Zdravím,
kamarád mi dnes donesl NTB, že v každém prohlížeči vyskakují reklamní okna.
Prosím o kontrolu logu a pomoc.
Logfile of random's system information tool 1.10 (written by random/random)
Run by radek at 2015-12-26 08:50:30
Microsoft Windows 8.1
System drive C: has 141 GB (74%) free of 190 GB
Total RAM: 3980 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:50:40, on 26. 12. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\WINDOWS\SysWOW64\notepad.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera_crashreporter.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe
C:\Users\radek\Downloads\adwcleaner_5.026.exe
C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe
C:\Program Files\trend micro\radek.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [{A0D73BBC-B2EE-4192-8759-07759BC36F3E}] cmd.exe /C start /D "C:\Users\radek\AppData\Local\Temp" /B {A0D73BBC-B2EE-4192-8759-07759BC36F3E}.cmd
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
--
End of file - 8065 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {b24c3650-b338-49a1-a6e838ced482e512}
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\AVAST Software\Avast\setup\New\instup.exe" /instop:update_packages /wait
"C:\Program Files\AVAST Software\Avast\setup\New_b0108c5\instup.exe" /instop:update_packages /wait
C:\WINDOWS\system32\CompatTelRunner.exe
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun
taskeng.exe {533BFB16-FF10-44CE-A6B1-FC404E19C071}
"C:\Program Files\CCleaner\CCleaner64.exe"
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
"C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-bda3a203-f5cc-4115-ac9a-a64e457dc4f7 -SystemEventPortName:HostProcess-ed5a1b25-599b-4156-a233-5671f64004e7 -IoCancelEventPortName:HostProcess-d9a8f836-7ce5-4fd8-ad0d-9de08680a3e2 -NonStateChangingEventPortName:HostProcess-8dbf205e-4302-45e6-8844-67450cd27425 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:598a8f15-f3f8-409b-8fdd-2dc7d78bb119 -DeviceGroupId:WpdFsGroup
"F:\adwcleaner_5.021.exe"
"F:\adwcleaner_5.021.exe"
"F:\adwcleaner_5.021.exe"
NOTEPAD "C:\Users\radek\AppData\Local\Temp\jrt\TEMP\JRT.txt"
"C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\34.0.2036.25\opera_crashreporter.exe" --ran-launcher --crash-reporter-parent-id=160
"C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe" --type=gpu-process --channel="160.0.1361878087\783847285" --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --crash-reporter-pid=4676 --enable-proprietary-codecs-support-for-web-audio-api --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,29,57 --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.4229 --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --crash-reporter-pid=4676 --enable-proprietary-codecs-support-for-web-audio-api --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --crash-reporter-pid=4676 --enable-proprietary-codecs-support-for-web-audio-api --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="160.2.281174208\1558178773" /prefetch:673131151
"C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --lang=cs --disable-client-side-phishing-detection --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --crash-reporter-pid=4676 --enable-proprietary-codecs-support-for-web-audio-api --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="160.5.1229483734\1268576818" /prefetch:673131151
"C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --crash-reporter-pid=4676 --enable-proprietary-codecs-support-for-web-audio-api --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="160.7.1259423801\1747023656" /prefetch:673131151
"C:\Users\radek\Downloads\adwcleaner_5.026.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Program Files (x86)\Opera\34.0.2036.25\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-direct-npapi-requests --disable-win32k-renderer-lockdown --lang=cs --disable-client-side-phishing-detection --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --crash-reporter-pid=4676 --enable-proprietary-codecs-support-for-web-audio-api --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="160.8.945581439\1306863941" /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Users\radek\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3112277335-540287683-1230770047-1001Core.job - C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3112277335-540287683-1230770047-1001UA.job - C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-04 774144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-10 64640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-20 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2013-10-04 460288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-04 627712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-20 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2013-10-04 386048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-04 774144]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-04 627712]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-09-11 107192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-06-26 40336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSPRP]
C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2012-11-23 3187360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [2012-08-31 3423104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvastUI.exe]
C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-13 6108752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [2012-08-10 764032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtvStack]
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2012-08-10 127616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableS3S4]
c:\windows\temp\DisableS3S464\sethigh.cmd []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-05 144200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2015-06-01 411056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2015-06-01 183216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2015-06-01 453552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-28 91432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-18 13213328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowDesktopAsRun]
C:\Users\radek\AppData\Roaming\StartMenu\desktop.scf [2013-10-20 81]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartMenu]
C:\Users\radek\AppData\Roaming\StartMenu\StartMenu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateAdmin]
C:\Users\radek\AppData\Local\UpdateAdmin\UpdateAdmin.exe /RUN []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk]
C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2009-06-26 258048]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-13 6108752]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"{A0D73BBC-B2EE-4192-8759-07759BC36F3E}"=cmd.exe /C start /D C:\Users\radek\AppData\Local\Temp /B {A0D73BBC-B2EE-4192-8759-07759BC36F3E}.cmd []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2015-06-01 451584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\7BC6AB08.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\7BC6AB08.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-12-26 08:50:30 ----D---- C:\rsit
2015-12-26 08:50:30 ----D---- C:\Program Files\trend micro
2015-12-26 08:35:32 ----A---- C:\WINDOWS\system32\drivers\7BC6AB08.sys
2015-12-26 08:35:12 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_08.35.12_log.txt
2015-12-26 08:34:28 ----D---- C:\zoek_backup
2015-12-26 08:18:48 ----AD---- C:\3590F75ABA9E485486C100C1A9D4FF06ZZZ.ZZ..ZZ.ZZ..Z
2015-12-26 08:14:07 ----D---- C:\Program Files\CCleaner
2015-12-13 09:37:40 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2015-12-13 09:37:11 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2015-12-13 09:37:11 ----A---- C:\WINDOWS\system32\msctf.dll
2015-12-13 09:36:26 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2015-12-13 09:36:26 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2015-12-13 09:36:23 ----A---- C:\WINDOWS\system32\winlogon.exe
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\wininit.exe
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbport.sys
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbehci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbuhci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbohci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbd.sys
2015-12-13 06:32:52 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-13 06:32:48 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-12-13 06:32:48 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-12-13 06:32:47 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-13 06:32:46 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-13 06:32:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-13 06:32:45 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-13 06:32:32 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-13 06:32:32 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-13 06:32:31 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-12-13 06:32:30 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-12-13 06:32:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-13 06:32:29 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-13 06:32:28 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\system32\ieui.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\winresume.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\winload.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-12-13 06:27:11 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-13 06:27:11 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-05 08:13:34 ----D---- C:\Program Files\Common Files\AV
======List of files/folders modified in the last 1 month======
2015-12-26 08:50:30 ----RD---- C:\Program Files
2015-12-26 08:47:49 ----D---- C:\WINDOWS\Prefetch
2015-12-26 08:42:22 ----D---- C:\WINDOWS\Temp
2015-12-26 08:42:18 ----D---- C:\AdwCleaner
2015-12-26 08:41:54 ----SHD---- C:\System Volume Information
2015-12-26 08:35:54 ----RD---- C:\WINDOWS\System32
2015-12-26 08:35:54 ----D---- C:\WINDOWS\Inf
2015-12-26 08:35:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 08:35:32 ----D---- C:\WINDOWS\system32\drivers
2015-12-26 08:34:32 ----D---- C:\WINDOWS\SysWOW64
2015-12-26 08:31:40 ----D---- C:\Windows
2015-12-26 08:18:37 ----DC---- C:\WINDOWS\Panther
2015-12-26 08:18:37 ----D---- C:\WINDOWS\debug
2015-12-26 08:17:12 ----D---- C:\WINDOWS\system32\config
2015-12-26 08:14:10 ----D---- C:\WINDOWS\system32\Tasks
2015-12-26 08:07:25 ----D---- C:\WINDOWS\CbsTemp
2015-12-26 08:07:03 ----D---- C:\WINDOWS\WinSxS
2015-12-26 08:04:11 ----RD---- C:\Program Files (x86)
2015-12-26 08:01:07 ----D---- C:\WINDOWS\system32\sru
2015-12-15 21:22:08 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-12-15 10:57:42 ----D---- C:\WINDOWS\rescache
2015-12-15 10:46:31 ----D---- C:\WINDOWS\system32\catroot2
2015-12-15 10:44:19 ----D---- C:\WINDOWS\Microsoft.NET
2015-12-15 10:37:35 ----RSD---- C:\WINDOWS\assembly
2015-12-13 18:56:55 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-13 18:56:55 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-13 18:56:51 ----D---- C:\Program Files\Internet Explorer
2015-12-13 18:56:51 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-13 18:56:38 ----D---- C:\WINDOWS\system32\DriverStore
2015-12-13 10:05:14 ----D---- C:\WINDOWS\system32\MRT
2015-12-13 09:59:38 ----A---- C:\WINDOWS\system32\MRT.exe
2015-12-13 09:56:28 ----D---- C:\WINDOWS\AppReadiness
2015-12-13 06:18:19 ----D---- C:\Program Files (x86)\Opera
2015-12-05 21:18:55 ----A---- C:\WINDOWS\system32\ServiceFilter.ini
2015-12-05 08:13:34 ----D---- C:\Program Files\Common Files
2015-12-05 08:13:34 ----D---- C:\Program Files (x86)\Common Files
2015-12-05 07:55:40 ----D---- C:\WINDOWS\Tasks
2015-12-01 18:19:27 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-07-20 65224]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-07-20 274808]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 ngvss;ngvss; C:\WINDOWS\system32\drivers\ngvss.sys [2015-07-20 115152]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-07-20 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-11-13 1059656]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-11-13 449992]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2013-11-01 252688]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2013-11-01 126736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-07-20 28656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-07-20 90968]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-07-20 150160]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-07-20 273824]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 AthBTPort;@oem9.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2012-08-10 88728]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 ATP;@oem4.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2013-04-16 65784]
R3 BTATH_A2DP;@oem8.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2012-08-10 344216]
R3 btath_avdt;@oem8.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2012-08-10 114840]
R3 BTATH_BUS;@oem5.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys [2012-08-10 33944]
R3 BTATH_HCRP;@oem11.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2012-08-10 178840]
R3 BTATH_LWFLT;@oem19.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2012-08-10 76952]
R3 BTATH_RCP;@oem15.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2012-08-10 135832]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-01-28 593000]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 HIDSwitch;@oem14.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2012-05-31 21152]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-06-01 5384176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 IntcDAud;@oem30.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-10-26 342528]
R3 kbfiltr;@oem16.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MEIx64;@oem32.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S0 7BC6AB08;7BC6AB08; C:\WINDOWS\system32\drivers\7BC6AB08.sys [2015-12-26 478392]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 FTDIBUS;@oem38.inf,%SvcDesc%;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2014-01-31 94704]
S3 FTSER2K;@oem37.inf,%SvcDesc%;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2014-10-21 79872]
S3 IT9135BDA;@oem26.inf,%IT9135Devcie.FriendlyName%;IT9135 BDA Devices; C:\WINDOWS\System32\Drivers\IT9135BDA.sys [2014-06-15 165504]
S3 ubloxusb;ubloxusb; C:\WINDOWS\system32\DRIVERS\ubloxusb.sys [2009-11-27 95232]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2013-11-01 140560]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-20 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-06-26 81088]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-07-20 4047768]
S2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2012-12-18 1221808]
S3 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-11-14 106880]
S3 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
S3 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2012-08-10 211584]
S3 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-06-01 290224]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
S3 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
S3 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
S3 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
S3 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Vyskakující okna prohlížeče pomoc
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakující okna prohlížeče pomoc
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vyskakující okna prohlížeče pomoc
# AdwCleaner v5.026 - Logfile created 26/12/2015 at 10:39:48
# Updated 21/12/2015 by Xplode
# Database : 2015-12-23.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : radek - JELIMAN
# Running from : C:\Users\radek\Desktop\adwcleaner_5.026 (1).exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [658 bytes] ##########
# Updated 21/12/2015 by Xplode
# Database : 2015-12-23.1 [Server]
# Operating system : Windows 8.1 (x64)
# Username : radek - JELIMAN
# Running from : C:\Users\radek\Desktop\adwcleaner_5.026 (1).exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [658 bytes] ##########
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakující okna prohlížeče pomoc
Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.:files
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3112277335-540287683-1230770047-1001Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3112277335-540287683-1230770047-1001UA.job
C:\Users\radek\AppData\Local\Temp /B {A0D73BBC-B2EE-4192-8759-07759BC36F3E}.cmd
C:\WINDOWS\system32\drivers\7BC6AB08.sys
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]/64
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"{A0D73BBC-B2EE-4192-8759-07759BC36F3E}"=-
:services
7BC6AB08
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vyskakující okna prohlížeče pomoc
Logfile of random's system information tool 1.10 (written by random/random)
Run by radek at 2015-12-26 18:39:23
Microsoft Windows 8.1
System drive C: has 141 GB (74%) free of 190 GB
Total RAM: 3980 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:39:25, on 26. 12. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal
Running processes:
C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\ASUS\APRP\APRP.EXE
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\trend micro\radek.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8120 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
taskhostex.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
dashost.exe {2d34b8d8-3576-4239-8e4bb5243db72078}
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\WINDOWS\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\WINDOWS\system32\hkcmd.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\WINDOWS\system32\igfxtray.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
KBFiltr.exe
"C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\12262015_183530.log
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-4d574ddf-4f16-4813-b872-ad5dd3481063 -SystemEventPortName:HostProcess-93aa335c-e6aa-4743-930d-a9f337e65d39 -IoCancelEventPortName:HostProcess-bb2bafaf-35b5-4c5a-89d7-5922157506f8 -NonStateChangingEventPortName:HostProcess-2c810ba8-3d2e-4049-8a39-450749fca59f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:96c51562-7b10-4926-8f7e-c9a0ff00e6f3 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\radek\Documents\odvirovani\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-04 774144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-10 64640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-20 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2013-10-04 460288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-04 627712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-20 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2013-10-04 386048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-04 627712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-09-11 107192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-06-26 40336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSPRP]
C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2012-11-23 3187360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [2012-08-31 3423104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvastUI.exe]
C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-13 6108752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [2012-08-10 764032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtvStack]
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2012-08-10 127616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableS3S4]
c:\windows\temp\DisableS3S464\sethigh.cmd []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-05 144200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2015-06-01 411056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2015-06-01 183216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Exploit]
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2015-11-18 2621240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2015-06-01 453552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-28 91432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-18 13213328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowDesktopAsRun]
C:\Users\radek\AppData\Roaming\StartMenu\desktop.scf [2013-10-20 81]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartMenu]
C:\Users\radek\AppData\Roaming\StartMenu\StartMenu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateAdmin]
C:\Users\radek\AppData\Local\UpdateAdmin\UpdateAdmin.exe /RUN []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk]
C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2009-06-26 258048]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-13 6108752]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2015-06-01 451584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\7BC6AB08.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87400417.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\7BC6AB08.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\87400417.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-12-26 18:33:04 ----D---- C:\_OTM
2015-12-26 14:37:41 ----D---- C:\Program Files (x86)\FileASSASSIN
2015-12-26 14:36:05 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-12-26 14:33:34 ----D---- C:\ProgramData\Malwarebytes Anti-Exploit
2015-12-26 14:33:32 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Exploit
2015-12-26 14:32:52 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2015-12-26 14:32:19 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-26 14:32:19 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2015-12-26 14:32:19 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2015-12-26 14:32:19 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2015-12-26 13:48:23 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-12-26 13:48:21 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2015-12-26 10:49:05 ----SD---- C:\WINDOWS\SYSWOW64\Microsoft
2015-12-26 10:41:24 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_10.41.24_log.txt
2015-12-26 10:41:01 ----A---- C:\Users\radek\AppData\Roaming\sp_data.sys
2015-12-26 10:17:32 ----D---- C:\TDSSKiller_Quarantine
2015-12-26 10:13:48 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_10.13.48_log.txt
2015-12-26 08:50:30 ----D---- C:\rsit
2015-12-26 08:50:30 ----D---- C:\Program Files\trend micro
2015-12-26 08:35:32 ----A---- C:\WINDOWS\system32\drivers\7BC6AB08.sys
2015-12-26 08:35:12 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_08.35.12_log.txt
2015-12-26 08:34:28 ----D---- C:\zoek_backup
2015-12-26 08:14:07 ----D---- C:\Program Files\CCleaner
2015-12-13 09:37:40 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2015-12-13 09:37:11 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2015-12-13 09:37:11 ----A---- C:\WINDOWS\system32\msctf.dll
2015-12-13 09:36:26 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2015-12-13 09:36:26 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2015-12-13 09:36:23 ----A---- C:\WINDOWS\system32\winlogon.exe
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\wininit.exe
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbport.sys
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbehci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbuhci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbohci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbd.sys
2015-12-13 06:32:52 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-13 06:32:48 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-12-13 06:32:48 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-12-13 06:32:47 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-13 06:32:46 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-13 06:32:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-13 06:32:45 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-13 06:32:32 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-13 06:32:32 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-13 06:32:31 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-12-13 06:32:30 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-12-13 06:32:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-13 06:32:29 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-13 06:32:28 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\system32\ieui.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\winresume.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\winload.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-12-13 06:27:11 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-13 06:27:11 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-05 08:13:34 ----D---- C:\Program Files\Common Files\AV
======List of files/folders modified in the last 1 month======
2015-12-26 18:38:21 ----D---- C:\WINDOWS\Temp
2015-12-26 18:38:07 ----D---- C:\WINDOWS\Prefetch
2015-12-26 18:37:57 ----A---- C:\WINDOWS\system32\ServiceFilter.ini
2015-12-26 18:37:55 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-12-26 18:36:47 ----D---- C:\Windows
2015-12-26 18:33:05 ----D---- C:\WINDOWS\Tasks
2015-12-26 18:32:39 ----D---- C:\WINDOWS\system32\config
2015-12-26 18:30:36 ----D---- C:\WINDOWS\Microsoft.NET
2015-12-26 18:26:34 ----D---- C:\WINDOWS\debug
2015-12-26 18:00:02 ----D---- C:\WINDOWS\system32\sru
2015-12-26 14:43:37 ----RD---- C:\WINDOWS\System32
2015-12-26 14:43:37 ----D---- C:\WINDOWS\Inf
2015-12-26 14:43:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 14:37:41 ----RD---- C:\Program Files (x86)
2015-12-26 14:36:05 ----HD---- C:\ProgramData
2015-12-26 14:32:52 ----D---- C:\WINDOWS\system32\drivers
2015-12-26 14:32:19 ----D---- C:\ProgramData\Malwarebytes
2015-12-26 14:27:00 ----D---- C:\WINDOWS\WinSxS
2015-12-26 14:25:26 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-12-26 14:25:24 ----SD---- C:\WINDOWS\system32\GWX
2015-12-26 14:25:13 ----D---- C:\WINDOWS\SysWOW64
2015-12-26 13:52:59 ----D---- C:\WINDOWS\CbsTemp
2015-12-26 12:38:45 ----SHD---- C:\System Volume Information
2015-12-26 10:40:22 ----D---- C:\Program Files (x86)\Bluetooth Suite
2015-12-26 10:39:48 ----D---- C:\AdwCleaner
2015-12-26 10:16:10 ----D---- C:\WINDOWS\system32\NDF
2015-12-26 08:50:30 ----RD---- C:\Program Files
2015-12-26 08:18:37 ----DC---- C:\WINDOWS\Panther
2015-12-26 08:14:10 ----D---- C:\WINDOWS\system32\Tasks
2015-12-15 10:57:42 ----D---- C:\WINDOWS\rescache
2015-12-15 10:46:31 ----D---- C:\WINDOWS\system32\catroot2
2015-12-15 10:37:35 ----RSD---- C:\WINDOWS\assembly
2015-12-13 18:56:55 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-13 18:56:55 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-13 18:56:51 ----D---- C:\Program Files\Internet Explorer
2015-12-13 18:56:51 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-13 18:56:38 ----D---- C:\WINDOWS\system32\DriverStore
2015-12-13 10:05:14 ----D---- C:\WINDOWS\system32\MRT
2015-12-13 09:59:38 ----A---- C:\WINDOWS\system32\MRT.exe
2015-12-13 09:56:28 ----D---- C:\WINDOWS\AppReadiness
2015-12-13 06:18:19 ----D---- C:\Program Files (x86)\Opera
2015-12-05 08:13:34 ----D---- C:\Program Files\Common Files
2015-12-05 08:13:34 ----D---- C:\Program Files (x86)\Common Files
2015-12-01 18:19:27 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 7BC6AB08;7BC6AB08; C:\WINDOWS\system32\drivers\7BC6AB08.sys [2015-12-26 478392]
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-07-20 65224]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-07-20 274808]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 ngvss;ngvss; C:\WINDOWS\system32\drivers\ngvss.sys [2015-07-20 115152]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-07-20 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-11-13 1059656]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-11-13 449992]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [2015-11-18 63064]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2013-11-01 252688]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2013-11-01 126736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-07-20 28656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-07-20 90968]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-07-20 150160]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-07-20 273824]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 AthBTPort;@oem9.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2012-08-10 88728]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 ATP;@oem4.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2013-04-16 65784]
R3 BTATH_A2DP;@oem8.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2012-08-10 344216]
R3 btath_avdt;@oem8.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2012-08-10 114840]
R3 BTATH_BUS;@oem5.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys [2012-08-10 33944]
R3 BTATH_HCRP;@oem11.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2012-08-10 178840]
R3 BTATH_LWFLT;@oem19.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2012-08-10 76952]
R3 BTATH_RCP;@oem15.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2012-08-10 135832]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-01-28 593000]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 HIDSwitch;@oem14.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2012-05-31 21152]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-06-01 5384176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 IntcDAud;@oem30.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-10-26 342528]
R3 kbfiltr;@oem16.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-10-05 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2015-12-26 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-10-05 64216]
R3 MEIx64;@oem32.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 FTDIBUS;@oem38.inf,%SvcDesc%;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2014-01-31 94704]
S3 FTSER2K;@oem37.inf,%SvcDesc%;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2014-10-21 79872]
S3 IT9135BDA;@oem26.inf,%IT9135Devcie.FriendlyName%;IT9135 BDA Devices; C:\WINDOWS\System32\Drivers\IT9135BDA.sys [2014-06-15 165504]
S3 ubloxusb;ubloxusb; C:\WINDOWS\system32\DRIVERS\ubloxusb.sys [2009-11-27 95232]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2013-11-01 140560]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2012-12-18 1221808]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-20 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-06-26 81088]
R3 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-11-14 106880]
R3 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R3 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-07-20 4047768]
R3 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R3 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R3 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R3 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R3 MbaeSvc;Malwarebytes Anti-Exploit Service; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [2015-11-18 739640]
R3 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-05 1135416]
R3 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-10-05 1513784]
R3 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-06-01 290224]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
-----------------EOF-----------------
Run by radek at 2015-12-26 18:39:23
Microsoft Windows 8.1
System drive C: has 141 GB (74%) free of 190 GB
Total RAM: 3980 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:39:25, on 26. 12. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal
Running processes:
C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\ASUS\APRP\APRP.EXE
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\trend micro\radek.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8120 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
taskhostex.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
dashost.exe {2d34b8d8-3576-4239-8e4bb5243db72078}
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\WINDOWS\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\WINDOWS\system32\hkcmd.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\WINDOWS\system32\igfxtray.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
KBFiltr.exe
"C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\12262015_183530.log
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-4d574ddf-4f16-4813-b872-ad5dd3481063 -SystemEventPortName:HostProcess-93aa335c-e6aa-4743-930d-a9f337e65d39 -IoCancelEventPortName:HostProcess-bb2bafaf-35b5-4c5a-89d7-5922157506f8 -NonStateChangingEventPortName:HostProcess-2c810ba8-3d2e-4049-8a39-450749fca59f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:96c51562-7b10-4926-8f7e-c9a0ff00e6f3 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\radek\Documents\odvirovani\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-04 774144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-10 64640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-20 655480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2013-10-04 460288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-04 627712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-20 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2013-10-04 386048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-04 627712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-09-11 107192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-06-26 40336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSPRP]
C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2012-11-23 3187360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [2012-08-31 3423104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvastUI.exe]
C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-13 6108752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [2012-08-10 764032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtvStack]
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2012-08-10 127616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableS3S4]
c:\windows\temp\DisableS3S464\sethigh.cmd []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\radek\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-05 144200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2015-06-01 411056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2015-06-01 183216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Exploit]
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2015-11-18 2621240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2015-06-01 453552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-28 91432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-18 13213328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowDesktopAsRun]
C:\Users\radek\AppData\Roaming\StartMenu\desktop.scf [2013-10-20 81]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartMenu]
C:\Users\radek\AppData\Roaming\StartMenu\StartMenu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateAdmin]
C:\Users\radek\AppData\Local\UpdateAdmin\UpdateAdmin.exe /RUN []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TMMonitor.lnk]
C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2009-06-26 258048]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-13 6108752]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2015-06-01 451584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\7BC6AB08.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87400417.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\7BC6AB08.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\87400417.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-12-26 18:33:04 ----D---- C:\_OTM
2015-12-26 14:37:41 ----D---- C:\Program Files (x86)\FileASSASSIN
2015-12-26 14:36:05 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-12-26 14:33:34 ----D---- C:\ProgramData\Malwarebytes Anti-Exploit
2015-12-26 14:33:32 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Exploit
2015-12-26 14:32:52 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2015-12-26 14:32:19 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-26 14:32:19 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2015-12-26 14:32:19 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2015-12-26 14:32:19 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2015-12-26 13:48:23 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2015-12-26 13:48:21 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2015-12-26 10:49:05 ----SD---- C:\WINDOWS\SYSWOW64\Microsoft
2015-12-26 10:41:24 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_10.41.24_log.txt
2015-12-26 10:41:01 ----A---- C:\Users\radek\AppData\Roaming\sp_data.sys
2015-12-26 10:17:32 ----D---- C:\TDSSKiller_Quarantine
2015-12-26 10:13:48 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_10.13.48_log.txt
2015-12-26 08:50:30 ----D---- C:\rsit
2015-12-26 08:50:30 ----D---- C:\Program Files\trend micro
2015-12-26 08:35:32 ----A---- C:\WINDOWS\system32\drivers\7BC6AB08.sys
2015-12-26 08:35:12 ----A---- C:\TDSSKiller.3.1.0.5_26.12.2015_08.35.12_log.txt
2015-12-26 08:34:28 ----D---- C:\zoek_backup
2015-12-26 08:14:07 ----D---- C:\Program Files\CCleaner
2015-12-13 09:37:40 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2015-12-13 09:37:11 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2015-12-13 09:37:11 ----A---- C:\WINDOWS\system32\msctf.dll
2015-12-13 09:36:26 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2015-12-13 09:36:26 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2015-12-13 09:36:23 ----A---- C:\WINDOWS\system32\winlogon.exe
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\wininit.exe
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbport.sys
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2015-12-13 09:36:22 ----A---- C:\WINDOWS\system32\drivers\usbehci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbuhci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbohci.sys
2015-12-13 09:36:21 ----A---- C:\WINDOWS\system32\drivers\usbd.sys
2015-12-13 06:32:52 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-13 06:32:48 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-12-13 06:32:48 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-12-13 06:32:47 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-13 06:32:46 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-13 06:32:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-13 06:32:45 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-13 06:32:32 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-13 06:32:32 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-13 06:32:31 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-12-13 06:32:30 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-12-13 06:32:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-13 06:32:29 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-13 06:32:28 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-12-13 06:32:27 ----A---- C:\WINDOWS\system32\ieui.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-13 06:32:26 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-12-13 06:32:25 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-12-13 06:32:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-12-13 06:32:23 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\winresume.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\winload.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-13 06:29:03 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-12-13 06:29:02 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-12-13 06:29:01 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-12-13 06:29:00 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-12-13 06:27:13 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-12-13 06:27:11 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-13 06:27:11 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-05 08:13:34 ----D---- C:\Program Files\Common Files\AV
======List of files/folders modified in the last 1 month======
2015-12-26 18:38:21 ----D---- C:\WINDOWS\Temp
2015-12-26 18:38:07 ----D---- C:\WINDOWS\Prefetch
2015-12-26 18:37:57 ----A---- C:\WINDOWS\system32\ServiceFilter.ini
2015-12-26 18:37:55 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-12-26 18:36:47 ----D---- C:\Windows
2015-12-26 18:33:05 ----D---- C:\WINDOWS\Tasks
2015-12-26 18:32:39 ----D---- C:\WINDOWS\system32\config
2015-12-26 18:30:36 ----D---- C:\WINDOWS\Microsoft.NET
2015-12-26 18:26:34 ----D---- C:\WINDOWS\debug
2015-12-26 18:00:02 ----D---- C:\WINDOWS\system32\sru
2015-12-26 14:43:37 ----RD---- C:\WINDOWS\System32
2015-12-26 14:43:37 ----D---- C:\WINDOWS\Inf
2015-12-26 14:43:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 14:37:41 ----RD---- C:\Program Files (x86)
2015-12-26 14:36:05 ----HD---- C:\ProgramData
2015-12-26 14:32:52 ----D---- C:\WINDOWS\system32\drivers
2015-12-26 14:32:19 ----D---- C:\ProgramData\Malwarebytes
2015-12-26 14:27:00 ----D---- C:\WINDOWS\WinSxS
2015-12-26 14:25:26 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-12-26 14:25:24 ----SD---- C:\WINDOWS\system32\GWX
2015-12-26 14:25:13 ----D---- C:\WINDOWS\SysWOW64
2015-12-26 13:52:59 ----D---- C:\WINDOWS\CbsTemp
2015-12-26 12:38:45 ----SHD---- C:\System Volume Information
2015-12-26 10:40:22 ----D---- C:\Program Files (x86)\Bluetooth Suite
2015-12-26 10:39:48 ----D---- C:\AdwCleaner
2015-12-26 10:16:10 ----D---- C:\WINDOWS\system32\NDF
2015-12-26 08:50:30 ----RD---- C:\Program Files
2015-12-26 08:18:37 ----DC---- C:\WINDOWS\Panther
2015-12-26 08:14:10 ----D---- C:\WINDOWS\system32\Tasks
2015-12-15 10:57:42 ----D---- C:\WINDOWS\rescache
2015-12-15 10:46:31 ----D---- C:\WINDOWS\system32\catroot2
2015-12-15 10:37:35 ----RSD---- C:\WINDOWS\assembly
2015-12-13 18:56:55 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-13 18:56:55 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-13 18:56:51 ----D---- C:\Program Files\Internet Explorer
2015-12-13 18:56:51 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-13 18:56:38 ----D---- C:\WINDOWS\system32\DriverStore
2015-12-13 10:05:14 ----D---- C:\WINDOWS\system32\MRT
2015-12-13 09:59:38 ----A---- C:\WINDOWS\system32\MRT.exe
2015-12-13 09:56:28 ----D---- C:\WINDOWS\AppReadiness
2015-12-13 06:18:19 ----D---- C:\Program Files (x86)\Opera
2015-12-05 08:13:34 ----D---- C:\Program Files\Common Files
2015-12-05 08:13:34 ----D---- C:\Program Files (x86)\Common Files
2015-12-01 18:19:27 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 7BC6AB08;7BC6AB08; C:\WINDOWS\system32\drivers\7BC6AB08.sys [2015-12-26 478392]
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-07-20 65224]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-07-20 274808]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 ngvss;ngvss; C:\WINDOWS\system32\drivers\ngvss.sys [2015-07-20 115152]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-07-20 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-11-13 1059656]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-11-13 449992]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [2015-11-18 63064]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2013-11-01 252688]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2013-11-01 126736]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-07-20 28656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-07-20 90968]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-07-20 150160]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-07-20 273824]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 AthBTPort;@oem9.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2012-08-10 88728]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 ATP;@oem4.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2013-04-16 65784]
R3 BTATH_A2DP;@oem8.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2012-08-10 344216]
R3 btath_avdt;@oem8.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2012-08-10 114840]
R3 BTATH_BUS;@oem5.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys [2012-08-10 33944]
R3 BTATH_HCRP;@oem11.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2012-08-10 178840]
R3 BTATH_LWFLT;@oem19.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2012-08-10 76952]
R3 BTATH_RCP;@oem15.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2012-08-10 135832]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-01-28 593000]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 HIDSwitch;@oem14.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2012-05-31 21152]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-06-01 5384176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 IntcDAud;@oem30.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-10-26 342528]
R3 kbfiltr;@oem16.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-10-05 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2015-12-26 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-10-05 64216]
R3 MEIx64;@oem32.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 FTDIBUS;@oem38.inf,%SvcDesc%;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2014-01-31 94704]
S3 FTSER2K;@oem37.inf,%SvcDesc%;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2014-10-21 79872]
S3 IT9135BDA;@oem26.inf,%IT9135Devcie.FriendlyName%;IT9135 BDA Devices; C:\WINDOWS\System32\Drivers\IT9135BDA.sys [2014-06-15 165504]
S3 ubloxusb;ubloxusb; C:\WINDOWS\system32\DRIVERS\ubloxusb.sys [2009-11-27 95232]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2013-11-01 140560]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2012-12-18 1221808]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-20 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-06-26 81088]
R3 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-11-14 106880]
R3 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R3 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-07-20 4047768]
R3 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R3 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R3 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R3 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R3 MbaeSvc;Malwarebytes Anti-Exploit Service; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [2015-11-18 739640]
R3 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-05 1135416]
R3 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-10-05 1513784]
R3 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-06-01 290224]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakující okna prohlížeče pomoc
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vyskakující okna prohlížeče pomoc
Díky moc, vypadá to, že je vše OK.
Známý si pro NTB zítra přijede tak uvidíme co řekne on, je to kamioňák co si bere NTB na cesty takže to patřičně otestuje.
Moc děkuju za rychlou a ochotnou pomoc.
Známý si pro NTB zítra přijede tak uvidíme co řekne on, je to kamioňák co si bere NTB na cesty takže to patřičně otestuje.
Moc děkuju za rychlou a ochotnou pomoc.
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vyskakující okna prohlížeče pomoc
To jsem rád a nemáte zač! 
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?