Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu RSIT

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
wormik
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 17 srp 2015 10:55

Prosím o kontrolu RSIT

#1 Příspěvek od wormik »

Dobrý deň, v poslednom čase mám problém s ethernet portom, skúšal som vypnúť zapnúť, zmeniť nastavenia, reinštalovať drivre ale nič nepomohlo.
Taktiež som už rok nekontroloval PC ohľadom vírusov, ale používam antivírus a som opatrný tak snáď je to v poriadku a ten port by s vírusom nemusel súvisieť...
Ďakujem za kontrolu

Logfile of random's system information tool 1.10 (written by random/random)
Run by Roman at 2015-08-17 11:57:55
Microsoft Windows 8.1
System drive C: has 415 GB (46%) free of 911 GB
Total RAM: 7986 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:57:59, on 17.8.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\UMonit64.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe
C:\Users\Roman\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera_crashreporter.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
C:\Program Files\trend micro\Roman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\Run: [MiPhoneManager] "C:\Users\Roman\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe"
O4 - Global Startup: SteelSeries Engine 3.lnk = C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.line6.net
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing)
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESL Wire Helper Service (EslWireHelper) - Unknown owner - C:\Program Files\EslWire\service\WireHelperSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ExpressCache - Condusiv Technologies - C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 14102 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe 43018448784
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\EslWire\service\WireHelperSvc.exe"
dashost.exe {b86e18c2-d43f-43e5-915f34bf1fe2202b}
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe"
C:\WINDOWS\SysWOW64\srvany.exe
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ad8a8381-44aa-401c-9db4-b56d03993baa -SystemEventPortName:HostProcess-49afa151-e398-4a8a-9ae5-75cecc71e396 -IoCancelEventPortName:HostProcess-78cb24d6-fdc7-4bd5-bef0-0339470010e5 -NonStateChangingEventPortName:HostProcess-6e9d8f03-367c-44b6-90e4-8a3a6aede12f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a607ebec-93e8-432f-a514-8ba372d04db7 -DeviceGroupId:WudfDefaultDevicePool
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\system32\MRT.exe /EHB /Q
C:\WINDOWS\system32\svchost.exe -k netsvcs
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 94a89845-f8ab-4f48-bdd7-c78d963e67ce
\??\C:\WINDOWS\system32\conhost.exe 0x4

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\WINDOWS\system32\nvvsvc.exe -session
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Windows\RTFTrack.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Windows\SysWOW64\UMonit64.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
"C:\Users\Roman\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe"
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Roman\AppData\Local\Steam\htmlcache" -steampid 872 -buildid 1439401440 -steamid "0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=3224 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --disable-gpu-compositing --channel="3224.0.1232218313\71461187" /prefetch:673131151
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe

"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --alt-high-dpi-setting=96 --ran-launcher
"C:\Program Files (x86)\Opera\31.0.1889.99\opera_crashreporter.exe" --alt-high-dpi-setting=96 --ran-launcher --crash-reporter-parent-id=7876
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --type=gpu-process --channel="7876.0.1835538514\1312417586" --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,23,46,56 --gpu-vendor-id=0x10de --gpu-device-id=0x0fe4 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.5560 --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=120 --disable-direct-npapi-requests --disable-touch-adjustment --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --ppapi-flash-path="C:\WINDOWS\SysWOW64\Macromed\Flash\pepflashplayer32_18_0_0_232.dll" --ppapi-flash-version=18.0.0.232 --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="7876.2.1513037812\1201171780" /prefetch:673131151
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=120 --disable-direct-npapi-requests --disable-touch-adjustment --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --ppapi-flash-path="C:\WINDOWS\SysWOW64\Macromed\Flash\pepflashplayer32_18_0_0_232.dll" --ppapi-flash-version=18.0.0.232 --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="7876.3.243469689\1929836451" /prefetch:673131151
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=120 --disable-direct-npapi-requests --disable-touch-adjustment --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --ppapi-flash-path="C:\WINDOWS\SysWOW64\Macromed\Flash\pepflashplayer32_18_0_0_232.dll" --ppapi-flash-version=18.0.0.232 --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="7876.4.548727649\1207525163" /prefetch:673131151
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=120 --disable-direct-npapi-requests --disable-touch-adjustment --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=sk --disable-client-side-phishing-detection --ppapi-flash-path="C:\WINDOWS\SysWOW64\Macromed\Flash\pepflashplayer32_18_0_0_232.dll" --ppapi-flash-version=18.0.0.232 --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="7876.5.661646429\1148553690" /prefetch:673131151
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=3224 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --disable-gpu-compositing --channel="3224.12.160355350\1379969537" /prefetch:673131151
"C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=120 --disable-direct-npapi-requests --disable-touch-adjustment --disable-win32k-renderer-lockdown --enable-deferred-image-decoding --lang=sk --disable-client-side-phishing-detection --ppapi-flash-path="C:\WINDOWS\SysWOW64\Macromed\Flash\pepflashplayer32_18_0_0_232.dll" --ppapi-flash-version=18.0.0.232 --with-feature:hi-resolution-thumbnails=off --with-feature:hidpi-speed-dial-tiles=off --crash-reporter-pid=5460 --enable-mse-h264-support --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="7876.9.589505570\3779247" /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe179_ Global\UsGthrCtrlFltPipeMssGthrPipe179 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\WmiApSrv.exe
"C:\Users\Roman\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player PPAPI Notifier.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe -check pepperplugin
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-884764461-3326907717-3377673253-1002Core1d0c24c68f82b7a.job - C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 551848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-07-14 2335960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 212904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-05-17 2891592]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-05-28 13545032]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-05-20 1308232]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2013-03-06 6346312]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-04-30 36352]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2013-04-12 7770936]
"UMonit64"=C:\windows\SysWOW64\UMonit64.exe [2013-04-09 40960]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-09-15 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-09-29 17097200]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-09-29 193008]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-07-24 2634896]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2015-07-24 1710568]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"Dropbox Update"=C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16 134512]
"MiPhoneManager"=C:\Users\Roman\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [2015-07-19 146224]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2013-03-09 95192]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-31 43816]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-07 6109776]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-09-01 152392]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2014-12-13 3838800]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SteelSeries Engine 3.lnk - C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"PromptOnSecureDesktop"=0
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux1"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux2"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-17 11:57:55 ----D---- C:\rsit
2015-08-17 11:57:55 ----D---- C:\Program Files\trend micro
2015-08-17 03:30:42 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2015-08-17 03:30:27 ----D---- C:\ProgramData\Malwarebytes
2015-08-17 03:30:27 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-17 03:30:27 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2015-08-17 03:30:27 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2015-08-17 03:30:27 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2015-08-14 13:35:19 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2015-08-14 13:33:28 ----D---- C:\WINDOWS\LastGood
2015-08-14 13:31:56 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2015-08-14 13:31:56 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2015-08-14 13:31:56 ----A---- C:\WINDOWS\system32\nvopencl.dll
2015-08-14 13:31:56 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2015-08-14 13:31:55 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2015-08-14 13:31:55 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2015-08-14 13:31:55 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2015-08-14 13:31:55 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2015-08-14 13:31:55 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2015-08-14 13:31:54 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2015-08-14 13:31:54 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2015-08-14 13:31:54 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\system32\nvdispgenco6435560.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\system32\nvdispco6435560.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2015-08-14 13:31:53 ----A---- C:\WINDOWS\system32\nvcuda.dll
2015-08-14 13:31:48 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2015-08-14 13:31:48 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2015-08-12 22:18:58 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 22:18:58 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wups2.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wups.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-08-12 13:24:12 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-08-12 13:24:11 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-08-12 13:24:11 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-08-12 13:24:11 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-08-12 13:24:11 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-08-12 13:24:11 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-08-12 13:24:11 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-08-12 13:23:28 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-08-12 13:23:26 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-08-12 13:23:25 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-08-12 13:23:24 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-08-12 13:23:24 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-08-12 13:23:23 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-08-12 13:23:23 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-08-12 13:23:23 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-08-12 13:23:23 ----A---- C:\WINDOWS\system32\wininet.dll
2015-08-12 13:23:23 ----A---- C:\WINDOWS\system32\ieui.dll
2015-08-12 13:23:22 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-08-12 13:23:22 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-08-12 13:23:22 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 13:23:22 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\jscript.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-08-12 13:23:21 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-08-12 13:23:19 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2015-08-12 13:23:19 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2015-08-12 13:23:19 ----A---- C:\WINDOWS\system32\WebClnt.dll
2015-08-12 13:23:19 ----A---- C:\WINDOWS\system32\davclnt.dll
2015-08-12 13:23:17 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-08-12 13:23:17 ----A---- C:\WINDOWS\system32\sysmain.dll
2015-08-12 13:23:17 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 13:23:17 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-08-12 13:23:17 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2015-08-12 13:23:15 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2015-08-12 13:23:15 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2015-08-12 13:23:15 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2015-08-12 13:22:58 ----A---- C:\WINDOWS\system32\csrsrv.dll
2015-08-12 13:22:58 ----A---- C:\WINDOWS\system32\basesrv.dll
2015-08-12 13:22:57 ----A---- C:\WINDOWS\SYSWOW64\notepad.exe
2015-08-12 13:22:57 ----A---- C:\WINDOWS\system32\notepad.exe
2015-08-12 13:22:57 ----A---- C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-08-12 13:22:57 ----A---- C:\WINDOWS\notepad.exe
2015-08-12 13:22:56 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2015-08-12 13:22:56 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2015-08-12 13:22:56 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2015-08-12 13:22:56 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-08-12 13:22:56 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-08-12 13:22:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\system32\win32k.sys
2015-08-12 13:22:55 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-08-12 13:22:55 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-10 16:33:02 ----D---- C:\Program Files (x86)\GhostMouse
2015-08-10 16:23:05 ----D---- C:\Users\Roman\AppData\Roaming\asoftech
2015-08-10 16:11:49 ----D---- C:\Program Files (x86)\ReMouse Standard
2015-08-07 12:16:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2015-08-07 12:16:01 ----A---- C:\WINDOWS\avastSS.scr
2015-07-31 22:34:18 ----A---- C:\WINDOWS\system32\nvdispgenco6435362.dll
2015-07-31 22:34:17 ----A---- C:\WINDOWS\system32\nvdispco6435362.dll
2015-07-23 22:01:56 ----D---- C:\ProgramData\boost_interprocess
2015-07-23 22:01:48 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2015-07-23 22:01:48 ----A---- C:\WINDOWS\system32\nvdispgenco6435330.dll
2015-07-23 22:01:48 ----A---- C:\WINDOWS\system32\nvdispco6435330.dll
2015-07-23 22:01:48 ----A---- C:\WINDOWS\system32\drivers\nvhda64v.sys
2015-07-23 21:57:19 ----A---- C:\WINDOWS\SYSWOW64\nvaudcap32v.dll
2015-07-23 21:57:19 ----A---- C:\WINDOWS\system32\drivers\nvvad64v.sys
2015-07-21 23:39:40 ----D---- C:\Program Files (x86)\tightvnc-1.3.10_x86_viewer
2015-07-21 23:33:26 ----A---- C:\Program Files (x86)\putty.exe
2015-07-19 21:48:05 ----D---- C:\ProgramData\Thunder Network
2015-07-19 21:48:00 ----D---- C:\Xiaomi
2015-07-19 21:47:23 ----A---- C:\WINDOWS\system32\WinUSBCoInstaller2.dll
2015-07-19 21:47:23 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2015-07-19 21:47:17 ----D---- C:\Users\Roman\AppData\Roaming\Xiaomi
2015-07-19 21:33:51 ----A---- C:\WINDOWS\SYSWOW64\qcCoInstaller.dll

======List of files/folders modified in the last 1 month======

2015-08-17 11:57:55 ----RD---- C:\Program Files
2015-08-17 11:52:23 ----D---- C:\WINDOWS\Prefetch
2015-08-17 11:40:58 ----D---- C:\Program Files (x86)\Steam
2015-08-17 11:27:06 ----D---- C:\WINDOWS\system32\config
2015-08-17 11:23:24 ----D---- C:\WINDOWS\Temp
2015-08-17 11:22:20 ----SHD---- C:\WINDOWS\Installer
2015-08-17 11:21:54 ----D---- C:\WINDOWS\Microsoft.NET
2015-08-17 11:00:00 ----D---- C:\WINDOWS\system32\sru
2015-08-17 09:22:59 ----D---- C:\WINDOWS\AppReadiness
2015-08-17 09:21:03 ----D---- C:\WINDOWS\system32\Tasks
2015-08-17 09:15:56 ----SHD---- C:\$Recycle.Bin
2015-08-17 09:14:55 ----RD---- C:\Users
2015-08-17 03:30:42 ----D---- C:\WINDOWS\system32\drivers
2015-08-17 03:30:27 ----RD---- C:\Program Files (x86)
2015-08-17 03:30:27 ----HD---- C:\ProgramData
2015-08-17 03:19:16 ----D---- C:\WINDOWS\Inf
2015-08-17 02:58:55 ----D---- C:\WINDOWS\system32\NDF
2015-08-17 00:18:03 ----RD---- C:\Mp3
2015-08-16 15:57:52 ----D---- C:\Users\Roman\AppData\Roaming\Dropbox
2015-08-15 22:12:13 ----D---- C:\WINDOWS\Tasks
2015-08-15 22:10:55 ----SHD---- C:\System Volume Information
2015-08-14 18:09:30 ----D---- C:\Program Files (x86)\foobar2000
2015-08-14 15:09:30 ----D---- C:\Users\Roman\AppData\Roaming\TS3Client
2015-08-14 13:35:41 ----D---- C:\ProgramData\NVIDIA Corporation
2015-08-14 13:35:31 ----D---- C:\ProgramData\NVIDIA
2015-08-14 13:35:25 ----D---- C:\WINDOWS\SysWOW64
2015-08-14 13:35:17 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-14 13:34:18 ----RD---- C:\WINDOWS\System32
2015-08-14 13:33:28 ----D---- C:\Windows
2015-08-14 00:01:16 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-08-14 00:00:51 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-08-13 20:09:56 ----RSD---- C:\WINDOWS\assembly
2015-08-13 20:09:32 ----D---- C:\ProgramData\Microsoft Help
2015-08-13 12:21:08 ----D---- C:\WINDOWS\rescache
2015-08-13 12:05:25 ----D---- C:\WINDOWS\WinSxS
2015-08-13 01:26:09 ----D---- C:\WINDOWS\system32\drivers\en-US
2015-08-13 01:26:09 ----D---- C:\Program Files\Windows Defender
2015-08-13 01:26:09 ----D---- C:\Program Files (x86)\Windows Defender
2015-08-13 01:26:08 ----D---- C:\WINDOWS\system32\sk-SK
2015-08-13 01:26:08 ----D---- C:\Program Files\Internet Explorer
2015-08-13 01:26:08 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-12 22:19:24 ----D---- C:\WINDOWS\CbsTemp
2015-08-12 22:09:52 ----D---- C:\WINDOWS\system32\MRT
2015-08-12 22:09:49 ----A---- C:\WINDOWS\system32\MRT.exe
2015-08-12 22:05:31 ----A---- C:\WINDOWS\win.ini
2015-08-12 13:25:22 ----HD---- C:\Program Files\WindowsApps
2015-08-12 13:22:10 ----D---- C:\WINDOWS\system32\catroot2
2015-08-11 00:48:42 ----D---- C:\Users\Roman\AppData\Roaming\TeamViewer
2015-08-10 16:25:16 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-08-10 16:11:58 ----D---- C:\WINDOWS\ShellNew
2015-08-08 15:55:07 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-08-07 13:06:30 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2015-08-07 13:06:30 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2015-08-07 13:06:30 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2015-08-07 13:06:30 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2015-08-07 13:06:30 ----A---- C:\WINDOWS\system32\OpenCL.dll
2015-08-07 13:06:30 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2015-08-07 13:06:30 ----A---- C:\WINDOWS\system32\nvapi64.dll
2015-08-07 06:34:33 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2015-08-07 06:34:33 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2015-08-07 06:34:33 ----A---- C:\WINDOWS\system32\nvshext.dll
2015-08-07 06:34:32 ----A---- C:\WINDOWS\SYSWOW64\oemdspif.dll
2015-08-07 06:34:32 ----A---- C:\WINDOWS\system32\nvmctray.dll
2015-08-07 06:34:31 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2015-08-07 06:34:31 ----A---- C:\WINDOWS\system32\nvcpl.dll
2015-08-06 19:08:30 ----D---- C:\Program Files (x86)\Opera
2015-08-06 12:11:12 ----RSD---- C:\WINDOWS\Fonts
2015-08-06 10:53:24 ----D---- C:\WINDOWS\debug
2015-08-06 01:35:40 ----D---- C:\Program Files\CCleaner
2015-08-06 00:57:33 ----RD---- C:\Roman
2015-08-02 18:18:13 ----D---- C:\Program Files (x86)\TeamViewer
2015-07-27 14:52:15 ----D---- C:\ProgramData\Lenovo
2015-07-27 14:51:53 ----D---- C:\Program Files (x86)\Lenovo
2015-07-24 06:21:23 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2015-07-24 06:21:23 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2015-07-24 06:21:14 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2015-07-24 06:21:14 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2015-07-23 06:06:23 ----A---- C:\WINDOWS\SYSWOW64\SET8A45.tmp
2015-07-23 06:06:23 ----A---- C:\WINDOWS\SYSWOW64\SET7A14.tmp
2015-07-23 06:06:23 ----A---- C:\WINDOWS\SYSWOW64\SET686C.tmp
2015-07-23 06:06:23 ----A---- C:\WINDOWS\system32\SET6529.tmp
2015-07-23 06:06:23 ----A---- C:\WINDOWS\system32\SET399C.tmp
2015-07-19 21:23:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-08-07 65224]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-08-07 274808]
R0 ESLWireAC;ESLWireAC; C:\WINDOWS\system32\drivers\ESLWireACD.sys [2015-01-14 105760]
R0 excsd;ExpressCache Storage Filter Driver; C:\WINDOWS\system32\DRIVERS\excsd.sys [2013-07-03 112912]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-04-30 677360]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2013-09-29 39008]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-08-07 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-08-13 1048344]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-08-07 447944]
R1 dtsoftbus01;@oem69.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-07-11 283064]
R1 excfs;ExpressCache File System Filter Driver; C:\WINDOWS\system32\DRIVERS\excfs.sys [2013-07-03 25872]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-08-07 28656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-08-07 90968]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-08-07 150672]
R3 ACPIVPC;@oem59.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2013-09-29 33560]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2013-03-28 1366328]
R3 ETD;@oem5.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-05-16 374536]
R3 ETDSMBus;ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [2013-05-16 22280]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 Hamachi;LogMeIn Hamachi Virtual Miniport); C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [2014-12-13 45112]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2013-01-16 69240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-05-28 3432776]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MEIx64;@oem3.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2013-05-16 64624]
R3 NETwNe64;@oem61.inf,%NIC_Service_DispName_WIN8_64%;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [2013-10-08 3345376]
R3 NVHDA;@oem115.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-06-17 204648]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2015-08-07 11076216]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-07-24 19600]
R3 nvvad_WaveExtensible;@oem113.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2015-07-03 47976]
R3 rtsuvc;@oem49.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2013-03-06 8243144]
R3 sshid;@oem71.inf,%sshid.SvcDesc%;SteelSeries HID Service; C:\WINDOWS\System32\drivers\sshid.sys [2014-08-13 38912]
R3 teamviewervpn;@oem65.inf,%DeviceDescription%;TeamViewer VPN Adapter; C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2013-10-17 35112]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
S3 AMPPAL;Intel(r) Centrino(r) Wireless Bluetooth(r) + High Speed Virtual Adapter; C:\WINDOWS\System32\drivers\AMPPAL.sys [2013-04-11 165344]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 dg_ssudbus;@oem74.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 GeneStor;@oem58.inf,%GENESTOR.SvcDesc%;Genesys Logic Storage Driver; C:\WINDOWS\System32\drivers\GeneStor.sys [2013-03-22 91368]
S3 L6GX;@oem67.inf,%L6GX_DDI.SvcDesc%;Service - Line 6 GX; C:\WINDOWS\System32\Drivers\L6GX64.sys [2014-03-01 772864]
S3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 ssudmdm;@oem85.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 USBAAPL64;@oem1.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2014-07-28 54784]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2014-03-18 121088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-07 146600]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2013-03-19 1124728]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2013-03-19 1161592]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 EslWireHelper;ESL Wire Helper Service; C:\Program Files\EslWire\service\WireHelperSvc.exe [2014-01-28 663056]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-08-28 626416]
R2 ExpressCache;ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [2013-07-03 107792]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-07-24 1155216]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-04-30 15344]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-05-16 131544]
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [2013-04-15 161736]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-05-16 169432]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-07-24 1871504]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2015-07-24 5544592]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2015-08-07 937592]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-08-28 149744]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-08-07 410744]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-06-18 5495056]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [2013-09-29 68368]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-08-12 838336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-18 144200]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-05-16 366552]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-06-18 1871160]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2014-08-02 72704]
S3 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-08-28 43336]
S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-18 144200]
S3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2014-12-13 2530640]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-09-01 640840]
S3 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2014-12-02 417552]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-08-28 273136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2015-07-01 22008]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu RSIT

#2 Příspěvek od altrok »

Krasny den Vam preju :bye:



:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner[Cx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

wormik
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 17 srp 2015 10:55

Re: Prosím o kontrolu RSIT

#3 Příspěvek od wormik »

# AdwCleaner v5.000 - Logfile created 17/08/2015 at 21:00:06
# Updated 14/08/2015 by Xplode
# Database : 2015-08-16.2 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Roman - ROMAN
# Running from : C:\Users\Roman\Desktop\adwcleaner_5.000.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
[-] Key Deleted : HKCU\Software\Softonic
[!] Key Not Deleted : [x64] HKCU\Software\Softonic

***** [ Web browsers ] *****


*************************

:: Proxy settings cleared
:: Winsock settings cleared

*************************

C:\AdwCleaner[C1].txt - [978 octets] - [17/08/2015 21:00:06]
C:\AdwCleaner[S1].txt - [991 octets] - [17/08/2015 20:58:57]

########## EOF - C:\AdwCleaner[C1].txt - [1102 octets] ##########

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu RSIT

#4 Příspěvek od altrok »

:arrow: Dejte log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

wormik
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 17 srp 2015 10:55

Re: Prosím o kontrolu RSIT

#5 Příspěvek od wormik »

Stránku od Pána Vyoseka (pre stiahnutie FRSTLauncheru) mi Avast zablokoval a nechce ma na tú stránku pustiť.

//ospravedlňujem sa, reagoval som skorej ako som dočítal jeho príspevok :D deaktivoval som AV idem spraviť scan

wormik
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 17 srp 2015 10:55

Re: Prosím o kontrolu RSIT

#6 Příspěvek od wormik »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-08-2015
Ran by Roman (administrator) on ROMAN (17-08-2015 22:27:31)
Running from C:\Users\Roman\Desktop
Loaded Profiles: Roman (Available Profiles: Roman & wormi_000 & Romanko)
Platform: Windows 8.1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\EslWire\service\WireHelperSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
() C:\Windows\SysWOW64\srvany.exe
() C:\Windows\KMService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Windows\SysWOW64\UMonit64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2013-05-17] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13545032 2013-05-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6346312 2013-03-06] (Realtek semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-04-30] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [UMonit64] => C:\windows\SysWOW64\UMonit64.exe [40960 2013-04-09] ()
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17097200 2013-09-29] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-09-29] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-24] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-10-31] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-09] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776 2015-08-07] (AVAST Software)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [Dropbox Update] => C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-16] (Dropbox, Inc.)
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [MiPhoneManager] => C:\Users\Roman\AppData\Local\MiPhoneManager\main\MiPhoneHelper.exe [146224 2015-07-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2014-08-05]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Roman\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-07] (AVAST Software)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6E0BABD7-64B9-4A8E-8DB8-C3F58E2B82C4}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BD56C5F7-3DAF-45FB-B62F-A167CBCEB939}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-21] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-07] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-07] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-884764461-3326907717-3377673253-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Roman\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-24] (Unity Technologies ApS)

Chrome:
=======
CHR Profile: C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-25]
CHR Extension: (Google Docs) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-25]
CHR Extension: (Google Drive) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-25]
CHR Extension: (YouTube) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-25]
CHR Extension: (Steam inventory helper) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2015-06-18]
CHR Extension: (Google Search) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-25]
CHR Extension: (Google Sheets) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-25]
CHR Extension: (LoungeDestroyer) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2015-06-18]
CHR Extension: (CS:GO Lounge Bump Bot) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhfkidfnhjcjjamcbdepeohblphlamgk [2015-06-19]
CHR Extension: (Super Auto Refresh) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkhjakkgopekjlempoplnjclgedabddk [2015-08-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-25]
CHR Extension: (Gmail) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-25]

Opera:
=======
OPR Extension: (Gerald) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\niofholngoecgnpgamgbiiijcjlllpge [2014-09-11]
OPR Extension: (Adblock Plus) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2014-09-11]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-08-02] (Adobe Systems) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-07] (AVAST Software)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [663056 2014-01-28] ()
R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [107792 2013-07-03] (Condusiv Technologies)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-24] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-16] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [161736 2013-04-15] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-16] (Intel Corporation)
R2 KMService; C:\WINDOWS\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed]
S3 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-12-02] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-24] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-24] (NVIDIA Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22008 2015-07-01] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-09-29] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-07] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-07] (AVAST Software)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1366328 2013-03-28] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-07-11] (Disc Soft Ltd)
R0 ESLWireAC; C:\Windows\System32\drivers\ESLWireACD.sys [105760 2015-01-14] (<Turtle Entertainment>)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22280 2013-05-16] (ELAN Microelectronic Corp.)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [25872 2013-07-03] (Condusiv Technologies)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [112912 2013-07-03] (Condusiv Technologies)
S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [91368 2013-03-22] (GenesysLogic)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45112 2014-12-13] (LogMeIn Inc.)
S3 L6GX; C:\Windows\System32\Drivers\L6GX64.sys [772864 2014-03-01] (Line 6)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-24] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47976 2015-07-03] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243144 2013-03-06] (Realtek Semiconductor Corp.)
R3 sshid; C:\Windows\System32\drivers\sshid.sys [38912 2014-08-13] (SteelSeries ApS)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-17 22:27 - 2015-08-17 22:27 - 00026104 _____ C:\Users\Roman\Desktop\FRST.txt
2015-08-17 22:26 - 2015-08-17 22:27 - 00000000 ____D C:\FRST
2015-08-17 22:26 - 2015-08-17 22:26 - 00029696 _____ C:\Users\Roman\AppData\Local\MSGBOX.EXE
2015-08-17 22:26 - 2015-08-17 22:26 - 00015327 _____ C:\Users\Roman\Desktop\LM.bat
2015-08-17 22:25 - 2015-08-17 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe
2015-08-17 22:20 - 2015-08-17 22:20 - 02173440 _____ (Farbar) C:\Users\Roman\Desktop\FRST64.exe
2015-08-17 21:32 - 2015-08-17 21:32 - 00000000 ___SH C:\DkHyperbootSync
2015-08-17 21:00 - 2015-08-17 21:00 - 00001179 _____ C:\AdwCleaner[C1].txt
2015-08-17 20:58 - 2015-08-17 20:59 - 00000991 _____ C:\AdwCleaner[S1].txt
2015-08-17 20:58 - 2015-08-17 20:58 - 00000000 ____D C:\AdwCleaner
2015-08-17 20:57 - 2015-08-17 20:57 - 01563648 _____ C:\Users\Roman\Desktop\adwcleaner_5.000.exe
2015-08-17 11:57 - 2015-08-17 11:58 - 00000000 ____D C:\rsit
2015-08-17 11:57 - 2015-08-17 11:57 - 01222144 _____ C:\Users\Roman\Desktop\RSITx64.exe
2015-08-17 11:57 - 2015-08-17 11:57 - 00000000 ____D C:\Program Files\trend micro
2015-08-17 09:35 - 2015-08-17 09:35 - 00000000 ___RD C:\Users\Romanko\OneDrive
2015-08-17 09:35 - 2015-08-17 09:35 - 00000000 ___RD C:\Users\Romanko\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2015-08-17 09:35 - 2015-08-17 03:30 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Romanko\Downloads\mbam-setup-2.1.8.1057.exe
2015-08-17 09:35 - 2015-08-10 16:32 - 00842440 _____ (ghost-mouse.com ) C:\Users\Romanko\Downloads\GhostMouse-Setup.exe
2015-08-17 09:35 - 2015-08-10 16:22 - 03151568 _____ (Asoftech ) C:\Users\Romanko\Downloads\ata.exe
2015-08-17 09:35 - 2015-08-10 16:11 - 01162728 _____ (AutomaticSolution Software ) C:\Users\Romanko\Downloads\ReMouseStandard-Setup.exe
2015-08-17 09:35 - 2015-08-10 16:08 - 12275352 _____ (AutoIt Team) C:\Users\Romanko\Downloads\autoit-v3-setup (1).exe
2015-08-17 09:35 - 2015-08-10 16:03 - 12275352 _____ (AutoIt Team) C:\Users\Romanko\Downloads\autoit-v3-setup.exe
2015-08-17 09:35 - 2015-08-06 20:43 - 02449376 _____ (Megaify Software ) C:\Users\Romanko\Downloads\DriverToolkitInstaller.exe
2015-08-17 09:32 - 2015-08-17 09:35 - 00000000 ___RD C:\Users\Romanko\Dropbox
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ___SD C:\Users\Romanko\Documents\Moje tvary
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\Youcam
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\TmForever
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\Rockstar Games
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\My Games
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\Line 6
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\Lenovo
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\ESL Match Media
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\CyberLink
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\Avatar
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\AutomaticSolution Software
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\Documents\Adobe
2015-08-17 09:32 - 2015-08-17 09:32 - 00000000 ____D C:\Users\Romanko\.android
2015-08-17 09:30 - 2014-08-12 15:47 - 00000000 _____ C:\Users\Romanko\agent.log
2015-08-17 09:21 - 2015-08-17 09:21 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-884764461-3326907717-3377673253-1005
2015-08-17 09:17 - 2015-08-17 09:17 - 00000000 ____D C:\Users\Romanko\AppData\Roaming\Intel Corporation
2015-08-17 09:16 - 2015-08-17 09:16 - 00000000 ____D C:\Users\Romanko\AppData\Roaming\AVAST Software
2015-08-17 09:15 - 2015-08-17 09:18 - 00002295 _____ C:\Users\Romanko\Desktop\Google Chrome.lnk
2015-08-17 09:15 - 2015-08-17 09:17 - 00000000 ____D C:\Users\Romanko\AppData\Local\Packages
2015-08-17 09:15 - 2015-08-17 09:16 - 00000000 ____D C:\Users\Romanko\AppData\Roaming\Adobe
2015-08-17 09:15 - 2015-08-17 09:15 - 00001450 _____ C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-17 09:15 - 2015-08-17 09:15 - 00000000 ____D C:\Users\Romanko\AppData\Roaming\Intel
2015-08-17 09:15 - 2015-08-17 09:15 - 00000000 ____D C:\Users\Romanko\AppData\Local\VirtualStore
2015-08-17 09:15 - 2015-08-17 09:15 - 00000000 ____D C:\Users\Romanko\AppData\Local\NVIDIA
2015-08-17 09:15 - 2015-08-17 09:15 - 00000000 ____D C:\Users\Romanko\AppData\Local\Google
2015-08-17 09:14 - 2015-08-17 09:35 - 00000000 ____D C:\Users\Romanko
2015-08-17 09:14 - 2015-08-17 09:16 - 00001133 _____ C:\Users\Romanko\Desktop\Cyberlink Power2Go.lnk
2015-08-17 09:14 - 2015-08-17 09:14 - 00000020 ___SH C:\Users\Romanko\ntuser.ini
2015-08-17 09:14 - 2015-08-13 01:26 - 00000000 ___RD C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-17 09:14 - 2015-08-12 22:06 - 00000000 ___RD C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-17 09:14 - 2015-04-23 22:38 - 00000000 ___RD C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-17 09:14 - 2014-09-01 14:37 - 00000000 ____D C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-08-17 09:14 - 2014-09-01 14:37 - 00000000 ____D C:\Users\Romanko\AppData\Local\Microsoft Help
2015-08-17 09:14 - 2014-03-18 12:17 - 00000369 _____ C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-17 09:14 - 2014-03-18 12:17 - 00000369 _____ C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-17 09:14 - 2013-08-22 17:36 - 00000000 ____D C:\Users\Romanko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-17 09:14 - 2013-02-05 00:18 - 00000189 _____ C:\Users\Romanko\Desktop\Lenovo Telephony Start Now.url
2015-08-17 09:08 - 2015-08-17 09:08 - 00002295 _____ C:\Users\wormi_000\Desktop\Google Chrome.lnk
2015-08-17 09:08 - 2015-08-17 09:08 - 00001450 _____ C:\Users\wormi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-17 09:08 - 2015-08-17 09:08 - 00000000 ____D C:\Users\wormi_000\AppData\Roaming\Intel
2015-08-17 09:08 - 2015-08-17 09:08 - 00000000 ____D C:\Users\wormi_000\AppData\Roaming\Adobe
2015-08-17 09:08 - 2015-08-17 09:08 - 00000000 ____D C:\Users\wormi_000\AppData\Local\VirtualStore
2015-08-17 09:08 - 2015-08-17 09:08 - 00000000 ____D C:\Users\wormi_000\AppData\Local\Packages
2015-08-17 09:08 - 2015-08-17 09:08 - 00000000 ____D C:\Users\wormi_000\AppData\Local\NVIDIA
2015-08-17 09:08 - 2015-08-17 09:08 - 00000000 ____D C:\Users\wormi_000\AppData\Local\Google
2015-08-17 03:30 - 2015-08-17 21:33 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-08-17 03:30 - 2015-08-17 03:30 - 00001122 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-17 03:30 - 2015-08-17 03:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-17 03:30 - 2015-08-17 03:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-17 03:30 - 2015-08-17 03:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-17 03:30 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-08-17 03:30 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-08-17 03:30 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-08-17 03:29 - 2015-08-17 03:30 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Roman\Downloads\mbam-setup-2.1.8.1057.exe
2015-08-14 13:35 - 2015-08-07 06:22 - 00573048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2015-08-14 13:33 - 2015-08-14 13:33 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-08-14 13:31 - 2015-08-07 13:06 - 42840184 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 37819000 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 22520624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 18540336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 16630096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 15510112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 14928048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 13656016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 12179496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 11076216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-08-14 13:31 - 2015-08-07 13:06 - 02937648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 02624816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 01898104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435560.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 01558832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435560.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 01063216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 01059960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 00985208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 00931448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 00512720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 00421544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 00408184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-08-14 13:31 - 2015-08-07 13:06 - 00364152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2015-08-13 11:45 - 2015-08-17 21:01 - 00000963 _____ C:\WINDOWS\setupact.log
2015-08-13 11:45 - 2015-08-13 11:45 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-13 11:44 - 2015-08-17 21:00 - 00040772 _____ C:\WINDOWS\PFRO.log
2015-08-12 22:18 - 2015-07-30 16:04 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 22:18 - 2015-07-30 15:48 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 21:14 - 2015-08-12 21:14 - 00000000 ____D C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-12 13:24 - 2015-07-19 03:58 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-08-12 13:24 - 2015-07-18 20:51 - 03704320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-12 13:24 - 2015-07-18 20:31 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-08-12 13:24 - 2015-07-18 20:31 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-08-12 13:24 - 2015-07-18 20:31 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-08-12 13:24 - 2015-07-18 20:29 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-08-12 13:24 - 2015-07-18 20:29 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-08-12 13:24 - 2015-07-18 20:29 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-08-12 13:24 - 2015-07-18 20:28 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-08-12 13:24 - 2015-07-18 20:12 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-08-12 13:24 - 2015-07-18 20:10 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-12 13:24 - 2015-07-18 20:09 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-08-12 13:24 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-08-12 13:24 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-08-12 13:24 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-08-12 13:24 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-08-12 13:23 - 2015-07-16 23:14 - 25192448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-12 13:23 - 2015-07-16 22:36 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-08-12 13:23 - 2015-07-16 22:36 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-08-12 13:23 - 2015-07-16 22:35 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-12 13:23 - 2015-07-16 22:26 - 05923328 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-12 13:23 - 2015-07-16 22:23 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-08-12 13:23 - 2015-07-16 22:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-08-12 13:23 - 2015-07-16 22:20 - 19870208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-12 13:23 - 2015-07-16 21:53 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-08-12 13:23 - 2015-07-16 21:51 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-08-12 13:23 - 2015-07-16 21:50 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-08-12 13:23 - 2015-07-16 21:45 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-12 13:23 - 2015-07-16 21:45 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-08-12 13:23 - 2015-07-16 21:41 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-08-12 13:23 - 2015-07-16 21:39 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-08-12 13:23 - 2015-07-16 21:38 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-08-12 13:23 - 2015-07-16 21:36 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-08-12 13:23 - 2015-07-16 21:34 - 14451200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 13:23 - 2015-07-16 21:32 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-08-12 13:23 - 2015-07-16 21:14 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-12 13:23 - 2015-07-16 21:13 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-08-12 13:23 - 2015-07-16 21:12 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-12 13:23 - 2015-07-16 21:12 - 02427904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-12 13:23 - 2015-07-16 21:10 - 12856832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 13:23 - 2015-07-16 21:06 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-08-12 13:23 - 2015-07-16 21:01 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-12 13:23 - 2015-07-16 20:52 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-12 13:23 - 2015-07-16 20:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 13:23 - 2015-07-16 20:42 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-12 13:23 - 2015-07-16 20:38 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-12 13:23 - 2015-07-16 20:37 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-08-12 13:23 - 2015-07-16 02:29 - 07458648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 13:23 - 2015-07-16 02:29 - 01735000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 13:23 - 2015-07-16 02:29 - 00101720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 13:23 - 2015-07-16 02:28 - 01499920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 13:23 - 2015-07-10 19:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 13:23 - 2015-07-07 11:40 - 00270168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-08-12 13:23 - 2015-07-07 11:40 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-08-12 13:23 - 2015-07-07 11:40 - 00044560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-08-12 13:23 - 2015-07-02 00:19 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-08-12 13:23 - 2015-07-02 00:16 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\davclnt.dll
2015-08-12 13:23 - 2015-07-01 23:37 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-08-12 13:23 - 2015-07-01 23:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\davclnt.dll
2015-08-12 13:22 - 2015-07-29 16:37 - 01994752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 13:22 - 2015-07-29 16:30 - 01381888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 13:22 - 2015-07-29 16:23 - 01559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 13:22 - 2015-07-24 20:57 - 04177408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-08-12 13:22 - 2015-07-24 20:57 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 13:22 - 2015-07-24 20:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-12 13:22 - 2015-07-24 19:27 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 13:22 - 2015-07-24 19:23 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-12 13:22 - 2015-07-14 05:22 - 02529880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-08-12 13:22 - 2015-07-14 05:21 - 01901776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-08-12 13:22 - 2015-07-13 21:46 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2015-08-12 13:22 - 2015-07-13 21:45 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2015-08-12 13:22 - 2015-07-10 20:19 - 01101824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 13:22 - 2015-07-10 19:42 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-08-12 13:22 - 2015-07-10 19:14 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2015-08-12 13:22 - 2015-07-10 19:13 - 07032320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2015-08-12 13:22 - 2015-07-10 18:47 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-08-12 13:22 - 2015-07-10 18:31 - 06213120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2015-08-12 13:22 - 2015-07-09 19:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 13:22 - 2015-07-09 19:13 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 13:22 - 2015-07-09 18:30 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 13:22 - 2015-05-12 02:24 - 00536920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-08-10 16:33 - 2015-08-10 16:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GhostMouse
2015-08-10 16:33 - 2015-08-10 16:33 - 00000000 ____D C:\Program Files (x86)\GhostMouse
2015-08-10 16:32 - 2015-08-10 16:32 - 00842440 _____ (ghost-mouse.com ) C:\Users\Roman\Downloads\GhostMouse-Setup.exe
2015-08-10 16:23 - 2015-08-10 16:25 - 00000000 ____D C:\Users\Roman\AppData\Roaming\asoftech
2015-08-10 16:22 - 2015-08-10 16:22 - 03151568 _____ (Asoftech ) C:\Users\Roman\Downloads\ata.exe
2015-08-10 16:11 - 2015-08-10 16:33 - 00000000 ____D C:\Users\Roman\Documents\AutomaticSolution Software
2015-08-10 16:11 - 2015-08-10 16:11 - 01162728 _____ (AutomaticSolution Software ) C:\Users\Roman\Downloads\ReMouseStandard-Setup.exe
2015-08-10 16:11 - 2015-08-10 16:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReMouse Standard
2015-08-10 16:11 - 2015-08-10 16:11 - 00000000 ____D C:\Program Files (x86)\ReMouse Standard
2015-08-10 16:08 - 2015-08-10 16:08 - 12275352 _____ (AutoIt Team) C:\Users\Roman\Downloads\autoit-v3-setup (1).exe
2015-08-10 16:04 - 2015-08-10 16:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3
2015-08-10 16:03 - 2015-08-10 16:03 - 12275352 _____ (AutoIt Team) C:\Users\Roman\Downloads\autoit-v3-setup.exe
2015-08-07 12:16 - 2015-08-07 12:16 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-07 12:16 - 2015-08-07 12:16 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-08-06 20:43 - 2015-08-06 20:43 - 02449376 _____ (Megaify Software ) C:\Users\Roman\Downloads\DriverToolkitInstaller.exe
2015-07-31 22:34 - 2015-07-23 06:06 - 01898128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435362.dll
2015-07-31 22:34 - 2015-07-23 06:06 - 01557648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435362.dll
2015-07-27 14:51 - 2015-07-27 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2015-07-23 22:01 - 2015-07-23 22:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-23 22:01 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435330.dll
2015-07-23 22:01 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435330.dll
2015-07-23 22:01 - 2015-06-17 11:10 - 00204648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2015-07-23 22:01 - 2015-06-17 11:10 - 00040280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2015-07-23 21:57 - 2015-07-03 06:28 - 00065896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2015-07-23 21:57 - 2015-07-03 06:28 - 00047976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2015-07-22 09:37 - 2015-07-22 09:37 - 00000000 ____D C:\Users\Roman\AppData\Local\CEF
2015-07-21 23:39 - 2015-07-22 00:14 - 00000000 ____D C:\Program Files (x86)\tightvnc-1.3.10_x86_viewer
2015-07-21 23:37 - 2015-07-21 23:37 - 00000600 _____ C:\Users\Roman\AppData\Local\PUTTY.RND
2015-07-21 23:33 - 2015-07-21 23:33 - 00524288 _____ (Simon Tatham) C:\Program Files (x86)\putty.exe
2015-07-19 21:48 - 2015-07-19 21:48 - 00000000 ____D C:\Xiaomi
2015-07-19 21:48 - 2015-07-19 21:48 - 00000000 ____D C:\Users\Public\Thunder Network
2015-07-19 21:48 - 2015-07-19 21:48 - 00000000 ____D C:\ProgramData\Thunder Network
2015-07-19 21:47 - 2015-07-19 21:47 - 01721576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01009.dll
2015-07-19 21:47 - 2015-07-19 21:47 - 01002728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinUSBCoInstaller2.dll
2015-07-19 21:47 - 2015-07-19 21:47 - 00000000 ____D C:\Users\Roman\AppData\Roaming\Xiaomi
2015-07-19 21:47 - 2015-07-19 21:47 - 00000000 ____D C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xiaomi
2015-07-19 21:47 - 2015-07-19 21:47 - 00000000 ____D C:\Users\Roman\AppData\Local\MiPhoneManager
2015-07-19 21:36 - 2015-07-19 21:36 - 00002100 _____ C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\MiFlash.lnk
2015-07-19 21:36 - 2015-07-19 21:36 - 00000000 ____D C:\Users\Roman\.android
2015-07-19 21:33 - 2014-05-09 09:54 - 00116736 _____ (XiaoMi Corporation) C:\WINDOWS\SysWOW64\qcCoInstaller.dll
2015-07-19 19:57 - 2015-07-19 19:57 - 00000878 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-884764461-3326907717-3377673253-1002Core1d0c24c68f82b7a.job

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-17 22:22 - 2015-07-07 14:07 - 01635997 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-17 22:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-17 21:30 - 2015-06-18 22:09 - 00000956 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-17 21:13 - 2014-09-01 15:34 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-17 21:02 - 2015-06-18 22:09 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-17 21:01 - 2014-09-01 16:06 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-17 21:01 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-17 21:00 - 2013-09-29 13:34 - 00023040 _____ C:\WINDOWS\system32\VfService.trf
2015-08-17 21:00 - 2013-08-22 15:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-08-17 19:46 - 2014-07-04 22:38 - 00000000 ____D C:\Users\Roman\AppData\Roaming\TS3Client
2015-08-17 15:18 - 2014-07-04 23:10 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-884764461-3326907717-3377673253-1002
2015-08-17 09:22 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-17 02:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-08-17 00:18 - 2014-07-04 23:12 - 00000000 ___RD C:\Mp3
2015-08-16 22:04 - 2014-08-09 10:33 - 00000000 ___RD C:\Users\Roman\Dropbox
2015-08-16 15:57 - 2014-08-09 10:30 - 00000000 ____D C:\Users\Roman\AppData\Roaming\Dropbox
2015-08-16 01:20 - 2015-05-09 15:26 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-08-15 22:12 - 2015-05-09 15:26 - 00003850 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2015-08-14 18:09 - 2014-07-05 18:08 - 00000000 ____D C:\Program Files (x86)\foobar2000
2015-08-14 13:35 - 2014-09-01 14:21 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-14 00:01 - 2014-11-04 09:44 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2015-08-14 00:00 - 2014-11-04 09:43 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner
2015-08-13 20:09 - 2014-07-11 22:44 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 19:18 - 2014-09-25 10:21 - 01048344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-08-13 12:21 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-08-13 11:45 - 2013-08-22 16:44 - 05101400 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-13 01:26 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-13 01:26 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-13 01:26 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sk-SK
2015-08-13 01:26 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-13 01:26 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-12 22:19 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-12 22:18 - 2014-07-05 01:36 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 22:09 - 2014-07-05 01:36 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-12 22:08 - 2014-12-11 14:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-08-12 22:06 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 22:06 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 22:05 - 2012-07-26 07:26 - 00000167 _____ C:\WINDOWS\win.ini
2015-08-11 00:48 - 2014-07-23 12:52 - 00000000 ____D C:\Users\Roman\AppData\Roaming\TeamViewer
2015-08-10 16:25 - 2013-09-29 13:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-08-10 16:11 - 2014-03-18 11:46 - 00000000 ____D C:\WINDOWS\ShellNew
2015-08-08 15:55 - 2013-08-22 17:38 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 15:55 - 2013-08-22 17:38 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-07 17:05 - 2014-08-10 17:30 - 00000132 _____ C:\Users\Roman\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-08-07 13:06 - 2015-03-18 14:21 - 14673920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-08-07 13:06 - 2014-09-01 16:06 - 00112760 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-08-07 13:06 - 2014-09-01 16:06 - 00105080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2015-08-07 13:06 - 2014-09-01 16:05 - 17124832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-08-07 13:06 - 2014-09-01 16:05 - 03518248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-08-07 13:06 - 2013-12-26 19:42 - 12513288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-08-07 13:06 - 2013-12-26 19:42 - 03106384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-08-07 13:06 - 2013-12-26 19:42 - 00033050 _____ C:\WINDOWS\system32\nvinfo.pb
2015-08-07 12:16 - 2014-09-25 10:21 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00150672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-08-07 12:16 - 2014-09-25 10:21 - 00003924 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-07 06:34 - 2014-09-01 16:06 - 06883448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-08-07 06:34 - 2014-09-01 16:06 - 03492144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-08-07 06:34 - 2014-09-01 16:06 - 02558768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-08-07 06:34 - 2014-09-01 16:06 - 00937592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-08-07 06:34 - 2014-09-01 16:06 - 00580728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2015-08-07 06:34 - 2014-09-01 16:06 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-08-07 06:34 - 2014-09-01 16:06 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-08-06 19:08 - 2014-09-11 22:45 - 00003836 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1410468338
2015-08-06 19:08 - 2014-09-11 22:45 - 00000000 ____D C:\Program Files (x86)\Opera
2015-08-06 01:35 - 2014-07-05 02:23 - 00000000 ____D C:\Program Files\CCleaner
2015-08-06 00:57 - 2014-07-04 22:18 - 00000000 ___RD C:\Roman
2015-08-04 21:41 - 2014-12-16 21:50 - 00000000 ____D C:\Users\Roman\AppData\Local\ESL Wire Game Client
2015-08-03 14:09 - 2014-09-07 14:35 - 00000000 ____D C:\Users\Roman\AppData\Local\Deployment
2015-08-03 12:12 - 2014-09-06 21:53 - 05133709 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-08-02 18:18 - 2014-07-06 12:52 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-07-28 15:04 - 2015-02-12 20:02 - 00000991 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-07-28 15:04 - 2015-02-12 20:02 - 00000508 _____ C:\WINDOWS\system32\TeamViewer10_Hooks.log
2015-07-27 14:52 - 2013-09-29 13:32 - 00000000 ____D C:\ProgramData\Lenovo
2015-07-27 14:51 - 2015-05-07 10:19 - 00000000 ____D C:\WINDOWS\System32\Tasks\TVT
2015-07-27 14:51 - 2013-09-29 13:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-07-27 14:51 - 2013-09-29 13:30 - 00000000 ____D C:\Program Files (x86)\Lenovo
2015-07-24 06:21 - 2015-02-10 20:26 - 01756608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2015-07-24 06:21 - 2015-02-10 20:26 - 01710568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2015-07-24 06:21 - 2015-02-10 20:26 - 01423304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2015-07-24 06:21 - 2015-02-10 20:26 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2015-07-19 21:36 - 2014-09-01 14:31 - 00000000 ____D C:\Users\Roman
2015-07-19 21:23 - 2014-03-18 12:08 - 00865408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-18 18:25 - 2015-06-18 22:09 - 00003928 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-18 18:25 - 2015-06-18 22:09 - 00003692 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2014-07-07 18:01 - 2014-07-07 18:03 - 0002157 _____ () C:\Program Files\HWID.lnk
2014-07-07 18:02 - 2015-01-25 20:17 - 0000228 _____ () C:\Program Files\hwmonitorw.ini
2014-07-05 02:58 - 2014-05-05 10:11 - 1913064 _____ (CPUID) C:\Program Files\HWMonitor_x64.exe
2014-07-05 21:58 - 2014-07-06 23:02 - 0000228 _____ () C:\Program Files (x86)\hwmonitorw.ini
2015-07-21 23:33 - 2015-07-21 23:33 - 0524288 _____ (Simon Tatham) C:\Program Files (x86)\putty.exe
2014-07-05 18:05 - 2014-07-05 18:05 - 0017408 _____ () C:\Program Files (x86)\vibrance.exe
2014-08-10 17:30 - 2015-08-07 17:05 - 0000132 _____ () C:\Users\Roman\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-09-16 21:07 - 2014-09-16 21:07 - 0000096 _____ () C:\Users\Roman\AppData\Roaming\settings.xml
2015-08-17 22:26 - 2015-08-17 22:26 - 0029696 _____ () C:\Users\Roman\AppData\Local\MSGBOX.EXE
2015-07-21 23:37 - 2015-07-21 23:37 - 0000600 _____ () C:\Users\Roman\AppData\Local\PUTTY.RND
2014-07-31 00:05 - 2014-07-31 00:05 - 0007614 _____ () C:\Users\Roman\AppData\Local\Resmon.ResmonCfg
2013-09-29 13:32 - 2013-09-29 13:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Roman\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpn_vca3.dll
C:\Users\Roman\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Roman\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Roman\AppData\Local\Temp\nvStInst.exe
C:\Users\Roman\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-17 11:21

==================== End of log ============================
Přílohy
Addition.zip
Addition
(12.43 KiB) Staženo 51 x

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu RSIT

#7 Příspěvek od altrok »

:arrow: Odinstalujte starou a zranitelnou verzi javy Java 8 Update 31 (64-bit) a Java 8 Update 31. Pokud javu potrebujete, pak nainstalujte novou z java.com - pozor na adware pri jeji instalaci http://forum.viry.cz/viewtopic.php?p=1374438#p1374438 . Z hlediska bezpecnosti (exploity) je lepsi ji nemit.

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    File: C:\Program Files (x86)\vibrance.exe
    File: C:\WINDOWS\SysWOW64\srvany.exe
    File: C:\WINDOWS\KMService.exe
    File: %WinDir%\SECOH-QAD.exe
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-24] (NVIDIA Corporation)
    HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
    HKLM\...\Policies\Explorer: [NoFolderOptions] 0
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
    HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
    HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [Dropbox Update] => C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-16] (Dropbox, Inc.)
    
    2015-08-17 22:26 - 2015-08-17 22:26 - 00029696 _____ C:\Users\Roman\AppData\Local\MSGBOX.EXE
    2015-08-17 22:26 - 2015-08-17 22:26 - 00015327 _____ C:\Users\Roman\Desktop\LM.bat
    2015-08-17 22:25 - 2015-08-17 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe
    2015-08-17 21:00 - 2015-08-17 21:00 - 00001179 _____ C:\AdwCleaner[C1].txt
    2015-08-17 20:58 - 2015-08-17 20:59 - 00000991 _____ C:\AdwCleaner[S1].txt
    2015-08-17 20:58 - 2015-08-17 20:58 - 00000000 ____D C:\AdwCleaner
    2015-08-17 20:57 - 2015-08-17 20:57 - 01563648 _____ C:\Users\Roman\Desktop\adwcleaner_5.000.exe
    2015-08-17 11:57 - 2015-08-17 11:58 - 00000000 ____D C:\rsit
    2015-08-17 11:57 - 2015-08-17 11:57 - 01222144 _____ C:\Users\Roman\Desktop\RSITx64.exe
    2015-08-17 11:57 - 2015-08-17 11:57 - 00000000 ____D C:\Program Files\trend micro
    Task: {55945B33-EA89-4648-AF0A-5E2F13729826} - System32\Tasks\{5C69BA86-606B-417F-8FCE-B7DB8B147223} => pcalua.exe -a F:\SETUP.EXE -d F:\ -c -autorun
    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-884764461-3326907717-3377673253-1002Core1d0c24c68f82b7a.job => C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    EmptyTemp:
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

wormik
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 17 srp 2015 10:55

Re: Prosím o kontrolu RSIT

#8 Příspěvek od wormik »

Fix result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by Roman (2015-08-18 12:34:19) Run:1
Running from C:\Users\Roman\Desktop
Loaded Profiles: Roman (Available Profiles: Roman & wormi_000 & Romanko)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
File: C:\Program Files (x86)\vibrance.exe
File: C:\WINDOWS\SysWOW64\srvany.exe
File: C:\WINDOWS\KMService.exe
File: %WinDir%\SECOH-QAD.exe
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-24] (NVIDIA Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\...\Run: [Dropbox Update] => C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-16] (Dropbox, Inc.)

2015-08-17 22:26 - 2015-08-17 22:26 - 00029696 _____ C:\Users\Roman\AppData\Local\MSGBOX.EXE
2015-08-17 22:26 - 2015-08-17 22:26 - 00015327 _____ C:\Users\Roman\Desktop\LM.bat
2015-08-17 22:25 - 2015-08-17 22:25 - 00112640 _____ (forum.viry.cz) C:\Users\Roman\Desktop\FRSTLauncher.exe
2015-08-17 21:00 - 2015-08-17 21:00 - 00001179 _____ C:\AdwCleaner[C1].txt
2015-08-17 20:58 - 2015-08-17 20:59 - 00000991 _____ C:\AdwCleaner[S1].txt
2015-08-17 20:58 - 2015-08-17 20:58 - 00000000 ____D C:\AdwCleaner
2015-08-17 20:57 - 2015-08-17 20:57 - 01563648 _____ C:\Users\Roman\Desktop\adwcleaner_5.000.exe
2015-08-17 11:57 - 2015-08-17 11:58 - 00000000 ____D C:\rsit
2015-08-17 11:57 - 2015-08-17 11:57 - 01222144 _____ C:\Users\Roman\Desktop\RSITx64.exe
2015-08-17 11:57 - 2015-08-17 11:57 - 00000000 ____D C:\Program Files\trend micro
Task: {55945B33-EA89-4648-AF0A-5E2F13729826} - System32\Tasks\{5C69BA86-606B-417F-8FCE-B7DB8B147223} => pcalua.exe -a F:\SETUP.EXE -d F:\ -c -autorun
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-884764461-3326907717-3377673253-1002Core1d0c24c68f82b7a.job => C:\Users\Roman\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
EmptyTemp:
End
*****************

Processes closed successfully.

========================= File: C:\Program Files (x86)\vibrance.exe ========================

File not signed
MD5: 0744A0FAD2D4C3C0762D1505586F3F1F
Creation and modification date: 2014-07-05 18:05 - 2014-07-05 18:05
Size: 0017408
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name:
Description:
File Version:
Product Version:
Copyright:

====== End of File: ======


========================= File: C:\WINDOWS\SysWOW64\srvany.exe ========================

File not signed
MD5: 4635935FC972C582632BF45C26BFCB0E
Creation and modification date: 2014-07-11 22:51 - 2003-04-18 20:06
Size: 0008192
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name:
Description:
File Version:
Product Version:
Copyright:

====== End of File: ======


========================= File: C:\WINDOWS\KMService.exe ========================

File not signed
MD5: 82865FF17BC664C711EFA674759F9991
Creation and modification date: 2014-07-11 22:51 - 2010-04-10 10:03
Size: 0077824
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name:
Description:
File Version:
Product Version:
Copyright:

====== End of File: ======


========================= File: %WinDir%\SECOH-QAD.exe ========================

"%WinDir%\SECOH-QAD.exe" not found.
====== End of File: ======

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NvBackend => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS6ServiceManager => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-884764461-3326907717-3377673253-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Dropbox Update => value removed successfully
C:\Users\Roman\AppData\Local\MSGBOX.EXE => moved successfully.
C:\Users\Roman\Desktop\LM.bat => moved successfully.
"C:\Users\Roman\Desktop\FRSTLauncher.exe" => File/Folder not found.
C:\AdwCleaner[C1].txt => moved successfully.
C:\AdwCleaner[S1].txt => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\Roman\Desktop\adwcleaner_5.000.exe => moved successfully.
C:\rsit => moved successfully.
C:\Users\Roman\Desktop\RSITx64.exe => moved successfully.
C:\Program Files\trend micro => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55945B33-EA89-4648-AF0A-5E2F13729826}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55945B33-EA89-4648-AF0A-5E2F13729826}" => key removed successfully
C:\WINDOWS\System32\Tasks\{5C69BA86-606B-417F-8FCE-B7DB8B147223} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C69BA86-606B-417F-8FCE-B7DB8B147223}" => key removed successfully
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-884764461-3326907717-3377673253-1002Core1d0c24c68f82b7a.job => moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully.
EmptyTemp: => 1.3 GB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 12:34:33 ====

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu RSIT

#9 Příspěvek od altrok »

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    File: C:\WINDOWS\SYSWOW64\SET8A45.tmp
    File: C:\WINDOWS\SYSWOW64\SET7A14.tmp
    File: C:\WINDOWS\SYSWOW64\SET686C.tmp
    File: C:\WINDOWS\system32\SET6529.tmp
    File: C:\WINDOWS\system32\SET399C.tmp
    CMD: dir C:\WINDOWS\SYSWOW64\SET*.tmp
    CMD: dir C:\WINDOWS\system32\SET*.tmp
    CMD: del C:\WINDOWS\SYSWOW64\SET*.tmp
    CMD: del C:\WINDOWS\system32\SET*.tmp
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět