Dobrý deň, poprosil by som kontrolu logu, vopred ďakujem.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2016-10-26 17:02:58
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 807 GB (85%) free of 954 GB
Total RAM: 8173 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:03:12, on 26.10.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18427)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Xerox PanelMgr] C:\Windows\Xerox\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9736 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {ED5BAB1C-62D2-4764-BE07-5043E5FB1B46}
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Steam\bin\cef\cef.winxp\steamwebhelper.exe" "-cachedir=C:\Users\Martin\AppData\Local\Steam\htmlcache" "-steampid=2308" "-buildid=1476379980" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe" -nogui
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3556
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
\??\C:\Windows\system32\conhost.exe "-982887960-14524691591984751659-17349593151414168172-7947726311974935762065866777
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8149928e-630d-48e9-9251-cce16c360138 -SystemEventPortName:HostProcess-97793fa2-2911-4c75-8fc0-9361d93786a2 -IoCancelEventPortName:HostProcess-66d511b3-9389-4044-9b30-72e6a060ded7 -NonStateChangingEventPortName:HostProcess-1508d89f-fec3-40e6-a14f-1818f7a16c7f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d6438aa0-9ffc-462a-bea7-be6bede6c85c -DeviceGroupId:WpdFsGroup
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Users\Martin\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\way0un3z.default-1474130697613
prefs.js - "browser.startup.homepage" - "google.sk"
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.185 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.55.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.185 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24 790552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24 664848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-06-15 2398776]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-10-13 2860832]
"Spotify Web Helper"=C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-10-12 1483888]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-08-26 8912088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2016-09-01 67384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2016-09-09 176440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShadowPlay]
C:\Windows\system32\nvspcap64.dll [2016-06-15 1767760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-10-12 1483888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XperiaCompanion]
C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [2016-05-26 2062208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XperiaCompanionAgent]
C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [2016-05-26 2062208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Obrazovková spinka a spúšťač programu OneNote 2010.lnk]
C:\PROGRA~2\MICROS~2\Office14\ONENOTEM.EXE [2015-10-13 228552]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Xerox PanelMgr"=C:\Windows\Xerox\PanelMgr\SSMMgr.exe [2008-09-11 540672]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-17 9083840]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
GIGABYTE OC_GURU.lnk - C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
TP-LINK Wireless Configuration Utility.lnk - C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 month======
2016-10-26 17:02:58 ----D---- C:\rsit
2016-10-17 17:35:05 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2016-10-17 17:34:31 ----D---- C:\Users\Martin\AppData\Roaming\AVAST Software
2016-10-17 17:34:05 ----A---- C:\Windows\system32\drivers\aswvmm.sys
2016-10-17 17:34:05 ----A---- C:\Windows\system32\drivers\aswStm.sys
2016-10-17 17:34:05 ----A---- C:\Windows\system32\drivers\aswsp.sys
2016-10-17 17:34:05 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2016-10-17 17:34:04 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2016-10-17 17:34:04 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2016-10-17 17:34:04 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2016-10-17 17:34:03 ----A---- C:\Windows\system32\drivers\aswsnx.sys
2016-10-17 17:33:42 ----A---- C:\Windows\system32\aswBoot.exe
2016-10-17 17:33:39 ----A---- C:\Windows\avastSS.scr
2016-10-17 17:33:03 ----D---- C:\Program Files\AVAST Software
2016-09-29 17:32:47 ----A---- C:\Windows\system32\drivers\582E1694.sys
2016-09-27 17:38:48 ----A---- C:\Windows\system32\drivers\06CD7EEB.sys
======List of files/folders modified in the last 1 month======
2016-10-26 17:03:00 ----D---- C:\Program Files\trend micro
2016-10-26 15:53:53 ----D---- C:\Windows\Temp
2016-10-26 15:45:37 ----D---- C:\Windows\system32\config
2016-10-26 15:30:29 ----D---- C:\Program Files (x86)\Steam
2016-10-26 15:30:12 ----D---- C:\ProgramData\NVIDIA
2016-10-26 08:59:44 ----D---- C:\ALFA
2016-10-25 17:42:22 ----D---- C:\Users\Martin\AppData\Roaming\TS3Client
2016-10-25 17:38:45 ----D---- C:\Windows\system32\drivers
2016-10-25 16:50:32 ----D---- C:\ProgramData
2016-10-22 15:29:17 ----D---- C:\Users\Martin\AppData\Roaming\Spotify
2016-10-22 10:24:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-10-21 18:41:06 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2016-10-21 18:22:03 ----SHD---- C:\Windows\Installer
2016-10-21 18:20:56 ----D---- C:\ProgramData\Skype
2016-10-21 18:20:31 ----SHD---- C:\System Volume Information
2016-10-19 18:45:02 ----D---- C:\ProgramData\Package Cache
2016-10-17 17:58:54 ----RD---- C:\Program Files (x86)\Skype
2016-10-17 17:58:54 ----D---- C:\Program Files (x86)\Common Files
2016-10-17 17:38:26 ----D---- C:\Windows\system32\Tasks
2016-10-17 17:35:05 ----D---- C:\ProgramData\AVAST Software
2016-10-17 17:33:44 ----D---- C:\Windows\winsxs
2016-10-17 17:33:42 ----D---- C:\Windows\System32
2016-10-17 17:33:42 ----D---- C:\Windows
2016-10-17 17:33:03 ----D---- C:\Program Files
2016-10-17 17:29:56 ----D---- C:\Windows\system32\DriverStore
2016-10-17 17:29:56 ----D---- C:\Windows\inf
2016-10-16 19:44:22 ----RSD---- C:\Windows\assembly
2016-10-16 19:43:28 ----D---- C:\Windows\Logs
2016-10-14 10:39:45 ----D---- C:\Windows\SysWOW64
2016-10-11 18:49:17 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-10-11 18:49:10 ----D---- C:\Windows\system32\Macromed
2016-10-11 18:49:04 ----D---- C:\Windows\SYSWOW64\Macromed
2016-10-10 08:55:16 ----D---- C:\Program Files\Common Files\AV
2016-10-09 18:27:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-10-09 17:42:57 ----D---- C:\Program Files\CCleaner
2016-10-06 20:37:09 ----RD---- C:\Program Files (x86)
2016-10-06 20:37:09 ----D---- C:\ProgramData\Kaspersky Lab
2016-10-06 20:37:07 ----D---- C:\Windows\ELAMBKUP
2016-10-06 20:31:35 ----SD---- C:\Windows\system32\Microsoft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-10-17 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-10-17 293352]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-11-02 21616]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-10-17 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-10-17 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-10-17 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-10-17 513632]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 40816]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-10-17 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-10-17 163416]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2006-11-15 11576]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2014-05-23 1930240]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-07-29 56960]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-07-29 79104]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2016-08-26 223304]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-06-15 28216]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-04-14 56384]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S2 Angelnt;Angelnt; C:\Windows\System32\Drivers\ANGELNT.SYS []
S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2006-11-15 54072]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-10-17 37656]
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2013-12-04 44640]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2015-01-17 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2015-01-17 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2015-01-17 30528]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service; C:\Windows\system32\DRIVERS\InputFilter_FlexDef2b.sys [2010-06-19 17920]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 MouFilter_Mou_FlexDef4;HID Mouse(FlexDef4) Driver Service; C:\Windows\system32\DRIVERS\MouFilter_FlexDef4.sys [2010-10-20 15360]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-10 54784]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-09-16 82128]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-08-05 83768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-10-17 197128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-06-15 1165368]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-06-15 1881144]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-06-15 2522680]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2016-08-25 1362368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [2016-08-25 424384]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-06-15 3634232]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-11 270016]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2015-10-21 1369856]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-08-02 114688]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-09-09 651576]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-08-04 2122248]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-04 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Kontrola logu
Problem ani nie, len naposledy keď som dal vyhladavanie na googli mi google napisal: "nezvyčajna aktivita z vašej siete" a pytal odomňa captcha kod a na internete som sa dočital že to môže spôsobovať virus, tak preto ten log.
Re: Kontrola logu
Dobrá tak se mrknem hlouběji.
Stáhni a spusť AdwCleaner,
ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,
objeví se okno kde vlevo nahoře klikni na Scan.
Po dokončení skenu klikni na Clean,
proběhne restart PC kdy dojde ke smazání nepořádku.
Po té mi sem zkopíruj Report.
Spusť skener Cure It podle TOHOTO návodu
po skončení skenu mi sem nakopíruj výsledky - stačí konec logu se souhrnem.
(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Stáhni a spusť AdwCleaner,
ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,
objeví se okno kde vlevo nahoře klikni na Scan.
Po dokončení skenu klikni na Clean,
proběhne restart PC kdy dojde ke smazání nepořádku.
Po té mi sem zkopíruj Report.
Spusť skener Cure It podle TOHOTO návodu
po skončení skenu mi sem nakopíruj výsledky - stačí konec logu se souhrnem.
(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Re: Kontrola logu
OK, dal som všetko skontrolovať a tu sú tie výpisy.
Adwcleaner
# AdwCleaner v6.030 - *Logfile created 29/10/2016 *at 15:03:33
# *Updated on 19/10/2016 by Malwarebytes
# *Database : 2016-10-18.1 [*Local]
# *Operating System : Windows 7 Professional Service Pack 1 (X64)
# *Username : Martin - MARTIN-PC
# *Running from : C:\Users\Martin\Downloads\adwcleaner_6.030.exe
# *Mode: Clean
# *Support : hxxps://www.malwarebytes.com/support
***** [ *Services ] *****
***** [ *Folders ] *****
***** [ *Files ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ *Shortcuts ] *****
***** [ *Scheduled Tasks ] *****
***** [ *Registry ] *****
***** [ *Browsers ] *****
*************************
:: *"Tracing" keys deleted
:: *Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [790 *Bytes] - [29/10/2016 15:03:33]
C:\AdwCleaner\AdwCleaner[S0].txt - [1196 *Bytes] - [29/10/2016 15:03:23]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [937 *Bytes] ##########
Dr. Web scanner Cureit (len tu som nikde nenašiel úplnú kontrolu, tak som dal vlastnú a vybral to, čo mi program ponúkal)
Total 11866054406 bytes in 31623 files scanned (38203 objects)
Total 31592 files (38169 objects) are clean
There are no infected objects detected
Total 33 files are raised error condition
Scan time is 00:06:51.977
ComboFix
ComboFix 16-10-23.01 - Martin 29.10.2016 15:45:44.2.6 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1051.18.8173.6475 [GMT 2:00]
Running from: c:\users\Martin\Desktop\ComboFix.exe
AV: Avast Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Avast Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2016-09-28 to 2016-10-29 )))))))))))))))))))))))))))))))
.
.
2016-10-29 13:53 . 2016-10-29 13:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2016-10-29 13:53 . 2016-10-29 13:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-10-29 13:06 . 2016-10-29 13:06 -------- d-----w- c:\users\Martin\Doctor Web
2016-10-29 13:00 . 2016-10-29 13:03 -------- d-----w- C:\AdwCleaner
2016-10-26 15:02 . 2016-10-26 15:03 -------- d-----w- C:\rsit
2016-10-17 15:58 . 2016-10-17 15:58 -------- d-----w- c:\program files (x86)\Common Files\Skype
2016-09-29 15:32 . 2016-09-29 15:32 192216 ----a-w- c:\windows\system32\drivers\582E1694.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-10-29 13:42 . 2016-09-17 10:48 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-10-27 04:49 . 2012-12-29 08:47 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-10-27 04:49 . 2012-12-29 08:47 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-09-27 15:38 . 2016-09-27 15:38 192216 ----a-w- c:\windows\system32\drivers\06CD7EEB.sys
2016-09-18 11:56 . 2016-09-18 11:56 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9E0BB92C-E613-4557-BEA9-C77B269F2F0E}\offreg.5856.dll
2016-09-17 17:16 . 2016-09-17 17:16 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9E0BB92C-E613-4557-BEA9-C77B269F2F0E}\offreg.6464.dll
2016-08-25 23:28 . 2016-09-18 08:10 9086856 ----a-w- c:\windows\SysWow64\nvopencl.dll
2016-08-25 23:28 . 2016-09-18 08:10 8875408 ----a-w- c:\windows\SysWow64\nvptxJitCompiler.dll
2016-08-25 23:28 . 2016-09-18 08:10 54728 ----a-w- c:\windows\system32\nvhdap64.dll
2016-08-25 23:28 . 2016-09-18 08:10 493608 ----a-w- c:\windows\system32\nvumdshimx.dll
2016-08-25 23:28 . 2016-09-18 08:10 408784 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2016-08-25 23:28 . 2016-09-18 08:10 34801088 ----a-w- c:\windows\system32\nvoglv64.dll
2016-08-25 23:28 . 2016-09-18 08:10 28207672 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2016-08-25 23:28 . 2016-09-18 08:10 223304 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2016-08-25 23:28 . 2016-09-18 08:10 17263792 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2016-08-25 23:28 . 2016-09-18 08:10 153368 ----a-w- c:\windows\system32\nvoglshim64.dll
2016-08-25 23:28 . 2016-09-18 08:10 131536 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2016-08-25 23:28 . 2016-09-18 08:10 10865704 ----a-w- c:\windows\system32\nvptxJitCompiler.dll
2016-08-25 23:28 . 2016-09-18 08:10 10737632 ----a-w- c:\windows\system32\nvopencl.dll
2016-08-25 23:28 . 2016-09-18 08:10 956352 ----a-w- c:\windows\SysWow64\NvFBC.dll
2016-08-25 23:28 . 2016-09-18 08:10 941504 ----a-w- c:\windows\system32\NvIFR64.dll
2016-08-25 23:28 . 2016-09-18 08:10 892864 ----a-w- c:\windows\SysWow64\NvIFR.dll
2016-08-25 23:28 . 2016-09-18 08:10 8680696 ----a-w- c:\windows\SysWow64\nvcuda.dll
2016-08-25 23:28 . 2016-09-18 08:10 686896 ----a-w- c:\windows\system32\nvfatbinaryLoader.dll
2016-08-25 23:28 . 2016-09-18 08:10 575984 ----a-w- c:\windows\SysWow64\nvfatbinaryLoader.dll
2016-08-25 23:28 . 2016-09-18 08:10 520912 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2016-08-25 23:28 . 2016-09-18 08:10 437696 ----a-w- c:\windows\system32\NvIFROpenGL.dll
2016-08-25 23:28 . 2016-09-18 08:10 436088 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2016-08-25 23:28 . 2016-09-18 08:10 390200 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll
2016-08-25 23:28 . 2016-09-18 08:10 3594808 ----a-w- c:\windows\system32\nvcuvid.dll
2016-08-25 23:28 . 2016-09-18 08:10 3160512 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2016-08-25 23:28 . 2016-09-18 08:10 1920960 ----a-w- c:\windows\system32\nvdispco6437270.dll
2016-08-25 23:28 . 2016-09-18 08:10 181488 ----a-w- c:\windows\system32\nvinitx.dll
2016-08-25 23:28 . 2016-09-18 08:10 17463088 ----a-w- c:\windows\system32\nvd3dumx.dll
2016-08-25 23:28 . 2016-09-18 08:10 159352 ----a-w- c:\windows\SysWow64\nvinit.dll
2016-08-25 23:28 . 2016-09-18 08:10 1586744 ----a-w- c:\windows\system32\nvdispgenco6437270.dll
2016-08-25 23:28 . 2016-09-18 08:10 14093368 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2016-08-25 23:28 . 2016-09-18 08:10 10278080 ----a-w- c:\windows\system32\nvcuda.dll
2016-08-25 23:28 . 2016-09-18 08:10 1019960 ----a-w- c:\windows\system32\NvFBC64.dll
2016-08-25 23:28 . 2016-09-18 08:10 40070200 ----a-w- c:\windows\system32\nvcompiler.dll
2016-08-25 23:28 . 2016-09-18 08:10 35182648 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2016-08-25 23:28 . 2015-02-02 08:54 3917512 ----a-w- c:\windows\system32\nvapi64.dll
2016-08-25 23:28 . 2015-02-02 08:54 3456888 ----a-w- c:\windows\SysWow64\nvapi.dll
2016-08-25 23:28 . 2015-02-02 08:54 19848080 ----a-w- c:\windows\system32\nvwgf2umx.dll
2016-08-25 23:28 . 2015-02-02 08:54 14352816 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2016-08-25 23:28 . 2014-11-22 08:19 1588688 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2016-08-25 21:10 . 2016-03-16 10:02 2475064 ----a-w- c:\windows\system32\nvsvc64.dll
2016-08-25 21:10 . 2016-03-16 10:02 6385720 ----a-w- c:\windows\system32\nvcpl.dll
2016-08-25 21:10 . 2016-03-16 10:02 1764408 ----a-w- c:\windows\system32\nvsvcr.dll
2016-08-25 21:10 . 2016-03-16 10:02 1362368 ----a-w- c:\windows\system32\nvvsvc.exe
2016-08-25 21:10 . 2016-03-16 10:35 81856 ----a-w- c:\windows\system32\nv3dappshextr.dll
2016-08-25 21:10 . 2016-03-16 10:35 548408 ----a-w- c:\windows\system32\nv3dappshext.dll
2016-08-25 21:10 . 2016-03-16 10:02 71224 ----a-w- c:\windows\system32\nvshext.dll
2016-08-25 21:10 . 2016-03-16 10:02 393784 ----a-w- c:\windows\system32\nvmctray.dll
2016-08-25 20:50 . 2016-09-18 08:13 133056 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2016-08-22 15:18 . 2016-03-16 10:02 7320235 ----a-w- c:\windows\system32\nvcoproc.bin
2016-08-10 19:05 . 2012-12-03 14:00 147640136 -c--a-w- c:\windows\system32\MRT.exe
2016-08-08 12:06 . 2016-08-08 12:05 11376 ----a-w- c:\windows\SysWow64\drivers\SECDRV.SYS
2016-08-02 22:36 . 2016-09-13 14:17 11847048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9E0BB92C-E613-4557-BEA9-C77B269F2F0E}\mpengine.dll
2016-08-02 14:54 . 2016-08-10 15:46 394440 ----a-w- c:\windows\system32\iedkcs32.dll
2016-08-02 06:54 . 2016-08-10 15:46 25808384 ----a-w- c:\windows\system32\mshtml.dll
2016-08-02 06:47 . 2016-08-10 15:46 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2016-08-02 06:47 . 2016-08-10 15:46 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2016-08-02 06:32 . 2016-08-10 15:46 66560 ----a-w- c:\windows\system32\iesetup.dll
2016-08-02 06:32 . 2016-08-10 15:46 2894336 ----a-w- c:\windows\system32\iertutil.dll
2016-08-02 06:31 . 2016-08-10 15:46 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2016-08-02 06:31 . 2016-08-10 15:46 417792 ----a-w- c:\windows\system32\html.iec
2016-08-02 06:31 . 2016-08-10 15:46 572416 ----a-w- c:\windows\system32\vbscript.dll
2016-08-02 06:31 . 2016-08-10 15:46 88064 ----a-w- c:\windows\system32\MshtmlDac.dll
2016-08-02 06:24 . 2016-08-10 15:46 54784 ----a-w- c:\windows\system32\jsproxy.dll
2016-08-02 06:23 . 2016-08-10 15:46 34304 ----a-w- c:\windows\system32\iernonce.dll
2016-08-02 06:20 . 2016-08-10 15:46 615936 ----a-w- c:\windows\system32\ieui.dll
2016-08-02 06:19 . 2016-08-10 15:46 114688 ----a-w- c:\windows\system32\ieetwcollector.exe
2016-08-02 06:19 . 2016-08-10 15:46 144384 ----a-w- c:\windows\system32\ieUnatt.exe
2016-08-02 06:18 . 2016-08-10 15:46 814080 ----a-w- c:\windows\system32\jscript9diag.dll
2016-08-02 06:18 . 2016-08-10 15:46 817664 ----a-w- c:\windows\system32\jscript.dll
2016-08-02 06:18 . 2016-08-10 15:46 6047744 ----a-w- c:\windows\system32\jscript9.dll
2016-08-02 06:11 . 2016-08-10 15:46 969216 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2016-08-02 06:08 . 2016-08-10 15:46 489984 ----a-w- c:\windows\system32\dxtmsft.dll
2016-08-02 06:03 . 2016-08-10 15:46 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2016-08-02 06:00 . 2016-08-10 15:46 77824 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2016-08-02 05:59 . 2016-08-10 15:46 107520 ----a-w- c:\windows\system32\inseng.dll
2016-08-02 05:56 . 2016-08-10 15:46 199680 ----a-w- c:\windows\system32\msrating.dll
2016-08-02 05:55 . 2016-08-10 15:46 92160 ----a-w- c:\windows\system32\mshtmled.dll
2016-08-02 05:53 . 2016-08-10 15:46 315392 ----a-w- c:\windows\system32\dxtrans.dll
2016-08-02 05:51 . 2016-08-10 15:46 497664 ----a-w- c:\windows\SysWow64\vbscript.dll
2016-08-02 05:51 . 2016-08-10 15:46 62464 ----a-w- c:\windows\SysWow64\iesetup.dll
2016-08-02 05:51 . 2016-08-10 15:46 152064 ----a-w- c:\windows\system32\occache.dll
2016-08-02 05:51 . 2016-08-10 15:46 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2016-08-02 05:51 . 2016-08-10 15:46 341504 ----a-w- c:\windows\SysWow64\html.iec
2016-08-02 05:50 . 2016-08-10 15:46 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2016-08-02 05:41 . 2016-08-10 15:46 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2016-08-02 05:41 . 2016-08-10 15:46 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2016-08-02 05:40 . 2016-08-10 15:46 262144 ----a-w- c:\windows\system32\webcheck.dll
2016-08-02 05:38 . 2016-08-10 15:46 724992 ----a-w- c:\windows\system32\ie4uinit.exe
2016-08-02 05:38 . 2016-08-10 15:46 806400 ----a-w- c:\windows\system32\msfeeds.dll
2016-08-02 05:37 . 2016-08-10 15:46 1359360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2016-08-02 05:36 . 2016-08-10 15:46 2131456 ----a-w- c:\windows\system32\inetcpl.cpl
2016-08-02 05:29 . 2016-08-10 15:46 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2016-08-02 05:28 . 2016-08-10 15:46 15412224 ----a-w- c:\windows\system32\ieframe.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2016-10-13 2860832]
"Spotify Web Helper"="c:\users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2016-10-12 1483888]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2016-08-26 8912088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Xerox PanelMgr"="c:\windows\Xerox\PanelMgr\SSMMgr.exe" [2008-09-11 540672]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2016-10-28 9099440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2012-8-14 17432576]
TP-LINK Wireless Configuration Utility.lnk - c:\program files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe -nogui [2015-2-5 847872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 Angelnt;Angelnt;c:\windows\System32\Drivers\ANGELNT.SYS;c:\windows\SYSNATIVE\Drivers\ANGELNT.SYS [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2b.sys;c:\windows\SYSNATIVE\DRIVERS\InputFilter_FlexDef2b.sys [x]
R3 MouFilter_Mou_FlexDef4;HID Mouse(FlexDef4) Driver Service;c:\windows\system32\DRIVERS\MouFilter_FlexDef4.sys;c:\windows\SYSNATIVE\DRIVERS\MouFilter_FlexDef4.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 458561B0B0063FA1
*NewlyCreated* - 4F9562ACBA163CBD
*NewlyCreated* - NVSTREAMKMS
*Deregistered* - 458561B0B0063FA1
*Deregistered* - 4F9562ACBA163CBD
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2016-10-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-29 04:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2016-07-29 07:34 774104 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2016-07-29 07:34 774104 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2016-07-29 07:34 774104 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-10-17 15:33 1031520 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-06-15 2398776]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com/search?q={searchTerms}&r ... d=ie7&rlz=
mSearch Bar = www.google.com
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\way0un3z.default-1474130697613\
FF - prefs.js: browser.startup.homepage - google.sk
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1441774576-3188419790-1742766605-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1441774576-3188419790-1742766605-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-1441774576-3188419790-1742766605-1000\Software\SecuROM\License information*]
"datasecu"=hex:9c,53,9d,d1,f9,58,34,5b,d6,47,77,34,f1,2a,21,84,e9,d6,b5,68,e0,
f2,a1,4a,61,40,c4,f2,30,3b,e5,21,e8,dd,f7,d0,b2,6b,df,57,2b,29,23,c4,ca,7d,\
"rkeysecu"=hex:13,f8,18,3b,7d,2b,74,92,79,6f,3f,ad,f9,c0,16,03
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2016-10-29 15:56:11
ComboFix-quarantined-files.txt 2016-10-29 13:56
.
Pre-Run: 852 833 824 768 bytes free
Post-Run: 852 546 723 840 bytes free
.
- - End Of File - - 5665D65DE8642348B6DBA3433F5BC0F3
Adwcleaner
# AdwCleaner v6.030 - *Logfile created 29/10/2016 *at 15:03:33
# *Updated on 19/10/2016 by Malwarebytes
# *Database : 2016-10-18.1 [*Local]
# *Operating System : Windows 7 Professional Service Pack 1 (X64)
# *Username : Martin - MARTIN-PC
# *Running from : C:\Users\Martin\Downloads\adwcleaner_6.030.exe
# *Mode: Clean
# *Support : hxxps://www.malwarebytes.com/support
***** [ *Services ] *****
***** [ *Folders ] *****
***** [ *Files ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ *Shortcuts ] *****
***** [ *Scheduled Tasks ] *****
***** [ *Registry ] *****
***** [ *Browsers ] *****
*************************
:: *"Tracing" keys deleted
:: *Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [790 *Bytes] - [29/10/2016 15:03:33]
C:\AdwCleaner\AdwCleaner[S0].txt - [1196 *Bytes] - [29/10/2016 15:03:23]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [937 *Bytes] ##########
Dr. Web scanner Cureit (len tu som nikde nenašiel úplnú kontrolu, tak som dal vlastnú a vybral to, čo mi program ponúkal)
Total 11866054406 bytes in 31623 files scanned (38203 objects)
Total 31592 files (38169 objects) are clean
There are no infected objects detected
Total 33 files are raised error condition
Scan time is 00:06:51.977
ComboFix
ComboFix 16-10-23.01 - Martin 29.10.2016 15:45:44.2.6 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1051.18.8173.6475 [GMT 2:00]
Running from: c:\users\Martin\Desktop\ComboFix.exe
AV: Avast Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Avast Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2016-09-28 to 2016-10-29 )))))))))))))))))))))))))))))))
.
.
2016-10-29 13:53 . 2016-10-29 13:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2016-10-29 13:53 . 2016-10-29 13:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-10-29 13:06 . 2016-10-29 13:06 -------- d-----w- c:\users\Martin\Doctor Web
2016-10-29 13:00 . 2016-10-29 13:03 -------- d-----w- C:\AdwCleaner
2016-10-26 15:02 . 2016-10-26 15:03 -------- d-----w- C:\rsit
2016-10-17 15:58 . 2016-10-17 15:58 -------- d-----w- c:\program files (x86)\Common Files\Skype
2016-09-29 15:32 . 2016-09-29 15:32 192216 ----a-w- c:\windows\system32\drivers\582E1694.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-10-29 13:42 . 2016-09-17 10:48 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-10-27 04:49 . 2012-12-29 08:47 796352 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-10-27 04:49 . 2012-12-29 08:47 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-09-27 15:38 . 2016-09-27 15:38 192216 ----a-w- c:\windows\system32\drivers\06CD7EEB.sys
2016-09-18 11:56 . 2016-09-18 11:56 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9E0BB92C-E613-4557-BEA9-C77B269F2F0E}\offreg.5856.dll
2016-09-17 17:16 . 2016-09-17 17:16 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9E0BB92C-E613-4557-BEA9-C77B269F2F0E}\offreg.6464.dll
2016-08-25 23:28 . 2016-09-18 08:10 9086856 ----a-w- c:\windows\SysWow64\nvopencl.dll
2016-08-25 23:28 . 2016-09-18 08:10 8875408 ----a-w- c:\windows\SysWow64\nvptxJitCompiler.dll
2016-08-25 23:28 . 2016-09-18 08:10 54728 ----a-w- c:\windows\system32\nvhdap64.dll
2016-08-25 23:28 . 2016-09-18 08:10 493608 ----a-w- c:\windows\system32\nvumdshimx.dll
2016-08-25 23:28 . 2016-09-18 08:10 408784 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2016-08-25 23:28 . 2016-09-18 08:10 34801088 ----a-w- c:\windows\system32\nvoglv64.dll
2016-08-25 23:28 . 2016-09-18 08:10 28207672 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2016-08-25 23:28 . 2016-09-18 08:10 223304 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
2016-08-25 23:28 . 2016-09-18 08:10 17263792 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2016-08-25 23:28 . 2016-09-18 08:10 153368 ----a-w- c:\windows\system32\nvoglshim64.dll
2016-08-25 23:28 . 2016-09-18 08:10 131536 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2016-08-25 23:28 . 2016-09-18 08:10 10865704 ----a-w- c:\windows\system32\nvptxJitCompiler.dll
2016-08-25 23:28 . 2016-09-18 08:10 10737632 ----a-w- c:\windows\system32\nvopencl.dll
2016-08-25 23:28 . 2016-09-18 08:10 956352 ----a-w- c:\windows\SysWow64\NvFBC.dll
2016-08-25 23:28 . 2016-09-18 08:10 941504 ----a-w- c:\windows\system32\NvIFR64.dll
2016-08-25 23:28 . 2016-09-18 08:10 892864 ----a-w- c:\windows\SysWow64\NvIFR.dll
2016-08-25 23:28 . 2016-09-18 08:10 8680696 ----a-w- c:\windows\SysWow64\nvcuda.dll
2016-08-25 23:28 . 2016-09-18 08:10 686896 ----a-w- c:\windows\system32\nvfatbinaryLoader.dll
2016-08-25 23:28 . 2016-09-18 08:10 575984 ----a-w- c:\windows\SysWow64\nvfatbinaryLoader.dll
2016-08-25 23:28 . 2016-09-18 08:10 520912 ----a-w- c:\windows\system32\nvEncodeAPI64.dll
2016-08-25 23:28 . 2016-09-18 08:10 437696 ----a-w- c:\windows\system32\NvIFROpenGL.dll
2016-08-25 23:28 . 2016-09-18 08:10 436088 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll
2016-08-25 23:28 . 2016-09-18 08:10 390200 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll
2016-08-25 23:28 . 2016-09-18 08:10 3594808 ----a-w- c:\windows\system32\nvcuvid.dll
2016-08-25 23:28 . 2016-09-18 08:10 3160512 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2016-08-25 23:28 . 2016-09-18 08:10 1920960 ----a-w- c:\windows\system32\nvdispco6437270.dll
2016-08-25 23:28 . 2016-09-18 08:10 181488 ----a-w- c:\windows\system32\nvinitx.dll
2016-08-25 23:28 . 2016-09-18 08:10 17463088 ----a-w- c:\windows\system32\nvd3dumx.dll
2016-08-25 23:28 . 2016-09-18 08:10 159352 ----a-w- c:\windows\SysWow64\nvinit.dll
2016-08-25 23:28 . 2016-09-18 08:10 1586744 ----a-w- c:\windows\system32\nvdispgenco6437270.dll
2016-08-25 23:28 . 2016-09-18 08:10 14093368 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2016-08-25 23:28 . 2016-09-18 08:10 10278080 ----a-w- c:\windows\system32\nvcuda.dll
2016-08-25 23:28 . 2016-09-18 08:10 1019960 ----a-w- c:\windows\system32\NvFBC64.dll
2016-08-25 23:28 . 2016-09-18 08:10 40070200 ----a-w- c:\windows\system32\nvcompiler.dll
2016-08-25 23:28 . 2016-09-18 08:10 35182648 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2016-08-25 23:28 . 2015-02-02 08:54 3917512 ----a-w- c:\windows\system32\nvapi64.dll
2016-08-25 23:28 . 2015-02-02 08:54 3456888 ----a-w- c:\windows\SysWow64\nvapi.dll
2016-08-25 23:28 . 2015-02-02 08:54 19848080 ----a-w- c:\windows\system32\nvwgf2umx.dll
2016-08-25 23:28 . 2015-02-02 08:54 14352816 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2016-08-25 23:28 . 2014-11-22 08:19 1588688 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2016-08-25 21:10 . 2016-03-16 10:02 2475064 ----a-w- c:\windows\system32\nvsvc64.dll
2016-08-25 21:10 . 2016-03-16 10:02 6385720 ----a-w- c:\windows\system32\nvcpl.dll
2016-08-25 21:10 . 2016-03-16 10:02 1764408 ----a-w- c:\windows\system32\nvsvcr.dll
2016-08-25 21:10 . 2016-03-16 10:02 1362368 ----a-w- c:\windows\system32\nvvsvc.exe
2016-08-25 21:10 . 2016-03-16 10:35 81856 ----a-w- c:\windows\system32\nv3dappshextr.dll
2016-08-25 21:10 . 2016-03-16 10:35 548408 ----a-w- c:\windows\system32\nv3dappshext.dll
2016-08-25 21:10 . 2016-03-16 10:02 71224 ----a-w- c:\windows\system32\nvshext.dll
2016-08-25 21:10 . 2016-03-16 10:02 393784 ----a-w- c:\windows\system32\nvmctray.dll
2016-08-25 20:50 . 2016-09-18 08:13 133056 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2016-08-22 15:18 . 2016-03-16 10:02 7320235 ----a-w- c:\windows\system32\nvcoproc.bin
2016-08-10 19:05 . 2012-12-03 14:00 147640136 -c--a-w- c:\windows\system32\MRT.exe
2016-08-08 12:06 . 2016-08-08 12:05 11376 ----a-w- c:\windows\SysWow64\drivers\SECDRV.SYS
2016-08-02 22:36 . 2016-09-13 14:17 11847048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9E0BB92C-E613-4557-BEA9-C77B269F2F0E}\mpengine.dll
2016-08-02 14:54 . 2016-08-10 15:46 394440 ----a-w- c:\windows\system32\iedkcs32.dll
2016-08-02 06:54 . 2016-08-10 15:46 25808384 ----a-w- c:\windows\system32\mshtml.dll
2016-08-02 06:47 . 2016-08-10 15:46 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2016-08-02 06:47 . 2016-08-10 15:46 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2016-08-02 06:32 . 2016-08-10 15:46 66560 ----a-w- c:\windows\system32\iesetup.dll
2016-08-02 06:32 . 2016-08-10 15:46 2894336 ----a-w- c:\windows\system32\iertutil.dll
2016-08-02 06:31 . 2016-08-10 15:46 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2016-08-02 06:31 . 2016-08-10 15:46 417792 ----a-w- c:\windows\system32\html.iec
2016-08-02 06:31 . 2016-08-10 15:46 572416 ----a-w- c:\windows\system32\vbscript.dll
2016-08-02 06:31 . 2016-08-10 15:46 88064 ----a-w- c:\windows\system32\MshtmlDac.dll
2016-08-02 06:24 . 2016-08-10 15:46 54784 ----a-w- c:\windows\system32\jsproxy.dll
2016-08-02 06:23 . 2016-08-10 15:46 34304 ----a-w- c:\windows\system32\iernonce.dll
2016-08-02 06:20 . 2016-08-10 15:46 615936 ----a-w- c:\windows\system32\ieui.dll
2016-08-02 06:19 . 2016-08-10 15:46 114688 ----a-w- c:\windows\system32\ieetwcollector.exe
2016-08-02 06:19 . 2016-08-10 15:46 144384 ----a-w- c:\windows\system32\ieUnatt.exe
2016-08-02 06:18 . 2016-08-10 15:46 814080 ----a-w- c:\windows\system32\jscript9diag.dll
2016-08-02 06:18 . 2016-08-10 15:46 817664 ----a-w- c:\windows\system32\jscript.dll
2016-08-02 06:18 . 2016-08-10 15:46 6047744 ----a-w- c:\windows\system32\jscript9.dll
2016-08-02 06:11 . 2016-08-10 15:46 969216 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2016-08-02 06:08 . 2016-08-10 15:46 489984 ----a-w- c:\windows\system32\dxtmsft.dll
2016-08-02 06:03 . 2016-08-10 15:46 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2016-08-02 06:00 . 2016-08-10 15:46 77824 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2016-08-02 05:59 . 2016-08-10 15:46 107520 ----a-w- c:\windows\system32\inseng.dll
2016-08-02 05:56 . 2016-08-10 15:46 199680 ----a-w- c:\windows\system32\msrating.dll
2016-08-02 05:55 . 2016-08-10 15:46 92160 ----a-w- c:\windows\system32\mshtmled.dll
2016-08-02 05:53 . 2016-08-10 15:46 315392 ----a-w- c:\windows\system32\dxtrans.dll
2016-08-02 05:51 . 2016-08-10 15:46 497664 ----a-w- c:\windows\SysWow64\vbscript.dll
2016-08-02 05:51 . 2016-08-10 15:46 62464 ----a-w- c:\windows\SysWow64\iesetup.dll
2016-08-02 05:51 . 2016-08-10 15:46 152064 ----a-w- c:\windows\system32\occache.dll
2016-08-02 05:51 . 2016-08-10 15:46 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2016-08-02 05:51 . 2016-08-10 15:46 341504 ----a-w- c:\windows\SysWow64\html.iec
2016-08-02 05:50 . 2016-08-10 15:46 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2016-08-02 05:41 . 2016-08-10 15:46 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2016-08-02 05:41 . 2016-08-10 15:46 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2016-08-02 05:40 . 2016-08-10 15:46 262144 ----a-w- c:\windows\system32\webcheck.dll
2016-08-02 05:38 . 2016-08-10 15:46 724992 ----a-w- c:\windows\system32\ie4uinit.exe
2016-08-02 05:38 . 2016-08-10 15:46 806400 ----a-w- c:\windows\system32\msfeeds.dll
2016-08-02 05:37 . 2016-08-10 15:46 1359360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2016-08-02 05:36 . 2016-08-10 15:46 2131456 ----a-w- c:\windows\system32\inetcpl.cpl
2016-08-02 05:29 . 2016-08-10 15:46 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2016-08-02 05:28 . 2016-08-10 15:46 15412224 ----a-w- c:\windows\system32\ieframe.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2016-10-13 2860832]
"Spotify Web Helper"="c:\users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [2016-10-12 1483888]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2016-08-26 8912088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"Xerox PanelMgr"="c:\windows\Xerox\PanelMgr\SSMMgr.exe" [2008-09-11 540672]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2016-10-28 9099440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2012-8-14 17432576]
TP-LINK Wireless Configuration Utility.lnk - c:\program files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe -nogui [2015-2-5 847872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 Angelnt;Angelnt;c:\windows\System32\Drivers\ANGELNT.SYS;c:\windows\SYSNATIVE\Drivers\ANGELNT.SYS [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x]
R3 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2b.sys;c:\windows\SYSNATIVE\DRIVERS\InputFilter_FlexDef2b.sys [x]
R3 MouFilter_Mou_FlexDef4;HID Mouse(FlexDef4) Driver Service;c:\windows\system32\DRIVERS\MouFilter_FlexDef4.sys;c:\windows\SYSNATIVE\DRIVERS\MouFilter_FlexDef4.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [x]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 458561B0B0063FA1
*NewlyCreated* - 4F9562ACBA163CBD
*NewlyCreated* - NVSTREAMKMS
*Deregistered* - 458561B0B0063FA1
*Deregistered* - 4F9562ACBA163CBD
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2016-10-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-29 04:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2016-07-29 07:34 774104 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2016-07-29 07:34 774104 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2016-07-29 07:34 774104 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-10-17 15:33 1031520 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2016-06-15 2398776]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com/search?q={searchTerms}&r ... d=ie7&rlz=
mSearch Bar = www.google.com
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&oslať do programu OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\way0un3z.default-1474130697613\
FF - prefs.js: browser.startup.homepage - google.sk
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1441774576-3188419790-1742766605-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1441774576-3188419790-1742766605-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-1441774576-3188419790-1742766605-1000\Software\SecuROM\License information*]
"datasecu"=hex:9c,53,9d,d1,f9,58,34,5b,d6,47,77,34,f1,2a,21,84,e9,d6,b5,68,e0,
f2,a1,4a,61,40,c4,f2,30,3b,e5,21,e8,dd,f7,d0,b2,6b,df,57,2b,29,23,c4,ca,7d,\
"rkeysecu"=hex:13,f8,18,3b,7d,2b,74,92,79,6f,3f,ad,f9,c0,16,03
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2016-10-29 15:56:11
ComboFix-quarantined-files.txt 2016-10-29 13:56
.
Pre-Run: 852 833 824 768 bytes free
Post-Run: 852 546 723 840 bytes free
.
- - End Of File - - 5665D65DE8642348B6DBA3433F5BC0F3
Re: Kontrola logu
Porovnáno, uklizeno
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Pak dej vědět co ten problém s prohlížečem.

Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Pak dej vědět co ten problém s prohlížečem.
Re: Kontrola logu
Ďakujem za pomoc, prehliadač to spravil iba vtedy raz a odvtedy pokoj. Pokiaľ by som náhodou zistil čo to spôsobovalo dám vedieť.