Stránka 1 z 1

Prosím o kontrolu

Napsal: 05 lis 2016 19:44
od M.Lukes
Dobrý den,
poprosil bych kontrolu logu.. něják se mi nezdá dostatečná rychlost ntb a tak i celkově. Díky

Kód: Vybrat vše

Logfile of random's system information tool 1.14 (written by random/random) 
Run by Lukes at 2016-11-05 19:34:20
Microsoft Windows 8.1 
System drive C: has 202 GB (53%) free of 382 GB
Total RAM: 3982 MB (49% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:34:26, on 5. 11. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe
C:\Program Files\trend micro\Lukes_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 65.112.87.186 master.gamespy.com
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8554 bytes

======Enumerating Processes======

C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe  -first
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -l 3 -c
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" 
C:\Windows\system32\taskhostex.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\dashost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" 
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" 
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\DllHost.exe /Processid:{86D5EB8A-859F-4C7B-A76B-2BD819B7A850}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" 
"C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe" 
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe17_ Global\UsGthrCtrlFltPipeMssGthrPipe17 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 
C:\Windows\system32\taskhost.exe
"C:\Windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564 
"C:\Users\Lukes\Downloads\RSITx64.exe" 

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\ASUS Splendid ACMON - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\system32\tasks\ATK Package 36D18D69AFC3 - "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe" -CancelShutdown
C:\Windows\system32\tasks\avast! Emergency Update - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1465549442 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\{5650F51D-AA2F-4F8F-9CA1-F6AE42EC8F6C} - C:\Windows\system32\pcalua.exe -a C:\Users\Lukes\Desktop\gtasa120cz.exe -d C:\Users\Lukes\Desktop
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default

prefs.js - "browser.startup.homepage" -  "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" -  "http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&"

"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.205 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.205 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll


C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\
superstart@enjoyfreeware.org

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\searchplugins\
seznam-avast.xml

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Download YouTube Videos as MP4 - extension - {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}
Turn Off the Lights - extension - stefanvandamme@stefanvd.net
Super Start - extension - superstart@enjoyfreeware.org

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions.json
Super Start - extension - superstart@enjoyfreeware.org - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\superstart@enjoyfreeware.org
Who Deleted Me - extension - whodeletedme@deleted.io - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\whodeletedme@deleted.io.xpi
Avast Online Security - extension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF
Avast SafePrice - extension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Download YouTube Videos as MP4 - extension - {b9bfaf1c-a63f-47cd-8b9a-29526ced9060} - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
Adobe Acrobat DC - Create PDF - extension - web2pdfextension.15@web2pdf.adobedotcom - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
Turn Off the Lights - webextension - stefanvandamme@stefanvd.net - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\stefanvandamme@stefanvd.net.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\pluginreg.dat
Plugin - AdobeAAMDetect - 1.0.0.0 - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
Plugin - Adobe Acrobat - 15.20.20039.7108 - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll
Plugin - Google Update - 1.3.31.5 - C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
Plugin - Photo Gallery - 16.4.3528.331 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
Plugin - Silverlight Plug-In - 5.1.50901.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll
Plugin - Picasa - 3.0.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
Plugin - Google Earth Plugin - 7.1.7.2606 - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
Plugin - Shockwave Flash - 23.0.0.205 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll

=========Google Chrome=========

C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0  
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf   
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 2 Avast SafePrice 11.1.0.221
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.0.8
Extension gomekmidlodglbbmalcneegieacbdmki 2 Avast Online Security 11.1.0.955
Extension ighlmfonficnnppbhgegnpggnjokbikf 1 I Can See You 1.1
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension lneaknkopdijkpnocmklfnjbeapigfbh 1 Mapy Google 5.4.1
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.2.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Homepage: http://www.seznam.cz/
default_search_provider.search_url: 
C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage: 
default_search_provider.search_url: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\daanglpcpkjjlkhcbladppjphglbigam]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fcoadmpfijfcmokecmkgolhbaeclfage]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24 790552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24 664848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2016-10-25 1852352]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-27 9099440]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [2016-10-01 1868472]
""= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-11-05 19:34:20 ----D---- C:\rsit
2016-11-05 15:50:36 ----D---- C:\Program Files\Microsoft Silverlight
2016-11-05 15:50:36 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-11-05 15:29:57 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-11-05 15:29:57 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-11-05 15:29:57 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-11-05 15:29:57 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-31 16:04:13 ----D---- C:\Users\Lukes\AppData\Roaming\Seznam Browser-f405520b-42af-48f0-b5a7-43beced10083
2016-10-29 13:06:14 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-10-29 13:06:14 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-10-29 13:06:14 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvopencl.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvoglv64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvinitx.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvIFR64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvFBC64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvdispgenco6437570.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvdispco6437570.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvcuvid.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvcuda.dll
2016-10-29 13:06:05 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-10-29 13:06:05 ----A---- C:\Windows\system32\nvcompiler.dll
2016-10-25 19:04:59 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-10-25 17:11:29 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-10-25 17:11:29 ----A---- C:\Windows\system32\nvdispgenco6437563.dll
2016-10-25 17:11:29 ----A---- C:\Windows\system32\nvdispco6437563.dll
2016-10-22 16:27:29 ----D---- C:\Users\Lukes\AppData\Roaming\Steam
2016-10-22 15:49:40 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2016-10-22 15:48:53 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2016-10-22 15:48:45 ----D---- C:\Users\Lukes\AppData\Roaming\DAEMON Tools Lite
2016-10-22 15:48:39 ----D---- C:\Program Files\DAEMON Tools Lite
2016-10-22 15:47:59 ----D---- C:\ProgramData\DAEMON Tools Lite
2016-10-22 11:39:09 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2016-10-22 11:39:09 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\nvspcap64.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\nvspbridge64.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2016-10-21 21:01:05 ----A---- C:\Windows\NvContainerRecovery.bat
2016-10-21 20:57:36 ----A---- C:\Windows\system32\nvdispgenco6437557.dll
2016-10-21 20:57:36 ----A---- C:\Windows\system32\nvdispco6437557.dll
2016-10-20 16:19:09 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-10-20 16:19:09 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-10-20 15:54:24 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2016-10-20 15:54:24 ----A---- C:\Windows\system32\TsWpfWrp.exe
2016-10-20 15:08:28 ----A---- C:\Windows\system32\diagtrack.dll
2016-10-20 15:08:25 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2016-10-20 15:08:25 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\win32spl.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\vmrdvcore.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\SessEnv.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\msdtcprx.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\drivers\refs.sys
2016-10-20 15:08:23 ----AC---- C:\Windows\system32\drivers\msiscsi.sys
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\pdh.dll
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\iscsiwmi.dll
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\pdh.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\localspl.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\iscsiwmi.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\iscsiexe.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\DafPrintProvider.dll
2016-10-20 15:08:22 ----A---- C:\Windows\SYSWOW64\xolehlp.dll
2016-10-20 15:08:22 ----A---- C:\Windows\SYSWOW64\iscsidsc.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\xolehlp.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\iscsidsc.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\dab.dll
2016-10-20 14:48:28 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 14:48:28 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 14:48:19 ----D---- C:\Windows\SYSWOW64\XPSViewer
2016-10-20 14:48:18 ----D---- C:\Program Files\Reference Assemblies
2016-10-20 14:48:18 ----D---- C:\Program Files\MSBuild
2016-10-13 05:16:23 ----A---- C:\Windows\system32\mshtml.dll
2016-10-13 05:16:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-13 05:16:17 ----A---- C:\Windows\system32\jscript9.dll
2016-10-13 05:16:16 ----A---- C:\Windows\system32\ieframe.dll
2016-10-13 05:16:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-13 05:16:14 ----A---- C:\Windows\system32\DWrite.dll
2016-10-13 05:16:14 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-13 05:16:13 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-13 05:16:13 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-13 05:16:12 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\wininet.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\urlmon.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\iertutil.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\FntCache.dll
2016-10-13 05:16:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-13 05:16:10 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-13 05:16:10 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-13 05:16:10 ----A---- C:\Windows\system32\win32k.sys
2016-10-13 05:16:07 ----A---- C:\Windows\system32\winload.exe
2016-10-13 05:16:07 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-13 05:16:07 ----A---- C:\Windows\system32\GdiPlus.dll
2016-10-13 05:16:07 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-10-13 05:16:06 ----A---- C:\Windows\system32\vbscript.dll
2016-10-13 05:16:06 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-13 05:16:03 ----A---- C:\Windows\system32\winresume.exe
2016-10-13 05:16:03 ----A---- C:\Windows\system32\drivers\tm.sys
2016-10-13 05:16:02 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-13 05:16:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-13 05:16:02 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-13 05:16:00 ----A---- C:\Windows\SYSWOW64\offreg.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\offreg.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\jscript.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 11:27:08 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-09 11:25:55 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-09 11:25:55 ----A---- C:\Windows\system32\appraiser.dll
2016-10-09 11:25:55 ----A---- C:\Windows\system32\acmigration.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\invagent.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\generaltel.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\devinv.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\centel.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\aepic.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\aeinv.dll
2016-10-08 16:54:03 ----A---- C:\Windows\system32\nvdispgenco6437306.dll
2016-10-08 16:54:03 ----A---- C:\Windows\system32\nvdispco6437306.dll

======List of files/folders modified in the last 1 month======

2016-11-05 19:34:23 ----D---- C:\Program Files\trend micro
2016-11-05 19:34:00 ----D---- C:\Windows\system32\sru
2016-11-05 17:38:35 ----D---- C:\Windows\system32\drivers
2016-11-05 17:38:20 ----D---- C:\Windows\Temp
2016-11-05 17:29:23 ----D---- C:\Windows\Prefetch
2016-11-05 16:45:38 ----D---- C:\Windows\system32\DriverStore
2016-11-05 16:45:36 ----D---- C:\Windows\CbsTemp
2016-11-05 16:07:49 ----D---- C:\Users\Lukes\AppData\Roaming\uTorrent
2016-11-05 16:06:22 ----D---- C:\Windows\system32\config
2016-11-05 15:52:45 ----D---- C:\Windows\Inf
2016-11-05 15:52:39 ----SHD---- C:\Windows\Installer
2016-11-05 15:52:38 ----SD---- C:\ProgramData\Microsoft
2016-11-05 15:50:36 ----RD---- C:\Program Files (x86)
2016-11-05 15:50:36 ----D---- C:\Program Files
2016-11-05 15:50:13 ----SHD---- C:\System Volume Information
2016-11-05 15:49:33 ----D---- C:\Windows
2016-11-05 15:49:30 ----D---- C:\Windows\WinSxS
2016-11-05 15:45:11 ----RD---- C:\Windows\System32
2016-11-05 15:45:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-11-05 15:39:00 ----D---- C:\ProgramData\NVIDIA
2016-11-05 15:37:42 ----D---- C:\Windows\SysWOW64
2016-11-05 15:31:35 ----D---- C:\ProgramData\NVIDIA Corporation
2016-11-05 15:31:00 ----D---- C:\Windows\system32\Tasks
2016-11-05 15:30:13 ----D---- C:\Program Files\NVIDIA Corporation
2016-11-05 15:30:13 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-11-05 15:29:56 ----D---- C:\Program Files (x86)\VulkanRT
2016-11-05 01:24:27 ----D---- C:\Windows\SoftwareDistribution
2016-11-04 19:03:40 ----D---- C:\Windows\AppReadiness
2016-11-04 17:45:47 ----D---- C:\Program Files (x86)\Steam
2016-11-04 09:55:49 ----D---- C:\Windows\Microsoft.NET
2016-11-02 17:26:51 ----D---- C:\Program Files (x86)\Google
2016-11-01 10:51:10 ----HD---- C:\ProgramData
2016-10-29 13:11:48 ----D---- C:\Windows\system32\catroot2
2016-10-28 11:00:39 ----D---- C:\Users\Lukes\AppData\Roaming\Clip2Net
2016-10-26 16:12:06 ----D---- C:\Windows\system32\Macromed
2016-10-26 16:12:04 ----D---- C:\Windows\SYSWOW64\Macromed
2016-10-26 08:47:41 ----D---- C:\Windows\system32\NDF
2016-10-26 00:04:52 ----D---- C:\Windows\Logs
2016-10-25 22:39:31 ----A---- C:\Windows\system32\nvapi64.dll
2016-10-25 21:17:53 ----A---- C:\Windows\system32\nvsvc64.dll
2016-10-25 21:17:53 ----A---- C:\Windows\system32\nvcpl.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvsvcr.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvshext.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvmctray.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-10-25 19:05:12 ----RSD---- C:\Windows\assembly
2016-10-24 22:54:15 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-10-22 17:28:54 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-22 17:28:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-10-21 18:45:15 ----D---- C:\Users\Lukes\AppData\Roaming\Skype
2016-10-21 16:50:17 ----D---- C:\ProgramData\Skype
2016-10-20 17:51:47 ----D---- C:\Windows\rescache
2016-10-20 16:03:34 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-10-20 16:03:34 ----D---- C:\Windows\system32\cs-CZ
2016-10-20 15:11:45 ----RD---- C:\Windows\ToastData
2016-10-20 14:53:09 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 14:52:48 ----D---- C:\Program Files\Rockstar Games
2016-10-20 14:48:19 ----RSD---- C:\Windows\Fonts
2016-10-20 14:48:19 ----D---- C:\Windows\SYSWOW64\MUI
2016-10-20 14:48:19 ----D---- C:\Windows\system32\MUI
2016-10-17 17:21:04 ----RD---- C:\Program Files (x86)\Skype
2016-10-17 17:21:04 ----D---- C:\Program Files (x86)\Common Files
2016-10-14 14:48:39 ----D---- C:\Fraps
2016-10-14 08:56:20 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 08:56:20 ----D---- C:\Windows\system32\appraiser
2016-10-14 08:56:19 ----D---- C:\Program Files\Internet Explorer
2016-10-14 08:56:19 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-14 08:56:18 ----D---- C:\Windows\system32\Boot
2016-10-13 19:38:27 ----D---- C:\Windows\debug
2016-10-13 05:31:05 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-13 05:30:57 ----D---- C:\Windows\system32\MRT
2016-10-13 05:21:07 ----AC---- C:\Windows\system32\MRT.exe
2016-10-10 16:25:27 ----HD---- C:\Program Files (x86)\InstallShield Installation Information

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-08-23 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-10-13 293352]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-08-23 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-08-23 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-09-13 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-09-23 513632]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-08-23 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-08-23 163416]
R3 athr;@oem6.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2013-08-14 3837440]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-09 81920]
R3 HIDSwitch;@oem1.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\Windows\System32\drivers\AsHIDSwitch64.sys [2013-11-04 20280]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-08-27 3797424]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-06-18 4496600]
R3 IntcDAud;@oem8.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-07-20 38976]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-10-25 14033976]
R3 nvvad_WaveExtensible;@oem30.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-10-25 46016]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-11-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-08-23 37656]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2015-06-09 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-06-09 1201664]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-07-22 130688]
S3 dtlitescsibus;@oem26.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2016-10-22 30264]
S3 dtliteusbbus;@oem27.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2016-10-22 47672]
S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-07-20 50240]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-10-25 27584]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-07-22 164992]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2015-10-10 78848]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-09-16 82128]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-09-26 2207960]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [2014-03-26 115512]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-08-23 197128]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-08-27 330136]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-25 456640]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-10-25 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-10-25 1163712]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-04 154440]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-09-14 2195472]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-26 270016]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll"=%SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-08-27 291744]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-04 154440]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-10-22 172488]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-25 456640]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-09-14 2130440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 05 lis 2016 19:56
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Prosím o kontrolu

Napsal: 05 lis 2016 20:37
od M.Lukes

Kód: Vybrat vše

# AdwCleaner v6.030 - Log soubor vytvořen 05/11/2016 na 20:32:13
# Aktualizováno dne 19/10/2016 z Malwarebytes
# Databáze : 2016-11-05.1 [Server]
# Operační systém : Windows 8.1  (X64)
# Uživatelské jméno : Lukes - LUKES_CZ
# Beží od : C:\Users\Lukes\Desktop\adwcleaner_6.030.exe
# Mod: Čištění
# Podpora : hxxps://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Adresáře ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKLM\SOFTWARE\Classes\AVSAsyncBuffer.AVSVideoTimeShift
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AVSAsyncBuffer.AVSVideoTimeShift.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AVSAsyncBuffer.UVideoTimeShift
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AVSAsyncBuffer.UVideoTimeShift.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\AVSAsyncBuffer.AVSVideoTimeShift
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\AVSAsyncBuffer.AVSVideoTimeShift.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\AVSAsyncBuffer.UVideoTimeShift
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\AVSAsyncBuffer.UVideoTimeShift.1


***** [ Prohlížeče ] *****

[-] [C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:slunecnice.cz
[-] [C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Profile 1\Web data] [Search Provider] Smazání:slunecnice.cz
[-] [C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Profile 1] [startup_urls] Smazání:hxxp://home.sweetim.com/?crg=3.1010000.10011&barid={B7477902-B40F-11E1-B431-065400261419}


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1895 Bajtů] - [05/11/2016 20:32:13]
C:\AdwCleaner\AdwCleaner[S0].txt - [2301 Bajtů] - [05/11/2016 20:30:32]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [2043 Bajtů] ##########

Re: Prosím o kontrolu

Napsal: 05 lis 2016 21:02
od Rudy
Dejte nový log RSIT.

Re: Prosím o kontrolu

Napsal: 06 lis 2016 14:52
od M.Lukes

Kód: Vybrat vše

Logfile of random's system information tool 1.14 (written by random/random) 
Run by Lukes at 2016-11-06 14:49:58
Microsoft Windows 8.1 
System drive C: has 203 GB (53%) free of 382 GB
Total RAM: 3982 MB (60% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:02, on 6. 11. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Lukes_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 65.112.87.186 master.gamespy.com
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8490 bytes

======Enumerating Processes======

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\dashost.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\WinLogon.exe -SpecialSession
C:\Windows\System32\dwm.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe 
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -l 3 -c
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" 
C:\Windows\system32\taskhostex.exe
C:\Windows\system32\igfxEM.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" 
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" 
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" 
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe78_ Global\UsGthrCtrlFltPipeMssGthrPipe78 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 
"C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568 
"C:\Users\Lukes\Downloads\RSITx64.exe" 
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\RunDll32.exe" "C:\Windows\system32\WerConCpl.dll", LaunchErcApp -responsepester

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\ASUS Splendid ACMON - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\system32\tasks\ATK Package 36D18D69AFC3 - "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe" -CancelShutdown
C:\Windows\system32\tasks\avast! Emergency Update - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1465549442 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\{5650F51D-AA2F-4F8F-9CA1-F6AE42EC8F6C} - C:\Windows\system32\pcalua.exe -a C:\Users\Lukes\Desktop\gtasa120cz.exe -d C:\Users\Lukes\Desktop
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default

prefs.js - "browser.startup.homepage" -  "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" -  "http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&"

"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.205 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.205 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll


C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\
superstart@enjoyfreeware.org

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\searchplugins\
seznam-avast.xml

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Download YouTube Videos as MP4 - extension - {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}
Turn Off the Lights - extension - stefanvandamme@stefanvd.net
Super Start - extension - superstart@enjoyfreeware.org

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions.json
Super Start - extension - superstart@enjoyfreeware.org - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\superstart@enjoyfreeware.org
Who Deleted Me - extension - whodeletedme@deleted.io - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\whodeletedme@deleted.io.xpi
Avast Online Security - extension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF
Avast SafePrice - extension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Download YouTube Videos as MP4 - extension - {b9bfaf1c-a63f-47cd-8b9a-29526ced9060} - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
Adobe Acrobat DC - Create PDF - extension - web2pdfextension.15@web2pdf.adobedotcom - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
Turn Off the Lights - webextension - stefanvandamme@stefanvd.net - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\stefanvandamme@stefanvd.net.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\pluginreg.dat
Plugin - AdobeAAMDetect - 1.0.0.0 - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
Plugin - Adobe Acrobat - 15.20.20039.7108 - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll
Plugin - Google Update - 1.3.31.5 - C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
Plugin - Photo Gallery - 16.4.3528.331 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
Plugin - Silverlight Plug-In - 5.1.50901.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll
Plugin - Picasa - 3.0.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
Plugin - Google Earth Plugin - 7.1.7.2606 - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
Plugin - Shockwave Flash - 23.0.0.205 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll

=========Google Chrome=========

C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0  
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf   
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 2 Avast SafePrice 11.1.0.221
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.0.8
Extension gomekmidlodglbbmalcneegieacbdmki 2 Avast Online Security 11.1.0.955
Extension ighlmfonficnnppbhgegnpggnjokbikf 1 I Can See You 1.1
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension lneaknkopdijkpnocmklfnjbeapigfbh 1 Mapy Google 5.4.1
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.2.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Homepage: http://www.seznam.cz/
default_search_provider.search_url: 
C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage: 
default_search_provider.search_url: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\daanglpcpkjjlkhcbladppjphglbigam]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fcoadmpfijfcmokecmkgolhbaeclfage]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24 790552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24 664848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2016-10-25 1852352]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-27 9099440]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [2016-10-01 1868472]
""= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-11-05 20:25:44 ----D---- C:\AdwCleaner
2016-11-05 19:34:20 ----D---- C:\rsit
2016-11-05 15:50:36 ----D---- C:\Program Files\Microsoft Silverlight
2016-11-05 15:50:36 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-11-05 15:29:57 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-11-05 15:29:57 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-11-05 15:29:57 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-11-05 15:29:57 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-31 16:04:13 ----D---- C:\Users\Lukes\AppData\Roaming\Seznam Browser-f405520b-42af-48f0-b5a7-43beced10083
2016-10-29 13:06:14 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-10-29 13:06:14 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-10-29 13:06:14 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvopencl.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvoglv64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvinitx.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvIFR64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvFBC64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvdispgenco6437570.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvdispco6437570.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvcuvid.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvcuda.dll
2016-10-29 13:06:05 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-10-29 13:06:05 ----A---- C:\Windows\system32\nvcompiler.dll
2016-10-25 19:04:59 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-10-25 17:11:29 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-10-25 17:11:29 ----A---- C:\Windows\system32\nvdispgenco6437563.dll
2016-10-25 17:11:29 ----A---- C:\Windows\system32\nvdispco6437563.dll
2016-10-22 16:27:29 ----D---- C:\Users\Lukes\AppData\Roaming\Steam
2016-10-22 15:49:40 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2016-10-22 15:48:53 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2016-10-22 15:48:45 ----D---- C:\Users\Lukes\AppData\Roaming\DAEMON Tools Lite
2016-10-22 15:48:39 ----D---- C:\Program Files\DAEMON Tools Lite
2016-10-22 15:47:59 ----D---- C:\ProgramData\DAEMON Tools Lite
2016-10-22 11:39:09 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2016-10-22 11:39:09 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\nvspcap64.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\nvspbridge64.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2016-10-21 21:01:05 ----A---- C:\Windows\NvContainerRecovery.bat
2016-10-21 20:57:36 ----A---- C:\Windows\system32\nvdispgenco6437557.dll
2016-10-21 20:57:36 ----A---- C:\Windows\system32\nvdispco6437557.dll
2016-10-20 16:19:09 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-10-20 16:19:09 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-10-20 15:54:24 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2016-10-20 15:54:24 ----A---- C:\Windows\system32\TsWpfWrp.exe
2016-10-20 15:08:28 ----A---- C:\Windows\system32\diagtrack.dll
2016-10-20 15:08:25 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2016-10-20 15:08:25 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\win32spl.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\vmrdvcore.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\SessEnv.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\msdtcprx.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\drivers\refs.sys
2016-10-20 15:08:23 ----AC---- C:\Windows\system32\drivers\msiscsi.sys
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\pdh.dll
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\iscsiwmi.dll
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\pdh.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\localspl.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\iscsiwmi.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\iscsiexe.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\DafPrintProvider.dll
2016-10-20 15:08:22 ----A---- C:\Windows\SYSWOW64\xolehlp.dll
2016-10-20 15:08:22 ----A---- C:\Windows\SYSWOW64\iscsidsc.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\xolehlp.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\iscsidsc.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\dab.dll
2016-10-20 14:48:28 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 14:48:28 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 14:48:19 ----D---- C:\Windows\SYSWOW64\XPSViewer
2016-10-20 14:48:18 ----D---- C:\Program Files\Reference Assemblies
2016-10-20 14:48:18 ----D---- C:\Program Files\MSBuild
2016-10-13 05:16:23 ----A---- C:\Windows\system32\mshtml.dll
2016-10-13 05:16:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-13 05:16:17 ----A---- C:\Windows\system32\jscript9.dll
2016-10-13 05:16:16 ----A---- C:\Windows\system32\ieframe.dll
2016-10-13 05:16:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-13 05:16:14 ----A---- C:\Windows\system32\DWrite.dll
2016-10-13 05:16:14 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-13 05:16:13 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-13 05:16:13 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-13 05:16:12 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\wininet.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\urlmon.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\iertutil.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\FntCache.dll
2016-10-13 05:16:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-13 05:16:10 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-13 05:16:10 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-13 05:16:10 ----A---- C:\Windows\system32\win32k.sys
2016-10-13 05:16:07 ----A---- C:\Windows\system32\winload.exe
2016-10-13 05:16:07 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-13 05:16:07 ----A---- C:\Windows\system32\GdiPlus.dll
2016-10-13 05:16:07 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-10-13 05:16:06 ----A---- C:\Windows\system32\vbscript.dll
2016-10-13 05:16:06 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-13 05:16:03 ----A---- C:\Windows\system32\winresume.exe
2016-10-13 05:16:03 ----A---- C:\Windows\system32\drivers\tm.sys
2016-10-13 05:16:02 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-13 05:16:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-13 05:16:02 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-13 05:16:00 ----A---- C:\Windows\SYSWOW64\offreg.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\offreg.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\jscript.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 11:27:08 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-09 11:25:55 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-09 11:25:55 ----A---- C:\Windows\system32\appraiser.dll
2016-10-09 11:25:55 ----A---- C:\Windows\system32\acmigration.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\invagent.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\generaltel.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\devinv.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\centel.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\aepic.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\aeinv.dll
2016-10-08 16:54:03 ----A---- C:\Windows\system32\nvdispgenco6437306.dll
2016-10-08 16:54:03 ----A---- C:\Windows\system32\nvdispco6437306.dll

======List of files/folders modified in the last 1 month======

2016-11-06 14:50:01 ----D---- C:\Program Files\trend micro
2016-11-06 14:39:02 ----D---- C:\Windows\system32\sru
2016-11-06 14:37:04 ----D---- C:\Windows\SoftwareDistribution
2016-11-06 02:52:23 ----D---- C:\Windows\Temp
2016-11-06 01:21:43 ----D---- C:\Windows\Prefetch
2016-11-06 01:00:38 ----D---- C:\Windows\Microsoft.NET
2016-11-05 20:54:00 ----RD---- C:\Windows\System32
2016-11-05 20:54:00 ----D---- C:\Windows\Inf
2016-11-05 20:54:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-11-05 20:50:22 ----D---- C:\Windows\debug
2016-11-05 20:50:22 ----D---- C:\Windows
2016-11-05 20:48:40 ----D---- C:\ProgramData\NVIDIA
2016-11-05 19:51:29 ----D---- C:\Windows\AppReadiness
2016-11-05 17:38:35 ----D---- C:\Windows\system32\drivers
2016-11-05 16:56:27 ----D---- C:\Windows\system32\config
2016-11-05 16:45:56 ----D---- C:\Windows\CbsTemp
2016-11-05 16:45:38 ----D---- C:\Windows\system32\DriverStore
2016-11-05 16:07:49 ----D---- C:\Users\Lukes\AppData\Roaming\uTorrent
2016-11-05 15:52:39 ----SHD---- C:\Windows\Installer
2016-11-05 15:52:38 ----SD---- C:\ProgramData\Microsoft
2016-11-05 15:50:36 ----RD---- C:\Program Files (x86)
2016-11-05 15:50:36 ----D---- C:\Program Files
2016-11-05 15:50:13 ----SHD---- C:\System Volume Information
2016-11-05 15:49:30 ----D---- C:\Windows\WinSxS
2016-11-05 15:37:42 ----D---- C:\Windows\SysWOW64
2016-11-05 15:31:35 ----D---- C:\ProgramData\NVIDIA Corporation
2016-11-05 15:31:00 ----D---- C:\Windows\system32\Tasks
2016-11-05 15:30:13 ----D---- C:\Program Files\NVIDIA Corporation
2016-11-05 15:30:13 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-11-05 15:29:56 ----D---- C:\Program Files (x86)\VulkanRT
2016-11-04 17:45:47 ----D---- C:\Program Files (x86)\Steam
2016-11-02 17:26:51 ----D---- C:\Program Files (x86)\Google
2016-11-01 10:51:10 ----HD---- C:\ProgramData
2016-10-29 13:11:48 ----D---- C:\Windows\system32\catroot2
2016-10-28 11:00:39 ----D---- C:\Users\Lukes\AppData\Roaming\Clip2Net
2016-10-26 16:12:06 ----D---- C:\Windows\system32\Macromed
2016-10-26 16:12:04 ----D---- C:\Windows\SYSWOW64\Macromed
2016-10-26 08:47:41 ----D---- C:\Windows\system32\NDF
2016-10-26 00:04:52 ----D---- C:\Windows\Logs
2016-10-25 22:39:31 ----A---- C:\Windows\system32\nvapi64.dll
2016-10-25 21:17:53 ----A---- C:\Windows\system32\nvsvc64.dll
2016-10-25 21:17:53 ----A---- C:\Windows\system32\nvcpl.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvsvcr.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvshext.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvmctray.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-10-25 19:05:12 ----RSD---- C:\Windows\assembly
2016-10-24 22:54:15 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-10-22 17:28:54 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-22 17:28:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-10-21 18:45:15 ----D---- C:\Users\Lukes\AppData\Roaming\Skype
2016-10-21 16:51:31 ----D---- C:\ProgramData\Skype
2016-10-20 17:51:47 ----D---- C:\Windows\rescache
2016-10-20 16:03:34 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-10-20 16:03:34 ----D---- C:\Windows\system32\cs-CZ
2016-10-20 15:11:45 ----RD---- C:\Windows\ToastData
2016-10-20 14:53:09 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 14:52:48 ----D---- C:\Program Files\Rockstar Games
2016-10-20 14:48:19 ----RSD---- C:\Windows\Fonts
2016-10-20 14:48:19 ----D---- C:\Windows\SYSWOW64\MUI
2016-10-20 14:48:19 ----D---- C:\Windows\system32\MUI
2016-10-17 17:21:04 ----RD---- C:\Program Files (x86)\Skype
2016-10-17 17:21:04 ----D---- C:\Program Files (x86)\Common Files
2016-10-14 14:48:39 ----D---- C:\Fraps
2016-10-14 08:56:20 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 08:56:20 ----D---- C:\Windows\system32\appraiser
2016-10-14 08:56:19 ----D---- C:\Program Files\Internet Explorer
2016-10-14 08:56:19 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-14 08:56:18 ----D---- C:\Windows\system32\Boot
2016-10-13 05:31:05 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-13 05:30:57 ----D---- C:\Windows\system32\MRT
2016-10-13 05:21:07 ----AC---- C:\Windows\system32\MRT.exe
2016-10-10 16:25:27 ----HD---- C:\Program Files (x86)\InstallShield Installation Information

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-08-23 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-10-13 293352]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-08-23 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-08-23 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-09-13 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-09-23 513632]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-08-23 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-08-23 163416]
R3 athr;@oem6.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2013-08-14 3837440]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-09 81920]
R3 HIDSwitch;@oem1.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\Windows\System32\drivers\AsHIDSwitch64.sys [2013-11-04 20280]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-08-27 3797424]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-06-18 4496600]
R3 IntcDAud;@oem8.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-07-20 38976]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-10-25 14033976]
R3 nvvad_WaveExtensible;@oem30.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-10-25 46016]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-11-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-08-23 37656]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2015-06-09 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-06-09 1201664]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-07-22 130688]
S3 dtlitescsibus;@oem26.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2016-10-22 30264]
S3 dtliteusbbus;@oem27.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2016-10-22 47672]
S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-07-20 50240]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-10-25 27584]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-07-22 164992]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2015-10-10 78848]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-09-16 82128]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-09-26 2207960]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [2014-03-26 115512]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-08-23 197128]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-08-27 330136]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-25 456640]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-10-25 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-10-25 1163712]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-04 154440]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-09-14 2195472]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-26 270016]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll"=%SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-08-27 291744]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-04 154440]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-10-22 172488]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-25 456640]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-09-14 2130440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 06 lis 2016 17:56
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
[Resethosts]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: Prosím o kontrolu

Napsal: 06 lis 2016 20:30
od M.Lukes

Kód: Vybrat vše

Logfile of random's system information tool 1.14 (written by random/random) 
Run by Lukes at 2016-11-06 20:28:55
Microsoft Windows 8.1 
System drive C: has 204 GB (53%) free of 382 GB
Total RAM: 3982 MB (64% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:28:58, on 6. 11. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Lukes_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8506 bytes

======Enumerating Processes======

C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe  -first
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" 
C:\Windows\system32\taskhostex.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -l 3 -c
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" 
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" 
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\dashost.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" 
C:\Windows\system32\taskeng.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 
"C:\Windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572 
"C:\Users\Lukes\Downloads\RSITx64.exe" 

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\ASUS Splendid ACMON - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\system32\tasks\ATK Package 36D18D69AFC3 - "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe" -CancelShutdown
C:\Windows\system32\tasks\avast! Emergency Update - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1465549442 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\{5650F51D-AA2F-4F8F-9CA1-F6AE42EC8F6C} - C:\Windows\system32\pcalua.exe -a C:\Users\Lukes\Desktop\gtasa120cz.exe -d C:\Users\Lukes\Desktop
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default

prefs.js - "browser.startup.homepage" -  "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" -  "http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&"

"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.205 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.205 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll


C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\
superstart@enjoyfreeware.org

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\searchplugins\
seznam-avast.xml

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Download YouTube Videos as MP4 - extension - {b9bfaf1c-a63f-47cd-8b9a-29526ced9060}
Turn Off the Lights - extension - stefanvandamme@stefanvd.net
Super Start - extension - superstart@enjoyfreeware.org

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions.json
Super Start - extension - superstart@enjoyfreeware.org - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\superstart@enjoyfreeware.org
Who Deleted Me - extension - whodeletedme@deleted.io - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\whodeletedme@deleted.io.xpi
Avast Online Security - extension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF
Avast SafePrice - extension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Download YouTube Videos as MP4 - extension - {b9bfaf1c-a63f-47cd-8b9a-29526ced9060} - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
Adobe Acrobat DC - Create PDF - extension - web2pdfextension.15@web2pdf.adobedotcom - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
Turn Off the Lights - webextension - stefanvandamme@stefanvd.net - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\stefanvandamme@stefanvd.net.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

C:\Users\Lukes\AppData\Roaming\Mozilla\Firefox\Profiles\riwm3jgo.default\pluginreg.dat
Plugin - AdobeAAMDetect - 1.0.0.0 - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
Plugin - Adobe Acrobat - 15.20.20039.7108 - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll
Plugin - Google Update - 1.3.31.5 - C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
Plugin - Photo Gallery - 16.4.3528.331 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
Plugin - Silverlight Plug-In - 5.1.50901.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll
Plugin - Picasa - 3.0.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
Plugin - Google Earth Plugin - 7.1.7.2606 - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
Plugin - Shockwave Flash - 23.0.0.205 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll

=========Google Chrome=========

C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0  
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf   
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 2 Avast SafePrice 11.1.0.221
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.0.8
Extension gomekmidlodglbbmalcneegieacbdmki 2 Avast Online Security 11.1.0.955
Extension ighlmfonficnnppbhgegnpggnjokbikf 1 I Can See You 1.1
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension lneaknkopdijkpnocmklfnjbeapigfbh 1 Mapy Google 5.4.1
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.2.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Homepage: http://www.seznam.cz/
default_search_provider.search_url: 
C:\Users\Lukes\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage: 
default_search_provider.search_url: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\daanglpcpkjjlkhcbladppjphglbigam]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fcoadmpfijfcmokecmkgolhbaeclfage]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24 790552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24 664848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-07-28 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-07-28 141496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2016-10-25 1852352]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-27 9099440]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [2016-10-01 1868472]
""= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-11-06 20:14:16 ----D---- C:\_OTM
2016-11-05 20:25:44 ----D---- C:\AdwCleaner
2016-11-05 19:34:20 ----D---- C:\rsit
2016-11-05 15:50:36 ----D---- C:\Program Files\Microsoft Silverlight
2016-11-05 15:50:36 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-11-05 15:29:57 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-11-05 15:29:57 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-11-05 15:29:57 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-11-05 15:29:57 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-31 16:04:13 ----D---- C:\Users\Lukes\AppData\Roaming\Seznam Browser-f405520b-42af-48f0-b5a7-43beced10083
2016-10-29 13:06:14 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-10-29 13:06:14 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-10-29 13:06:14 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-10-29 13:06:12 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvopencl.dll
2016-10-29 13:06:12 ----A---- C:\Windows\system32\nvoglv64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-10-29 13:06:11 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvinitx.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvIFR64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\NvFBC64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-10-29 13:06:11 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-10-29 13:06:10 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvdispgenco6437570.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvdispco6437570.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvcuvid.dll
2016-10-29 13:06:10 ----A---- C:\Windows\system32\nvcuda.dll
2016-10-29 13:06:05 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-10-29 13:06:05 ----A---- C:\Windows\system32\nvcompiler.dll
2016-10-25 19:04:59 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-10-25 17:11:29 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-10-25 17:11:29 ----A---- C:\Windows\system32\nvdispgenco6437563.dll
2016-10-25 17:11:29 ----A---- C:\Windows\system32\nvdispco6437563.dll
2016-10-22 16:27:29 ----D---- C:\Users\Lukes\AppData\Roaming\Steam
2016-10-22 15:49:40 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2016-10-22 15:48:53 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2016-10-22 15:48:45 ----D---- C:\Users\Lukes\AppData\Roaming\DAEMON Tools Lite
2016-10-22 15:48:39 ----D---- C:\Program Files\DAEMON Tools Lite
2016-10-22 15:47:59 ----D---- C:\ProgramData\DAEMON Tools Lite
2016-10-22 11:39:09 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2016-10-22 11:39:09 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\nvspcap64.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\nvspbridge64.dll
2016-10-22 11:39:09 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2016-10-21 21:01:05 ----A---- C:\Windows\NvContainerRecovery.bat
2016-10-21 20:57:36 ----A---- C:\Windows\system32\nvdispgenco6437557.dll
2016-10-21 20:57:36 ----A---- C:\Windows\system32\nvdispco6437557.dll
2016-10-20 16:19:09 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-10-20 16:19:09 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-10-20 15:54:24 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2016-10-20 15:54:24 ----A---- C:\Windows\system32\TsWpfWrp.exe
2016-10-20 15:08:28 ----A---- C:\Windows\system32\diagtrack.dll
2016-10-20 15:08:25 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2016-10-20 15:08:25 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\win32spl.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\vmrdvcore.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\SessEnv.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\msdtcprx.dll
2016-10-20 15:08:25 ----A---- C:\Windows\system32\drivers\refs.sys
2016-10-20 15:08:23 ----AC---- C:\Windows\system32\drivers\msiscsi.sys
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\pdh.dll
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\iscsiwmi.dll
2016-10-20 15:08:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\pdh.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\localspl.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\iscsiwmi.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\iscsiexe.dll
2016-10-20 15:08:23 ----A---- C:\Windows\system32\DafPrintProvider.dll
2016-10-20 15:08:22 ----A---- C:\Windows\SYSWOW64\xolehlp.dll
2016-10-20 15:08:22 ----A---- C:\Windows\SYSWOW64\iscsidsc.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\xolehlp.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\iscsidsc.dll
2016-10-20 15:08:22 ----A---- C:\Windows\system32\dab.dll
2016-10-20 14:48:28 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 14:48:28 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 14:48:19 ----D---- C:\Windows\SYSWOW64\XPSViewer
2016-10-20 14:48:18 ----D---- C:\Program Files\Reference Assemblies
2016-10-20 14:48:18 ----D---- C:\Program Files\MSBuild
2016-10-13 05:16:23 ----A---- C:\Windows\system32\mshtml.dll
2016-10-13 05:16:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-13 05:16:17 ----A---- C:\Windows\system32\jscript9.dll
2016-10-13 05:16:16 ----A---- C:\Windows\system32\ieframe.dll
2016-10-13 05:16:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-13 05:16:14 ----A---- C:\Windows\system32\DWrite.dll
2016-10-13 05:16:14 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-13 05:16:13 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-13 05:16:13 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-13 05:16:12 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\wininet.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\urlmon.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\iertutil.dll
2016-10-13 05:16:12 ----A---- C:\Windows\system32\FntCache.dll
2016-10-13 05:16:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-13 05:16:10 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-13 05:16:10 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-13 05:16:10 ----A---- C:\Windows\system32\win32k.sys
2016-10-13 05:16:07 ----A---- C:\Windows\system32\winload.exe
2016-10-13 05:16:07 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-13 05:16:07 ----A---- C:\Windows\system32\GdiPlus.dll
2016-10-13 05:16:07 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-13 05:16:06 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-10-13 05:16:06 ----A---- C:\Windows\system32\vbscript.dll
2016-10-13 05:16:06 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-13 05:16:05 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-13 05:16:03 ----A---- C:\Windows\system32\winresume.exe
2016-10-13 05:16:03 ----A---- C:\Windows\system32\drivers\tm.sys
2016-10-13 05:16:02 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-13 05:16:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-13 05:16:02 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-13 05:16:00 ----A---- C:\Windows\SYSWOW64\offreg.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\offreg.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-13 05:16:00 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-13 05:15:59 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\jscript.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-13 05:15:59 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 11:27:08 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-09 11:25:55 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-09 11:25:55 ----A---- C:\Windows\system32\appraiser.dll
2016-10-09 11:25:55 ----A---- C:\Windows\system32\acmigration.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\invagent.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\generaltel.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\devinv.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\centel.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\aepic.dll
2016-10-09 11:25:54 ----A---- C:\Windows\system32\aeinv.dll
2016-10-08 16:54:03 ----A---- C:\Windows\system32\nvdispgenco6437306.dll
2016-10-08 16:54:03 ----A---- C:\Windows\system32\nvdispco6437306.dll

======List of files/folders modified in the last 1 month======

2016-11-06 20:28:57 ----D---- C:\Program Files\trend micro
2016-11-06 20:26:05 ----RD---- C:\Windows\System32
2016-11-06 20:26:05 ----D---- C:\Windows\Inf
2016-11-06 20:26:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-11-06 20:23:41 ----D---- C:\Windows\Temp
2016-11-06 20:21:32 ----D---- C:\Windows
2016-11-06 20:19:03 ----D---- C:\ProgramData\NVIDIA
2016-11-06 20:17:31 ----D---- C:\Windows\system32\drivers\etc
2016-11-06 20:17:00 ----D---- C:\Windows\system32\sru
2016-11-06 20:14:18 ----D---- C:\Windows\Prefetch
2016-11-06 19:39:24 ----D---- C:\Windows\AppReadiness
2016-11-06 17:47:21 ----D---- C:\Windows\system32\drivers
2016-11-06 14:37:04 ----D---- C:\Windows\SoftwareDistribution
2016-11-06 01:00:38 ----D---- C:\Windows\Microsoft.NET
2016-11-05 20:50:22 ----D---- C:\Windows\debug
2016-11-05 16:56:27 ----D---- C:\Windows\system32\config
2016-11-05 16:45:56 ----D---- C:\Windows\CbsTemp
2016-11-05 16:45:38 ----D---- C:\Windows\system32\DriverStore
2016-11-05 16:07:49 ----D---- C:\Users\Lukes\AppData\Roaming\uTorrent
2016-11-05 15:52:39 ----SHD---- C:\Windows\Installer
2016-11-05 15:52:38 ----SD---- C:\ProgramData\Microsoft
2016-11-05 15:50:36 ----RD---- C:\Program Files (x86)
2016-11-05 15:50:36 ----D---- C:\Program Files
2016-11-05 15:50:13 ----SHD---- C:\System Volume Information
2016-11-05 15:49:30 ----D---- C:\Windows\WinSxS
2016-11-05 15:37:42 ----D---- C:\Windows\SysWOW64
2016-11-05 15:31:35 ----D---- C:\ProgramData\NVIDIA Corporation
2016-11-05 15:31:00 ----D---- C:\Windows\system32\Tasks
2016-11-05 15:30:13 ----D---- C:\Program Files\NVIDIA Corporation
2016-11-05 15:30:13 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-11-05 15:29:56 ----D---- C:\Program Files (x86)\VulkanRT
2016-11-04 17:45:47 ----D---- C:\Program Files (x86)\Steam
2016-11-02 17:26:51 ----D---- C:\Program Files (x86)\Google
2016-11-01 10:51:10 ----HD---- C:\ProgramData
2016-10-29 13:11:48 ----D---- C:\Windows\system32\catroot2
2016-10-28 11:00:39 ----D---- C:\Users\Lukes\AppData\Roaming\Clip2Net
2016-10-26 16:12:06 ----D---- C:\Windows\system32\Macromed
2016-10-26 16:12:04 ----D---- C:\Windows\SYSWOW64\Macromed
2016-10-26 08:47:41 ----D---- C:\Windows\system32\NDF
2016-10-26 00:04:52 ----D---- C:\Windows\Logs
2016-10-25 22:39:31 ----A---- C:\Windows\system32\nvapi64.dll
2016-10-25 21:17:53 ----A---- C:\Windows\system32\nvsvc64.dll
2016-10-25 21:17:53 ----A---- C:\Windows\system32\nvcpl.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvsvcr.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvshext.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nvmctray.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-10-25 21:17:51 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-10-25 19:05:12 ----RSD---- C:\Windows\assembly
2016-10-24 22:54:15 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-10-22 17:28:54 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-22 17:28:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-10-21 18:45:15 ----D---- C:\Users\Lukes\AppData\Roaming\Skype
2016-10-21 16:51:31 ----D---- C:\ProgramData\Skype
2016-10-20 17:51:47 ----D---- C:\Windows\rescache
2016-10-20 16:03:34 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-10-20 16:03:34 ----D---- C:\Windows\system32\cs-CZ
2016-10-20 15:11:45 ----RD---- C:\Windows\ToastData
2016-10-20 14:53:09 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 14:52:48 ----D---- C:\Program Files\Rockstar Games
2016-10-20 14:48:19 ----RSD---- C:\Windows\Fonts
2016-10-20 14:48:19 ----D---- C:\Windows\SYSWOW64\MUI
2016-10-20 14:48:19 ----D---- C:\Windows\system32\MUI
2016-10-17 17:21:04 ----RD---- C:\Program Files (x86)\Skype
2016-10-17 17:21:04 ----D---- C:\Program Files (x86)\Common Files
2016-10-14 14:48:39 ----D---- C:\Fraps
2016-10-14 08:56:20 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 08:56:20 ----D---- C:\Windows\system32\appraiser
2016-10-14 08:56:19 ----D---- C:\Program Files\Internet Explorer
2016-10-14 08:56:19 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-14 08:56:18 ----D---- C:\Windows\system32\Boot
2016-10-13 05:31:05 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-13 05:30:57 ----D---- C:\Windows\system32\MRT
2016-10-13 05:21:07 ----AC---- C:\Windows\system32\MRT.exe
2016-10-10 16:25:27 ----HD---- C:\Program Files (x86)\InstallShield Installation Information

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-08-23 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-10-13 293352]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-08-23 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-08-23 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-09-13 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-09-23 513632]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-08-23 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-08-23 163416]
R3 athr;@oem6.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2013-08-14 3837440]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-09 81920]
R3 HIDSwitch;@oem1.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\Windows\System32\drivers\AsHIDSwitch64.sys [2013-11-04 20280]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-08-27 3797424]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-06-18 4496600]
R3 IntcDAud;@oem8.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-07-20 38976]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-10-25 14033976]
R3 nvvad_WaveExtensible;@oem30.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-10-25 46016]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-11-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-08-23 37656]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2015-06-09 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-06-09 1201664]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-07-22 130688]
S3 dtlitescsibus;@oem26.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2016-10-22 30264]
S3 dtliteusbbus;@oem27.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2016-10-22 47672]
S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-07-20 50240]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-10-25 27584]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-07-22 164992]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2015-10-10 78848]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-09-16 82128]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-09-26 2207960]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [2014-03-26 115512]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-08-23 197128]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-08-27 330136]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-25 456640]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-10-25 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-10-25 1163712]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-04 154440]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-09-14 2195472]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-26 270016]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll"=%SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-08-27 291744]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-04 154440]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-10-22 172488]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-10-25 456640]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-09-14 2130440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 06 lis 2016 21:01
od Rudy
Smazáno. Nastala nějaká změna?

Re: Prosím o kontrolu

Napsal: 07 lis 2016 11:56
od M.Lukes
Notebook je svižnější :) ale zas mi nejde naistalovat aktualizace, a já nevím proč se mi to pořád děje. Také mám problém s tím pomalým načítáním jak jsem psal předtím zde: http://forum.viry.cz/viewtopic.php?f=13&t=148920 Řešil jste se semnou, a obnova pomohla. Jenže už žádnou nemám :D Takhle.. to načítání jak jsem psal předtím šlo uplně v pohodě, když jsem neměl naistalovaný žádný aktualizace, protože jsem byl po formátu.. všechno šlo uplně rychle. Ale když už mám všechny ty aktualizace naistalovaný, tak to načítání je jiný.. myslím si, že to dělá nějáká aktualizace, protože s jednou aktualizací měl problém každý, že se něják podělal systém nebo co.. Je něják možné zjistit nebo něco udělat proč mi to tak dělá? přeinstalaci už nechci ted dělat, a na win 10 i když už je mám napořád zdarma nechci jít. Co zkusit advanced systemcare?

Re: Prosím o kontrolu

Napsal: 07 lis 2016 18:13
od Rudy
AdvancedSystemCare vám nemohu doporučit, on vidí chyby i tam a lze si jím snadno počkodit systém. Buď aktualizace vypněte do příštích pravidelných. Občas se podaří, že to nové aktualizace opraví, nebo použijte WUFix: http://redirect.viglink.com/?format=go& ... &txt=WUFix . Je to dávkový soubor, spustíte ho poklepáním a přidáním.

Re: Prosím o kontrolu

Napsal: 11 lis 2016 14:02
od M.Lukes
Tak ono to fakt pomohlo :D notebook je jako předtím bez jediného zpomalení. Děkuji Vám za pomoc! :)

Re: Prosím o kontrolu

Napsal: 11 lis 2016 18:37
od Rudy
To jsem rád a nemáte zač! :)