Stránka 1 z 1

Preventivka

Napsal: 27 srp 2016 14:55
od jupiland
Zdravím,
v poslední době se PC poněkud zasekává po startu, trvá mu třeba 5 minut, než vůbec spustí aplikaci, tak jsem si řekla, jestli byste se mi na to nekouknuli :)
Děkuji :)

Logfile of random's system information tool 1.10 (written by random/random)
Run by J. S. at 2016-08-27 15:44:30
Microsoft Windows 10 Pro
System drive C: has 81 GB (71%) free of 114 GB
Total RAM: 8079 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:44:39, on 27.08.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0545)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Granus\DPWrite.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\ExcellentRelax\2016\ExcellentIntense.exe
C:\Program Files (x86)\OpenOffice 4\program\scalc.exe
C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files\trend micro\J. S..exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: DPWrite.lnk = C:\Granus\DPWrite.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Biometric and Context Agent Service (IntelBCAsvc) - Intel(R) Corporation - C:\Program Files\Intel\BCA\pabeSvc64.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: Intel Security True Key (TrueKey) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) - McAfee, Inc. - C:\Program Files\TrueKey\McTkSchedulerService.exe
O23 - Service: Intel Security True Key Helper Service (TrueKeyServiceHelper) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9812 bytes

======Listing Processes======







C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\SysWow64\IntelCpHeciSvc.exe
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ab3ac8db-4bdb-413c-a9f2-7afb4caeb8a4 -SystemEventPortName:HostProcess-08863c86-ce40-45b8-8e6a-8a25860ebb1a -IoCancelEventPortName:HostProcess-52a71624-0b45-4193-a638-6bb76d722ca2 -NonStateChangingEventPortName:HostProcess-1c0c6772-c7f6-45c7-abc2-a264719dc9f5 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6bbc1638-efaf-4901-80f6-a55167343040 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe"

"C:\Program Files\Intel\BCA\pabeSvc64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k appmodel
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\TrueKey\McTkSchedulerService.exe"
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey DC5A79C7-7B4E-2F1D-280E-BC7708EB6E97 -Reinvoke


C:\Windows\System32\WinLogon.exe -SpecialSession
"dwm.exe"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe"
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\Version9\TeamViewer9_Logfile.log
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe"
"C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe"
"C:\Granus\DPWrite.exe"
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Photosmart C5100 series#1464858632" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\System32\InstallAgent.exe -Embedding
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\ExcellentRelax\2016\ExcellentIntense.exe"
"C:\Program Files (x86)\OpenOffice 4\program\scalc.exe" -o "C:\Users\J. S.\Desktop\Cizinecká policie\26.8.2016.ods"
"C:\Program Files (x86)\OpenOffice 4\program\scalc.exe" -o "C:\Users\J. S.\Desktop\Cizinecká policie\26.8.2016.ods" -calc
"C:\Program Files (x86)\OpenOffice 4\program\scalc.exe" "-o" "C:\Users\J. S.\Desktop\Cizinecká policie\26.8.2016.ods" "-calc" "-env:OOO_CWD=2C:\\Users\\J. S.\\Desktop\\Cizinecká policie"
C:\Windows\splwow64.exe 8192
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
"fontdrvhost.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer

"C:\Program Files\Defraggler\Defraggler64.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe184_ Global\UsGthrCtrlFltPipeMssGthrPipe184 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 628 632 640 8192 636
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\J. S.\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\J. S.\AppData\Roaming\Mozilla\Firefox\Profiles\m6g8a8u2.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 22.0.0.209 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.91.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.91.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 22.0.0.209 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-11 462400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-11 173120]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe [2015-08-04 2926336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-08-26 633024]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-07-13 8891608]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"=C:\Windows\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\J. S.\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"=C:\Windows\system32\cmd.exe [2015-10-30 233984]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-04-01 596504]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe

C:\Users\J. S.\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
DPWrite.lnk - C:\Granus\DPWrite.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-08-27 15:44:30 ----D---- C:\rsit
2016-08-27 15:44:30 ----D---- C:\Program Files\trend micro
2016-08-26 16:31:43 ----D---- C:\Program Files\Defraggler
2016-08-26 16:25:01 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2016-08-26 16:24:40 ----D---- C:\ProgramData\Malwarebytes
2016-08-26 16:24:40 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-26 16:24:40 ----A---- C:\Windows\system32\drivers\mwac.sys
2016-08-26 16:24:40 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2016-08-26 16:24:40 ----A---- C:\Windows\system32\drivers\mbam.sys
2016-08-26 14:09:45 ----D---- C:\Program Files\CCleaner
2016-08-26 07:03:54 ----D---- C:\Users\J. S.\AppData\Roaming\Skype
2016-08-10 16:03:35 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 16:03:34 ----A---- C:\Windows\SYSWOW64\wldp.dll
2016-08-10 16:03:34 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2016-08-10 16:03:34 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2016-08-10 16:03:34 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-08-10 16:03:34 ----A---- C:\Windows\system32\dbgeng.dll
2016-08-10 16:03:33 ----A---- C:\Windows\system32\WWAHost.exe
2016-08-10 16:03:33 ----A---- C:\Windows\system32\rdpudd.dll
2016-08-10 16:03:33 ----A---- C:\Windows\system32\rdpcorets.dll
2016-08-10 16:03:32 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryClient.dll
2016-08-10 16:03:32 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 16:03:32 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2016-08-10 16:03:32 ----A---- C:\Windows\system32\wmp.dll
2016-08-10 16:03:31 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-08-10 16:03:30 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-08-10 16:03:30 ----A---- C:\Windows\system32\MusNotification.exe
2016-08-10 16:03:30 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-08-10 16:03:30 ----A---- C:\Windows\system32\drivers\cng.sys
2016-08-10 16:03:29 ----A---- C:\Windows\system32\wevtutil.exe
2016-08-10 16:03:29 ----A---- C:\Windows\system32\lsasrv.dll
2016-08-10 16:03:28 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.dll
2016-08-10 16:03:28 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 16:03:28 ----A---- C:\Windows\system32\MusNotificationUx.exe
2016-08-10 16:03:27 ----A---- C:\Windows\system32\win32kbase.sys
2016-08-10 16:03:27 ----A---- C:\Windows\system32\NetSetupApi.dll
2016-08-10 16:03:27 ----A---- C:\Windows\system32\musdialoghandlers.dll
2016-08-10 16:03:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-08-10 16:03:27 ----A---- C:\Windows\system32\cdd.dll
2016-08-10 16:03:26 ----A---- C:\Windows\system32\win32kfull.sys
2016-08-10 16:03:26 ----A---- C:\Windows\system32\usocore.dll
2016-08-10 16:03:26 ----A---- C:\Windows\system32\NetSetupSvc.dll
2016-08-10 16:03:26 ----A---- C:\Windows\system32\NetSetupEngine.dll
2016-08-10 16:03:26 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 16:03:25 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 16:03:25 ----A---- C:\Windows\system32\TpmTasks.dll
2016-08-10 16:03:24 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-08-10 16:03:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-08-10 16:03:24 ----A---- C:\Windows\system32\mstscax.dll
2016-08-10 16:03:23 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2016-08-10 16:03:23 ----A---- C:\Windows\SYSWOW64\tdlrecover.exe
2016-08-10 16:03:23 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-08-10 16:03:23 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2016-08-10 16:03:23 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2016-08-10 16:03:22 ----A---- C:\Windows\system32\wwansvc.dll
2016-08-10 16:03:22 ----A---- C:\Windows\system32\WUDFPlatform.dll
2016-08-10 16:03:22 ----A---- C:\Windows\system32\winsrv.dll
2016-08-10 16:03:22 ----A---- C:\Windows\system32\RecoveryDrive.exe
2016-08-10 16:03:21 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-08-10 16:03:21 ----A---- C:\Windows\system32\GdiPlus.dll
2016-08-10 16:03:21 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-08-10 16:03:21 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-08-10 16:03:20 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-08-10 16:03:20 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2016-08-10 16:03:20 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2016-08-10 16:03:19 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-08-10 16:03:19 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-08-10 16:03:19 ----A---- C:\Windows\system32\wuauclt.exe
2016-08-10 16:03:19 ----A---- C:\Windows\system32\sppwinob.dll
2016-08-10 16:03:18 ----A---- C:\Windows\system32\wuaueng.dll
2016-08-10 16:03:18 ----A---- C:\Windows\system32\wininet.dll
2016-08-10 16:03:18 ----A---- C:\Windows\system32\urlmon.dll
2016-08-10 16:03:18 ----A---- C:\Windows\system32\sppobjs.dll
2016-08-10 16:03:18 ----A---- C:\Windows\system32\iertutil.dll
2016-08-10 16:03:17 ----A---- C:\Windows\SYSWOW64\wevtutil.exe
2016-08-10 16:03:17 ----A---- C:\Windows\system32\wuapi.dll
2016-08-10 16:03:17 ----A---- C:\Windows\system32\drivers\storport.sys
2016-08-10 16:03:17 ----A---- C:\Windows\system32\drivers\pci.sys
2016-08-10 16:03:16 ----A---- C:\Windows\system32\wshbth.dll
2016-08-10 16:03:16 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-08-10 16:03:16 ----A---- C:\Windows\system32\BluetoothApis.dll
2016-08-10 16:03:15 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-08-10 16:03:14 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 16:03:14 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 16:03:14 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 16:03:14 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 16:03:14 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 16:03:13 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 16:03:13 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 16:03:13 ----A---- C:\Windows\system32\tileobjserver.dll
2016-08-10 16:03:13 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-08-10 16:03:13 ----A---- C:\Windows\system32\appraiser.dll
2016-08-10 16:03:13 ----A---- C:\Windows\system32\acmigration.dll
2016-08-10 16:03:12 ----A---- C:\Windows\system32\tdlrecover.exe
2016-08-10 16:03:12 ----A---- C:\Windows\system32\LockAppHost.exe
2016-08-10 16:03:12 ----A---- C:\Windows\system32\IdCtrls.dll
2016-08-10 16:03:11 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-08-10 16:03:11 ----A---- C:\Windows\system32\wldp.dll
2016-08-10 16:03:10 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-08-10 16:03:10 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2016-08-10 16:03:10 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 16:03:09 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2016-08-10 16:03:09 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2016-08-10 16:03:09 ----A---- C:\Windows\SYSWOW64\ActiveSyncProvider.dll
2016-08-10 16:03:08 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-08-10 16:03:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-08-10 16:03:08 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-08-10 16:03:07 ----A---- C:\Windows\SYSWOW64\IdCtrls.dll
2016-08-10 16:03:07 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2016-08-10 16:03:07 ----A---- C:\Windows\system32\jscript9.dll
2016-08-10 16:03:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-08-10 16:03:06 ----A---- C:\Windows\system32\Chakra.dll
2016-08-10 16:03:05 ----A---- C:\Windows\system32\ieframe.dll
2016-08-10 16:03:05 ----A---- C:\Windows\system32\Chakradiag.dll
2016-08-10 16:03:05 ----A---- C:\Windows\system32\edgehtml.dll
2016-08-10 16:03:04 ----A---- C:\Windows\system32\wuuhext.dll
2016-08-10 16:03:03 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-08-10 16:03:03 ----A---- C:\Windows\system32\ole32.dll
2016-08-10 16:03:03 ----A---- C:\Windows\system32\mshtml.dll
2016-08-10 16:03:03 ----A---- C:\Windows\system32\LogonController.dll
2016-08-10 16:03:03 ----A---- C:\Windows\system32\ieapfltr.dll
2016-08-10 16:03:02 ----A---- C:\Windows\system32\shell32.dll
2016-08-10 16:03:02 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 16:03:00 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-08-10 16:02:59 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2016-08-10 16:02:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-08-10 16:02:59 ----A---- C:\Windows\system32\SensorsApi.dll
2016-08-10 16:02:59 ----A---- C:\Windows\system32\msfeeds.dll
2016-08-10 16:02:58 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-08-10 16:02:58 ----A---- C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 16:02:58 ----A---- C:\Windows\system32\kerberos.dll
2016-08-10 16:02:58 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-08-10 16:02:57 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 16:02:57 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-08-10 16:02:57 ----A---- C:\Windows\system32\SensorService.dll
2016-08-10 16:02:57 ----A---- C:\Windows\system32\iedkcs32.dll
2016-08-10 16:02:57 ----A---- C:\Windows\system32\ie4uinit.exe
2016-08-10 16:02:57 ----A---- C:\Windows\system32\bthserv.dll
2016-08-05 14:37:14 ----D---- C:\Granus

======List of files/folders modified in the last 1 month======

2016-08-27 15:44:33 ----D---- C:\Windows\Prefetch
2016-08-27 15:44:30 ----RD---- C:\Program Files
2016-08-27 15:44:19 ----D---- C:\Windows\Temp
2016-08-27 15:11:00 ----D---- C:\Windows\system32\sru
2016-08-27 13:48:04 ----D---- C:\Windows\AppReadiness
2016-08-27 12:04:05 ----HD---- C:\Program Files\WindowsApps
2016-08-26 16:25:14 ----RD---- C:\Program Files (x86)
2016-08-26 16:25:01 ----D---- C:\Windows\system32\drivers
2016-08-26 16:24:40 ----HD---- C:\ProgramData
2016-08-26 16:22:06 ----D---- C:\Windows\System32
2016-08-26 16:22:06 ----D---- C:\Windows\INF
2016-08-26 16:22:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-08-26 16:11:52 ----D---- C:\Windows
2016-08-26 14:09:50 ----D---- C:\Windows\system32\Tasks
2016-08-26 12:10:44 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-26 07:05:40 ----AD---- C:\Program Files\Mozilla Firefox
2016-08-22 11:50:57 ----D---- C:\Windows\system32\DriverStore
2016-08-16 11:35:26 ----D---- C:\Windows\Panther
2016-08-16 11:35:25 ----D---- C:\Windows\debug
2016-08-15 13:10:25 ----D---- C:\Program Files\McAfee Security Scan
2016-08-14 03:57:10 ----D---- C:\Windows\system32\config
2016-08-13 22:23:20 ----D---- C:\Windows\rescache
2016-08-13 22:12:30 ----D---- C:\Windows\WinSxS
2016-08-13 22:12:09 ----D---- C:\Windows\system32\catroot2
2016-08-13 22:10:28 ----D---- C:\Windows\Microsoft.NET
2016-08-13 03:31:01 ----RD---- C:\Windows\ImmersiveControlPanel
2016-08-13 03:31:01 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-08-13 03:31:01 ----D---- C:\Windows\SysWOW64
2016-08-13 03:31:01 ----D---- C:\Windows\system32\en-US
2016-08-13 03:31:01 ----D---- C:\Windows\system32\cs-CZ
2016-08-13 03:31:01 ----D---- C:\Windows\system32\appraiser
2016-08-13 03:31:00 ----D---- C:\Program Files\Windows Journal
2016-08-13 03:31:00 ----D---- C:\Program Files\Internet Explorer
2016-08-13 03:31:00 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-12 22:04:08 ----D---- C:\Windows\system32\SecureBootUpdates
2016-08-12 22:04:08 ----D---- C:\Windows\CbsTemp
2016-08-12 22:04:07 ----D---- C:\Windows\system32\MRT
2016-08-12 22:03:00 ----AC---- C:\Windows\system32\MRT.exe
2016-08-04 17:23:39 ----D---- C:\Windows\system32\NDF
2016-08-04 07:11:12 ----SHD---- C:\Windows\Installer
2016-08-04 07:11:12 ----HD---- C:\Config.Msi
2016-07-31 12:18:54 ----D---- C:\Program Files (x86)\McAfee
2016-07-31 12:18:52 ----D---- C:\Program Files\TrueKey

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-08-03 263296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-08-03 197288]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2016-08-03 181416]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 dot4;@oem10.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2012-09-25 151968]
R3 Dot4Print;@oem11.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\Windows\System32\drivers\Dot4Prt.sys [2012-09-25 27040]
R3 dot4usb;@oem10.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2012-09-25 49056]
R3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\Windows\System32\drivers\e1i63x64.sys [2015-10-30 472576]
R3 FTDIBUS;@oem14.inf,%SvcDesc%;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2012-04-13 75016]
R3 FTSER2K;@oem15.inf,%SvcDesc%;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2012-04-13 85384]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2016-05-03 3811288]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTDVHD64.sys [2015-08-04 2558208]
R3 IntcDAud;@oem9.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 iwdbus;@oem6.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-12-01 38896]
R3 MEIx64;@oem3.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverW8x64.sys [2016-01-19 202032]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2016-08-03 15488]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-10-30 34144]
S3 ALCATELUSB;@oem19.inf,%ALCATELUSB.SvcDesc%;Alcatel HSPA Modem Service; C:\Windows\System32\Drivers\AlcatelUsb.sys [2012-08-22 25088]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\Windows\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-11-22 117248]
S3 dg_ssudbus;@oem28.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-07-22 130688]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 intaud_WaveExtensible;@oem5.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-12-01 50160]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 NuidFltr;@oem2.inf,%NuidFltr.SvcDesc%;NUID filter driver; C:\Windows\System32\drivers\NuidFltr.sys [2007-08-31 20392]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 ssudmdm;@oem30.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-07-22 164992]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2016-04-23 63488]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\Windows\system32\drivers\ufx01000.sys [2016-05-28 258912]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\Windows\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\Windows\System32\drivers\ufxsynopsys.sys [2016-04-23 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\Windows\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\Windows\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\Windows\System32\drivers\urssynopsys.sys [2015-10-30 27488]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2016-08-03 2780160]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2016-05-03 337888]
R2 IntelBCAsvc;Intel(R) Biometric and Context Agent Service; C:\Program Files\Intel\BCA\pabeSvc64.exe [2016-05-06 3026584]
R2 OneSyncSvc_69e0bf;Hostitel synchronizace_69e0bf; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2015-04-09 5258512]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 TrueKey;Intel Security True Key; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [2016-07-22 908256]
R2 TrueKeyScheduler;Intel Security True Key Scheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [2016-07-22 15736]
R3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2016-05-03 299488]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_145d47bd;Hostitel synchronizace_145d47bd; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_a05f079;Hostitel synchronizace_a05f079; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12 270016]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [2016-07-19 327944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_145d47bd;Služba zasílání zpráv_145d47bd; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_69e0bf;Služba zasílání zpráv_69e0bf; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_a05f079;Služba zasílání zpráv_a05f079; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-08-26 167880]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_145d47bd;Data kontaktů_145d47bd; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_69e0bf;Data kontaktů_69e0bf; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_a05f079;Data kontaktů_a05f079; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\Windows\system32\TieringEngineService.exe [2015-10-30 290304]
S3 TrueKeyServiceHelper;Intel Security True Key Helper Service; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [2016-07-22 86864]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_145d47bd;Úložiště uživatelských dat_145d47bd; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_69e0bf;Úložiště uživatelských dat_69e0bf; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_a05f079;Úložiště uživatelských dat_a05f079; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\Windows\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Re: Preventivka

Napsal: 29 srp 2016 17:20
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Preventivka

Napsal: 30 srp 2016 15:12
od jupiland
Já se omlouvám, ale nejde mi to sem vložit, ani text, ani print screen, ani vložit jako přílohu.... :/ nicméně nic to nenašlo...všude je napsáno "Nebyly nalezeny žádné škodlivé.... "

Re: Preventivka

Napsal: 30 srp 2016 17:02
od Rudy
Vy neznáte kopírovat/vložit? Program otevře textový soubor, zněhož text zkopírujete a sem vložíte.

Re: Preventivka

Napsal: 31 srp 2016 12:33
od jupiland
Tak zas tak hloupá nejsem ;) ale prostě to nejde...zkopíruju to, ale vložit to nejde, ani když to vyjmu, ani prostě nijak podobně....
Jakože to nejde vložit nikam, ani třeba do jinýho programu...prostě jak kdyby se to nezkopírovalo.... a ano, zkoušla jsem to klávesovou zkratkou i přes pravé tlačítko myši...nic :)

Re: Preventivka

Napsal: 31 srp 2016 17:16
od Rudy
Divné, že všem ostatním to jde. Pokud je to OK, dejte log FRST: http://forum.viry.cz/viewtopic.php?f=30&t=133101 . Budu-li mazat přímo z RSIT, riskuji poškození systému.

Re: Preventivka

Napsal: 07 zář 2016 14:59
od jupiland
Zdravím, moc se omlouvám, ale bohužel už nemám k PC přístup, byl pracovní a nakonec ho šéf vyměnil, takže....díky za pomoc a znovu se omlouvám.

Re: Preventivka

Napsal: 07 zář 2016 17:18
od Rudy
Měl byste číst pravidla: http://forum.viry.cz/viewtopic.php?f=12&t=5601 (bod 6). Podle tohoto ustanovení neservisujeme firemní PC. Důvod je uveden v pravidlech. Jsme servisem pouze pro home usery. Nemáte zač!.