Stránka 1 z 1

Prosím o kontrolu

Napsal: 29 pro 2016 22:00
od maulej
Logfile of random's system information tool 1.10 (written by random/random)
Run by hugo at 2016-12-29 21:41:44
Microsoft Windows 7 Home Premium Service Pack 1
System drive H: has 42 GB (16%) free of 254 GB
Total RAM: 3070 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:43:02, on 29.12.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18538)
Boot mode: Normal

Running processes:
H:\Windows\system32\Dwm.exe
H:\Windows\system32\taskhost.exe
H:\Windows\Explorer.EXE
H:\Windows\System32\CTHELPER.EXE
H:\Program Files\AVG\Framework\Common\avguix.exe
H:\Program Files\AVG\Av\avgui.exe
H:\Program Files\BrownyInd\Brother\BrIndicator.exe
H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
H:\Program Files\ControlCenter4\BrCtrlCntr.exe
H:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
H:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPMixDSP.exe
H:\Program Files\PicPick\picpick.exe
H:\Windows\system32\taskeng.exe
H:\Program Files\CCleaner\CCleaner.exe
H:\Program Files\NVIDIA Corporation\Display\nvtray.exe
H:\Program Files\ControlCenter4\BrCcUxSys.exe
H:\Windows\system32\ctfmon.exe
H:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
H:\Program Files\totalcmd\TOTALCMD.EXE
H:\Program Files\Browny02\Brother\BrStMonW.exe
H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
H:\Windows\system32\OptionalFeatures.exe
H:\Windows\system32\taskhost.exe
H:\Program Files\Mozilla Firefox\plugin-container.exe
H:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_24_0_0_186.exe
H:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_24_0_0_186.exe
H:\Install\Utils\RSIT.exe
H:\Program Files\trend micro\hugo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Wondershare Video Converter Ultimate 7.1.0 - {451C804F-C205-4F03-B48E-537EC94937BF} - H:\PROGRA~2\WONDER~2\VIDEOC~1\WSBROW~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: McAfee WebAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - H:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AvgUi] "H:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [AVG_UI] "H:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=av
O4 - HKLM\..\Run: [ControlCenter4] H:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] H:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [BrStsInd00] H:\Program Files\BrownyInd\Brother\BrIndicator.exe /AUTORUN
O4 - HKLM\..\Run: [BCSSync] "H:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [LWS] H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [DelaypluginInstall] H:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
O4 - HKLM\..\Run: [SwitchBoard] H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "H:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [PicPick Start] "H:\Program Files\PicPick\picpick.exe" /startup
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3290210395-743186196-717925178-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3290210395-743186196-717925178-1003\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3290210395-743186196-717925178-1003.bak\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-21-3290210395-743186196-717925178-1003.bak\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "H:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "H:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://H:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O9 - Extra 'Tools' menuitem: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - H:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - H:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: WSWSVCUchrome - {1CA93FF0-A218-44F1 - (no file)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - H:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - H:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgwdsvcx.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - H:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - H:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - H:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PACE License Services (PaceLicenseDServices) - PACE Anti-Piracy, Inc. - H:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - H:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe

--
End of file - 9638 bytes

======Scheduled tasks folder======

H:\Windows\tasks\Adobe Flash Player Updater.job - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default

prefs.js - "browser.startup.homepage" - "www.google.cz"

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=H:\Program Files\McAfee\SiteAdvisor\saffplg.xpi


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=H:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=H:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=H:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88]
"Description"=Sibelius Scorch Plugin
"Path"=H:\Program Files\Sibelius Software\Scorch\npsibelius.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@software602.cz/602XML Filler]
"Description"=602XML Filler Plugin
"Path"=H:\Program Files\Software602\602XML\Filler\npfiller.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=H:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=H:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=H:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


H:\Program Files\Mozilla Firefox\plugins\
NPSibelius.dll
PDFNetC.dll
ScorchAxPlugin.dll
ScorchPDFWrapper.dll

H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\
cs@dictionaries.addons.mozilla.org
marcoagpinto@mail.telepac.pt
{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
{6AC85730-7D0F-4de0-B3FA-21142DD85326}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{451C804F-C205-4F03-B48E-537EC94937BF}]
Wondershare Video Converter Ultimate 7.1.0 - H:\PROGRA~2\WONDER~2\VIDEOC~1\WSBROW~1.DLL [2016-06-12 634000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2014-05-22 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor BHO - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2016-10-24 160288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - H:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"=H:\Windows\system32\CTHELPER.EXE [2009-02-23 23040]
"CTxfiHlp"=H:\Windows\system32\CTXFIHLP.EXE [2009-02-23 23552]
"AvgUi"=H:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"AVG_UI"=H:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"ControlCenter4"=H:\Program Files\ControlCenter4\BrCcBoot.exe [2016-02-03 139776]
"BrStsMon00"=H:\Program Files\Browny02\Brother\BrStMonW.exe [2012-12-27 4509184]
"BrStsInd00"=H:\Program Files\BrownyInd\Brother\BrIndicator.exe [2012-12-18 1885184]
"BCSSync"=H:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"LWS"=H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2012-09-12 204136]
"DelaypluginInstall"=H:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [2016-06-12 1971856]
"SwitchBoard"=H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=H:\Program Files\CCleaner\CCleaner.exe [2016-01-15 6628056]
"PicPick Start"=H:\Program Files\PicPick\picpick.exe [2016-09-29 19766728]
"Zoner Photo Studio Autoupdate"=H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud]
H:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-10-25 2383040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
H:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
H:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
H:\Program Files\Virtual PDF Printer\VirtualPDFPrinter.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
H:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
H:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2016-06-20 2131344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Device Detector 3.lnk]
H:\PROGRA~1\Olympus\DEVICE~1\DevDtct2.exe [2007-02-22 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2014-05-22 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=H:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.tscc"=H:\Windows\system32\tsccvid.dll
"vidc.tsc2"=H:\Windows\system32\tsc2_codec32.dll
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - H:\Windows\System32\Notepad.exe %1
.js - open - H:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-12-29 21:41:45 ----D---- H:\Program Files\trend micro
2016-12-29 21:41:44 ----D---- H:\rsit
2016-12-29 21:28:21 ----A---- H:\Windows\system32\TURegOpt.exe
2016-12-29 21:28:21 ----A---- H:\Windows\system32\authuitu.dll
2016-12-26 00:34:28 ----D---- H:\Windows\pss
2016-12-14 13:23:28 ----A---- H:\Windows\system32\mshtml.dll
2016-12-14 13:23:27 ----A---- H:\Windows\system32\ieframe.dll
2016-12-14 13:23:26 ----A---- H:\Windows\system32\jscript9.dll
2016-12-14 13:23:25 ----A---- H:\Windows\system32\winload.exe
2016-12-14 13:23:25 ----A---- H:\Windows\system32\wininet.dll
2016-12-14 13:23:25 ----A---- H:\Windows\system32\win32k.sys
2016-12-14 13:23:25 ----A---- H:\Windows\system32\crypt32.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\urlmon.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\ntoskrnl.exe
2016-12-14 13:23:24 ----A---- H:\Windows\system32\msi.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\iedkcs32.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\drivers\cng.sys
2016-12-14 13:23:24 ----A---- H:\Windows\system32\consent.exe
2016-12-14 13:23:24 ----A---- H:\Windows\system32\clfs.sys
2016-12-14 13:23:24 ----A---- H:\Windows\system32\bcrypt.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\bcdedit.exe
2016-12-14 13:23:23 ----A---- H:\Windows\system32\wintrust.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\usp10.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\user32.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\ntkrnlpa.exe
2016-12-14 13:23:23 ----A---- H:\Windows\system32\ntdll.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\nlsbres.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\hlink.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\gdi32.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\drivers\ksecpkg.sys
2016-12-14 13:23:23 ----A---- H:\Windows\system32\drivers\ksecdd.sys
2016-12-14 13:23:22 ----A---- H:\Windows\system32\vbscript.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\mshtmlmedia.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\jscript.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\iertutil.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\msiexec.exe
2016-12-14 13:23:21 ----A---- H:\Windows\system32\msfeeds.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\ieui.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\ieapfltr.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\webcheck.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\smss.exe
2016-12-14 13:23:20 ----A---- H:\Windows\system32\rpcrt4.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\occache.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\msrating.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\msihnd.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\mshtmled.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\jscript9diag.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\dxtrans.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\dxtmsft.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\drivers\mrxsmb.sys
2016-12-14 13:23:20 ----A---- H:\Windows\system32\authui.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\advapi32.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\srcore.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\msv1_0.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\MsSpellCheckingFacility.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\MshtmlDac.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\lsasrv.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\kerberos.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\jsproxy.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\JavaScriptCollectionAgent.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\inseng.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ieUnatt.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ieetwproxystub.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ie4uinit.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\drivers\mrxsmb10.sys
2016-12-14 13:23:19 ----A---- H:\Windows\system32\cryptsvc.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\cryptnet.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\appinfo.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\wdigest.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\TSpkg.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\sspisrv.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\sspicli.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\srclient.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\schannel.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\setbcdlocale.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\secur32.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\rstrui.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\rpchttp.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\ncrypt.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\msimsg.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\lsass.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\iesetup.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\iernonce.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\ieetwcollector.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\drivers\mrxsmb20.sys
2016-12-14 13:23:18 ----A---- H:\Windows\system32\drivers\appid.sys
2016-12-14 13:23:18 ----A---- H:\Windows\system32\csrsrv.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\cryptbase.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\credssp.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\auditpol.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidsvc.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidpolicyconverter.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidcertstorecheck.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidapi.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\apisetschema.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\tzres.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\msaudite.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\adtschema.dll
2016-12-14 13:23:16 ----A---- H:\Windows\system32\msobjs.dll
2016-12-14 13:23:16 ----A---- H:\Windows\system32\ieetwcollectorres.dll
2016-12-09 18:10:32 ----D---- H:\Program Files\Common Files\McAfee
2016-12-09 18:10:01 ----D---- H:\Users\hugo\AppData\Roaming\Anvsoft
2016-12-09 18:09:54 ----D---- H:\ProgramData\McAfee
2016-12-09 18:09:50 ----D---- H:\Program Files\McAfee
2016-12-09 18:09:36 ----D---- H:\Program Files\Anvsoft
2016-12-09 17:56:00 ----D---- H:\Users\hugo\AppData\Roaming\YouTube Downloader
2016-12-09 17:55:31 ----D---- H:\Program Files\YTD
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcr120_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcr110_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcr100_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcp120_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcp110_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\aspnet_counters.dll

======List of files/folders modified in the last 1 month======

2016-12-29 21:41:58 ----D---- H:\Windows\Temp
2016-12-29 21:41:45 ----RD---- H:\Program Files
2016-12-29 21:37:30 ----D---- H:\Windows\system32\Tasks
2016-12-29 21:37:28 ----D---- H:\Windows\Tasks
2016-12-29 21:32:38 ----D---- H:\ProgramData\Avg
2016-12-29 21:29:52 ----D---- H:\Windows\system32\config
2016-12-29 21:29:06 ----D---- H:\Windows
2016-12-29 21:28:57 ----D---- H:\Windows\inf
2016-12-29 21:28:27 ----SHD---- H:\Windows\Installer
2016-12-29 21:28:21 ----D---- H:\Windows\System32
2016-12-29 21:28:02 ----D---- H:\Program Files\AVG
2016-12-29 21:18:43 ----D---- H:\Users\hugo\AppData\Roaming\TeamViewer
2016-12-29 18:52:28 ----D---- H:\ProgramData\MFAData
2016-12-28 17:19:42 ----D---- H:\Users\hugo\AppData\Roaming\Audacity
2016-12-25 17:37:59 ----D---- H:\ProgramData\boost_interprocess
2016-12-25 12:43:47 ----D---- H:\Windows\debug
2016-12-23 16:12:19 ----D---- H:\Windows\system32\wdi
2016-12-23 14:49:37 ----SHD---- H:\System Volume Information
2016-12-23 14:49:32 ----D---- H:\Windows\rescache
2016-12-22 23:37:07 ----D---- H:\Audio
2016-12-22 10:35:28 ----D---- H:\Users\hugo\AppData\Roaming\EmuPatchMixDSP
2016-12-20 15:27:29 ----D---- H:\sken
2016-12-20 11:07:55 ----D---- H:\AJ
2016-12-19 14:16:36 ----D---- H:\Users\hugo\AppData\Roaming\vlc
2016-12-15 08:59:36 ----A---- H:\Windows\system32\PerfStringBackup.INI
2016-12-15 08:53:59 ----D---- H:\Windows\winsxs
2016-12-15 08:50:57 ----D---- H:\Program Files\Internet Explorer
2016-12-15 08:50:55 ----D---- H:\Windows\system32\en-US
2016-12-15 08:50:55 ----D---- H:\Windows\system32\drivers
2016-12-15 08:50:55 ----D---- H:\Windows\system32\cs-CZ
2016-12-15 08:50:51 ----D---- H:\Windows\system32\Boot
2016-12-15 08:50:47 ----D---- H:\Program Files\Mozilla Firefox
2016-12-14 22:03:32 ----D---- H:\Windows\Microsoft.NET
2016-12-14 22:03:23 ----D---- H:\ProgramData\Microsoft Help
2016-12-14 22:01:56 ----D---- H:\Windows\system32\MRT
2016-12-14 22:00:36 ----RSD---- H:\Windows\assembly
2016-12-14 21:57:39 ----AC---- H:\Windows\system32\MRT.exe
2016-12-14 14:20:46 ----D---- H:\Program Files\Mozilla Maintenance Service
2016-12-14 13:21:23 ----D---- H:\Windows\system32\catroot2
2016-12-13 22:17:12 ----A---- H:\Windows\system32\FlashPlayerApp.exe
2016-12-13 22:17:10 ----D---- H:\Windows\system32\Macromed
2016-12-09 18:10:32 ----D---- H:\Program Files\Common Files
2016-12-09 18:09:54 ----HD---- H:\ProgramData
2016-12-08 15:28:12 ----D---- H:\Windows\Prefetch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; H:\Windows\system32\DRIVERS\avgidshx.sys [2016-10-05 207616]
R0 Avglogx;AVG Logging Driver; H:\Windows\system32\DRIVERS\avglogx.sys [2016-02-16 287008]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; H:\Windows\system32\DRIVERS\avgmfx86.sys [2016-09-26 197376]
R0 Avgrkx86;AVG Anti-Rootkit Driver; H:\Windows\system32\DRIVERS\avgrkx86.sys [2016-06-01 47360]
R0 avgunivx;AVG Universal Driver; H:\Windows\system32\DRIVERS\avgunivx.sys [2016-06-20 65280]
R0 pciide;pciide; H:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; H:\Windows\System32\Drivers\PxHelp20.sys [2011-11-03 45968]
R0 rdyboost;ReadyBoost; H:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; H:\Windows\system32\DRIVERS\avgdiskx.sys [2016-05-13 134912]
R1 AVGIDSDriver;AVGIDSDriver; H:\Windows\system32\DRIVERS\avgidsdriverx.sys [2016-10-17 259328]
R1 AVGIDSShim;AVGIDSShim; H:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-11-20 31664]
R1 Avgldx86;AVG AVI Loader Driver; H:\Windows\system32\DRIVERS\avgldx86.sys [2016-10-19 219904]
R1 Avgtdix;AVG TDI Driver; H:\Windows\system32\DRIVERS\avgtdix.sys [2016-07-27 231680]
R1 ElbyCDIO;ElbyCDIO Driver; H:\Windows\System32\Drivers\ElbyCDIO.sys [2014-12-20 30616]
R2 Parvdm;Parvdm; H:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 COMMONFX.SYS;COMMONFX.SYS; H:\Windows\System32\drivers\COMMONFX.SYS [2009-02-23 98328]
R3 ctaud2k;Creative Audio Driver (WDM); H:\Windows\system32\drivers\ctaud2k.sys [2009-02-23 524824]
R3 CTEDSPIO.SYS;CTEDSPIO.SYS; H:\Windows\System32\drivers\CTEDSPIO.SYS [2009-02-23 134168]
R3 CTEDSPSY.SYS;CTEDSPSY.SYS; H:\Windows\System32\drivers\CTEDSPSY.SYS [2009-02-23 309784]
R3 ctprxy2k;Creative Proxy Driver; H:\Windows\system32\drivers\ctprxy2k.sys [2009-02-23 14360]
R3 ctsfm2k;Creative SoundFont Management Device Driver; H:\Windows\system32\drivers\ctsfm2k.sys [2009-02-23 159256]
R3 emupia;E-mu Plug-in Architecture Driver; H:\Windows\system32\drivers\emupia2k.sys [2009-02-23 95768]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; H:\Windows\system32\drivers\ha10kx2k.sys [2009-02-23 802840]
R3 mfesapsn;McAfee Process Start Notification Service; \??\H:\Program Files\McAfee\SiteAdvisor\mfesapsn.sys [2016-06-06 41600]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; H:\Windows\system32\drivers\nvhda32v.sys [2012-07-03 149352]
R3 ossrv;Creative OS Services Driver; H:\Windows\system32\drivers\ctoss2k.sys [2009-02-23 129560]
R3 RTL8167;Realtek 8167 NT Driver; H:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [2016-11-25 31792]
R3 usbscan;Ovladač skeneru USB; H:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
R3 VClone;VClone; H:\Windows\system32\DRIVERS\VClone.sys [2013-07-24 30720]
S3 aic78xx;aic78xx; H:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; H:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; H:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 COMMONFX;COMMONFX; H:\Windows\system32\drivers\COMMONFX.SYS [2009-02-23 98328]
S3 CT20XUT.SYS;CT20XUT.SYS; H:\Windows\System32\drivers\CT20XUT.SYS [2009-02-23 171032]
S3 CT20XUT;CT20XUT; H:\Windows\system32\drivers\CT20XUT.SYS [2009-02-23 171032]
S3 ctac32k;Creative AC3 Software Decoder; H:\Windows\system32\drivers\ctac32k.sys [2009-02-23 511000]
S3 CTAUDFX.SYS;CTAUDFX.SYS; H:\Windows\System32\drivers\CTAUDFX.SYS [2009-02-23 528920]
S3 CTAUDFX;CTAUDFX; H:\Windows\system32\drivers\CTAUDFX.SYS [2009-02-23 528920]
S3 CTEAPSFX.SYS;CTEAPSFX.SYS; H:\Windows\System32\drivers\CTEAPSFX.SYS [2009-02-23 163352]
S3 CTEAPSFX;CTEAPSFX; H:\Windows\system32\drivers\CTEAPSFX.SYS [2009-02-23 163352]
S3 CTEDSPFX.SYS;CTEDSPFX.SYS; H:\Windows\System32\drivers\CTEDSPFX.SYS [2009-02-23 259096]
S3 CTEDSPFX;CTEDSPFX; H:\Windows\system32\drivers\CTEDSPFX.SYS [2009-02-23 259096]
S3 CTEDSPIO;CTEDSPIO; H:\Windows\system32\drivers\CTEDSPIO.SYS [2009-02-23 134168]
S3 CTEDSPSY;CTEDSPSY; H:\Windows\system32\drivers\CTEDSPSY.SYS [2009-02-23 309784]
S3 CTERFXFX.SYS;CTERFXFX.SYS; H:\Windows\System32\drivers\CTERFXFX.SYS [2009-02-23 99352]
S3 CTERFXFX;CTERFXFX; H:\Windows\system32\drivers\CTERFXFX.SYS [2009-02-23 99352]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; H:\Windows\System32\drivers\CTEXFIFX.SYS [2009-02-23 1324056]
S3 CTEXFIFX;CTEXFIFX; H:\Windows\system32\drivers\CTEXFIFX.SYS [2009-02-23 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS; H:\Windows\System32\drivers\CTHWIUT.SYS [2009-02-23 72728]
S3 CTHWIUT;CTHWIUT; H:\Windows\system32\drivers\CTHWIUT.SYS [2009-02-23 72728]
S3 CTSBLFX.SYS;CTSBLFX.SYS; H:\Windows\System32\drivers\CTSBLFX.SYS [2009-02-23 534040]
S3 CTSBLFX;CTSBLFX; H:\Windows\system32\drivers\CTSBLFX.SYS [2009-02-23 534040]
S3 LVRS;Logitech RightSound Filter Driver; H:\Windows\system32\DRIVERS\lvrs.sys [2012-09-21 310504]
S3 LVUVC;Logitech HD Pro Webcam C920(UVC); H:\Windows\system32\DRIVERS\lvuvc.sys [2012-09-21 4261224]
S3 sisagp;Filtr SIS sběrnice AGP; H:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;TsUsbFlt; H:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; H:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; H:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VNUSB;VN Series Device; H:\Windows\system32\DRIVERS\VNUSB.sys [2006-04-07 38496]
S3 WinUsb;WinUsb; H:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; H:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-10-21 82128]
R2 AdobeUpdateService;AdobeUpdateService; H:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-25 744640]
R2 AGSService;Adobe Genuine Software Integrity Service; H:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-09-26 2207960]
R2 aspnet_state;Stavová služba ASP.NET; H:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2016-12-01 45752]
R2 AVGIDSAgent;AVGIDSAgent; H:\Program Files\AVG\Av\avgidsagent.exe [2016-11-02 4152896]
R2 avgsvc;AVG Service; H:\Program Files\AVG\Framework\Common\avgsvcx.exe [2016-12-06 935184]
R2 avgwd;AVG WatchDog; H:\Program Files\AVG\Av\avgwdsvcx.exe [2016-11-02 604824]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; H:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; H:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2016-10-24 160800]
R2 nvsvc;NVIDIA Display Driver Service; H:\Windows\system32\nvvsvc.exe [2012-10-02 645992]
R2 PaceLicenseDServices;PACE License Services; H:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-09-08 2932224]
R2 TeamViewer;TeamViewer 11; H:\Program Files\TeamViewer\TeamViewer_Service.exe [2016-08-08 7248144]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2016-11-25 3844880]
R3 BrYNSvc;BrYNSvc; H:\Program Files\Browny02\BrYNSvc.exe [2012-10-26 282112]
R3 osppsvc;Office Software Protection Platform; H:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; H:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-12-01 103608]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2016-07-15 154440]
S2 nvUpdatusService;NVIDIA Update Service Daemon; H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-12-13 270936]
S3 AvgAMPS;AvgAMPS; H:\Program Files\AVG\Av\avgamps.exe [2016-11-02 647864]
S3 gupdatem;Služba Google Update (gupdatem); H:\Program Files\Google\Update\GoogleUpdate.exe [2016-07-15 154440]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; H:\Windows\system32\IEEtwCollector.exe [2016-11-12 102912]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; H:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2014-12-04 30826680]
S3 MozillaMaintenance;Mozilla Maintenance Service; H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-12-14 172488]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SwitchBoard;SwitchBoard; H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; H:\Windows\system32\Wat\WatAdminSvc.exe [2016-07-16 1343400]
S4 NetMsmqActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]
S4 NetPipeActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]
S4 NetTcpActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 31 pro 2016 15:53
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Prosím o kontrolu

Napsal: 31 pro 2016 20:41
od maulej
Díky, zde log:

# AdwCleaner v6.041 - Log vytvořen 31/12/2016 v 20:32:48
# Aktualizováno dne 16/12/2016 z Malwarebytes
# Databáze : 2016-12-30.1 [Server]
# Operační systém : Windows 7 Home Premium Service Pack 1 (X86)
# Uživatelské jméno : hugo - HUGO-PC
# Spuštěno z : H:\Install\adwcleaner_6.041.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKU\S-1-5-21-3290210395-743186196-717925178-1001\Software\APN PIP
[-] Klíč smazán: HKU\S-1-5-21-3290210395-743186196-717925178-1001\Software\PRODUCTSETUP
[-] Klíč smazán: HKU\S-1-5-21-3290210395-743186196-717925178-1001\Software\csastats
[#] Klíč smazán po restartu: HKCU\Software\APN PIP
[#] Klíč smazán po restartu: HKCU\Software\PRODUCTSETUP
[#] Klíč smazán po restartu: HKCU\Software\csastats


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

H:\AdwCleaner\AdwCleaner[C0].txt - [1237 Bajty] - [31/12/2016 20:32:48]
H:\AdwCleaner\AdwCleaner[S0].txt - [1692 Bajty] - [31/12/2016 20:32:21]

########## EOF - H:\AdwCleaner\AdwCleaner[C0].txt - [1383 Bajty] ##########

Re: Prosím o kontrolu

Napsal: 31 pro 2016 21:13
od Rudy
Dejte nový log RSIT.

Re: Prosím o kontrolu

Napsal: 31 pro 2016 23:38
od maulej
Logfile of random's system information tool 1.10 (written by random/random)
Run by hugo at 2016-12-31 23:37:29
Microsoft Windows 7 Home Premium Service Pack 1
System drive H: has 41 GB (16%) free of 254 GB
Total RAM: 3070 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:38:13, on 31.12.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
H:\Windows\system32\Dwm.exe
H:\Windows\system32\taskhost.exe
H:\Windows\Explorer.EXE
H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
H:\Windows\System32\CTHELPER.EXE
H:\Program Files\AVG\Av\avgui.exe
H:\Program Files\Browny02\Brother\BrStMonW.exe
H:\Program Files\BrownyInd\Brother\BrIndicator.exe
H:\Program Files\AVG\Framework\Common\avguix.exe
H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
H:\Program Files\ControlCenter4\BrCtrlCntr.exe
H:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
H:\Program Files\PicPick\picpick.exe
H:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
H:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPMixDSP.exe
H:\Windows\system32\taskeng.exe
H:\Program Files\CCleaner\CCleaner.exe
H:\Program Files\ControlCenter4\BrCcUxSys.exe
H:\Program Files\NVIDIA Corporation\Display\nvtray.exe
H:\Windows\system32\ctfmon.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\totalcmd\TOTALCMD.EXE
H:\Install\Utils\RSIT.exe
H:\Program Files\trend micro\hugo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Wondershare Video Converter Ultimate 7.1.0 - {451C804F-C205-4F03-B48E-537EC94937BF} - H:\PROGRA~2\WONDER~2\VIDEOC~1\WSBROW~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: McAfee WebAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - H:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AvgUi] "H:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [AVG_UI] "H:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=av
O4 - HKLM\..\Run: [ControlCenter4] H:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] H:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [BrStsInd00] H:\Program Files\BrownyInd\Brother\BrIndicator.exe /AUTORUN
O4 - HKLM\..\Run: [BCSSync] "H:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [LWS] H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [DelaypluginInstall] H:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
O4 - HKLM\..\Run: [SwitchBoard] H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "H:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [PicPick Start] "H:\Program Files\PicPick\picpick.exe" /startup
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "H:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "H:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://H:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O9 - Extra 'Tools' menuitem: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - H:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - H:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: WSWSVCUchrome - {1CA93FF0-A218-44F1 - (no file)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - H:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - H:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgwdsvcx.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - H:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - H:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - H:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PACE License Services (PaceLicenseDServices) - PACE Anti-Piracy, Inc. - H:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - H:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe

--
End of file - 8458 bytes

======Scheduled tasks folder======

H:\Windows\tasks\Adobe Flash Player Updater.job - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default

prefs.js - "browser.startup.homepage" - "www.google.cz"

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=H:\Program Files\McAfee\SiteAdvisor\saffplg.xpi


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=H:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=H:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=H:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88]
"Description"=Sibelius Scorch Plugin
"Path"=H:\Program Files\Sibelius Software\Scorch\npsibelius.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@software602.cz/602XML Filler]
"Description"=602XML Filler Plugin
"Path"=H:\Program Files\Software602\602XML\Filler\npfiller.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=H:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=H:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=H:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


H:\Program Files\Mozilla Firefox\plugins\
NPSibelius.dll
PDFNetC.dll
ScorchAxPlugin.dll
ScorchPDFWrapper.dll

H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\
cs@dictionaries.addons.mozilla.org
marcoagpinto@mail.telepac.pt
{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
{6AC85730-7D0F-4de0-B3FA-21142DD85326}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{451C804F-C205-4F03-B48E-537EC94937BF}]
Wondershare Video Converter Ultimate 7.1.0 - H:\PROGRA~2\WONDER~2\VIDEOC~1\WSBROW~1.DLL [2016-06-12 634000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2014-05-22 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor BHO - h:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2016-10-24 160288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - H:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"=H:\Windows\system32\CTHELPER.EXE [2009-02-23 23040]
"CTxfiHlp"=H:\Windows\system32\CTXFIHLP.EXE [2009-02-23 23552]
"AvgUi"=H:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"AVG_UI"=H:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"ControlCenter4"=H:\Program Files\ControlCenter4\BrCcBoot.exe [2016-02-03 139776]
"BrStsMon00"=H:\Program Files\Browny02\Brother\BrStMonW.exe [2012-12-27 4509184]
"BrStsInd00"=H:\Program Files\BrownyInd\Brother\BrIndicator.exe [2012-12-18 1885184]
"BCSSync"=H:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"LWS"=H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2012-09-12 204136]
"DelaypluginInstall"=H:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [2016-06-12 1971856]
"SwitchBoard"=H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=H:\Program Files\CCleaner\CCleaner.exe [2016-01-15 6628056]
"PicPick Start"=H:\Program Files\PicPick\picpick.exe [2016-09-29 19766728]
"Zoner Photo Studio Autoupdate"=H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud]
H:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-10-25 2383040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
H:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
H:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
H:\Program Files\Virtual PDF Printer\VirtualPDFPrinter.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
H:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
H:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2016-06-20 2131344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Device Detector 3.lnk]
H:\PROGRA~1\Olympus\DEVICE~1\DevDtct2.exe [2007-02-22 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2014-05-22 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=H:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.tscc"=H:\Windows\system32\tsccvid.dll
"vidc.tsc2"=H:\Windows\system32\tsc2_codec32.dll
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - H:\Windows\System32\Notepad.exe %1
.js - open - H:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-12-31 20:30:05 ----D---- H:\AdwCleaner
2016-12-29 21:41:45 ----D---- H:\Program Files\trend micro
2016-12-29 21:41:44 ----D---- H:\rsit
2016-12-29 21:28:21 ----A---- H:\Windows\system32\TURegOpt.exe
2016-12-29 21:28:21 ----A---- H:\Windows\system32\authuitu.dll
2016-12-26 00:34:28 ----D---- H:\Windows\pss
2016-12-14 13:23:28 ----A---- H:\Windows\system32\mshtml.dll
2016-12-14 13:23:27 ----A---- H:\Windows\system32\ieframe.dll
2016-12-14 13:23:26 ----A---- H:\Windows\system32\jscript9.dll
2016-12-14 13:23:25 ----A---- H:\Windows\system32\winload.exe
2016-12-14 13:23:25 ----A---- H:\Windows\system32\wininet.dll
2016-12-14 13:23:25 ----A---- H:\Windows\system32\win32k.sys
2016-12-14 13:23:25 ----A---- H:\Windows\system32\crypt32.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\urlmon.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\ntoskrnl.exe
2016-12-14 13:23:24 ----A---- H:\Windows\system32\msi.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\iedkcs32.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\drivers\cng.sys
2016-12-14 13:23:24 ----A---- H:\Windows\system32\consent.exe
2016-12-14 13:23:24 ----A---- H:\Windows\system32\clfs.sys
2016-12-14 13:23:24 ----A---- H:\Windows\system32\bcrypt.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\bcdedit.exe
2016-12-14 13:23:23 ----A---- H:\Windows\system32\wintrust.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\usp10.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\user32.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\ntkrnlpa.exe
2016-12-14 13:23:23 ----A---- H:\Windows\system32\ntdll.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\nlsbres.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\hlink.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\gdi32.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\drivers\ksecpkg.sys
2016-12-14 13:23:23 ----A---- H:\Windows\system32\drivers\ksecdd.sys
2016-12-14 13:23:22 ----A---- H:\Windows\system32\vbscript.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\mshtmlmedia.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\jscript.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\iertutil.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\msiexec.exe
2016-12-14 13:23:21 ----A---- H:\Windows\system32\msfeeds.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\ieui.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\ieapfltr.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\webcheck.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\smss.exe
2016-12-14 13:23:20 ----A---- H:\Windows\system32\rpcrt4.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\occache.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\msrating.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\msihnd.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\mshtmled.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\jscript9diag.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\dxtrans.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\dxtmsft.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\drivers\mrxsmb.sys
2016-12-14 13:23:20 ----A---- H:\Windows\system32\authui.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\advapi32.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\srcore.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\msv1_0.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\MsSpellCheckingFacility.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\MshtmlDac.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\lsasrv.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\kerberos.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\jsproxy.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\JavaScriptCollectionAgent.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\inseng.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ieUnatt.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ieetwproxystub.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ie4uinit.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\drivers\mrxsmb10.sys
2016-12-14 13:23:19 ----A---- H:\Windows\system32\cryptsvc.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\cryptnet.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\appinfo.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\wdigest.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\TSpkg.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\sspisrv.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\sspicli.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\srclient.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\schannel.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\setbcdlocale.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\secur32.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\rstrui.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\rpchttp.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\ncrypt.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\msimsg.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\lsass.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\iesetup.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\iernonce.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\ieetwcollector.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\drivers\mrxsmb20.sys
2016-12-14 13:23:18 ----A---- H:\Windows\system32\drivers\appid.sys
2016-12-14 13:23:18 ----A---- H:\Windows\system32\csrsrv.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\cryptbase.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\credssp.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\auditpol.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidsvc.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidpolicyconverter.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidcertstorecheck.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidapi.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\apisetschema.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\tzres.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\msaudite.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\adtschema.dll
2016-12-14 13:23:16 ----A---- H:\Windows\system32\msobjs.dll
2016-12-14 13:23:16 ----A---- H:\Windows\system32\ieetwcollectorres.dll
2016-12-09 18:10:32 ----D---- H:\Program Files\Common Files\McAfee
2016-12-09 18:10:01 ----D---- H:\Users\hugo\AppData\Roaming\Anvsoft
2016-12-09 18:09:54 ----D---- H:\ProgramData\McAfee
2016-12-09 18:09:50 ----D---- H:\Program Files\McAfee
2016-12-09 18:09:36 ----D---- H:\Program Files\Anvsoft
2016-12-09 17:56:00 ----D---- H:\Users\hugo\AppData\Roaming\YouTube Downloader
2016-12-09 17:55:31 ----D---- H:\Program Files\YTD
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcr120_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcr110_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcr100_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcp120_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\msvcp110_clr0400.dll
2016-12-01 02:18:32 ----A---- H:\Windows\system32\aspnet_counters.dll

======List of files/folders modified in the last 1 month======

2016-12-31 23:37:41 ----D---- H:\Windows\Prefetch
2016-12-31 23:35:29 ----D---- H:\Windows\Temp
2016-12-31 20:35:24 ----D---- H:\ProgramData\MFAData
2016-12-31 20:33:26 ----D---- H:\Windows\system32\config
2016-12-31 20:29:49 ----D---- H:\Install
2016-12-31 19:35:06 ----D---- H:\Windows\rescache
2016-12-30 00:06:54 ----D---- H:\Windows\inf
2016-12-29 21:43:51 ----D---- H:\Windows\winsxs
2016-12-29 21:43:46 ----D---- H:\Windows\Panther
2016-12-29 21:43:39 ----RD---- H:\Program Files
2016-12-29 21:43:39 ----D---- H:\Windows\system32\cs-CZ
2016-12-29 21:43:39 ----D---- H:\Windows\System32
2016-12-29 21:43:39 ----D---- H:\Program Files\Internet Explorer
2016-12-29 21:43:10 ----SHD---- H:\System Volume Information
2016-12-29 21:37:30 ----D---- H:\Windows\system32\Tasks
2016-12-29 21:37:28 ----D---- H:\Windows\Tasks
2016-12-29 21:32:38 ----D---- H:\ProgramData\Avg
2016-12-29 21:29:06 ----D---- H:\Windows
2016-12-29 21:28:27 ----SHD---- H:\Windows\Installer
2016-12-29 21:28:02 ----D---- H:\Program Files\AVG
2016-12-29 21:18:43 ----D---- H:\Users\hugo\AppData\Roaming\TeamViewer
2016-12-28 17:19:42 ----D---- H:\Users\hugo\AppData\Roaming\Audacity
2016-12-25 17:37:59 ----D---- H:\ProgramData\boost_interprocess
2016-12-25 12:43:47 ----D---- H:\Windows\debug
2016-12-23 16:12:19 ----D---- H:\Windows\system32\wdi
2016-12-22 23:37:07 ----D---- H:\Audio
2016-12-22 10:35:28 ----D---- H:\Users\hugo\AppData\Roaming\EmuPatchMixDSP
2016-12-20 15:27:29 ----D---- H:\sken
2016-12-20 11:07:55 ----D---- H:\AJ
2016-12-19 14:16:36 ----D---- H:\Users\hugo\AppData\Roaming\vlc
2016-12-15 08:59:36 ----A---- H:\Windows\system32\PerfStringBackup.INI
2016-12-15 08:50:55 ----D---- H:\Windows\system32\en-US
2016-12-15 08:50:55 ----D---- H:\Windows\system32\drivers
2016-12-15 08:50:51 ----D---- H:\Windows\system32\Boot
2016-12-15 08:50:47 ----D---- H:\Program Files\Mozilla Firefox
2016-12-14 22:03:32 ----D---- H:\Windows\Microsoft.NET
2016-12-14 22:03:23 ----D---- H:\ProgramData\Microsoft Help
2016-12-14 22:01:56 ----D---- H:\Windows\system32\MRT
2016-12-14 22:00:36 ----RSD---- H:\Windows\assembly
2016-12-14 21:57:39 ----AC---- H:\Windows\system32\MRT.exe
2016-12-14 14:20:46 ----D---- H:\Program Files\Mozilla Maintenance Service
2016-12-14 13:21:23 ----D---- H:\Windows\system32\catroot2
2016-12-13 22:17:12 ----A---- H:\Windows\system32\FlashPlayerApp.exe
2016-12-13 22:17:10 ----D---- H:\Windows\system32\Macromed
2016-12-09 18:10:32 ----D---- H:\Program Files\Common Files
2016-12-09 18:09:54 ----HD---- H:\ProgramData

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; H:\Windows\system32\DRIVERS\avgidshx.sys [2016-10-05 207616]
R0 Avglogx;AVG Logging Driver; H:\Windows\system32\DRIVERS\avglogx.sys [2016-02-16 287008]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; H:\Windows\system32\DRIVERS\avgmfx86.sys [2016-09-26 197376]
R0 Avgrkx86;AVG Anti-Rootkit Driver; H:\Windows\system32\DRIVERS\avgrkx86.sys [2016-06-01 47360]
R0 avgunivx;AVG Universal Driver; H:\Windows\system32\DRIVERS\avgunivx.sys [2016-06-20 65280]
R0 pciide;pciide; H:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; H:\Windows\System32\Drivers\PxHelp20.sys [2011-11-03 45968]
R0 rdyboost;ReadyBoost; H:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; H:\Windows\system32\DRIVERS\avgdiskx.sys [2016-05-13 134912]
R1 AVGIDSDriver;AVGIDSDriver; H:\Windows\system32\DRIVERS\avgidsdriverx.sys [2016-10-17 259328]
R1 AVGIDSShim;AVGIDSShim; H:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-11-20 31664]
R1 Avgldx86;AVG AVI Loader Driver; H:\Windows\system32\DRIVERS\avgldx86.sys [2016-10-19 219904]
R1 Avgtdix;AVG TDI Driver; H:\Windows\system32\DRIVERS\avgtdix.sys [2016-07-27 231680]
R1 ElbyCDIO;ElbyCDIO Driver; H:\Windows\System32\Drivers\ElbyCDIO.sys [2014-12-20 30616]
R2 Parvdm;Parvdm; H:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 COMMONFX.SYS;COMMONFX.SYS; H:\Windows\System32\drivers\COMMONFX.SYS [2009-02-23 98328]
R3 ctaud2k;Creative Audio Driver (WDM); H:\Windows\system32\drivers\ctaud2k.sys [2009-02-23 524824]
R3 CTEDSPIO.SYS;CTEDSPIO.SYS; H:\Windows\System32\drivers\CTEDSPIO.SYS [2009-02-23 134168]
R3 CTEDSPSY.SYS;CTEDSPSY.SYS; H:\Windows\System32\drivers\CTEDSPSY.SYS [2009-02-23 309784]
R3 ctprxy2k;Creative Proxy Driver; H:\Windows\system32\drivers\ctprxy2k.sys [2009-02-23 14360]
R3 ctsfm2k;Creative SoundFont Management Device Driver; H:\Windows\system32\drivers\ctsfm2k.sys [2009-02-23 159256]
R3 emupia;E-mu Plug-in Architecture Driver; H:\Windows\system32\drivers\emupia2k.sys [2009-02-23 95768]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; H:\Windows\system32\drivers\ha10kx2k.sys [2009-02-23 802840]
R3 mfesapsn;McAfee Process Start Notification Service; \??\H:\Program Files\McAfee\SiteAdvisor\mfesapsn.sys [2016-06-06 41600]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; H:\Windows\system32\drivers\nvhda32v.sys [2012-07-03 149352]
R3 ossrv;Creative OS Services Driver; H:\Windows\system32\drivers\ctoss2k.sys [2009-02-23 129560]
R3 RTL8167;Realtek 8167 NT Driver; H:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [2016-11-25 31792]
R3 VClone;VClone; H:\Windows\system32\DRIVERS\VClone.sys [2013-07-24 30720]
S3 aic78xx;aic78xx; H:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; H:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; H:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 COMMONFX;COMMONFX; H:\Windows\system32\drivers\COMMONFX.SYS [2009-02-23 98328]
S3 CT20XUT.SYS;CT20XUT.SYS; H:\Windows\System32\drivers\CT20XUT.SYS [2009-02-23 171032]
S3 CT20XUT;CT20XUT; H:\Windows\system32\drivers\CT20XUT.SYS [2009-02-23 171032]
S3 ctac32k;Creative AC3 Software Decoder; H:\Windows\system32\drivers\ctac32k.sys [2009-02-23 511000]
S3 CTAUDFX.SYS;CTAUDFX.SYS; H:\Windows\System32\drivers\CTAUDFX.SYS [2009-02-23 528920]
S3 CTAUDFX;CTAUDFX; H:\Windows\system32\drivers\CTAUDFX.SYS [2009-02-23 528920]
S3 CTEAPSFX.SYS;CTEAPSFX.SYS; H:\Windows\System32\drivers\CTEAPSFX.SYS [2009-02-23 163352]
S3 CTEAPSFX;CTEAPSFX; H:\Windows\system32\drivers\CTEAPSFX.SYS [2009-02-23 163352]
S3 CTEDSPFX.SYS;CTEDSPFX.SYS; H:\Windows\System32\drivers\CTEDSPFX.SYS [2009-02-23 259096]
S3 CTEDSPFX;CTEDSPFX; H:\Windows\system32\drivers\CTEDSPFX.SYS [2009-02-23 259096]
S3 CTEDSPIO;CTEDSPIO; H:\Windows\system32\drivers\CTEDSPIO.SYS [2009-02-23 134168]
S3 CTEDSPSY;CTEDSPSY; H:\Windows\system32\drivers\CTEDSPSY.SYS [2009-02-23 309784]
S3 CTERFXFX.SYS;CTERFXFX.SYS; H:\Windows\System32\drivers\CTERFXFX.SYS [2009-02-23 99352]
S3 CTERFXFX;CTERFXFX; H:\Windows\system32\drivers\CTERFXFX.SYS [2009-02-23 99352]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; H:\Windows\System32\drivers\CTEXFIFX.SYS [2009-02-23 1324056]
S3 CTEXFIFX;CTEXFIFX; H:\Windows\system32\drivers\CTEXFIFX.SYS [2009-02-23 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS; H:\Windows\System32\drivers\CTHWIUT.SYS [2009-02-23 72728]
S3 CTHWIUT;CTHWIUT; H:\Windows\system32\drivers\CTHWIUT.SYS [2009-02-23 72728]
S3 CTSBLFX.SYS;CTSBLFX.SYS; H:\Windows\System32\drivers\CTSBLFX.SYS [2009-02-23 534040]
S3 CTSBLFX;CTSBLFX; H:\Windows\system32\drivers\CTSBLFX.SYS [2009-02-23 534040]
S3 LVRS;Logitech RightSound Filter Driver; H:\Windows\system32\DRIVERS\lvrs.sys [2012-09-21 310504]
S3 LVUVC;Logitech HD Pro Webcam C920(UVC); H:\Windows\system32\DRIVERS\lvuvc.sys [2012-09-21 4261224]
S3 sisagp;Filtr SIS sběrnice AGP; H:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;TsUsbFlt; H:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbscan;Ovladač skeneru USB; H:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; H:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; H:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VNUSB;VN Series Device; H:\Windows\system32\DRIVERS\VNUSB.sys [2006-04-07 38496]
S3 WinUsb;WinUsb; H:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; H:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-10-21 82128]
R2 AdobeUpdateService;AdobeUpdateService; H:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-25 744640]
R2 AGSService;Adobe Genuine Software Integrity Service; H:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-09-26 2207960]
R2 aspnet_state;Stavová služba ASP.NET; H:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2016-12-01 45752]
R2 AVGIDSAgent;AVGIDSAgent; H:\Program Files\AVG\Av\avgidsagent.exe [2016-11-02 4152896]
R2 avgsvc;AVG Service; H:\Program Files\AVG\Framework\Common\avgsvcx.exe [2016-12-06 935184]
R2 avgwd;AVG WatchDog; H:\Program Files\AVG\Av\avgwdsvcx.exe [2016-11-02 604824]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; H:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; H:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2016-10-24 160800]
R2 nvsvc;NVIDIA Display Driver Service; H:\Windows\system32\nvvsvc.exe [2012-10-02 645992]
R2 PaceLicenseDServices;PACE License Services; H:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-09-08 2932224]
R2 TeamViewer;TeamViewer 11; H:\Program Files\TeamViewer\TeamViewer_Service.exe [2016-08-08 7248144]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; H:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2016-11-25 3844880]
R3 BrYNSvc;BrYNSvc; H:\Program Files\Browny02\BrYNSvc.exe [2012-10-26 282112]
R3 osppsvc;Office Software Protection Platform; H:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; H:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-12-01 103608]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2016-07-15 154440]
S2 nvUpdatusService;NVIDIA Update Service Daemon; H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-12-13 270936]
S3 AvgAMPS;AvgAMPS; H:\Program Files\AVG\Av\avgamps.exe [2016-11-02 647864]
S3 gupdatem;Služba Google Update (gupdatem); H:\Program Files\Google\Update\GoogleUpdate.exe [2016-07-15 154440]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; H:\Windows\system32\IEEtwCollector.exe [2016-11-12 102912]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; H:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2014-12-04 30826680]
S3 MozillaMaintenance;Mozilla Maintenance Service; H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-12-14 172488]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SwitchBoard;SwitchBoard; H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; H:\Windows\system32\Wat\WatAdminSvc.exe [2016-07-16 1343400]
S4 NetMsmqActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]
S4 NetPipeActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]
S4 NetTcpActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 01 led 2017 11:13
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: Prosím o kontrolu

Napsal: 01 led 2017 20:13
od maulej
Logfile of random's system information tool 1.14 (written by random/random)
Run by hugo at 2017-01-01 20:10:55
Microsoft Windows 7 Home Premium Service Pack 1
System drive H: has 42 GB (17%) free of 254 GB
Total RAM: 3070 MB (56% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:11:27, on 1.1.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
H:\Windows\system32\taskhost.exe
H:\Windows\system32\Dwm.exe
H:\Windows\Explorer.EXE
H:\Program Files\NVIDIA Corporation\Display\nvtray.exe
H:\Windows\System32\CTHELPER.EXE
H:\Program Files\Browny02\Brother\BrStMonW.exe
H:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPMixDSP.exe
H:\Program Files\AVG\Av\avgui.exe
H:\Program Files\BrownyInd\Brother\BrIndicator.exe
H:\Program Files\AVG\Framework\Common\avguix.exe
H:\Program Files\ControlCenter4\BrCtrlCntr.exe
H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
H:\Program Files\PicPick\picpick.exe
H:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
H:\Windows\system32\taskeng.exe
H:\Program Files\CCleaner\CCleaner.exe
H:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
H:\Program Files\ControlCenter4\BrCcUxSys.exe
H:\Windows\system32\ctfmon.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Install\Utils\RSIT.exe
H:\Program Files\trend micro\hugo_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Wondershare Video Converter Ultimate 7.1.0 - {451C804F-C205-4F03-B48E-537EC94937BF} - H:\PROGRA~2\WONDER~2\VIDEOC~1\WSBROW~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - H:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AvgUi] "H:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [AVG_UI] "H:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=av
O4 - HKLM\..\Run: [ControlCenter4] H:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] H:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [BrStsInd00] H:\Program Files\BrownyInd\Brother\BrIndicator.exe /AUTORUN
O4 - HKLM\..\Run: [BCSSync] "H:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [LWS] H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [DelaypluginInstall] H:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
O4 - HKLM\..\Run: [SwitchBoard] H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "H:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [PicPick Start] "H:\Program Files\PicPick\picpick.exe" /startup
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] H:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "H:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "H:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://H:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - H:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - H:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: WSWSVCUchrome - {1CA93FF0-A218-44F1 - (no file)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - H:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - H:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgidsagent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - H:\Program Files\AVG\Av\avgwdsvcx.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - H:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - H:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - H:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PACE License Services (PaceLicenseDServices) - PACE Anti-Piracy, Inc. - H:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Airytec Switch Off - Task Scheduler (SwOffScheduler) - Airytec - H:\Program Files\Airytec\Switch Off\swoff.exe
O23 - Service: Airytec Switch Off - Web Interface (SwOffWeb) - Airytec - H:\Program Files\Airytec\Switch Off\swoff.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - H:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 7756 bytes

======Scheduled tasks folder======

H:\Windows\tasks\Adobe Flash Player Updater.job - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
H:\Windows\system32\tasks\Adobe Acrobat Update Task - H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
H:\Windows\system32\tasks\Adobe Flash Player Updater - H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
H:\Windows\system32\tasks\AdobeAAMUpdater-1.0-hugo-PC-hugo - H:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -mode=scheduled
H:\Windows\system32\tasks\AVG EUpdate Task - avgsetupx.exe /eu
H:\Windows\system32\tasks\CCleanerSkipUAC - "H:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
H:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - H:\Program Files\Google\Update\GoogleUpdate.exe /c
H:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - H:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
H:\Windows\system32\tasks\User_Feed_Synchronization-{0148DDC8-9976-427C-BEBB-9C5D847388FB} - H:\Windows\system32\msfeedssync.exe sync
H:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-3290210395-743186196-717925178-1001 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
H:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - %systemroot%\system32\sc.exe start osppsvc
H:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
H:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
H:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
H:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
H:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
H:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
H:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
H:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
H:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
H:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
H:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
H:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
H:\Windows\system32\tasks\Microsoft\Windows\Setup\EOSNotify - %windir%\system32\EOSNotify.exe
H:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
H:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
H:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
H:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate_scheduled - %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
H:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
H:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
H:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
H:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
H:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
H:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
H:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
H:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
H:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
H:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
H:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Mozilla firefox=========

ProfilePath - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default

prefs.js - "browser.startup.homepage" - "www.google.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=H:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=H:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=H:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88]
"Description"=Sibelius Scorch Plugin
"Path"=H:\Program Files\Sibelius Software\Scorch\npsibelius.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@software602.cz/602XML Filler]
"Description"=602XML Filler Plugin
"Path"=H:\Program Files\Software602\602XML\Filler\npfiller.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=H:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=H:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=H:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


H:\Program Files\Mozilla Firefox\plugins\
NPSibelius.dll
PDFNetC.dll
ScorchAxPlugin.dll
ScorchPDFWrapper.dll

H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\
cs@dictionaries.addons.mozilla.org
marcoagpinto@mail.telepac.pt
{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
{6AC85730-7D0F-4de0-B3FA-21142DD85326}

H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
British English Dictionary (Marco Pinto) - dictionary - marcoagpinto@mail.telepac.pt
FEBE - extension - {4BBDD651-70CF-4821-84F8-2B918CF89CA3}
ColorZilla - extension - {6AC85730-7D0F-4de0-B3FA-21142DD85326}
Český slovník pro kontrolu pravopisu - dictionary - cs@dictionaries.addons.mozilla.org

H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions.json
Český slovník pro kontrolu pravopisu - dictionary - cs@dictionaries.addons.mozilla.org - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\cs@dictionaries.addons.mozilla.org
FEBE - extension - {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
ColorZilla - extension - {6AC85730-7D0F-4de0-B3FA-21142DD85326} - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - H:\Program Files\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - H:\Program Files\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - H:\Program Files\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - H:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - H:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
British English Dictionary (Marco Pinto) - dictionary - marcoagpinto@mail.telepac.pt - H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\extensions\marcoagpinto@mail.telepac.pt

H:\Users\hugo\AppData\Roaming\Mozilla\Firefox\Profiles\opoirmnn.default\pluginreg.dat
Plugin - AdobeAAMDetect - 3.0.0.0 - H:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
Plugin - Adobe Acrobat - 15.20.20039.7108 - H:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
Plugin - VLC Web Plugin - 2.2.4.0 - H:\Program Files\VideoLAN\VLC\npvlc.dll
Plugin - Google Update - 1.3.32.7 - H:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll
Plugin - Software602 Form Filler - 4.15.0.0 - H:\Program Files\Software602\602XML\Filler\npfiller.dll
Plugin - ScorchPlugin - 6.2.0.88 - H:\Program Files\Sibelius Software\Scorch\NPSibelius.dll
Plugin - Microsoft Office 2010 - 14.0.4730.1010 - H:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
Plugin - Microsoft Office 2010 - 14.0.4761.1000 - H:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
Plugin - Shockwave Flash - 24.0.0.186 - H:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll

=========Google Chrome=========

H:\Users\hugo\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension fheoggkfdfchfphceeifdbepaooicaho 2 McAfee® WebAdvisor 5.0.331.0
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mdddabjhelpilpnpgondfmehhcplpiin 1 Upravte a pošlete snímek obrazovky 8.4.5
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.1
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension oeopbcgkkoapgobdbedcemjljbihmemj 1 Checker Plus for Gmail™ 19.3.5
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5516.1005.0.3
Homepage:
default_search_provider.search_url:
H:\Users\hugo\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{451C804F-C205-4F03-B48E-537EC94937BF}]
Wondershare Video Converter Ultimate 7.1.0 - H:\PROGRA~2\WONDER~2\VIDEOC~1\WSBROW~1.DLL [2016-06-12 634000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2014-05-22 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - H:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"=H:\Windows\system32\CTHELPER.EXE [2009-02-23 23040]
"CTxfiHlp"=H:\Windows\system32\CTXFIHLP.EXE [2009-02-23 23552]
"AvgUi"=H:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"AVG_UI"=H:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"ControlCenter4"=H:\Program Files\ControlCenter4\BrCcBoot.exe [2016-02-03 139776]
"BrStsMon00"=H:\Program Files\Browny02\Brother\BrStMonW.exe [2012-12-27 4509184]
"BrStsInd00"=H:\Program Files\BrownyInd\Brother\BrIndicator.exe [2012-12-18 1885184]
"BCSSync"=H:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"LWS"=H:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2012-09-12 204136]
"DelaypluginInstall"=H:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [2016-06-12 1971856]
"SwitchBoard"=H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=H:\Program Files\CCleaner\CCleaner.exe [2016-01-15 6628056]
"PicPick Start"=H:\Program Files\PicPick\picpick.exe [2016-09-29 19766728]
"Zoner Photo Studio Autoupdate"=H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud]
H:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-10-25 2383040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
H:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
H:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
H:\Program Files\Virtual PDF Printer\VirtualPDFPrinter.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
H:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
H:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2016-06-20 2131344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
H:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\H:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Device Detector 3.lnk]
H:\PROGRA~1\Olympus\DEVICE~1\DevDtct2.exe [2007-02-22 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=H:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2014-05-22 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="H:\Program Files\Google\Chrome\Application\55.0.2883.87\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=H:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.tscc"=H:\Windows\system32\tsccvid.dll
"vidc.tsc2"=H:\Windows\system32\tsc2_codec32.dll
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - H:\Windows\System32\Notepad.exe %1
.js - open - H:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-01-01 01:44:31 ----D---- H:\Users\hugo\AppData\Roaming\Airytec
2017-01-01 01:44:27 ----D---- H:\Program Files\Airytec
2016-12-31 20:30:05 ----D---- H:\AdwCleaner
2016-12-29 21:41:45 ----D---- H:\Program Files\trend micro
2016-12-29 21:41:44 ----D---- H:\rsit
2016-12-26 00:34:28 ----D---- H:\Windows\pss
2016-12-14 13:23:28 ----A---- H:\Windows\system32\mshtml.dll
2016-12-14 13:23:27 ----A---- H:\Windows\system32\ieframe.dll
2016-12-14 13:23:26 ----A---- H:\Windows\system32\jscript9.dll
2016-12-14 13:23:25 ----A---- H:\Windows\system32\winload.exe
2016-12-14 13:23:25 ----A---- H:\Windows\system32\wininet.dll
2016-12-14 13:23:25 ----A---- H:\Windows\system32\win32k.sys
2016-12-14 13:23:25 ----A---- H:\Windows\system32\crypt32.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\urlmon.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\ntoskrnl.exe
2016-12-14 13:23:24 ----A---- H:\Windows\system32\msi.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\iedkcs32.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\drivers\cng.sys
2016-12-14 13:23:24 ----A---- H:\Windows\system32\consent.exe
2016-12-14 13:23:24 ----A---- H:\Windows\system32\clfs.sys
2016-12-14 13:23:24 ----A---- H:\Windows\system32\bcrypt.dll
2016-12-14 13:23:24 ----A---- H:\Windows\system32\bcdedit.exe
2016-12-14 13:23:23 ----A---- H:\Windows\system32\wintrust.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\usp10.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\user32.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\ntkrnlpa.exe
2016-12-14 13:23:23 ----A---- H:\Windows\system32\ntdll.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\nlsbres.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\hlink.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\gdi32.dll
2016-12-14 13:23:23 ----A---- H:\Windows\system32\drivers\ksecpkg.sys
2016-12-14 13:23:23 ----A---- H:\Windows\system32\drivers\ksecdd.sys
2016-12-14 13:23:22 ----A---- H:\Windows\system32\vbscript.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\mshtmlmedia.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\jscript.dll
2016-12-14 13:23:22 ----A---- H:\Windows\system32\iertutil.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\msiexec.exe
2016-12-14 13:23:21 ----A---- H:\Windows\system32\msfeeds.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\ieui.dll
2016-12-14 13:23:21 ----A---- H:\Windows\system32\ieapfltr.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\webcheck.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\smss.exe
2016-12-14 13:23:20 ----A---- H:\Windows\system32\rpcrt4.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\occache.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\msrating.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\msihnd.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\mshtmled.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\jscript9diag.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\dxtrans.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\dxtmsft.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\drivers\mrxsmb.sys
2016-12-14 13:23:20 ----A---- H:\Windows\system32\authui.dll
2016-12-14 13:23:20 ----A---- H:\Windows\system32\advapi32.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\srcore.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\msv1_0.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\MsSpellCheckingFacility.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\MshtmlDac.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\lsasrv.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\kerberos.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\jsproxy.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\JavaScriptCollectionAgent.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\inseng.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ieUnatt.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ieetwproxystub.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\ie4uinit.exe
2016-12-14 13:23:19 ----A---- H:\Windows\system32\drivers\mrxsmb10.sys
2016-12-14 13:23:19 ----A---- H:\Windows\system32\cryptsvc.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\cryptnet.dll
2016-12-14 13:23:19 ----A---- H:\Windows\system32\appinfo.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\wdigest.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\TSpkg.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\sspisrv.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\sspicli.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\srclient.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\schannel.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\setbcdlocale.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\secur32.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\rstrui.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\rpchttp.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\ncrypt.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\msimsg.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\lsass.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\iesetup.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\iernonce.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\ieetwcollector.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\drivers\mrxsmb20.sys
2016-12-14 13:23:18 ----A---- H:\Windows\system32\drivers\appid.sys
2016-12-14 13:23:18 ----A---- H:\Windows\system32\csrsrv.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\cryptbase.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\credssp.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\auditpol.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidsvc.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidpolicyconverter.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidcertstorecheck.exe
2016-12-14 13:23:18 ----A---- H:\Windows\system32\appidapi.dll
2016-12-14 13:23:18 ----A---- H:\Windows\system32\apisetschema.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\tzres.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\msaudite.dll
2016-12-14 13:23:17 ----A---- H:\Windows\system32\adtschema.dll
2016-12-14 13:23:16 ----A---- H:\Windows\system32\msobjs.dll
2016-12-14 13:23:16 ----A---- H:\Windows\system32\ieetwcollectorres.dll
2016-12-09 18:10:01 ----D---- H:\Users\hugo\AppData\Roaming\Anvsoft
2016-12-09 18:09:54 ----D---- H:\ProgramData\McAfee
2016-12-09 18:09:36 ----D---- H:\Program Files\Anvsoft
2016-12-09 17:56:00 ----D---- H:\Users\hugo\AppData\Roaming\YouTube Downloader
2016-12-09 17:55:31 ----D---- H:\Program Files\YTD

======List of files/folders modified in the last 1 month======

2017-01-01 20:11:05 ----D---- H:\Windows\Prefetch
2017-01-01 20:10:59 ----D---- H:\Windows\Temp
2017-01-01 20:00:20 ----D---- H:\ProgramData\MFAData
2017-01-01 20:00:04 ----D---- H:\Windows
2017-01-01 19:58:43 ----D---- H:\Windows\system32\config
2017-01-01 19:54:15 ----D---- H:\Install
2017-01-01 19:34:59 ----D---- H:\Users\hugo\AppData\Roaming\TeamViewer
2017-01-01 19:34:48 ----D---- H:\Windows\Panther
2017-01-01 19:34:48 ----D---- H:\Windows\inf
2017-01-01 01:44:27 ----RD---- H:\Program Files
2017-01-01 01:29:56 ----D---- H:\Program Files\Common Files
2016-12-31 23:43:24 ----D---- H:\Program Files\Acro Software
2016-12-31 23:43:22 ----D---- H:\Windows\System32
2016-12-31 23:43:07 ----SHD---- H:\Windows\Installer
2016-12-31 19:35:06 ----D---- H:\Windows\rescache
2016-12-29 21:43:51 ----D---- H:\Windows\winsxs
2016-12-29 21:43:39 ----D---- H:\Windows\system32\cs-CZ
2016-12-29 21:43:39 ----D---- H:\Program Files\Internet Explorer
2016-12-29 21:43:10 ----SHD---- H:\System Volume Information
2016-12-29 21:37:30 ----D---- H:\Windows\system32\Tasks
2016-12-29 21:37:28 ----D---- H:\Windows\Tasks
2016-12-29 21:32:38 ----D---- H:\ProgramData\Avg
2016-12-29 21:28:02 ----D---- H:\Program Files\AVG
2016-12-28 17:19:42 ----D---- H:\Users\hugo\AppData\Roaming\Audacity
2016-12-25 17:37:59 ----D---- H:\ProgramData\boost_interprocess
2016-12-25 12:43:47 ----D---- H:\Windows\debug
2016-12-23 16:12:19 ----D---- H:\Windows\system32\wdi
2016-12-22 23:37:07 ----D---- H:\Audio
2016-12-22 10:35:28 ----D---- H:\Users\hugo\AppData\Roaming\EmuPatchMixDSP
2016-12-20 15:27:29 ----D---- H:\sken
2016-12-20 11:07:55 ----D---- H:\AJ
2016-12-19 14:16:36 ----D---- H:\Users\hugo\AppData\Roaming\vlc
2016-12-15 08:59:36 ----A---- H:\Windows\system32\PerfStringBackup.INI
2016-12-15 08:50:55 ----D---- H:\Windows\system32\en-US
2016-12-15 08:50:55 ----D---- H:\Windows\system32\drivers
2016-12-15 08:50:51 ----D---- H:\Windows\system32\Boot
2016-12-15 08:50:47 ----D---- H:\Program Files\Mozilla Firefox
2016-12-14 22:03:32 ----D---- H:\Windows\Microsoft.NET
2016-12-14 22:03:23 ----D---- H:\ProgramData\Microsoft Help
2016-12-14 22:01:56 ----D---- H:\Windows\system32\MRT
2016-12-14 22:00:36 ----RSD---- H:\Windows\assembly
2016-12-14 21:57:39 ----AC---- H:\Windows\system32\MRT.exe
2016-12-14 14:20:46 ----D---- H:\Program Files\Mozilla Maintenance Service
2016-12-14 13:21:23 ----D---- H:\Windows\system32\catroot2
2016-12-13 22:17:12 ----A---- H:\Windows\system32\FlashPlayerApp.exe
2016-12-13 22:17:10 ----D---- H:\Windows\system32\Macromed
2016-12-09 18:09:54 ----HD---- H:\ProgramData

File H:\Windows\system32\winlogon.exe is digitally signed
File H:\Windows\system32\wininit.exe is digitally signed
File H:\Windows\explorer.exe is digitally signed
File H:\Windows\system32\svchost.exe is digitally signed
File H:\Windows\system32\services.exe is digitally signed
File H:\Windows\system32\User32.dll is digitally signed
File H:\Windows\system32\userinit.exe is digitally signed
File H:\Windows\system32\rpcss.dll is digitally signed
File H:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; H:\Windows\system32\DRIVERS\avgidshx.sys [2016-10-05 207616]
R0 Avglogx;AVG Logging Driver; H:\Windows\system32\DRIVERS\avglogx.sys [2016-02-16 287008]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; H:\Windows\system32\DRIVERS\avgmfx86.sys [2016-09-26 197376]
R0 Avgrkx86;AVG Anti-Rootkit Driver; H:\Windows\system32\DRIVERS\avgrkx86.sys [2016-06-01 47360]
R0 avgunivx;AVG Universal Driver; H:\Windows\system32\DRIVERS\avgunivx.sys [2016-06-20 65280]
R0 pciide;pciide; H:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; H:\Windows\System32\Drivers\PxHelp20.sys [2011-11-03 45968]
R0 rdyboost;ReadyBoost; H:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgdiskx;AVG Disk Driver; H:\Windows\system32\DRIVERS\avgdiskx.sys [2016-05-13 134912]
R1 AVGIDSDriver;AVGIDSDriver; H:\Windows\system32\DRIVERS\avgidsdriverx.sys [2016-10-17 259328]
R1 AVGIDSShim;AVGIDSShim; H:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-11-20 31664]
R1 Avgldx86;AVG AVI Loader Driver; H:\Windows\system32\DRIVERS\avgldx86.sys [2016-10-19 219904]
R1 Avgtdix;AVG TDI Driver; H:\Windows\system32\DRIVERS\avgtdix.sys [2016-07-27 231680]
R1 ElbyCDIO;ElbyCDIO Driver; H:\Windows\System32\Drivers\ElbyCDIO.sys [2014-12-20 30616]
R2 Parvdm;Parvdm; H:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 COMMONFX.SYS;COMMONFX.SYS; H:\Windows\System32\drivers\COMMONFX.SYS [2009-02-23 98328]
R3 ctaud2k;Creative Audio Driver (WDM); H:\Windows\system32\drivers\ctaud2k.sys [2009-02-23 524824]
R3 CTEDSPIO.SYS;CTEDSPIO.SYS; H:\Windows\System32\drivers\CTEDSPIO.SYS [2009-02-23 134168]
R3 CTEDSPSY.SYS;CTEDSPSY.SYS; H:\Windows\System32\drivers\CTEDSPSY.SYS [2009-02-23 309784]
R3 ctprxy2k;Creative Proxy Driver; H:\Windows\system32\drivers\ctprxy2k.sys [2009-02-23 14360]
R3 ctsfm2k;Creative SoundFont Management Device Driver; H:\Windows\system32\drivers\ctsfm2k.sys [2009-02-23 159256]
R3 emupia;E-mu Plug-in Architecture Driver; H:\Windows\system32\drivers\emupia2k.sys [2009-02-23 95768]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; H:\Windows\system32\drivers\ha10kx2k.sys [2009-02-23 802840]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; H:\Windows\system32\drivers\nvhda32v.sys [2012-07-03 149352]
R3 ossrv;Creative OS Services Driver; H:\Windows\system32\drivers\ctoss2k.sys [2009-02-23 129560]
R3 RTL8167;Realtek 8167 NT Driver; H:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 VClone;VClone; H:\Windows\system32\DRIVERS\VClone.sys [2013-07-24 30720]
S3 aic78xx;aic78xx; H:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; H:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; H:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 COMMONFX;COMMONFX; H:\Windows\system32\drivers\COMMONFX.SYS [2009-02-23 98328]
S3 CT20XUT.SYS;CT20XUT.SYS; H:\Windows\System32\drivers\CT20XUT.SYS [2009-02-23 171032]
S3 CT20XUT;CT20XUT; H:\Windows\system32\drivers\CT20XUT.SYS [2009-02-23 171032]
S3 ctac32k;Creative AC3 Software Decoder; H:\Windows\system32\drivers\ctac32k.sys [2009-02-23 511000]
S3 CTAUDFX.SYS;CTAUDFX.SYS; H:\Windows\System32\drivers\CTAUDFX.SYS [2009-02-23 528920]
S3 CTAUDFX;CTAUDFX; H:\Windows\system32\drivers\CTAUDFX.SYS [2009-02-23 528920]
S3 CTEAPSFX.SYS;CTEAPSFX.SYS; H:\Windows\System32\drivers\CTEAPSFX.SYS [2009-02-23 163352]
S3 CTEAPSFX;CTEAPSFX; H:\Windows\system32\drivers\CTEAPSFX.SYS [2009-02-23 163352]
S3 CTEDSPFX.SYS;CTEDSPFX.SYS; H:\Windows\System32\drivers\CTEDSPFX.SYS [2009-02-23 259096]
S3 CTEDSPFX;CTEDSPFX; H:\Windows\system32\drivers\CTEDSPFX.SYS [2009-02-23 259096]
S3 CTEDSPIO;CTEDSPIO; H:\Windows\system32\drivers\CTEDSPIO.SYS [2009-02-23 134168]
S3 CTEDSPSY;CTEDSPSY; H:\Windows\system32\drivers\CTEDSPSY.SYS [2009-02-23 309784]
S3 CTERFXFX.SYS;CTERFXFX.SYS; H:\Windows\System32\drivers\CTERFXFX.SYS [2009-02-23 99352]
S3 CTERFXFX;CTERFXFX; H:\Windows\system32\drivers\CTERFXFX.SYS [2009-02-23 99352]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; H:\Windows\System32\drivers\CTEXFIFX.SYS [2009-02-23 1324056]
S3 CTEXFIFX;CTEXFIFX; H:\Windows\system32\drivers\CTEXFIFX.SYS [2009-02-23 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS; H:\Windows\System32\drivers\CTHWIUT.SYS [2009-02-23 72728]
S3 CTHWIUT;CTHWIUT; H:\Windows\system32\drivers\CTHWIUT.SYS [2009-02-23 72728]
S3 CTSBLFX.SYS;CTSBLFX.SYS; H:\Windows\System32\drivers\CTSBLFX.SYS [2009-02-23 534040]
S3 CTSBLFX;CTSBLFX; H:\Windows\system32\drivers\CTSBLFX.SYS [2009-02-23 534040]
S3 LVRS;Logitech RightSound Filter Driver; H:\Windows\system32\DRIVERS\lvrs.sys [2012-09-21 310504]
S3 LVUVC;Logitech HD Pro Webcam C920(UVC); H:\Windows\system32\DRIVERS\lvuvc.sys [2012-09-21 4261224]
S3 sisagp;Filtr SIS sběrnice AGP; H:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;TsUsbFlt; H:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbscan;Ovladač skeneru USB; H:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; H:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; H:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VNUSB;VN Series Device; H:\Windows\system32\DRIVERS\VNUSB.sys [2006-04-07 38496]
S3 WinUsb;WinUsb; H:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; H:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; H:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-10-21 82128]
R2 AdobeUpdateService;AdobeUpdateService; H:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-25 744640]
R2 AGSService;Adobe Genuine Software Integrity Service; H:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-09-26 2207960]
R2 aspnet_state;Stavová služba ASP.NET; H:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2016-12-01 45752]
R2 AVGIDSAgent;AVGIDSAgent; H:\Program Files\AVG\Av\avgidsagent.exe [2016-11-02 4152896]
R2 avgsvc;AVG Service; H:\Program Files\AVG\Framework\Common\avgsvcx.exe [2016-12-06 935184]
R2 avgwd;AVG WatchDog; H:\Program Files\AVG\Av\avgwdsvcx.exe [2016-11-02 604824]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 nvsvc;NVIDIA Display Driver Service; H:\Windows\system32\nvvsvc.exe [2012-10-02 645992]
R2 PaceLicenseDServices;PACE License Services; H:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2011-09-08 2932224]
R2 TeamViewer;TeamViewer 11; H:\Program Files\TeamViewer\TeamViewer_Service.exe [2016-08-08 7248144]
R3 BrYNSvc;BrYNSvc; H:\Program Files\Browny02\BrYNSvc.exe [2012-10-26 282112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; H:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-12-01 103608]
S2 gupdate;Služba Google Update (gupdate); H:\Program Files\Google\Update\GoogleUpdate.exe [2016-07-15 154440]
S2 nvUpdatusService;NVIDIA Update Service Daemon; H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S2 SwOffScheduler;Airytec Switch Off - Task Scheduler; H:\Program Files\Airytec\Switch Off\swoff.exe [2014-09-23 135168]
S2 SwOffWeb;Airytec Switch Off - Web Interface; H:\Program Files\Airytec\Switch Off\swoff.exe [2014-09-23 135168]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; H:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-12-13 270936]
S3 AvgAMPS;AvgAMPS; H:\Program Files\AVG\Av\avgamps.exe [2016-11-02 647864]
S3 gupdatem;Služba Google Update (gupdatem); H:\Program Files\Google\Update\GoogleUpdate.exe [2016-07-15 154440]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; H:\Windows\system32\IEEtwCollector.exe [2016-11-12 102912]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; H:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2014-12-04 30826680]
S3 MozillaMaintenance;Mozilla Maintenance Service; H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-12-14 172488]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; H:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 SwitchBoard;SwitchBoard; H:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; H:\Windows\system32\Wat\WatAdminSvc.exe [2016-07-16 1343400]
S4 NetMsmqActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]
S4 NetPipeActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]
S4 NetTcpActivator;@H:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; H:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-12-01 139944]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 01 led 2017 21:01
od Rudy
Smazáno. Log je již OK.

Re: Prosím o kontrolu

Napsal: 03 led 2017 11:49
od maulej
Díky moc, byl to virus nebo jen adware?

Re: Prosím o kontrolu

Napsal: 03 led 2017 18:32
od Rudy
Pouze AdWare. RSIT pak čistil jen dočasné složky.