zavirovaný počítač
Napsal: 15 kvě 2016 10:52
Dobrý den, prosím o kontrolu RSIT, mám obavu že mám opět zavirované PC.
Při přeinstalaci mi nenainstalovali žádný antivir, nyní je PC pomalý, vyskakují různé reklamy, vzkazy atd
Díky předem za pomoc Jitka
Logfile of random's system information tool 1.10 (written by random/random)
Run by uživatel at 2016-05-14 14:22:11
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 8 GB (8%) free of 100 GB
Total RAM: 4094 MB (68% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\GWX\GWX.exe"
szndesktop.exe default start
"C:\Users\uživatel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "1852246212-620685124-5834488461788985125-934267109-1862540832-1063942490-315615668
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskeng.exe {AA170804-D9A0-47BF-95A4-18DD66923194}
"C:\Program Files (x86)\OLBPre\OLBPre.exe" signup
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "http://trustedsurf.com/?ssid=1462300772 ... 704fccd219"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files\trend micro\uživatel.exe" /silentautolog
C:\Windows\System32\svchost.exe -k WerSvcGroup
"D:\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\6ktn20pq.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\6ktn20pq.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-20 172640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2016-01-29 1340192]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"=C:\Users\uživatel\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\uživatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-02-04 3014224]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-06-08 334896]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\OLBPre\OLBPre.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-05-14 14:20:43 ----D---- C:\rsit
2016-05-14 14:20:43 ----D---- C:\Program Files\trend micro
2016-05-14 08:27:25 ----D---- C:\Windows\rescache
2016-05-11 20:31:45 ----A---- C:\Windows\system32\win32k.sys
2016-05-11 20:31:42 ----A---- C:\Windows\SYSWOW64\tzres.dll
2016-05-11 20:31:42 ----A---- C:\Windows\system32\tzres.dll
2016-05-11 20:31:39 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-05-11 20:31:39 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-05-11 20:31:39 ----A---- C:\Windows\system32\cdd.dll
2016-05-11 20:31:37 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2016-05-11 20:31:36 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2016-05-11 20:31:36 ----A---- C:\Windows\system32\gdi32.dll
2016-05-11 20:31:36 ----A---- C:\Windows\system32\d3d10level9.dll
2016-05-11 20:31:34 ----A---- C:\Windows\system32\jnwmon.dll
2016-05-11 20:31:32 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2016-05-11 20:31:32 ----A---- C:\Windows\system32\InkEd.dll
2016-05-11 20:31:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-05-11 20:31:24 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-05-11 20:31:24 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-05-11 20:31:24 ----A---- C:\Windows\system32\iernonce.dll
2016-05-11 20:31:24 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-05-11 20:31:23 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-05-11 20:31:23 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-05-11 20:31:22 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-05-11 20:31:22 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-05-11 20:31:22 ----A---- C:\Windows\system32\ie4uinit.exe
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-05-11 20:31:21 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-05-11 20:31:21 ----A---- C:\Windows\system32\inseng.dll
2016-05-11 20:31:19 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-05-11 20:31:19 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-05-11 20:31:19 ----A---- C:\Windows\system32\urlmon.dll
2016-05-11 20:31:19 ----A---- C:\Windows\system32\occache.dll
2016-05-11 20:31:19 ----A---- C:\Windows\system32\iedkcs32.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-05-11 20:31:18 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-05-11 20:31:17 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-05-11 20:31:17 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-05-11 20:31:17 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-05-11 20:31:17 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-05-11 20:31:17 ----A---- C:\Windows\system32\msfeeds.dll
2016-05-11 20:31:17 ----A---- C:\Windows\system32\dxtrans.dll
2016-05-11 20:31:16 ----A---- C:\Windows\system32\iesetup.dll
2016-05-11 20:31:16 ----A---- C:\Windows\system32\ieapfltr.dll
2016-05-11 20:31:15 ----A---- C:\Windows\system32\iertutil.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-05-11 20:31:14 ----A---- C:\Windows\system32\vbscript.dll
2016-05-11 20:31:13 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-05-11 20:31:13 ----A---- C:\Windows\system32\jsproxy.dll
2016-05-11 20:31:11 ----A---- C:\Windows\system32\dxtmsft.dll
2016-05-11 20:31:10 ----A---- C:\Windows\system32\ieui.dll
2016-05-11 20:31:08 ----A---- C:\Windows\system32\mshtmled.dll
2016-05-11 20:31:08 ----A---- C:\Windows\system32\ieframe.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\webcheck.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\jscript.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\ieUnatt.exe
2016-05-11 20:31:06 ----A---- C:\Windows\system32\wininet.dll
2016-05-11 20:31:06 ----A---- C:\Windows\system32\jscript9diag.dll
2016-05-11 20:31:06 ----A---- C:\Windows\system32\jscript9.dll
2016-05-11 20:31:04 ----A---- C:\Windows\system32\msrating.dll
2016-05-11 20:31:04 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-05-11 20:31:03 ----A---- C:\Windows\system32\mshtml.dll
2016-05-11 20:29:31 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-05-11 20:29:31 ----A---- C:\Windows\system32\rpcrt4.dll
2016-05-11 20:29:31 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-05-11 20:29:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-05-11 20:29:31 ----A---- C:\Windows\system32\kerberos.dll
2016-05-11 20:29:30 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-05-11 20:29:30 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-05-11 20:29:30 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-05-11 20:29:30 ----A---- C:\Windows\system32\ntdll.dll
2016-05-11 20:29:30 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-05-11 20:29:29 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-05-11 20:29:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-05-11 20:29:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-05-11 20:29:29 ----A---- C:\Windows\system32\certcli.dll
2016-05-11 20:29:28 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-05-11 20:29:28 ----A---- C:\Windows\system32\smss.exe
2016-05-11 20:29:28 ----A---- C:\Windows\system32\kernel32.dll
2016-05-11 20:29:28 ----A---- C:\Windows\system32\advapi32.dll
2016-05-11 20:29:27 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\wow64win.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\schannel.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\msv1_0.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\KernelBase.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-05-11 20:29:26 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-05-11 20:29:25 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\wow64.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\winsrv.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\wdigest.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\TSpkg.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\sspicli.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\srcore.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\ncrypt.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\conhost.exe
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\wow64cpu.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\sspisrv.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\srclient.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\secur32.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\rpchttp.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\lsass.exe
2016-05-11 20:29:24 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-05-11 20:29:24 ----A---- C:\Windows\system32\drivers\appid.sys
2016-05-11 20:29:24 ----A---- C:\Windows\system32\csrsrv.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\cryptbase.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\appidsvc.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\appidapi.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-05-11 20:29:23 ----A---- C:\Windows\system32\rstrui.exe
2016-05-11 20:29:23 ----A---- C:\Windows\system32\ntvdm64.dll
2016-05-11 20:29:23 ----A---- C:\Windows\system32\credssp.dll
2016-05-11 20:29:23 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-05-11 20:29:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-05-11 20:29:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-05-11 20:29:22 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-05-11 20:29:22 ----A---- C:\Windows\system32\auditpol.exe
2016-05-11 20:29:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-05-11 20:29:21 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-05-11 20:29:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-05-11 20:29:21 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-05-11 20:29:21 ----A---- C:\Windows\system32\apisetschema.dll
2016-05-11 20:29:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\user.exe
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-05-11 20:29:20 ----A---- C:\Windows\system32\msobjs.dll
2016-05-11 20:29:20 ----A---- C:\Windows\system32\msaudite.dll
2016-05-11 20:29:20 ----A---- C:\Windows\system32\adtschema.dll
2016-05-11 20:29:13 ----A---- C:\Windows\system32\WindowsCodecs.dll
2016-05-11 20:29:12 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2016-05-06 16:18:59 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-05-01 12:33:16 ----ASH---- C:\pagefile.sys
2016-04-29 21:46:46 ----D---- C:\Program Files (x86)\OLBPre
2016-04-28 20:32:14 ----HD---- C:\$WINDOWS.~BT
2016-04-17 18:22:38 ----D---- C:\Users\uživatel\AppData\Roaming\Ancestry
======List of files/folders modified in the last 1 month======
2016-05-14 14:22:01 ----D---- C:\Windows\Prefetch
2016-05-14 14:20:43 ----RD---- C:\Program Files
2016-05-14 13:17:17 ----D---- C:\Windows\Temp
2016-05-14 09:00:34 ----D---- C:\Program Files (x86)\Steam
2016-05-14 08:27:25 ----D---- C:\Windows
2016-05-14 03:26:51 ----D---- C:\Users\uživatel\AppData\Roaming\Seznam.cz
2016-05-14 03:26:38 ----D---- C:\Windows\System32
2016-05-14 03:26:38 ----D---- C:\Windows\inf
2016-05-14 03:26:38 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-05-14 03:21:40 ----D---- C:\Windows\winsxs
2016-05-14 03:21:28 ----D---- C:\Windows\system32\config
2016-05-14 03:20:05 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-05-14 03:20:05 ----D---- C:\Windows\SysWOW64
2016-05-14 03:20:05 ----D---- C:\Windows\system32\drivers
2016-05-14 03:20:05 ----D---- C:\Windows\system32\cs-CZ
2016-05-14 03:17:19 ----D---- C:\Windows\Microsoft.NET
2016-05-14 03:04:54 ----SHD---- C:\Windows\Installer
2016-05-14 03:04:52 ----D---- C:\ProgramData\Microsoft Help
2016-05-14 03:00:43 ----SHD---- C:\System Volume Information
2016-05-12 13:50:07 ----RSD---- C:\Windows\assembly
2016-05-12 13:17:18 ----D---- C:\Program Files (x86)\Opera
2016-05-12 13:17:17 ----D---- C:\Windows\system32\Tasks
2016-05-12 13:08:39 ----D---- C:\Windows\system32\appraiser
2016-05-12 13:08:38 ----D---- C:\Windows\ehome
2016-05-12 13:08:38 ----D---- C:\Program Files\Windows Journal
2016-05-12 13:08:36 ----D---- C:\Windows\SYSWOW64\en-US
2016-05-12 13:08:36 ----D---- C:\Program Files\Internet Explorer
2016-05-12 13:08:35 ----D---- C:\Windows\system32\en-US
2016-05-12 13:08:34 ----D---- C:\Program Files (x86)\Internet Explorer
2016-05-12 13:08:30 ----D---- C:\Windows\AppPatch
2016-05-12 13:08:29 ----D---- C:\Windows\system32\Boot
2016-05-11 20:29:04 ----D---- C:\Windows\system32\catroot2
2016-05-11 19:04:28 ----RD---- C:\Program Files (x86)
2016-05-11 19:04:24 ----D---- C:\Windows\Tasks
2016-05-07 17:39:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-05-06 21:45:36 ----SD---- C:\Windows\SYSWOW64\GWX
2016-05-06 21:45:36 ----SD---- C:\Windows\system32\GWX
2016-04-28 20:37:32 ----D---- C:\Windows\Panther
2016-04-22 09:57:45 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-11-13 289120]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-11-13 133816]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 127488]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 18944]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 161280]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-04-22 82128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-01-29 23808]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-01-29 374344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-25 144200]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-25 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-04-23 114688]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-05-06 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-02-04 835152]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-08-25 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------
Při přeinstalaci mi nenainstalovali žádný antivir, nyní je PC pomalý, vyskakují různé reklamy, vzkazy atd
Díky předem za pomoc Jitka
Logfile of random's system information tool 1.10 (written by random/random)
Run by uživatel at 2016-05-14 14:22:11
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 8 GB (8%) free of 100 GB
Total RAM: 4094 MB (68% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\GWX\GWX.exe"
szndesktop.exe default start
"C:\Users\uživatel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "1852246212-620685124-5834488461788985125-934267109-1862540832-1063942490-315615668
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskeng.exe {AA170804-D9A0-47BF-95A4-18DD66923194}
"C:\Program Files (x86)\OLBPre\OLBPre.exe" signup
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "http://trustedsurf.com/?ssid=1462300772 ... 704fccd219"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files\trend micro\uživatel.exe" /silentautolog
C:\Windows\System32\svchost.exe -k WerSvcGroup
"D:\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\6ktn20pq.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\6ktn20pq.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-20 172640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2016-01-29 1340192]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"cz.seznam.software.autoupdate"=C:\Users\uživatel\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\uživatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-02-04 3014224]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-06-08 334896]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\OLBPre\OLBPre.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-05-14 14:20:43 ----D---- C:\rsit
2016-05-14 14:20:43 ----D---- C:\Program Files\trend micro
2016-05-14 08:27:25 ----D---- C:\Windows\rescache
2016-05-11 20:31:45 ----A---- C:\Windows\system32\win32k.sys
2016-05-11 20:31:42 ----A---- C:\Windows\SYSWOW64\tzres.dll
2016-05-11 20:31:42 ----A---- C:\Windows\system32\tzres.dll
2016-05-11 20:31:39 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-05-11 20:31:39 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-05-11 20:31:39 ----A---- C:\Windows\system32\cdd.dll
2016-05-11 20:31:37 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2016-05-11 20:31:36 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2016-05-11 20:31:36 ----A---- C:\Windows\system32\gdi32.dll
2016-05-11 20:31:36 ----A---- C:\Windows\system32\d3d10level9.dll
2016-05-11 20:31:34 ----A---- C:\Windows\system32\jnwmon.dll
2016-05-11 20:31:32 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2016-05-11 20:31:32 ----A---- C:\Windows\system32\InkEd.dll
2016-05-11 20:31:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-05-11 20:31:24 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-05-11 20:31:24 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-05-11 20:31:24 ----A---- C:\Windows\system32\iernonce.dll
2016-05-11 20:31:24 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-05-11 20:31:23 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-05-11 20:31:23 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-05-11 20:31:22 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-05-11 20:31:22 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-05-11 20:31:22 ----A---- C:\Windows\system32\ie4uinit.exe
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-05-11 20:31:21 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-05-11 20:31:21 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-05-11 20:31:21 ----A---- C:\Windows\system32\inseng.dll
2016-05-11 20:31:19 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-05-11 20:31:19 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-05-11 20:31:19 ----A---- C:\Windows\system32\urlmon.dll
2016-05-11 20:31:19 ----A---- C:\Windows\system32\occache.dll
2016-05-11 20:31:19 ----A---- C:\Windows\system32\iedkcs32.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-05-11 20:31:18 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-05-11 20:31:18 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-05-11 20:31:17 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-05-11 20:31:17 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-05-11 20:31:17 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-05-11 20:31:17 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-05-11 20:31:17 ----A---- C:\Windows\system32\msfeeds.dll
2016-05-11 20:31:17 ----A---- C:\Windows\system32\dxtrans.dll
2016-05-11 20:31:16 ----A---- C:\Windows\system32\iesetup.dll
2016-05-11 20:31:16 ----A---- C:\Windows\system32\ieapfltr.dll
2016-05-11 20:31:15 ----A---- C:\Windows\system32\iertutil.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-05-11 20:31:14 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-05-11 20:31:14 ----A---- C:\Windows\system32\vbscript.dll
2016-05-11 20:31:13 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-05-11 20:31:13 ----A---- C:\Windows\system32\jsproxy.dll
2016-05-11 20:31:11 ----A---- C:\Windows\system32\dxtmsft.dll
2016-05-11 20:31:10 ----A---- C:\Windows\system32\ieui.dll
2016-05-11 20:31:08 ----A---- C:\Windows\system32\mshtmled.dll
2016-05-11 20:31:08 ----A---- C:\Windows\system32\ieframe.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\webcheck.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\jscript.dll
2016-05-11 20:31:07 ----A---- C:\Windows\system32\ieUnatt.exe
2016-05-11 20:31:06 ----A---- C:\Windows\system32\wininet.dll
2016-05-11 20:31:06 ----A---- C:\Windows\system32\jscript9diag.dll
2016-05-11 20:31:06 ----A---- C:\Windows\system32\jscript9.dll
2016-05-11 20:31:04 ----A---- C:\Windows\system32\msrating.dll
2016-05-11 20:31:04 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-05-11 20:31:03 ----A---- C:\Windows\system32\mshtml.dll
2016-05-11 20:29:31 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-05-11 20:29:31 ----A---- C:\Windows\system32\rpcrt4.dll
2016-05-11 20:29:31 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-05-11 20:29:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-05-11 20:29:31 ----A---- C:\Windows\system32\kerberos.dll
2016-05-11 20:29:30 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-05-11 20:29:30 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-05-11 20:29:30 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-05-11 20:29:30 ----A---- C:\Windows\system32\ntdll.dll
2016-05-11 20:29:30 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-05-11 20:29:29 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-05-11 20:29:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-05-11 20:29:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-05-11 20:29:29 ----A---- C:\Windows\system32\certcli.dll
2016-05-11 20:29:28 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-05-11 20:29:28 ----A---- C:\Windows\system32\smss.exe
2016-05-11 20:29:28 ----A---- C:\Windows\system32\kernel32.dll
2016-05-11 20:29:28 ----A---- C:\Windows\system32\advapi32.dll
2016-05-11 20:29:27 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\wow64win.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\schannel.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\msv1_0.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\KernelBase.dll
2016-05-11 20:29:27 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-05-11 20:29:26 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-05-11 20:29:25 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\wow64.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\winsrv.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\wdigest.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\TSpkg.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\sspicli.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\srcore.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\ncrypt.dll
2016-05-11 20:29:25 ----A---- C:\Windows\system32\conhost.exe
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-05-11 20:29:24 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\wow64cpu.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\sspisrv.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\srclient.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\secur32.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\rpchttp.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\lsass.exe
2016-05-11 20:29:24 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-05-11 20:29:24 ----A---- C:\Windows\system32\drivers\appid.sys
2016-05-11 20:29:24 ----A---- C:\Windows\system32\csrsrv.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\cryptbase.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\appidsvc.dll
2016-05-11 20:29:24 ----A---- C:\Windows\system32\appidapi.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-05-11 20:29:23 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-05-11 20:29:23 ----A---- C:\Windows\system32\rstrui.exe
2016-05-11 20:29:23 ----A---- C:\Windows\system32\ntvdm64.dll
2016-05-11 20:29:23 ----A---- C:\Windows\system32\credssp.dll
2016-05-11 20:29:23 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-05-11 20:29:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-05-11 20:29:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-05-11 20:29:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-05-11 20:29:22 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-05-11 20:29:22 ----A---- C:\Windows\system32\auditpol.exe
2016-05-11 20:29:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-05-11 20:29:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-05-11 20:29:21 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-05-11 20:29:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-05-11 20:29:21 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-05-11 20:29:21 ----A---- C:\Windows\system32\apisetschema.dll
2016-05-11 20:29:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\user.exe
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-05-11 20:29:20 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-05-11 20:29:20 ----A---- C:\Windows\system32\msobjs.dll
2016-05-11 20:29:20 ----A---- C:\Windows\system32\msaudite.dll
2016-05-11 20:29:20 ----A---- C:\Windows\system32\adtschema.dll
2016-05-11 20:29:13 ----A---- C:\Windows\system32\WindowsCodecs.dll
2016-05-11 20:29:12 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2016-05-06 16:18:59 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-05-01 12:33:16 ----ASH---- C:\pagefile.sys
2016-04-29 21:46:46 ----D---- C:\Program Files (x86)\OLBPre
2016-04-28 20:32:14 ----HD---- C:\$WINDOWS.~BT
2016-04-17 18:22:38 ----D---- C:\Users\uživatel\AppData\Roaming\Ancestry
======List of files/folders modified in the last 1 month======
2016-05-14 14:22:01 ----D---- C:\Windows\Prefetch
2016-05-14 14:20:43 ----RD---- C:\Program Files
2016-05-14 13:17:17 ----D---- C:\Windows\Temp
2016-05-14 09:00:34 ----D---- C:\Program Files (x86)\Steam
2016-05-14 08:27:25 ----D---- C:\Windows
2016-05-14 03:26:51 ----D---- C:\Users\uživatel\AppData\Roaming\Seznam.cz
2016-05-14 03:26:38 ----D---- C:\Windows\System32
2016-05-14 03:26:38 ----D---- C:\Windows\inf
2016-05-14 03:26:38 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-05-14 03:21:40 ----D---- C:\Windows\winsxs
2016-05-14 03:21:28 ----D---- C:\Windows\system32\config
2016-05-14 03:20:05 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-05-14 03:20:05 ----D---- C:\Windows\SysWOW64
2016-05-14 03:20:05 ----D---- C:\Windows\system32\drivers
2016-05-14 03:20:05 ----D---- C:\Windows\system32\cs-CZ
2016-05-14 03:17:19 ----D---- C:\Windows\Microsoft.NET
2016-05-14 03:04:54 ----SHD---- C:\Windows\Installer
2016-05-14 03:04:52 ----D---- C:\ProgramData\Microsoft Help
2016-05-14 03:00:43 ----SHD---- C:\System Volume Information
2016-05-12 13:50:07 ----RSD---- C:\Windows\assembly
2016-05-12 13:17:18 ----D---- C:\Program Files (x86)\Opera
2016-05-12 13:17:17 ----D---- C:\Windows\system32\Tasks
2016-05-12 13:08:39 ----D---- C:\Windows\system32\appraiser
2016-05-12 13:08:38 ----D---- C:\Windows\ehome
2016-05-12 13:08:38 ----D---- C:\Program Files\Windows Journal
2016-05-12 13:08:36 ----D---- C:\Windows\SYSWOW64\en-US
2016-05-12 13:08:36 ----D---- C:\Program Files\Internet Explorer
2016-05-12 13:08:35 ----D---- C:\Windows\system32\en-US
2016-05-12 13:08:34 ----D---- C:\Program Files (x86)\Internet Explorer
2016-05-12 13:08:30 ----D---- C:\Windows\AppPatch
2016-05-12 13:08:29 ----D---- C:\Windows\system32\Boot
2016-05-11 20:29:04 ----D---- C:\Windows\system32\catroot2
2016-05-11 19:04:28 ----RD---- C:\Program Files (x86)
2016-05-11 19:04:24 ----D---- C:\Windows\Tasks
2016-05-07 17:39:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-05-06 21:45:36 ----SD---- C:\Windows\SYSWOW64\GWX
2016-05-06 21:45:36 ----SD---- C:\Windows\system32\GWX
2016-04-28 20:37:32 ----D---- C:\Windows\Panther
2016-04-22 09:57:45 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-11-13 289120]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-11-13 133816]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 127488]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 18944]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 161280]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-04-22 82128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-01-29 23808]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-01-29 374344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-25 144200]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-25 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-04-23 114688]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-05-06 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-02-04 835152]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-08-25 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------