-1392591902-1605008389-1006 User Startup: Dropbox.lnk = Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Miriam')
O4 - Global Startup: iSCTsysTray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrcmSetSecurity - Intel - C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DCService.exe - Unknown owner - C:\ProgramData\DatacardService\DCService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12250 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe 606491744256
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\ProgramData\DatacardService\DCService.exe
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
dashost.exe {fb5a94f9-a310-4288-b8fdb0a5f6e22a05}
"C:\WINDOWS\system32\rundll32.exe" "c:\Program Files (x86)\DeltaFix\DeltaFix.dll",serv
"C:\WINDOWS\system32\rundll32.exe" "c:\Program Files (x86)\DeltaFix\DeltaFix.dll",serv
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e7a16716-276a-46d3-b69a-5767b0c48f29 -SystemEventPortName:HostProcess-9a705a89-aedb-4e74-a930-04e5520ba7fd -IoCancelEventPortName:HostProcess-c3030ab9-887c-42ac-8964-c6431832c14b -NonStateChangingEventPortName:HostProcess-5f095770-44b1-480d-9ede-1e36fb49bad2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6f5c276b-30c3-4024-8c9e-7cb7d57bec44 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\WINDOWS\Explorer.EXE
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Apoint2K\Apoint.exe"
"C:\Windows\RTFTrack.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Windows\SysWOW64\UMonit64.exe"
"C:\WINDOWS\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe"
"C:\Program Files\Apoint2K\HidFind.exe"
"Apntex.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe"
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe"
"C:\Users\Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\WINDOWS\syswow64\wwahost.exe" -ServerName:App.wwa
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Internet Explorer\iexplore.exe" -ServerName:DefaultBrowserServer
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4264 CREDAT:267777 /prefetch:1
"C:\WINDOWS\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding
"D:\Program Files\WinRAR\WinRAR.exe" "C:\Users\Miriam\Downloads\Microsoft Toolkit-exe.rar"
"D:\Program Files (x86)\Steam\Steam.exe"
"D:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Miriam\AppData\Local\Steam\htmlcache" -steampid 9952 -buildid 1424305157 -steamid "0" --blacklist-accelerated-compositing --process-per-tab --disable-accelerated-video-decode --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"D:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --enable-pinch --disable-accelerated-compositing --disable-gpu-compositing --channel="9168.0.727946680\5186850" /prefetch:673131151
"D:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --enable-pinch --disable-accelerated-compositing --disable-gpu-compositing --channel="9168.1.1833900959\204705048" /prefetch:673131151
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4264 CREDAT:2299409 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.mystartsearch.com/?type=sc&t ... XXW3713NNH
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="12072.0.294824049\1687144167" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3316 --ignored=" --type=renderer " /prefetch:822062411
/QuitInfo:00000000000011BC;0000000000001298;
/loadhooks /Parent:000000000000261c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="12072.13.161386586\196599636" --font-cache-shared-handle=2956 /prefetch:673131151
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="12072.22.1078025223\1229204642" --font-cache-shared-handle=3476 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="12072.23.1834945750\723372519" --ppapi-flash-args=enable_hw_video_decode=1 --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="12072.52.751248215\827728866" --font-cache-shared-handle=7552 /prefetch:673131151
"C:\Program Files\CCleaner\CCleaner64.exe"

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="12072.59.1210991458\587209444" --font-cache-shared-handle=8132 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="12072.60.1853484830\1163849990" --font-cache-shared-handle=7964 /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe123_ Global\UsGthrCtrlFltPipeMssGthrPipe123 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
"C:\Users\Miriam\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}

======Scheduled tasks folder======

C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1687900140-1392591902-1605008389-1006Core.job - C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1687900140-1392591902-1605008389-1006UA.job - C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1dac034-9fd9-4c13-a388-d2e10e57707f}]
Movies Toolbar (Dist. by Bandoo Media, Inc.) - C:\Program Files (x86)\ilividmoviestoolbar181\IE\searchresultsDx64.dll [2013-12-11 131536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1dac034-9fd9-4c13-a388-d2e10e57707f}]
Movies Toolbar (Dist. by Bandoo Media, Inc.) - C:\Program Files (x86)\ilividmoviestoolbar181\IE\searchresultsDx.dll [2013-12-11 115664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}]
buenosearch Helper Object - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\bh\buenosearch.dll [2013-11-08 280984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{d1dac034-9fd9-4c13-a388-d2e10e57707f} - Movies Toolbar (Dist. by Bandoo Media, Inc.) - C:\Program Files (x86)\ilividmoviestoolbar181\IE\searchresultsDx64.dll [2013-12-11 131536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{d1dac034-9fd9-4c13-a388-d2e10e57707f} - Movies Toolbar (Dist. by Bandoo Media, Inc.) - C:\Program Files (x86)\ilividmoviestoolbar181\IE\searchresultsDx.dll [2013-12-11 115664]
{828DC97A-2277-4E10-92A9-4907FA0922A9} - buenosearch Toolbar - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\buenosearchTlbr.dll [2013-11-08 297368]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-06-26 13626072]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-06-05 1311304]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-10-04 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-10-04 771032]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-10-04 769496]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2013-07-17 687448]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-08-03 6340312]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2013-05-21 7830328]
"UMonit64"=C:\windows\SysWOW64\UMonit64.exe [2013-02-28 40960]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2013-11-03 15792112]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2013-11-03 101360]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-02-13 169768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-07-18 53753984]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
""= []
"HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-08-04 30264]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
iSCTsysTray.lnk - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-10-04 623616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-26 12:37:12 ----D---- C:\Program Files\trend micro
2015-07-26 12:37:11 ----D---- C:\rsit
2015-07-25 18:35:05 ----D---- C:\unetbtin
2015-07-24 18:05:52 ----RD---- C:\Program Files (x86)\Skype
2015-07-24 18:05:43 ----D---- C:\ProgramData\Skype
2015-07-23 09:19:24 ----A---- C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2015-07-22 12:32:36 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-16 12:11:08 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-16 12:11:08 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-16 12:11:07 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-16 12:11:06 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2015-07-16 12:11:03 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-16 12:11:00 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-07-16 12:10:59 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2015-07-16 12:10:59 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-16 12:10:57 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-16 12:10:51 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-16 12:10:48 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-16 12:10:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-16 12:10:45 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-16 12:10:44 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-07-16 12:10:43 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-16 12:10:42 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-16 12:10:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2015-07-16 12:10:19 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2015-07-15 10:10:53 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 10:10:52 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 10:10:50 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2015-07-15 10:10:50 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 10:10:49 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 10:10:49 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 10:10:47 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\certcli.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 10:10:40 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 10:10:38 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-07-15 10:10:32 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 10:10:29 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-07-15 10:10:29 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 10:10:28 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 10:10:27 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 10:10:23 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 10:10:19 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-07-15 10:09:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 10:09:49 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-07-15 10:09:45 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 10:09:45 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 10:09:44 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-07-15 10:09:44 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-07-15 10:09:26 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 10:09:25 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 10:09:23 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-07-15 10:09:22 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 10:09:19 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-07-15 10:09:19 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-07-15 10:09:18 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-07-15 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2015-07-15 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-07-15 10:09:16 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-07-15 10:09:16 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-07-15 10:09:15 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 10:09:14 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-07-15 10:09:12 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 10:09:12 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 10:09:10 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-07-15 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-07-15 10:09:09 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 10:09:08 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-07-15 10:08:45 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 10:08:44 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-07-15 10:08:43 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 10:08:42 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2015-07-15 10:08:35 ----A---- C:\WINDOWS\system32\apphelp.dll

======List of files/folders modified in the last 1 month======

2015-07-26 12:37:12 ----RD---- C:\Program Files
2015-07-26 12:36:29 ----D---- C:\WINDOWS\Prefetch
2015-07-26 12:10:44 ----D---- C:\WINDOWS\Temp
2015-07-26 12:08:17 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-26 12:00:00 ----D---- C:\WINDOWS\system32\sru
2015-07-26 09:06:06 ----SHD---- C:\WINDOWS\Installer
2015-07-25 12:01:34 ----RD---- C:\WINDOWS\System32
2015-07-25 12:01:34 ----D---- C:\WINDOWS\Inf
2015-07-25 12:01:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-25 07:05:20 ----SD---- C:\WINDOWS\system32\GWX
2015-07-24 18:06:00 ----D---- C:\Program Files (x86)\Common Files
2015-07-24 18:05:52 ----RD---- C:\Program Files (x86)
2015-07-24 18:05:43 ----HD---- C:\ProgramData
2015-07-24 09:46:29 ----D---- C:\WINDOWS\rescache
2015-07-24 07:53:56 ----SHD---- C:\System Volume Information
2015-07-24 06:37:34 ----D---- C:\WINDOWS\AppReadiness
2015-07-23 09:31:55 ----D---- C:\WINDOWS\system32\config
2015-07-23 09:31:38 ----D---- C:\WINDOWS\system32\catroot
2015-07-23 09:24:55 ----A---- C:\IFRToolLog.txt
2015-07-23 09:19:16 ----D---- C:\WINDOWS\WinSxS
2015-07-22 15:00:36 ----D---- C:\WINDOWS\SysWOW64
2015-07-22 04:37:34 ----D---- C:\WINDOWS\CbsTemp
2015-07-22 04:24:43 ----D---- C:\WINDOWS\system32\DriverStore
2015-07-18 22:25:32 ----D---- C:\WINDOWS\apppatch
2015-07-18 22:25:31 ----D---- C:\WINDOWS\system32\sk-SK
2015-07-18 22:25:30 ----D---- C:\WINDOWS\system32\drivers
2015-07-18 22:25:29 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-18 22:25:28 ----RD---- C:\WINDOWS\ToastData
2015-07-18 22:25:26 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-18 22:25:26 ----D---- C:\WINDOWS\system32\wbem
2015-07-18 22:25:26 ----D---- C:\WINDOWS\system32\appraiser
2015-07-18 22:25:25 ----D---- C:\WINDOWS\WinStore
2015-07-18 22:25:24 ----D---- C:\Program Files\Internet Explorer
2015-07-18 22:25:24 ----D---- C:\Program Files (x86)\Internet Explorer
2015-07-18 18:48:37 ----D---- C:\ProgramData\Microsoft Help
2015-07-18 18:29:09 ----D---- C:\WINDOWS\system32\MRT
2015-07-16 12:52:14 ----D---- C:\WINDOWS\Tasks
2015-07-16 12:52:13 ----D---- C:\WINDOWS\system32\Tasks
2015-07-16 12:39:08 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-07-16 12:16:29 ----HD---- C:\Program Files\WindowsApps
2015-07-15 10:41:53 ----D---- C:\Program Files (x86)\Google
2015-07-15 10:07:57 ----D---- C:\WINDOWS\system32\catroot2
2015-07-15 10:05:10 ----A---- C:\WINDOWS\system32\wuaext.dll
2015-07-13 23:10:13 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-07-05 12:08:23 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2015-07-03 10:21:09 ----D---- C:\ProgramData\Energy Manager
2015-07-03 08:43:04 ----A---- C:\WINDOWS\system32\MRT.exe
2015-07-02 10:21:29 ----D---- C:\ProgramData\{52e7496f-9e0f-afd8-52e7-7496f9e025be}

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-03-22 678384]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-11-03 39008]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 acpials;@sensorsalsdriver.inf,%kbfiltr.SvcDesc%;ALS Sensor Filter; C:\WINDOWS\System32\drivers\acpials.sys [2014-10-29 9216]
R3 ACPIVPC;@oem61.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-11-03 35600]
R3 ApfiltrService;@oem11.inf,%Filter.SvcDesc%;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2013-07-17 498992]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2013-04-24 1385272]
R3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [2010-05-22 83456]
R3 ibtusb;@oem8.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R) 4.0 + HS Adapter; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2013-06-03 115656]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-04 4185600]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\WINDOWS\system32\DRIVERS\ikbevent.sys [2013-04-16 21048]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\imsevent.sys [2013-04-16 21048]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-26 3462616]
R3 ISCT;@oem55.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\WINDOWS\System32\drivers\ISCTD64.sys [2013-04-16 46568]
R3 iwdbus;@oem69.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-09-26 27032]
R3 MarvinBus;@oem71.inf,%MarvinBus.SVCDESC%;Pinnacle Marvin Bus 64; C:\WINDOWS\System32\drivers\MarvinBus64.sys [2005-09-23 261120]
R3 MEIx64;@oem65.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-05-09 99800]
R3 NETwNe64;@oem63.inf,%NIC_Service_DispName_WIN8_64%;Intel(R) Wireless Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew02.sys [2013-10-08 3648480]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTL8168;@oem10.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-04-10 801864]
R3 rtsuvc;@oem30.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-08-03 8873688]
R3 SensorsAlsDriver;@sensorsalsdriver.inf,%WudfSensorsAlsDriverDisplayName%;UMDF Reflector service for SensorsAlsDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [2014-10-29 226304]
R3 usb3Hub;@oem60.inf,%usb3Hub.SVCDESC%;UoIP Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [2013-05-29 206744]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S1 MpKslf339b538;MpKslf339b538; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7C514631-EE90-4747-ADC9-AFF5C28A6A0B}\MpKslf339b538.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [2010-03-20 114560]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
S3 GeneStor;@oem9.inf,%GENESTOR.SvcDesc%;Genesys Logic Storage Driver; C:\WINDOWS\System32\drivers\GeneStor.sys [2013-02-22 79592]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2010-03-25 120704]
S3 intaud_WaveExtensible;@oem68.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-09-26 39320]
S3 IntcDAud;@oem57.inf,%IntcDAud.SvcDesc%;Intel(R) Zvuk pre obrazovky; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-05-17 442368]
S3 USBAAPL64;@oem89.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2013-06-24 1132920]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2013-04-24 1153400]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 BrcmSetSecurity;BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [2013-05-29 101536]
R2 DCService.exe;DCService.exe; C:\ProgramData\DatacardService\DCService.exe [2010-05-08 229376]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-08-28 626416]
R2 fc67e7a0;DeltaFix; C:\WINDOWS\syswow64\rundll32.exe [2014-10-29 51200]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-06-24 136704]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-03-22 15344]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2014-12-29 158864]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-05-09 131544]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-06-26 156616]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2013-04-16 182760]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-05-09 169432]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2015-03-06 584632]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-05-09 368600]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-08-28 149744]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-11-03 68368]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-02-13 643880]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-02-19 835776]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-04 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15 107848]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-23 136120]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184]
S3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28 174368]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-08-28 273136]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: kontrola logu, podozrenie na vírusi

Napsal: 26 črc 2015 12:27
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: kontrola logu, podozrenie na vírusi

Napsal: 26 črc 2015 12:47
od jardo
Isiel som presne podla krokov, dal som scan potom clean a nasledne sa restartoval pocitac s tym ze pri zapnuti mi to zobrazi log, ale ziadny mi tu neozobrazilo.

Re: kontrola logu, podozrenie na vírusi

Napsal: 26 črc 2015 16:00
od Rudy
Log vypadá takto: http://forum.viry.cz/viewtopic.php?f=13 ... 9#p1407544 . Objeví se po restartu. Někde by tam měl být.

Re: kontrola logu, podozrenie na vírusi

Napsal: 26 črc 2015 16:20
od jardo
tak tu je to

# AdwCleaner v4.208 - Log vytvorený 26/07/2015 at 13:40:37
# Aktualizované 09/07/2015 by Xplode
# Databáza : 2015-07-26.1 [Server]
# Operačný systém : Windows 8.1 (x64)
# Uživateľské meno : Jaro - LENOVO-PC
# Spustené z : C:\Users\Miriam\Desktop\adwcleaner_4.208.exe
# Nastavenia : Čistenie

***** [ Služby ] *****

Služba Zmazané : IHProtect Service
[#] Služba Zmazané : fc67e7a0

***** [ Súbory / Priečinky ] *****

[#] Priečinok Zmazané : C:\ProgramData\BitGuard
[#] Priečinok Zmazané : C:\ProgramData\Browser Manager
[#] Priečinok Zmazané : C:\ProgramData\BrowserProtect
Priečinok Zmazané : C:\ProgramData\DSearchLink
Priečinok Zmazané : C:\ProgramData\torchcrashhandler
Priečinok Zmazané : C:\ProgramData\IHProtectUpDate
Priečinok Zmazané : C:\ProgramData\{52e7496f-9e0f-afd8-52e7-7496f9e025be}
Priečinok Zmazané : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
Priečinok Zmazané : C:\Program Files (x86)\buenosearch LTD
Priečinok Zmazané : C:\Program Files (x86)\EZDownloader
Priečinok Zmazané : C:\Program Files (x86)\ilividmoviestoolbar181
Priečinok Zmazané : C:\Program Files (x86)\DeltaFix
Priečinok Zmazané : C:\Program Files (x86)\XTab
Priečinok Zmazané : C:\Program Files (x86)\uneisales
Priečinok Zmazané : C:\Program Files (x86)\unisAles
Priečinok Zmazané : C:\Program Files (x86)\youtubeadblocker
Priečinok Zmazané : C:\Users\Jaro\AppData\Local\Temp\mt_ffx
Priečinok Zmazané : C:\Users\Jaro\AppData\Local\buenosearch
Priečinok Zmazané : C:\Users\Jaro\AppData\LocalLow\ilividmoviestoolbar181
Priečinok Zmazané : C:\Users\Jaro\AppData\Roaming\BabSolution
Priečinok Zmazané : C:\Users\Jaro\AppData\Roaming\buenosearch LTD
Priečinok Zmazané : C:\Users\Jaro\AppData\Roaming\Systweak
Priečinok Zmazané : C:\Users\Miriam\AppData\Local\iMesh
Priečinok Zmazané : C:\Users\Miriam\AppData\LocalLow\ilividmoviestoolbar181
Priečinok Zmazané : C:\Users\Miriam\AppData\Roaming\Systweak
Priečinok Zmazané : C:\Users\Miriam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\torch
Priečinok Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Extensions\lijicndbkjoplmhnclmoahmcaffaeapp
Priečinok Zmazané : C:\ProgramData\dkkgedajmffchbncmoceinnffokclmdo
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lijicndbkjoplmhnclmoahmcaffaeapp_0.localstorage
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lijicndbkjoplmhnclmoahmcaffaeapp_0.localstorage-journal
Súbor Zmazané : C:\WINDOWS\System32\roboot64.exe
Súbor Zmazané : C:\Users\Jaro\Desktop\Live PC Help.lnk
Súbor Zmazané : C:\Users\Miriam\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iMesh.lnk
Súbor Zmazané : C:\Users\Miriam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iMesh.lnk
Súbor Zmazané : C:\Users\Miriam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage-journal
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal
Súbor Zmazané : C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.skistart.com_0.localstorage-journal

***** [ Naplánované úlohy ] *****


***** [ Zástupcovia ] *****

Zástupca Dezinfikované : C:\Users\Jaro\Desktop\Search.lnk
Zástupca Dezinfikované : C:\Users\Jaro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Zástupca Dezinfikované : C:\Users\Jaro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Zástupca Dezinfikované : C:\Users\Jaro\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk

***** [ Registre ] *****

Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\b
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\buenosearch.buenosearchappCore
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\buenosearch.buenosearchappCore.1
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\buenosearch.buenosearchdskBnd
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\buenosearch.buenosearchdskBnd.1
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\buenosearch.buenosearchHlpr
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\buenosearch.buenosearchHlpr.1
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\esrv.buenosearchESrvc
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\esrv.buenosearchESrvc.1
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{4CC15FBA-46A4-4CB5-BFAF-F2335365AE76}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{5B6E533F-F78F-4525-B316-312BAF1295D1}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{8322EB6E-B594-41F6-A30B-CF3F800E1874}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\TypeLib\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\TypeLib\{E6772887-C1E1-405E-94BB-D8760A1CF8DF}
Kľúč registra Zmazané : HKLM\SOFTWARE\Classes\TypeLib\{AEF2BB85-DF75-41E2-8366-FB89A5F869F9}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Kľúč registra Zmazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{708D0DD7-FBC0-4437-B525-C098F450A62C}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Hodnota Zmazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{828DC97A-2277-4E10-92A9-4907FA0922A9}]
Hodnota Zmazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D1DAC034-9FD9-4C13-A388-D2E10E57707F}]
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\CLSID\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Hodnota Zmazané : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D1DAC034-9FD9-4C13-A388-D2E10E57707F}]
Kľúč registra Zmazané : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Dáta Obnovené : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Kľúč registra Zmazané : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Kľúč registra Zmazané : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Kľúč registra Zmazané : HKCU\Software\APNDTX
Kľúč registra Zmazané : HKCU\Software\BABSOLUTION
Kľúč registra Zmazané : HKCU\Software\buenosearch LTD
Kľúč registra Zmazané : HKCU\Software\ilivid
Kľúč registra Zmazané : HKCU\Software\ilividmoviestoolbar181
Kľúč registra Zmazané : HKCU\Software\Softonic
Kľúč registra Zmazané : HKCU\Software\systweak
Kľúč registra Zmazané : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Kľúč registra Zmazané : HKLM\SOFTWARE\buenosearch LTD
Kľúč registra Zmazané : HKLM\SOFTWARE\SupDp
Kľúč registra Zmazané : HKLM\SOFTWARE\systweak
Kľúč registra Zmazané : HKLM\SOFTWARE\mystartsearchSoftware
Kľúč registra Zmazané : HKLM\SOFTWARE\IHProtect
Kľúč registra Zmazané : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\buenosearch
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbar181IE
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XTab
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
Kľúč registra Zmazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}

***** [ Webové prehliadače ] *****

-\\ Internet Explorer v11.0.9600.17840

Nastavenie Obnovené : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Nastavenie Obnovené : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavenie Obnovené : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavenie Obnovené : HKCU\Software\Microsoft\Internet Explorer\Main [First Home Page]
Nastavenie Obnovené : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavenie Obnovené : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavenie Obnovené : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Nastavenie Obnovené : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavenie Obnovené : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavenie Obnovené : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v44.0.2403.107

[C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Zmazané [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=1315&systemid=406&v=n11551-287&apn_uid=9444403019834473&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
[C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Zmazané [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Miriam\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Zmazané [Homepage] : hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 51-287&t=4

*************************

AdwCleaner[R0].txt - [18271 bajtov] - [26/07/2015 13:39:01]
AdwCleaner[S0].txt - [15553 bajtov] - [26/07/2015 13:40:37]

########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [15614 bajtov] ##########

Re: kontrola logu, podozrenie na vírusi

Napsal: 26 črc 2015 17:20
od Rudy
OK. Dejte nový log RSIT.

Re: kontrola logu, podozrenie na vírusi

Napsal: 27 črc 2015 06:43
od jardo
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jaro at 2015-07-27 07:42:09
Microsoft Windows 8.1
System drive C: has 351 GB (81%) free of 433 GB
Total RAM: 3816 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:42:12, on 27.7.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\UMonit64.exe
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Users\Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Lenovo\Lenovo Messenger\NotificationsViewHost.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jaro.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\RunOnce: [Report] \AdwCleaner\AdwCleaner[S0].txt
O4 - HKUS\S-1-5-21-1687900140-1392591902-1605008389-1006\..\Run: [Dropbox Update] "C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c (User 'Miriam')
O4 - S-1-5-21-1687900140-1392591902-1605008389-1006 Startup: Dropbox.lnk = Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Miriam')
O4 - S-1-5-21-1687900140-1392591902-1605008389-1006 User Startup: Dropbox.lnk = Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Miriam')
O4 - Global Startup: iSCTsysTray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrcmSetSecurity - Intel - C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DCService.exe - Unknown owner - C:\ProgramData\DatacardService\DCService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 9811 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe 670804443888
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\ProgramData\DatacardService\DCService.exe
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
dashost.exe {f3f3cdc2-fb2c-46fc-8e40b7b9bea1b8d0}
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-39089df9-bdbb-416f-9dec-30c978271faa -SystemEventPortName:HostProcess-4db311e4-fcfb-455a-b158-d14e916057c4 -IoCancelEventPortName:HostProcess-a2fa4fed-3d0c-463f-a9b8-49806b1eaac0 -NonStateChangingEventPortName:HostProcess-adcb8576-9363-49af-b47c-d7c325bf32b2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ae55247a-3eaa-4cd9-9a65-1bd0b7dbc13e -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\WINDOWS\Explorer.EXE
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
/QuitInfo:0000000000000E54;0000000000000C54;
/loadhooks /Parent:00000000000014cc
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.mystartsearch.com/?type=sc&t ... XXW3713NNH
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2740.0.724249481\1703286705" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3316 --ignored=" --type=renderer " /prefetch:822062411
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Apoint2K\Apoint.exe"
"C:\Windows\RTFTrack.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Windows\SysWOW64\UMonit64.exe"
"C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe"
"Apntex.exe"
"C:\Program Files\Apoint2K\HidFind.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe"
"C:\Users\Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2740.4.1735301730\870119615" --ppapi-flash-args=enable_hw_video_decode=1 --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledWithReno/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="2740.5.1644128627\18140831" --font-cache-shared-handle=3884 /prefetch:673131151
"C:\WINDOWS\system32\GWX\GWX.exe"
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledWithReno/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="2740.7.743620418\536377951" --font-cache-shared-handle=3256 /prefetch:673131151
"C:\Program Files (x86)\Lenovo\Lenovo Messenger\NotificationsViewHost.exe" -taskbar

C:\WINDOWS\system32\msiexec.exe /V
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe27_ Global\UsGthrCtrlFltPipeMssGthrPipe27 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1687900140-1392591902-1605008389-100628_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1687900140-1392591902-1605008389-100628 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledWithReno/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="2740.13.1335047343\1950288044" --font-cache-shared-handle=5272 /prefetch:673131151
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
"C:\Users\Miriam\Downloads\RSITx64.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}

======Scheduled tasks folder======

C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1687900140-1392591902-1605008389-1006Core.job - C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1687900140-1392591902-1605008389-1006UA.job - C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-06-26 13626072]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-06-05 1311304]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-10-04 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-10-04 771032]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-10-04 769496]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2013-07-17 687448]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-08-03 6340312]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2013-05-21 7830328]
"UMonit64"=C:\windows\SysWOW64\UMonit64.exe [2013-02-28 40960]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2013-11-03 15792112]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2013-11-03 101360]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-02-13 169768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-07-18 53753984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Report"=\AdwCleaner\AdwCleaner[S0].txt [2015-07-26 15778]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
""= []
"HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-08-04 30264]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
iSCTsysTray.lnk - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-10-04 623616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-26 13:43:24 ----A---- C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2015-07-26 13:38:22 ----D---- C:\AdwCleaner
2015-07-26 12:37:12 ----D---- C:\Program Files\trend micro
2015-07-26 12:37:11 ----D---- C:\rsit
2015-07-25 18:35:05 ----D---- C:\unetbtin
2015-07-24 18:05:52 ----RD---- C:\Program Files (x86)\Skype
2015-07-24 18:05:43 ----D---- C:\ProgramData\Skype
2015-07-22 12:32:36 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-16 12:11:08 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-16 12:11:08 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-16 12:11:07 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-16 12:11:06 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2015-07-16 12:11:03 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-16 12:11:00 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-07-16 12:10:59 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2015-07-16 12:10:59 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-16 12:10:57 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-16 12:10:51 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-16 12:10:48 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-16 12:10:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-16 12:10:45 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-16 12:10:44 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-07-16 12:10:43 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-16 12:10:42 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-16 12:10:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2015-07-16 12:10:19 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2015-07-15 10:10:53 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 10:10:52 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 10:10:50 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2015-07-15 10:10:50 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 10:10:49 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 10:10:49 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 10:10:47 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\certcli.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 10:10:40 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 10:10:38 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-07-15 10:10:32 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 10:10:29 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-07-15 10:10:29 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 10:10:28 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 10:10:27 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 10:10:23 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 10:10:19 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-07-15 10:09:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 10:09:49 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-07-15 10:09:45 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 10:09:45 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 10:09:44 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-07-15 10:09:44 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-07-15 10:09:26 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 10:09:25 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 10:09:23 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-07-15 10:09:22 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 10:09:19 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-07-15 10:09:19 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-07-15 10:09:18 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-07-15 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2015-07-15 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-07-15 10:09:16 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-07-15 10:09:16 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-07-15 10:09:15 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 10:09:14 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-07-15 10:09:12 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 10:09:12 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 10:09:10 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-07-15 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-07-15 10:09:09 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 10:09:08 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-07-15 10:08:45 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 10:08:44 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-07-15 10:08:43 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 10:08:42 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2015-07-15 10:08:35 ----A---- C:\WINDOWS\system32\apphelp.dll

======List of files/folders modified in the last 1 month======

2015-07-27 07:41:32 ----D---- C:\WINDOWS\Prefetch
2015-07-27 07:39:11 ----SHD---- C:\WINDOWS\Installer
2015-07-27 07:39:11 ----D---- C:\WINDOWS\Temp
2015-07-27 07:34:48 ----D---- C:\WINDOWS\system32\catroot
2015-07-27 07:31:08 ----D---- C:\WINDOWS\system32\config
2015-07-27 07:24:44 ----D---- C:\WINDOWS\system32\sru
2015-07-26 18:11:36 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-26 13:43:24 ----RD---- C:\WINDOWS\System32
2015-07-26 13:40:46 ----HD---- C:\ProgramData
2015-07-26 13:40:45 ----RD---- C:\Program Files (x86)
2015-07-26 12:37:12 ----RD---- C:\Program Files
2015-07-25 12:01:34 ----D---- C:\WINDOWS\Inf
2015-07-25 12:01:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-25 07:05:20 ----SD---- C:\WINDOWS\system32\GWX
2015-07-24 18:06:00 ----D---- C:\Program Files (x86)\Common Files
2015-07-24 09:46:29 ----D---- C:\WINDOWS\rescache
2015-07-24 07:53:56 ----SHD---- C:\System Volume Information
2015-07-24 06:37:34 ----D---- C:\WINDOWS\AppReadiness
2015-07-23 09:24:55 ----A---- C:\IFRToolLog.txt
2015-07-23 09:19:16 ----D---- C:\WINDOWS\WinSxS
2015-07-22 15:00:36 ----D---- C:\WINDOWS\SysWOW64
2015-07-22 14:25:50 ----D---- C:\WINDOWS\CbsTemp
2015-07-22 04:24:43 ----D---- C:\WINDOWS\system32\DriverStore
2015-07-18 22:25:32 ----D---- C:\WINDOWS\apppatch
2015-07-18 22:25:31 ----D---- C:\WINDOWS\system32\sk-SK
2015-07-18 22:25:30 ----D---- C:\WINDOWS\system32\drivers
2015-07-18 22:25:29 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-18 22:25:28 ----RD---- C:\WINDOWS\ToastData
2015-07-18 22:25:26 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-18 22:25:26 ----D---- C:\WINDOWS\system32\wbem
2015-07-18 22:25:26 ----D---- C:\WINDOWS\system32\appraiser
2015-07-18 22:25:25 ----D---- C:\WINDOWS\WinStore
2015-07-18 22:25:24 ----D---- C:\Program Files\Internet Explorer
2015-07-18 22:25:24 ----D---- C:\Program Files (x86)\Internet Explorer
2015-07-18 18:48:37 ----D---- C:\ProgramData\Microsoft Help
2015-07-18 18:29:09 ----D---- C:\WINDOWS\system32\MRT
2015-07-16 12:52:14 ----D---- C:\WINDOWS\Tasks
2015-07-16 12:52:13 ----D---- C:\WINDOWS\system32\Tasks
2015-07-16 12:39:08 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-07-16 12:16:29 ----HD---- C:\Program Files\WindowsApps
2015-07-15 10:41:53 ----D---- C:\Program Files (x86)\Google
2015-07-15 10:07:57 ----D---- C:\WINDOWS\system32\catroot2
2015-07-15 10:05:10 ----A---- C:\WINDOWS\system32\wuaext.dll
2015-07-13 23:10:13 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-07-05 12:08:23 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2015-07-03 10:21:09 ----D---- C:\ProgramData\Energy Manager
2015-07-03 08:43:04 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-03-22 678384]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-11-03 39008]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 acpials;@sensorsalsdriver.inf,%kbfiltr.SvcDesc%;ALS Sensor Filter; C:\WINDOWS\System32\drivers\acpials.sys [2014-10-29 9216]
R3 ACPIVPC;@oem61.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-11-03 35600]
R3 ApfiltrService;@oem11.inf,%Filter.SvcDesc%;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2013-07-17 498992]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2013-04-24 1385272]
R3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [2010-05-22 83456]
R3 ibtusb;@oem8.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R) 4.0 + HS Adapter; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2013-06-03 115656]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-04 4185600]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\WINDOWS\system32\DRIVERS\ikbevent.sys [2013-04-16 21048]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\imsevent.sys [2013-04-16 21048]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-26 3462616]
R3 IntcDAud;@oem57.inf,%IntcDAud.SvcDesc%;Intel(R) Zvuk pre obrazovky; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-05-17 442368]
R3 ISCT;@oem55.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\WINDOWS\System32\drivers\ISCTD64.sys [2013-04-16 46568]
R3 iwdbus;@oem69.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-09-26 27032]
R3 MarvinBus;@oem71.inf,%MarvinBus.SVCDESC%;Pinnacle Marvin Bus 64; C:\WINDOWS\System32\drivers\MarvinBus64.sys [2005-09-23 261120]
R3 MEIx64;@oem65.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-05-09 99800]
R3 NETwNe64;@oem63.inf,%NIC_Service_DispName_WIN8_64%;Intel(R) Wireless Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew02.sys [2013-10-08 3648480]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTL8168;@oem10.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-04-10 801864]
R3 rtsuvc;@oem30.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-08-03 8873688]
R3 SensorsAlsDriver;@sensorsalsdriver.inf,%WudfSensorsAlsDriverDisplayName%;UMDF Reflector service for SensorsAlsDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [2014-10-29 226304]
R3 usb3Hub;@oem60.inf,%usb3Hub.SVCDESC%;UoIP Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [2013-05-29 206744]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S1 MpKslf339b538;MpKslf339b538; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7C514631-EE90-4747-ADC9-AFF5C28A6A0B}\MpKslf339b538.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [2010-03-20 114560]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
S3 GeneStor;@oem9.inf,%GENESTOR.SvcDesc%;Genesys Logic Storage Driver; C:\WINDOWS\System32\drivers\GeneStor.sys [2013-02-22 79592]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2010-03-25 120704]
S3 intaud_WaveExtensible;@oem68.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-09-26 39320]
S3 USBAAPL64;@oem89.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2013-06-24 1132920]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2013-04-24 1153400]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 BrcmSetSecurity;BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [2013-05-29 101536]
R2 DCService.exe;DCService.exe; C:\ProgramData\DatacardService\DCService.exe [2010-05-08 229376]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-08-28 626416]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-06-24 136704]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-03-22 15344]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-05-09 131544]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-06-26 156616]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2013-04-16 182760]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-05-09 169432]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2015-03-06 584632]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-05-09 368600]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-08-28 149744]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-11-03 68368]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-02-13 643880]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-04 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15 107848]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-23 136120]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184]
S3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28 174368]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-08-28 273136]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-02-19 835776]

-----------------EOF-----------------

Re: kontrola logu, podozrenie na vírusi

Napsal: 27 črc 2015 15:54
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\system32\WPRO_41_2001woem.tmp

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: kontrola logu, podozrenie na vírusi

Napsal: 27 črc 2015 18:14
od jardo
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jaro at 2015-07-27 19:13:32
Microsoft Windows 8.1
System drive C: has 352 GB (81%) free of 433 GB
Total RAM: 3816 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:13:41, on 27.7.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\SysWOW64\UMonit64.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jaro.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKLM\..\RunOnce: [OTM] "C:\Users\Miriam\Desktop\OTM.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\RunOnce: [Report] \AdwCleaner\AdwCleaner[S0].txt
O4 - HKUS\S-1-5-21-1687900140-1392591902-1605008389-1006\..\Run: [Dropbox Update] "C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c (User 'Miriam')
O4 - S-1-5-21-1687900140-1392591902-1605008389-1006 Startup: Dropbox.lnk = Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Miriam')
O4 - S-1-5-21-1687900140-1392591902-1605008389-1006 User Startup: Dropbox.lnk = Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Miriam')
O4 - Global Startup: iSCTsysTray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrcmSetSecurity - Intel - C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DCService.exe - Unknown owner - C:\ProgramData\DatacardService\DCService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 9740 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe 525353310544
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\ProgramData\DatacardService\DCService.exe
dashost.exe {fa052f8f-92e8-4a5d-99db0271a80b1d0b}
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-75a9d51a-cdab-4a1a-9f1d-4234b28affb0 -SystemEventPortName:HostProcess-2dd6193b-1a61-413b-9caf-bb517153bf2a -IoCancelEventPortName:HostProcess-69628565-d23d-4972-9dbd-9a0547bc12bc -NonStateChangingEventPortName:HostProcess-ac7daf00-532d-4a81-9879-640fb3861067 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:15c8f4ad-a9f6-4aad-81af-1685515edfef -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\Explorer.EXE
"C:\ProgramData\DatacardService\DCSHelper.exe"
taskeng.exe {86E2A65A-480E-4863-9914-1347011DDAA5}
taskhostex.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
/QuitInfo:0000000000000BD4;0000000000000BD8;
/loadhooks /Parent:0000000000001148
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 584 588 596 65536 592
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Apoint2K\Apoint.exe"
"C:\Windows\RTFTrack.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"Apntex.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files\Apoint2K\HidFind.exe"
"C:\WINDOWS\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Windows\SysWOW64\UMonit64.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.mystartsearch.com/?type=sc&t ... XXW3713NNH
"C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe"
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe"
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5404.0.462006113\2108016086" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3316 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Miriam\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5404.3.433201841\381896208" --font-cache-shared-handle=3772 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5404.5.1484013845\407708482" --font-cache-shared-handle=4636 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/*ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5404.6.1925930182\1704353808" --font-cache-shared-handle=5084 /prefetch:673131151

C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe -Embedding
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding

"C:\Users\Miriam\Downloads\RSITx64.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1687900140-1392591902-1605008389-1006Core.job - C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-1687900140-1392591902-1605008389-1006UA.job - C:\Users\Miriam\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-06-26 13626072]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-06-05 1311304]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-10-04 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-10-04 771032]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-10-04 769496]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2013-07-17 687448]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-08-03 6340312]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2013-05-21 7830328]
"UMonit64"=C:\windows\SysWOW64\UMonit64.exe [2013-02-28 40960]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2013-11-03 15792112]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2013-11-03 101360]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-02-13 169768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-07-18 53753984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Report"=\AdwCleaner\AdwCleaner[S0].txt [2015-07-26 15778]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
""= []
"HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-08-04 30264]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"OTM"=C:\Users\Miriam\Desktop\OTM.exe [2015-07-27 522240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
iSCTsysTray.lnk - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-10-04 623616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-27 19:11:42 ----A---- C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2015-07-27 19:08:26 ----D---- C:\_OTM
2015-07-26 13:38:22 ----D---- C:\AdwCleaner
2015-07-26 12:37:12 ----D---- C:\Program Files\trend micro
2015-07-26 12:37:11 ----D---- C:\rsit
2015-07-25 18:35:05 ----D---- C:\unetbtin
2015-07-24 18:05:52 ----RD---- C:\Program Files (x86)\Skype
2015-07-24 18:05:43 ----D---- C:\ProgramData\Skype
2015-07-22 12:32:36 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-07-22 12:32:35 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-16 12:11:10 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-16 12:11:08 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-16 12:11:08 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-16 12:11:07 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-16 12:11:06 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2015-07-16 12:11:03 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-16 12:11:00 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-07-16 12:10:59 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2015-07-16 12:10:59 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-16 12:10:57 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-07-16 12:10:53 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-16 12:10:52 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-16 12:10:51 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-16 12:10:48 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-16 12:10:47 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-16 12:10:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-16 12:10:45 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-16 12:10:44 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-07-16 12:10:43 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-16 12:10:42 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-16 12:10:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2015-07-16 12:10:19 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2015-07-15 10:10:53 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 10:10:52 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-07-15 10:10:51 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 10:10:50 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2015-07-15 10:10:50 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 10:10:49 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 10:10:49 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 10:10:48 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 10:10:47 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-15 10:10:47 ----A---- C:\WINDOWS\system32\certcli.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 10:10:42 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 10:10:40 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 10:10:38 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-07-15 10:10:32 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 10:10:31 ----A---- C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 10:10:30 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 10:10:29 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-07-15 10:10:29 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 10:10:28 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 10:10:27 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 10:10:23 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 10:10:19 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-07-15 10:09:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 10:09:49 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-07-15 10:09:45 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 10:09:45 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 10:09:44 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-07-15 10:09:44 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-07-15 10:09:26 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 10:09:25 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 10:09:23 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-07-15 10:09:22 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 10:09:21 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 10:09:19 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-07-15 10:09:19 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-07-15 10:09:18 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-07-15 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2015-07-15 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-07-15 10:09:16 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-07-15 10:09:16 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-07-15 10:09:15 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 10:09:14 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-07-15 10:09:12 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 10:09:12 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 10:09:11 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 10:09:10 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-07-15 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-07-15 10:09:09 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 10:09:08 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-07-15 10:08:45 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 10:08:44 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-07-15 10:08:43 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 10:08:42 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2015-07-15 10:08:35 ----A---- C:\WINDOWS\system32\apphelp.dll

======List of files/folders modified in the last 1 month======

2015-07-27 19:13:23 ----D---- C:\WINDOWS\Temp
2015-07-27 19:13:20 ----D---- C:\WINDOWS\Prefetch
2015-07-27 19:11:42 ----RD---- C:\WINDOWS\System32
2015-07-27 19:08:28 ----D---- C:\WINDOWS\Tasks
2015-07-27 19:02:00 ----D---- C:\WINDOWS\system32\sru
2015-07-27 13:58:03 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-27 07:39:11 ----SHD---- C:\WINDOWS\Installer
2015-07-27 07:34:48 ----D---- C:\WINDOWS\system32\catroot
2015-07-27 07:31:08 ----D---- C:\WINDOWS\system32\config
2015-07-26 13:40:46 ----HD---- C:\ProgramData
2015-07-26 13:40:45 ----RD---- C:\Program Files (x86)
2015-07-26 12:37:12 ----RD---- C:\Program Files
2015-07-25 12:01:34 ----D---- C:\WINDOWS\Inf
2015-07-25 12:01:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-25 07:05:20 ----SD---- C:\WINDOWS\system32\GWX
2015-07-24 18:06:00 ----D---- C:\Program Files (x86)\Common Files
2015-07-24 09:46:29 ----D---- C:\WINDOWS\rescache
2015-07-24 07:53:56 ----SHD---- C:\System Volume Information
2015-07-24 06:37:34 ----D---- C:\WINDOWS\AppReadiness
2015-07-23 09:24:55 ----A---- C:\IFRToolLog.txt
2015-07-23 09:19:16 ----D---- C:\WINDOWS\WinSxS
2015-07-22 15:00:36 ----D---- C:\WINDOWS\SysWOW64
2015-07-22 14:25:50 ----D---- C:\WINDOWS\CbsTemp
2015-07-22 04:24:43 ----D---- C:\WINDOWS\system32\DriverStore
2015-07-18 22:25:32 ----D---- C:\WINDOWS\apppatch
2015-07-18 22:25:31 ----D---- C:\WINDOWS\system32\sk-SK
2015-07-18 22:25:30 ----D---- C:\WINDOWS\system32\drivers
2015-07-18 22:25:29 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-18 22:25:28 ----RD---- C:\WINDOWS\ToastData
2015-07-18 22:25:26 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-18 22:25:26 ----D---- C:\WINDOWS\system32\wbem
2015-07-18 22:25:26 ----D---- C:\WINDOWS\system32\appraiser
2015-07-18 22:25:25 ----D---- C:\WINDOWS\WinStore
2015-07-18 22:25:24 ----D---- C:\Program Files\Internet Explorer
2015-07-18 22:25:24 ----D---- C:\Program Files (x86)\Internet Explorer
2015-07-18 18:48:37 ----D---- C:\ProgramData\Microsoft Help
2015-07-18 18:29:09 ----D---- C:\WINDOWS\system32\MRT
2015-07-16 12:52:13 ----D---- C:\WINDOWS\system32\Tasks
2015-07-16 12:39:08 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-07-16 12:16:29 ----HD---- C:\Program Files\WindowsApps
2015-07-15 10:41:53 ----D---- C:\Program Files (x86)\Google
2015-07-15 10:07:57 ----D---- C:\WINDOWS\system32\catroot2
2015-07-15 10:05:10 ----A---- C:\WINDOWS\system32\wuaext.dll
2015-07-13 23:10:13 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-07-05 12:08:23 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2015-07-03 10:21:09 ----D---- C:\ProgramData\Energy Manager
2015-07-03 08:43:04 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-03-22 678384]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-11-03 39008]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 acpials;@sensorsalsdriver.inf,%kbfiltr.SvcDesc%;ALS Sensor Filter; C:\WINDOWS\System32\drivers\acpials.sys [2014-10-29 9216]
R3 ACPIVPC;@oem61.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-11-03 35600]
R3 ApfiltrService;@oem11.inf,%Filter.SvcDesc%;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2013-07-17 498992]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2013-04-24 1385272]
R3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [2010-05-22 83456]
R3 ibtusb;@oem8.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R) 4.0 + HS Adapter; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2013-06-03 115656]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-04 4185600]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\WINDOWS\system32\DRIVERS\ikbevent.sys [2013-04-16 21048]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\imsevent.sys [2013-04-16 21048]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-26 3462616]
R3 IntcDAud;@oem57.inf,%IntcDAud.SvcDesc%;Intel(R) Zvuk pre obrazovky; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-05-17 442368]
R3 ISCT;@oem55.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\WINDOWS\System32\drivers\ISCTD64.sys [2013-04-16 46568]
R3 iwdbus;@oem69.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-09-26 27032]
R3 MarvinBus;@oem71.inf,%MarvinBus.SVCDESC%;Pinnacle Marvin Bus 64; C:\WINDOWS\System32\drivers\MarvinBus64.sys [2005-09-23 261120]
R3 MEIx64;@oem65.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-05-09 99800]
R3 NETwNe64;@oem63.inf,%NIC_Service_DispName_WIN8_64%;Intel(R) Wireless Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew02.sys [2013-10-08 3648480]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTL8168;@oem10.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-04-10 801864]
R3 rtsuvc;@oem30.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-08-03 8873688]
R3 SensorsAlsDriver;@sensorsalsdriver.inf,%WudfSensorsAlsDriverDisplayName%;UMDF Reflector service for SensorsAlsDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [2014-10-29 226304]
R3 usb3Hub;@oem60.inf,%usb3Hub.SVCDESC%;UoIP Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [2013-05-29 206744]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S1 MpKslf339b538;MpKslf339b538; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7C514631-EE90-4747-ADC9-AFF5C28A6A0B}\MpKslf339b538.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [2010-03-20 114560]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
S3 GeneStor;@oem9.inf,%GENESTOR.SvcDesc%;Genesys Logic Storage Driver; C:\WINDOWS\System32\drivers\GeneStor.sys [2013-02-22 79592]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2010-03-25 120704]
S3 intaud_WaveExtensible;@oem68.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-09-26 39320]
S3 USBAAPL64;@oem89.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-20 77128]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2013-06-24 1132920]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2013-04-24 1153400]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 BrcmSetSecurity;BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [2013-05-29 101536]
R2 DCService.exe;DCService.exe; C:\ProgramData\DatacardService\DCService.exe [2010-05-08 229376]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-08-28 626416]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-06-24 136704]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-03-22 15344]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-05-09 131544]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-06-26 156616]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2013-04-16 182760]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-05-09 169432]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2015-03-06 584632]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-05-09 368600]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-08-28 149744]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-11-03 68368]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-02-13 643880]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-04 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15 107848]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-23 136120]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184]
S3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28 174368]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-08-28 273136]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-02-19 835776]

-----------------EOF-----------------

Re: kontrola logu, podozrenie na vírusi

Napsal: 27 črc 2015 18:59
od Rudy
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. PC by již měl být čistý.

Re: kontrola logu, podozrenie na vírusi

Napsal: 27 črc 2015 19:17
od jardo
super, velmi pekne dakujem :)

Re: kontrola logu, podozrenie na vírusi

Napsal: 27 črc 2015 20:16
od Rudy
Nemáte zač! :)