Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Prosím o kontrolu logu

#1 Příspěvek od darkane »

Připadá mi pomalejší net.
zde je log
děkuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by darkane at 2015-08-17 19:57:43
Microsoft Windows 8.1
System drive C: has 192 GB (39%) free of 486 GB
Total RAM: 8081 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:57:45, on 17. 8. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\trend micro\darkane.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [EPSONE57E5F (Epson Stylus SX430)] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE /FU "C:\Users\DARKA_~1\AppData\Local\Temp\E_S5E8.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Global Startup: SRS PC Sound.lnk = C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - DefaultPrefix: http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text=
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Micro Star SCM - Micro-Star International Co., Ltd. - C:\Program Files (x86)\System Control Manager\MSIService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10968 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {a5ab1d34-f417-4d4e-a8fa1551a447fa1f}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
taskeng.exe {512B999B-B159-4BBF-AAE9-B1ED93B262F1}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\System Control Manager\MSIService.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
ngservice.exe pipeserver
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0df713a2-f104-44e3-828b-15211e68ecf4 -SystemEventPortName:HostProcess-047f0b98-ebf5-4e9d-a463-e6b6c4e92976 -IoCancelEventPortName:HostProcess-235f2d2b-004d-4f53-8db1-d0d7f90b7621 -NonStateChangingEventPortName:HostProcess-4a2e481d-cc92-42d5-97ca-969605351b91 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:38473788-6153-464d-b6a9-2bd20252a792 -DeviceGroupId:WpdFsGroup
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f62e2474-d92a-4af4-9afd-ab642cfa0bf5 -SystemEventPortName:HostProcess-730416e6-b737-468b-a450-b067b14fb2bd -IoCancelEventPortName:HostProcess-cf86c2aa-b8bd-4e0f-9463-9f503443ffad -NonStateChangingEventPortName:HostProcess-87a9509d-0ff7-4fcb-b2f2-49abf0b0d79d -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:be42b07f-4139-4cb1-b257-f87c11a38ca9 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 568 572 580 65536 576

C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\darka_000\Desktop\RSITx64.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\searchplugins\
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-22 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-19 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-22 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-19 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-11-28 2859344]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-11-28 13192848]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2012-08-27 11577216]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"Radio Manager"=C:\Program Files (x86)\SCM\Radio Manager.exe [2012-09-13 403848]
"SCM"=C:\Program Files (x86)\SCM\SCM.exe [2012-09-13 399776]
"Služba Acronis Scheduler2"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2014-05-30 383992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EPSONE57E5F (Epson Stylus SX430)"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [2011-01-20 232448]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-07-17 8418584]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-09-13 56128]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2012-05-23 502328]
"MGSysCtrl"=C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe [2009-11-06 2244608]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-12 5515496]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SRS PC Sound.lnk - C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll, C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-17 19:55:50 ----D---- C:\rsit
2015-08-17 19:43:03 ----A---- C:\AdwCleaner[C8].txt
2015-08-17 19:36:26 ----A---- C:\AdwCleaner[S9].txt
2015-08-17 19:33:40 ----A---- C:\AdwCleaner[S8].txt
2015-08-16 16:18:47 ----D---- C:\Program Files (x86)\RehanFX
2015-08-16 16:18:47 ----D---- C:\Program Files (x86)\Movie Maker
2015-08-12 06:56:27 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 06:56:27 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 06:34:54 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\invagent.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\devinv.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-08-12 06:34:52 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-08-12 06:34:37 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-08-12 06:34:37 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-08-12 06:34:37 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-08-12 06:33:59 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-08-12 06:33:57 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-08-12 06:33:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-08-12 06:33:53 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-08-12 06:33:52 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-08-12 06:33:51 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-08-12 06:33:51 ----A---- C:\WINDOWS\system32\wininet.dll
2015-08-12 06:33:51 ----A---- C:\WINDOWS\system32\ieui.dll
2015-08-12 06:33:50 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-08-12 06:33:50 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-08-12 06:33:50 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\system32\jscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-08-12 06:32:56 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2015-08-12 06:32:56 ----A---- C:\WINDOWS\system32\WebClnt.dll
2015-08-12 06:32:55 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2015-08-12 06:32:55 ----A---- C:\WINDOWS\system32\davclnt.dll
2015-08-12 06:32:43 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 06:32:42 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-08-12 06:32:42 ----A---- C:\WINDOWS\system32\sysmain.dll
2015-08-12 06:32:42 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-08-12 06:32:42 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2015-08-12 06:31:22 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 06:31:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2015-08-12 06:31:05 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2015-08-12 06:31:05 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2015-08-12 06:31:05 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2015-08-12 06:30:48 ----A---- C:\WINDOWS\system32\csrsrv.dll
2015-08-12 06:30:48 ----A---- C:\WINDOWS\system32\basesrv.dll
2015-08-12 06:30:47 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2015-08-12 06:30:47 ----A---- C:\WINDOWS\system32\netcfgx.dll
2015-08-12 06:30:47 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2015-08-12 06:30:46 ----A---- C:\WINDOWS\SYSWOW64\notepad.exe
2015-08-12 06:30:46 ----A---- C:\WINDOWS\system32\notepad.exe
2015-08-12 06:30:46 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-08-12 06:30:46 ----A---- C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-08-12 06:30:46 ----A---- C:\WINDOWS\notepad.exe
2015-08-12 06:30:45 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2015-08-12 06:30:45 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2015-08-12 06:30:45 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\system32\mstscax.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2015-08-12 06:30:43 ----A---- C:\WINDOWS\system32\win32k.sys
2015-08-12 06:30:43 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-08-12 06:30:43 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2015-08-12 06:30:42 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-05 12:41:02 ----D---- C:\Users\darka_000\AppData\Roaming\Solveig Multimedia
2015-08-05 12:35:34 ----D---- C:\Users\darka_000\AppData\Roaming\HyperCam
2015-08-03 07:15:07 ----RD---- C:\Program Files (x86)\Skype
2015-07-27 15:08:48 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-07-27 15:08:46 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2015-07-26 15:01:54 ----HD---- C:\_acestream_cache_
2015-07-26 14:58:06 ----D---- C:\Users\darka_000\AppData\Roaming\.ACEStream
2015-07-26 14:57:04 ----D---- C:\Users\darka_000\AppData\Roaming\ACEStream

======List of files/folders modified in the last 1 month======

2015-08-17 19:57:44 ----D---- C:\Program Files\trend micro
2015-08-17 19:52:51 ----RD---- C:\WINDOWS\System32
2015-08-17 19:52:51 ----D---- C:\WINDOWS\Inf
2015-08-17 19:52:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-17 19:51:47 ----D---- C:\WINDOWS\Minidump
2015-08-17 19:51:47 ----D---- C:\WINDOWS\debug
2015-08-17 19:51:47 ----D---- C:\Windows
2015-08-17 19:51:46 ----D---- C:\WINDOWS\Temp
2015-08-17 19:51:03 ----D---- C:\WINDOWS\Prefetch
2015-08-17 19:47:54 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-08-17 19:00:01 ----D---- C:\WINDOWS\system32\sru
2015-08-17 18:52:31 ----D---- C:\Users\darka_000\AppData\Roaming\Skype
2015-08-17 08:38:53 ----D---- C:\WINDOWS\Microsoft.NET
2015-08-17 08:24:01 ----D---- C:\WINDOWS\system32\config
2015-08-16 16:28:43 ----SHD---- C:\WINDOWS\Installer
2015-08-16 16:18:47 ----RD---- C:\Program Files (x86)
2015-08-16 16:18:31 ----SHD---- C:\System Volume Information
2015-08-16 09:24:44 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-16 09:24:37 ----D---- C:\WINDOWS\WinSxS
2015-08-15 10:07:31 ----D---- C:\Users\darka_000\AppData\Roaming\Mp3tag
2015-08-15 09:40:07 ----D---- C:\WINDOWS\AppReadiness
2015-08-15 09:40:06 ----HD---- C:\Program Files\WindowsApps
2015-08-13 19:12:00 ----D---- C:\WINDOWS\rescache
2015-08-12 17:45:23 ----D---- C:\WINDOWS\SysWOW64
2015-08-12 17:43:12 ----RSD---- C:\WINDOWS\assembly
2015-08-12 13:41:51 ----D---- C:\WINDOWS\system32\drivers
2015-08-12 13:41:51 ----D---- C:\Program Files\Windows Defender
2015-08-12 13:41:51 ----D---- C:\Program Files (x86)\Windows Defender
2015-08-12 13:41:48 ----D---- C:\Program Files\Internet Explorer
2015-08-12 13:41:48 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-12 13:41:47 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2015-08-12 06:58:15 ----D---- C:\ProgramData\Microsoft Help
2015-08-12 06:58:15 ----A---- C:\WINDOWS\win.ini
2015-08-12 06:56:23 ----D---- C:\WINDOWS\CbsTemp
2015-08-12 06:54:04 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-12 06:54:04 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 06:53:16 ----D---- C:\WINDOWS\system32\MRT
2015-08-12 06:46:21 ----A---- C:\WINDOWS\system32\MRT.exe
2015-08-12 06:42:47 ----SD---- C:\WINDOWS\system32\CompatTel
2015-08-12 06:42:47 ----D---- C:\WINDOWS\system32\appraiser
2015-08-12 06:42:47 ----D---- C:\WINDOWS\apppatch
2015-08-12 06:25:39 ----D---- C:\WINDOWS\system32\catroot2
2015-08-11 07:53:04 ----D---- C:\WINDOWS\system32\catroot
2015-08-10 07:41:12 ----D---- C:\WINDOWS\Tasks
2015-08-09 21:53:24 ----D---- C:\AdwCleaner
2015-08-09 18:38:59 ----D---- C:\WINDOWS\SoftwareDistribution
2015-08-09 17:01:43 ----D---- C:\Program Files\CCleaner
2015-08-09 13:47:42 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-09 13:47:36 ----D---- C:\WINDOWS\Acronis
2015-08-09 13:09:15 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-08 15:55:07 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-08-07 10:22:56 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-05 12:35:24 ----D---- C:\Program Files (x86)\Common Files
2015-08-03 07:15:13 ----D---- C:\ProgramData\Skype
2015-08-02 15:13:25 ----D---- C:\WINDOWS\system32\wbem
2015-08-01 21:07:16 ----D---- C:\WINDOWS\system32\NDF
2015-07-29 11:18:02 ----DC---- C:\WINDOWS\Panther
2015-07-29 11:08:06 ----HD---- C:\$Windows.~BT
2015-07-27 11:36:59 ----D---- C:\Program Files (x86)\Mp3tag
2015-07-26 14:59:11 ----D---- C:\Users\darka_000\AppData\Roaming\vlc
2015-07-25 18:05:20 ----SD---- C:\WINDOWS\system32\GWX
2015-07-19 18:55:21 ----D---- C:\WINDOWS\system32\Tasks
2015-07-19 14:53:45 ----D---- C:\ProgramData\Oracle
2015-07-19 14:52:57 ----D---- C:\Program Files (x86)\Java
2015-07-19 14:52:15 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2015-07-18 17:39:18 ----D---- C:\Users\darka_000\AppData\Roaming\dvdcss

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-04-22 65736]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-04-22 272248]
R0 fltsrv;Acronis Storage Filter Management; C:\WINDOWS\system32\DRIVERS\fltsrv.sys [2015-02-18 118560]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-02 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2015-02-18 276256]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-04-22 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-04-22 1047320]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-06-27 442264]
R1 dtsoftbus01;@oem19.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2015-01-19 283200]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-04-22 29168]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-04-22 89944]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-04-22 137288]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-22 273824]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-08-29 857472]
R3 ETD;@oem7.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-11-28 295760]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-08-06 68136]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-11-28 4142864]
R3 IntcDAud;@oem25.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-11-28 342528]
R3 iwdbus;@oem34.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;@oem27.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-11-28 62784]
R3 NETwNe64;@netwew00.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows 8; C:\WINDOWS\system32\DRIVERS\NETwew00.sys [2013-07-08 3344352]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2010-01-18 14136]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-09-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 intaud_WaveExtensible;@oem33.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 ipadtst;ipadtst; \??\C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [2011-12-12 17936]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBSTOR;@oem4.inf,%RSUSBSTOR.SvcDesc%;RtsUStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUStor.sys [2012-11-28 252048]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 ssudserd;@oem22.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys [2014-01-22 206080]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-04-22 343336]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-08-27 1112000]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-09-06 1124288]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-09-02 14904]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-11-28 165760]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-11-28 276864]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files (x86)\System Control Manager\MSIService.exe [2009-07-09 160768]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2012-05-23 142904]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-30 920864]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2012-11-28 201360]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-11-28 364416]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-22 4034896]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-07 148136]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Vidim tam MBAM. Pokud jste nedelal, udelejte sken. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

:???: Jestli jste tuto kontrolu delal, nasel neco?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#3 Příspěvek od darkane »

Proveden test MBAM.
zde výsledek :arrow:

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 18. 8. 2015
Čas skenování: 20:43
Protokol: log.txt
Správce: Ano

Verze: 2.1.8.1057
Databáze malwaru: v2015.08.18.07
Databáze rootkitů: v2015.08.16.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: darkane

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 740441
Uplynulý čas: 2 hod, 58 min, 6 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 1
PUP.Optional.OutBrowse.A, HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\SOFTWARE\OB, , [410ede2c8407072f12b202b2788cff01],

Hodnoty registru: 5
PUP.Optional.OutBrowse.A, HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\SOFTWARE\OB|monitype6, 1/3/15 23:21:50, , [410ede2c8407072f12b202b2788cff01]
PUP.Optional.OutBrowse.A, HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\SOFTWARE\OB|monitype10, 1/3/15 23:23:12, , [5bf456b4c0cbac8a9c2807ad679d8779]
PUP.Optional.OutBrowse.A, HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\SOFTWARE\OB|monitype19, 1/3/15 23:23:12, , [5bf4c248c5c6d462c9fbc3f1fc0849b7]
PUP.Optional.OutBrowse.A, HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\SOFTWARE\OB|monitype20, 1/3/15 23:23:12, , [27289179cebdf73f8e3606ae28dc5da3]
PUP.Optional.OutBrowse.A, HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\SOFTWARE\OB|monitype22, 1/3/15 23:23:12, , [e966ec1e840737ffedd74272c83ce818]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 1
PUP.Optional.Bundle, C:\Users\darka_000\Downloads\adobeacrobatreader-lista-centrumcz.exe, , [afa09b6f1f6cf64040365942907146ba],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu

#4 Příspěvek od Márty84 »

Nalezy nechte odstranit. Po odstraneni a restartu pc udelejte novy test (tentokrat staci jen Sken hrozeb - bude rychlejsi). Napiste vysledek a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#5 Příspěvek od darkane »

Zde je nový výsledek po skenu. Zdá se být čisto, ale zatuhl mi dvakrát ntb a reagoval jen na ctrl-alt-delete. Ani Metro(dlaždice) bez odezvy. Napadlo mě dát starší bod obnovení.


Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 19. 8. 2015
Čas skenování: 9:06
Protokol: log2.txt
Správce: Ano

Verze: 2.1.8.1057
Databáze malwaru: v2015.08.19.01
Databáze rootkitů: v2015.08.16.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: darkane

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 451254
Uplynulý čas: 32 min, 35 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 0
(Nenalezeny žádné škodlivé položky)

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu

#6 Příspěvek od Márty84 »

darkane píše:Napadlo mě dát starší bod obnovení.
No pokud to udelate, nema smysl pokracovat v cisteni, protoze se to tam zas vrati :arcisit:


:arrow: MBAM muzete odinstalovat.

:???: K zatuhnuti doslo pri jake cinnosti?

:arrow: V logu vidim ADWCleaner. Znovu ho pouzijte a dejte jeho log.



:arrow: Pak dejte novy log z RSIT

a k tomu

:arrow: Dejte logy podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach :)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#7 Příspěvek od darkane »

MBAM - odinstalován
K zatuhnutí došlo při pokusu vypnout ntb klasickým spůsobem v Metru a podruhé, když skončil MBAM sken a byl otevřen ještě půl hoďky na ploše.

:arrow: FRST64 log v příloze

Zde log AdwCleaner

# AdwCleaner v5.000 - Logfile created 19/08/2015 at 10:27:40
# Updated 14/08/2015 by Xplode
# Database : 2015-08-18.2 [Server]
# Operating system : Windows 8.1 (x64)
# Username : darkane - DARKANE
# Running from : C:\Users\darka_000\Desktop\adwcleaner_5.000.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >
[-] [C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : >

*************************

:: Proxy settings cleared
:: Winsock settings cleared

*************************

C:\AdwCleaner[C9].txt - [2513 octets] - [19/08/2015 10:27:40]
C:\AdwCleaner[S10].txt - [2454 octets] - [19/08/2015 10:21:24]

########## EOF - C:\AdwCleaner[C9].txt - [2640 octets] ##########



log RSIT

Logfile of random's system information tool 1.10 (written by random/random)
Run by darkane at 2015-08-19 10:34:17
Microsoft Windows 8.1
System drive C: has 194 GB (40%) free of 486 GB
Total RAM: 8081 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:18, on 19. 8. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\trend micro\darkane.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [EPSONE57E5F (Epson Stylus SX430)] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE /FU "C:\Users\DARKA_~1\AppData\Local\Temp\E_S5E8.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\darka_000\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\darka_000\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - Global Startup: SRS PC Sound.lnk = C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - DefaultPrefix: http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text=
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Micro Star SCM - Micro-Star International Co., Ltd. - C:\Program Files (x86)\System Control Manager\MSIService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11393 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
taskhostex.exe
taskeng.exe {84979772-2E5D-45A8-B4FC-EBFC5639E319}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {f65b4b6e-140e-47a0-9dab1d92d3747a51}
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" /rep_new
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\System Control Manager\MSIService.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
"C:\WINDOWS\system32\GWX\GWX.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
igfxEM.exe
igfxHK.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0ac287d9-17be-424c-889c-289ee5f4a2e8 -SystemEventPortName:HostProcess-5286be2e-2e5f-40e6-94d3-8eb7225b0072 -IoCancelEventPortName:HostProcess-43ae65d9-9310-4fe8-baab-54f2f4497007 -NonStateChangingEventPortName:HostProcess-80832649-7541-4695-bfe4-6663dc0fea38 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:92e2d137-b4bd-4d9a-a12a-3c2f35eafef4 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
ngservice.exe pipeserver
"C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\WINDOWS\system32\vssvc.exe
C:\WINDOWS\System32\svchost.exe -k swprv
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"

C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\darka_000\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=Quicksearch_12454&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\searchplugins\
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-22 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-19 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-22 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-19 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-11-28 2859344]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-11-28 13192848]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2012-08-27 11577216]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"Radio Manager"=C:\Program Files (x86)\SCM\Radio Manager.exe [2012-09-13 403848]
"SCM"=C:\Program Files (x86)\SCM\SCM.exe [2012-09-13 399776]
"Služba Acronis Scheduler2"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2014-05-30 383992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EPSONE57E5F (Epson Stylus SX430)"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [2011-01-20 232448]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"cz.seznam.software.autoupdate"=C:\Users\darka_000\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\darka_000\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-09-13 56128]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2012-05-23 502328]
"MGSysCtrl"=C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe [2009-11-06 2244608]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-12 5515496]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SRS PC Sound.lnk - C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll, C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-19 10:30:10 ----D---- C:\rsit
2015-08-19 10:27:40 ----A---- C:\AdwCleaner[C9].txt
2015-08-19 10:21:24 ----A---- C:\AdwCleaner[S10].txt
2015-08-19 10:21:18 ----D---- C:\AdwCleaner
2015-08-19 05:15:03 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-08-19 05:15:02 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-08-18 17:10:43 ----D---- C:\Program Files (x86)\Seznam.cz
2015-08-16 16:18:47 ----D---- C:\Program Files (x86)\RehanFX
2015-08-16 16:18:47 ----D---- C:\Program Files (x86)\Movie Maker
2015-08-12 06:56:27 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 06:56:27 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 06:34:54 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\invagent.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\devinv.dll
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-08-12 06:34:53 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-08-12 06:34:52 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-08-12 06:34:38 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-08-12 06:34:37 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-08-12 06:34:37 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-08-12 06:34:37 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-08-12 06:33:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-08-12 06:33:53 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-08-12 06:33:52 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-08-12 06:33:51 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-08-12 06:33:51 ----A---- C:\WINDOWS\system32\wininet.dll
2015-08-12 06:33:51 ----A---- C:\WINDOWS\system32\ieui.dll
2015-08-12 06:33:50 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-08-12 06:33:50 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-08-12 06:33:50 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-08-12 06:33:49 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-08-12 06:33:48 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\system32\jscript.dll
2015-08-12 06:33:47 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-08-12 06:32:56 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2015-08-12 06:32:56 ----A---- C:\WINDOWS\system32\WebClnt.dll
2015-08-12 06:32:55 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2015-08-12 06:32:55 ----A---- C:\WINDOWS\system32\davclnt.dll
2015-08-12 06:32:43 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 06:32:42 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-08-12 06:32:42 ----A---- C:\WINDOWS\system32\sysmain.dll
2015-08-12 06:32:42 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-08-12 06:32:42 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2015-08-12 06:31:22 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 06:31:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2015-08-12 06:31:05 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2015-08-12 06:31:05 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2015-08-12 06:31:05 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2015-08-12 06:30:48 ----A---- C:\WINDOWS\system32\csrsrv.dll
2015-08-12 06:30:48 ----A---- C:\WINDOWS\system32\basesrv.dll
2015-08-12 06:30:47 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2015-08-12 06:30:47 ----A---- C:\WINDOWS\system32\netcfgx.dll
2015-08-12 06:30:47 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2015-08-12 06:30:46 ----A---- C:\WINDOWS\SYSWOW64\notepad.exe
2015-08-12 06:30:46 ----A---- C:\WINDOWS\system32\notepad.exe
2015-08-12 06:30:46 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-08-12 06:30:46 ----A---- C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-08-12 06:30:46 ----A---- C:\WINDOWS\notepad.exe
2015-08-12 06:30:45 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2015-08-12 06:30:45 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2015-08-12 06:30:45 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\system32\mstscax.dll
2015-08-12 06:30:44 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2015-08-12 06:30:43 ----A---- C:\WINDOWS\system32\win32k.sys
2015-08-12 06:30:43 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-08-12 06:30:43 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2015-08-12 06:30:42 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-08-12 06:30:42 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-05 12:41:02 ----D---- C:\Users\darka_000\AppData\Roaming\Solveig Multimedia
2015-08-05 12:35:34 ----D---- C:\Users\darka_000\AppData\Roaming\HyperCam
2015-08-03 07:15:07 ----RD---- C:\Program Files (x86)\Skype
2015-07-27 15:08:48 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-07-27 15:08:46 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2015-07-26 15:01:54 ----HD---- C:\_acestream_cache_
2015-07-26 14:58:06 ----D---- C:\Users\darka_000\AppData\Roaming\.ACEStream
2015-07-26 14:57:04 ----D---- C:\Users\darka_000\AppData\Roaming\ACEStream

======List of files/folders modified in the last 1 month======

2015-08-19 10:34:17 ----D---- C:\Program Files\trend micro
2015-08-19 10:33:35 ----RD---- C:\WINDOWS\System32
2015-08-19 10:33:35 ----D---- C:\WINDOWS\Inf
2015-08-19 10:33:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-19 10:31:15 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-08-19 10:29:53 ----D---- C:\WINDOWS\Prefetch
2015-08-19 10:29:31 ----D---- C:\WINDOWS\Temp
2015-08-19 10:22:41 ----D---- C:\Users\darka_000\AppData\Roaming\Skype
2015-08-19 10:20:44 ----RD---- C:\Program Files (x86)
2015-08-19 10:20:42 ----D---- C:\WINDOWS\system32\drivers
2015-08-19 10:00:01 ----D---- C:\WINDOWS\system32\sru
2015-08-19 07:07:45 ----D---- C:\WINDOWS\Microsoft.NET
2015-08-19 05:22:45 ----D---- C:\WINDOWS\system32\config
2015-08-19 05:15:51 ----D---- C:\WINDOWS\WinSxS
2015-08-19 05:15:51 ----D---- C:\WINDOWS\CbsTemp
2015-08-19 05:15:50 ----D---- C:\WINDOWS\SysWOW64
2015-08-19 00:06:39 ----D---- C:\Windows
2015-08-19 00:06:34 ----D---- C:\WINDOWS\de-DE
2015-08-18 20:30:55 ----SHD---- C:\WINDOWS\Installer
2015-08-18 20:30:50 ----D---- C:\WINDOWS\system32\Tasks
2015-08-18 20:30:49 ----D---- C:\Program Files (x86)\Adobe
2015-08-18 20:30:00 ----SHD---- C:\System Volume Information
2015-08-18 17:12:23 ----D---- C:\Users\darka_000\AppData\Roaming\Adobe
2015-08-18 17:10:46 ----D---- C:\Users\darka_000\AppData\Roaming\Seznam.cz
2015-08-18 17:07:33 ----D---- C:\ProgramData\Adobe
2015-08-18 10:02:14 ----HD---- C:\Program Files\WindowsApps
2015-08-18 10:02:14 ----D---- C:\WINDOWS\AppReadiness
2015-08-17 21:13:22 ----D---- C:\WINDOWS\system32\NDF
2015-08-17 20:42:42 ----D---- C:\WINDOWS\debug
2015-08-17 19:51:47 ----D---- C:\WINDOWS\Minidump
2015-08-16 09:24:44 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-15 10:07:31 ----D---- C:\Users\darka_000\AppData\Roaming\Mp3tag
2015-08-13 19:12:00 ----D---- C:\WINDOWS\rescache
2015-08-12 17:43:12 ----RSD---- C:\WINDOWS\assembly
2015-08-12 13:41:51 ----D---- C:\Program Files\Windows Defender
2015-08-12 13:41:51 ----D---- C:\Program Files (x86)\Windows Defender
2015-08-12 13:41:48 ----D---- C:\Program Files\Internet Explorer
2015-08-12 13:41:48 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-12 13:41:47 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2015-08-12 06:58:15 ----D---- C:\ProgramData\Microsoft Help
2015-08-12 06:58:15 ----A---- C:\WINDOWS\win.ini
2015-08-12 06:54:04 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-12 06:54:04 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-08-12 06:53:16 ----D---- C:\WINDOWS\system32\MRT
2015-08-12 06:46:21 ----A---- C:\WINDOWS\system32\MRT.exe
2015-08-12 06:42:47 ----SD---- C:\WINDOWS\system32\CompatTel
2015-08-12 06:42:47 ----D---- C:\WINDOWS\system32\appraiser
2015-08-12 06:42:47 ----D---- C:\WINDOWS\apppatch
2015-08-12 06:25:39 ----D---- C:\WINDOWS\system32\catroot2
2015-08-11 07:53:04 ----D---- C:\WINDOWS\system32\catroot
2015-08-10 07:41:12 ----D---- C:\WINDOWS\Tasks
2015-08-09 18:38:59 ----D---- C:\WINDOWS\SoftwareDistribution
2015-08-09 17:01:43 ----D---- C:\Program Files\CCleaner
2015-08-09 13:47:42 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-09 13:47:36 ----D---- C:\WINDOWS\Acronis
2015-08-08 15:55:08 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-08-07 10:22:56 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-05 12:35:24 ----D---- C:\Program Files (x86)\Common Files
2015-08-03 07:15:13 ----D---- C:\ProgramData\Skype
2015-08-02 15:13:25 ----D---- C:\WINDOWS\system32\wbem
2015-07-29 11:18:02 ----DC---- C:\WINDOWS\Panther
2015-07-29 11:08:06 ----HD---- C:\$Windows.~BT
2015-07-27 11:36:59 ----D---- C:\Program Files (x86)\Mp3tag
2015-07-26 14:59:11 ----D---- C:\Users\darka_000\AppData\Roaming\vlc
2015-07-25 18:05:20 ----SD---- C:\WINDOWS\system32\GWX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-04-22 65736]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-04-22 272248]
R0 fltsrv;Acronis Storage Filter Management; C:\WINDOWS\system32\DRIVERS\fltsrv.sys [2015-02-18 118560]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-02 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2015-02-18 276256]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-04-22 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-04-22 1047320]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-06-27 442264]
R1 dtsoftbus01;@oem19.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2015-01-19 283200]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-04-22 29168]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-04-22 89944]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-04-22 137288]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-22 273824]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-08-29 857472]
R3 ETD;@oem7.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-11-28 295760]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-08-06 68136]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-11-28 4142864]
R3 IntcDAud;@oem25.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-11-28 342528]
R3 iwdbus;@oem34.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MEIx64;@oem27.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-11-28 62784]
R3 NETwNe64;@netwew00.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows 8; C:\WINDOWS\system32\DRIVERS\NETwew00.sys [2013-07-08 3344352]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2010-01-18 14136]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-09-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 intaud_WaveExtensible;@oem33.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 ipadtst;ipadtst; \??\C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [2011-12-12 17936]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBSTOR;@oem4.inf,%RSUSBSTOR.SvcDesc%;RtsUStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUStor.sys [2012-11-28 252048]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 ssudserd;@oem22.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys [2014-01-22 206080]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-04-22 343336]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-08-27 1112000]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-09-06 1124288]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-09-02 14904]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-11-28 165760]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-11-28 276864]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files (x86)\System Control Manager\MSIService.exe [2009-07-09 160768]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2012-05-23 142904]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-30 920864]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2012-11-28 201360]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-11-28 364416]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-22 4034896]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-07 148136]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------
Přílohy
FRST.rar
(28.36 KiB) Staženo 62 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu

#8 Příspěvek od Márty84 »

:arrow: Bude potreba odinstalovat chrome, vcetne nastaveni a profilu a smazat jeho pripadne zbytky. Pak jej znovu nainstalovat. Je v nem problem, ktery nejde odstranit skriptem.
Pokud nechcete prijit o zalozky, muzete si je zazalohovat pomoci ChromeBackup http://www.stahuj.centrum.cz/internet_a ... me-backup/



:arrow: Napiste mi velikost adresare plochy (C:\Users\darka_000\Plocha)


:arrow: Stahnete crystal disk info http://sourceforge.jp/projects/crystald ... 5_0_0.zip/
Spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)


:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\darka_000\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\darka_000\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

URLSearchHook: [S-1-5-21-2802680610-4246973846-2910803817-1002] ATTENTION => Default URLSearchHook is missing
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
DefaultPrefix-x32: => http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=8749493e63b4c989ac18f2836710354d&text= <==== ATTENTION

S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: {E2596254-7192-4BA9-88FC-A32415E14B09} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2015-07-07] ()

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#9 Příspěvek od darkane »

Takže :) zjistil jsem, že na ploše se mi povaluje 18gb, o čemž jsem nevěděl. Důvěřoval jsem a vysvětloval, že na plochu velké obsahy nepatří. Je to marný je to marný. Provedu čistku.

zde krystaldisk

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.0 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 8 [6.2 Build 9200] (x64)
Date : 2015/08/19 13:42:19

-- Controller Map ----------------------------------------------------------
+ Intel(R) 7 Series Chipset Family SATA AHCI Controller [ATA]
- WDC WD7500BPVT-22HXZT3
- TSSTcorp CDDVDW SN-208AB
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) WDC WD7500BPVT-22HXZT3 : 750,1 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(1) WDC WD7500BPVT-22HXZT3
----------------------------------------------------------------------------
Model : WDC WD7500BPVT-22HXZT3
Firmware : 01.01A01
Serial Number : WD-WX41E72VJ428
Disk Size : 750,1 GB (8,4/137,4/750,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1465149168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/300
Power On Hours : 9808 hod.
Power On Count : 1936 krát
Temparature : 40 C (104 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0060h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 183 178 _21 000000000729 Čas na roztočení ploten
04 _57 _57 __0 00000000A9D2 Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _87 _87 __0 000000002650 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _99 _99 __0 000000000790 Počet cyklů zapnutí zařízení
BF __1 __1 __0 0000000005DF Počet udalostí zaznamenaných otřesovým senzorem
C0 200 200 __0 000000000030 Počet vypnutí disku
C1 __1 __1 __0 000000220B58 Počet cyklů načítání/vymazání
C2 107 _92 __0 000000000028 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 200 200 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 003F 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 4537 4537 3256 4A34 3238
020: 0000 4000 0032 3031 2E30 3031 3031 5744 4320 5744
030: 3735 3030 4250 5654 2D32 585A 585A 5433 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 003F 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 1F06 1F06 0000 004C 0048
080: 01FE 0000 746B 7D09 6123 BC09 BC09 6123 207F 0053
090: 0053 0060 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 66F0 5754 0000 0000 0000 6003 6003 0000 5001 4EE6
110: 5835 06E8 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 16FE 012D 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 7035 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 101E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 B6A5



a zde fixlog

Fix result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by darkane (2015-08-19 13:46:55) Run:1
Running from C:\Users\darka_000\Desktop
Loaded Profiles: darkane (Available Profiles: UpdatusUser & darkane & Guest)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\darka_000\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\darka_000\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

URLSearchHook: [S-1-5-21-2802680610-4246973846-2910803817-1002] ATTENTION => Default URLSearchHook is missing
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - No File
DefaultPrefix-x32: => http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text= <==== ATTENTION

S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01]

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: {E2596254-7192-4BA9-88FC-A32415E14B09} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe [2015-07-07] ()

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => value removed successfully
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => value removed successfully
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully.
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully.
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
Could not restore Default URLSearchHook.
"HKCR\PROTOCOLS\Handler\skypec2c" => key removed successfully
HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix\\Default => value restored successfully
gupdate => service removed successfully
SkypeUpdate => service removed successfully
AdobeFlashPlayerUpdateSvc => service removed successfully
gupdatem => service removed successfully
SwitchBoard => service removed successfully
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E2596254-7192-4BA9-88FC-A32415E14B09}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2596254-7192-4BA9-88FC-A32415E14B09}" => key removed successfully
C:\WINDOWS\System32\Tasks\AutoKMS => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => key removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 449.4 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 13:48:09 ====

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu

#10 Příspěvek od Márty84 »

darkane píše:Takže :) zjistil jsem, že na ploše se mi povaluje 18gb, o čemž jsem nevěděl. Důvěřoval jsem a vysvětloval, že na plochu velké obsahy nepatří. Je to marný je to marný. Provedu čistku.
Potvrzuje se zname rceni - duveruj, ale proveruj :-D



:!: Vsechny tyto programy - vcetne pripadne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)

:arrow:
vyosek píše: :arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remove disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner http://www.filehippo.com/download_ccleaner a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!
(Pokud je v pc vice uzivatelskych uctu, pouzijte program i v nich)

:arrow: Defragmentujte disk(y) (SSD Disky ne!)
Stahnete program Defraggler https://www.piriform.com/defraggler/download/standard
Pri instalaci opet pozor na toolbar a dalsi nesmysly.
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak to s pc vypada. Nastala nejaka zmena?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#11 Příspěvek od darkane »

Uklidil jsem po čištění i na ploše, kde mám zhuba necelých 100 mega.
Vysmejčeno ccleanerem a momentálně defragmentuji. Jak koukám, bude to trvat docela dlouho.
:arrow: Je jasné zlepšení při použití internetu.
Mockrá děkuji za pomoc :worship: :idea:

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu

#12 Příspěvek od Márty84 »

Nemate zac! :)

Jsem rad, ze se to zlepsilo :happy: No a kdyby neco, staci se ozvat, budem tady ;-)

Mejte se a treba zase nekdy :bye:

:closed:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno