Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu. RAM vždy běží na 1GB!

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
linda_23
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 31 bře 2009 18:33

Prosím o kontrolu. RAM vždy běží na 1GB!

#1 Příspěvek od linda_23 »

Dobrý den. Počítač mi nějak zlobí, je pomalý a RAM je vždy na 1GB i když nic nedělám. Prosím o pomoc. Děkuji! :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Linda at 2013-05-31 20:31:28
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 21 GB (41%) free of 50 GB
Total RAM: 2047 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:31:33, on 31.5.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16576)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASC.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Linda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: ???????@Mail.Ru - {8984B388-A5BB-4DF7-B274-77B879E179DB} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: GomPicker - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Program Files (x86)\GRETECH\GomPicker\GomPickerBHO.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (file missing)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Advanced SystemCare Ultimate] "C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4076065141-316484736-1245102644-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4076065141-316484736-1245102644-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) - IOBit - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9929 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASC.exe"
"C:\Program Files (x86)\Internet Download Manager\IDMan.exe"
"C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3788.0.96951231\896532595" --supports-dual-gpus=false --gpu-vendor-id=0x10de --gpu-device-id=0x01d3 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.783 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadDisabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3788.2.1794308806\693263475" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.15.14_0\IDMGCExt.dll" --lang=cs --channel="3788.3.609282806\1833554546" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadDisabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwnd10/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3788.7.2060678883\719443355" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadDisabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwnd10/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3788.11.97131786\1791843126" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Linda\Downloads\Programs\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1w1xydni.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.202 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.202 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2013-04-30 400704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-03-19 6305912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
Hotspot Shield Class - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2013-04-30 364352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-03-19 4529272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL [2012-12-10 655744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0181C6E-9218-4792-9F3C-E8DF52B2F1AC}]
GretechBHO Class - C:\Program Files (x86)\GRETECH\GomPicker\GomPickerBHO.dll [2011-06-21 2529912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-10-17 13307496]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 4035152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"IDMan"=C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2013-05-27 3581816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\DellTPad\Apoint.exe [2011-11-24 392048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverScanner]
C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe delay 20000 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\No 1\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\No 1\AppData\Local\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2013-05-27 3581816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe -quiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Network balancing]
c:\users\no 1\appdata\roaming\svchost.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent]
C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [2011-12-14 190768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe -onlytray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCKeeper]
C:\Program Files\ZeoBIT\PCKeeper\PCKeeper.exe /autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerSuite]
C:\PROGRA~2\Uniblue\POWERS~1\launcher.exe delay 20000 -m []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\SbieCtrl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniKey]
C:\Users\No 1\AppData\Local\Temp\Rar$EX00.382\UniKeyNT.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-04-04 843712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-05-31 20:18:06 ----D---- C:\Users\Linda\AppData\Roaming\Skype
2013-05-31 20:15:51 ----D---- C:\Users\Linda\AppData\Roaming\IDM
2013-05-31 20:15:51 ----D---- C:\Users\Linda\AppData\Roaming\DMCache
2013-05-31 20:15:47 ----D---- C:\Program Files (x86)\Google
2013-05-31 20:01:05 ----D---- C:\Users\Linda\AppData\Roaming\IObit
2013-05-31 19:52:31 ----D---- C:\Users\Linda\AppData\Roaming\Mozilla
2013-05-31 19:52:11 ----D---- C:\Users\Linda\AppData\Roaming\ESET
2013-05-31 19:51:22 ----D---- C:\Users\Linda\AppData\Roaming\Adobe
2013-05-31 19:51:06 ----D---- C:\Users\Linda\AppData\Roaming\Identities
2013-05-31 19:50:54 ----SD---- C:\Users\Linda\AppData\Roaming\Microsoft
2013-05-31 19:50:54 ----D---- C:\Users\Linda\AppData\Roaming\Media Center Programs
2013-05-31 19:50:54 ----D---- C:\Users\Linda\AppData\Roaming\Macromedia
2013-05-31 19:18:43 ----D---- C:\ProgramData\.mono
2013-05-31 19:12:26 ----D---- C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
2013-05-31 19:12:18 ----D---- C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
2013-05-31 19:12:03 ----D---- C:\Program Files (x86)\IObit
2013-05-31 18:55:20 ----D---- C:\ProgramData\IDM
2013-05-31 18:55:16 ----D---- C:\Program Files (x86)\Internet Download Manager
2013-05-31 18:36:48 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2013-05-31 18:25:27 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-05-31 18:25:19 ----D---- C:\ProgramData\NVIDIA
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvvsvc.exe
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvsvcr.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvsvc64.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvshext.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvmctray.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvcpl.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-05-30 23:59:55 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-05-30 23:59:55 ----A---- C:\Windows\system32\elshyph.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\url.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\wininet.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\webcheck.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\urlmon.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\url.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-05-30 23:59:52 ----A---- C:\Windows\system32\msrating.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\msls31.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\mshtmled.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\licmgr10.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\jsproxy.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\inseng.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iesetup.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iertutil.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iernonce.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iedkcs32.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ieapfltr.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ieapfltr.dat
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ie4uinit.exe
2013-05-30 23:59:52 ----A---- C:\Windows\system32\icardie.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\dxtrans.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\dxtmsft.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\wextract.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\vbscript.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\pngfilt.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\occache.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshtmler.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshtml.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshta.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeedssync.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeeds.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\jscript9.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\jscript.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\imgutil.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iexpress.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\ieUnatt.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\ieui.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iesysprep.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iepeers.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-05-30 23:59:50 ----A---- C:\Windows\system32\ieframe.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-30 23:54:25 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2013-05-30 23:54:25 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2013-05-30 23:54:24 ----A---- C:\Windows\system32\XpsPrint.dll
2013-05-30 23:54:24 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-05-30 23:54:23 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2013-05-30 23:54:23 ----A---- C:\Windows\system32\WMPhoto.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\dxgi.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\d3d10warp.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\d2d1.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2013-05-30 23:54:21 ----A---- C:\Windows\system32\FntCache.dll
2013-05-30 23:54:21 ----A---- C:\Windows\system32\DWrite.dll
2013-05-30 23:54:20 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2013-05-30 23:54:20 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d11.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10level9.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10core.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10_1.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10.dll
2013-05-30 23:54:19 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2013-05-30 23:54:19 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2013-05-30 23:54:19 ----A---- C:\Windows\system32\UIAnimation.dll
2013-05-30 23:36:58 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-05-30 23:36:58 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-05-30 23:36:58 ----A---- C:\Windows\system32\atmlib.dll
2013-05-30 23:36:58 ----A---- C:\Windows\system32\atmfd.dll
2013-05-30 22:38:58 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-05-30 22:38:58 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-30 22:38:58 ----A---- C:\Windows\system32\cdd.dll
2013-05-30 22:38:53 ----A---- C:\Windows\system32\mstscax.dll
2013-05-30 22:38:52 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-05-30 22:38:50 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-05-30 22:38:50 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-05-30 22:38:50 ----A---- C:\Windows\system32\tsgqec.dll
2013-05-30 22:38:50 ----A---- C:\Windows\system32\aaclient.dll
2013-05-30 22:38:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-05-30 22:38:37 ----A---- C:\Windows\system32\tzres.dll
2013-05-30 22:38:23 ----A---- C:\Windows\system32\win32spl.dll
2013-05-30 22:38:22 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-05-30 22:38:21 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-05-30 22:38:13 ----A---- C:\Windows\system32\shell32.dll
2013-05-30 22:38:10 ----A---- C:\Windows\SYSWOW64\shell32.dll
2013-05-30 22:38:09 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2013-05-30 22:38:09 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-05-30 22:38:09 ----A---- C:\Windows\system32\shdocvw.dll
2013-05-30 22:38:09 ----A---- C:\Windows\system32\consent.exe
2013-05-30 22:38:09 ----A---- C:\Windows\system32\authui.dll
2013-05-30 22:38:08 ----A---- C:\Windows\system32\appinfo.dll
2013-05-30 22:37:19 ----A---- C:\Windows\system32\schannel.dll
2013-05-30 22:37:19 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-05-30 22:37:19 ----A---- C:\Windows\system32\drivers\cng.sys
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-05-30 22:37:18 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdrmemptylst.exe
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdpwsx.dll
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdpcorekmts.dll
2013-05-30 22:37:15 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-05-30 22:37:12 ----A---- C:\Windows\system32\win32k.sys
2013-05-30 22:37:10 ----A---- C:\Windows\system32\msxml6.dll
2013-05-30 22:37:10 ----A---- C:\Windows\system32\msxml3.dll
2013-05-30 22:37:09 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-05-30 22:37:09 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-05-30 22:37:08 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2013-05-30 22:37:08 ----A---- C:\Windows\system32\msxml3r.dll
2013-05-30 22:36:09 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-05-30 22:36:09 ----A---- C:\Windows\system32\dpnet.dll
2013-05-30 22:36:08 ----A---- C:\Windows\system32\ncrypt.dll
2013-05-30 22:36:07 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-05-30 22:36:06 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-05-30 22:36:06 ----A---- C:\Windows\system32\wintrust.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\wow64win.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\winsrv.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\KernelBase.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\kernel32.dll
2013-05-30 22:36:00 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-05-30 22:36:00 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-05-30 22:36:00 ----A---- C:\Windows\system32\conhost.exe
2013-05-30 22:35:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 22:35:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-05-30 22:35:59 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-05-30 22:35:59 ----A---- C:\Windows\system32\wow64.dll
2013-05-30 22:35:59 ----A---- C:\Windows\system32\ntvdm64.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 22:35:58 ----A---- C:\Windows\system32\wow64cpu.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-05-30 22:35:57 ----A---- C:\Windows\SYSWOW64\user.exe
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\netio.sys
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-05-30 22:35:44 ----A---- C:\Windows\system32\rdpcorets.dll
2013-05-30 22:35:44 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2013-05-30 22:34:38 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2013-05-30 22:34:38 ----A---- C:\Windows\system32\kerberos.dll
2013-05-30 22:34:36 ----A---- C:\Windows\system32\synceng.dll
2013-05-30 22:34:35 ----A---- C:\Windows\SYSWOW64\synceng.dll
2013-05-30 22:34:28 ----A---- C:\Windows\system32\taskhost.exe
2013-05-30 22:34:27 ----A---- C:\Windows\system32\browser.dll
2013-05-30 22:34:26 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2013-05-30 22:34:26 ----A---- C:\Windows\SYSWOW64\browcli.dll
2013-05-30 22:34:26 ----A---- C:\Windows\system32\netapi32.dll
2013-05-30 22:34:26 ----A---- C:\Windows\system32\browcli.dll
2013-05-30 22:34:23 ----A---- C:\Windows\system32\localspl.dll
2013-05-30 22:34:16 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-05-30 22:34:12 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-05-30 22:34:11 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-05-30 22:34:10 ----A---- C:\Windows\system32\smss.exe
2013-05-30 22:34:10 ----A---- C:\Windows\system32\csrsrv.dll
2013-05-30 22:34:09 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-05-30 22:33:53 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2013-05-30 22:33:48 ----A---- C:\Windows\system32\cdosys.dll
2013-05-30 22:33:17 ----A---- C:\Windows\system32\crypt32.dll
2013-05-30 22:33:16 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-05-30 22:33:16 ----A---- C:\Windows\system32\cryptsvc.dll
2013-05-30 22:33:16 ----A---- C:\Windows\system32\cryptnet.dll
2013-05-30 22:33:15 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-05-30 22:33:15 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wups2.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wucltux.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wuaueng.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wuauclt.exe
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wups.dll
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wudriver.dll
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wuapi.dll
2013-05-30 22:15:33 ----A---- C:\Windows\system32\wuwebv.dll
2013-05-30 22:15:33 ----A---- C:\Windows\system32\wuapp.exe
2013-05-27 06:42:50 ----A---- C:\Windows\system32\drivers\idmwfp.sys

======List of files/folders modified in the last 1 month======

2013-05-31 20:31:31 ----D---- C:\Windows\Temp
2013-05-31 20:31:31 ----D---- C:\Program Files\trend micro
2013-05-31 20:20:04 ----SHD---- C:\Windows\Installer
2013-05-31 20:20:04 ----SHD---- C:\Config.Msi
2013-05-31 20:16:59 ----RD---- C:\Program Files (x86)
2013-05-31 20:15:52 ----D---- C:\Windows\Tasks
2013-05-31 20:15:52 ----D---- C:\Windows\system32\Tasks
2013-05-31 20:14:38 ----D---- C:\Windows\system32\config
2013-05-31 20:11:47 ----RD---- C:\Users
2013-05-31 20:00:44 ----D---- C:\Windows
2013-05-31 19:51:22 ----D---- C:\Windows\inf
2013-05-31 19:51:02 ----SHD---- C:\$Recycle.Bin
2013-05-31 19:18:43 ----HD---- C:\ProgramData
2013-05-31 19:12:18 ----D---- C:\ProgramData\IObit
2013-05-31 19:12:00 ----D---- C:\Windows\winsxs
2013-05-31 18:57:14 ----D---- C:\Windows\system32\drivers
2013-05-31 18:55:18 ----D---- C:\Windows\SysWOW64
2013-05-31 18:46:37 ----D---- C:\ProgramData\Systweak
2013-05-31 18:46:35 ----D---- C:\Windows\System32
2013-05-31 18:46:26 ----D---- C:\Windows\Microsoft.NET
2013-05-31 18:46:25 ----RSD---- C:\Windows\assembly
2013-05-31 18:46:16 ----D---- C:\Windows\Panther
2013-05-31 18:46:13 ----D---- C:\Windows\Logs
2013-05-31 18:38:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-05-31 18:38:11 ----D---- C:\Windows\system32\cs-CZ
2013-05-31 18:32:02 ----D---- C:\Program Files (x86)\Yahoo!
2013-05-31 18:25:27 ----D---- C:\Program Files\NVIDIA Corporation
2013-05-31 18:25:26 ----D---- C:\Temp
2013-05-31 18:24:57 ----D---- C:\Windows\Help
2013-05-31 18:21:52 ----D---- C:\Windows\system32\catroot
2013-05-31 18:21:49 ----D---- C:\Windows\system32\DriverStore
2013-05-31 18:13:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-05-31 18:08:17 ----D---- C:\ProgramData\Skype
2013-05-31 18:08:04 ----RD---- C:\Program Files (x86)\Skype
2013-05-31 18:08:01 ----D---- C:\Program Files (x86)\Common Files
2013-05-31 18:02:51 ----SHD---- C:\System Volume Information
2013-05-31 17:48:16 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-31 00:14:26 ----D---- C:\Program Files\Internet Explorer
2013-05-31 00:14:26 ----D---- C:\Program Files (x86)\Internet Explorer
2013-05-31 00:14:25 ----D---- C:\Windows\SYSWOW64\migration
2013-05-31 00:14:25 ----D---- C:\Windows\SYSWOW64\en-US
2013-05-31 00:14:24 ----D---- C:\Windows\system32\migration
2013-05-31 00:14:24 ----D---- C:\Windows\system32\en-US
2013-05-31 00:14:24 ----D---- C:\Windows\PolicyDefinitions
2013-05-31 00:14:22 ----RSD---- C:\Windows\Fonts
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-TW
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-HK
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-CN
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\tr-TR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\sv-SE
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ru-RU
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pt-PT
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pt-BR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pl-PL
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\nl-NL
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\nb-NO
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ko-KR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ja-JP
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\it-IT
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\hu-HU
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\fr-FR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\fi-FI
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\es-ES
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\el-GR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\de-DE
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\da-DK
2013-05-31 00:14:21 ----D---- C:\Windows\system32\zh-TW
2013-05-31 00:14:21 ----D---- C:\Windows\system32\zh-HK
2013-05-31 00:14:21 ----D---- C:\Windows\system32\tr-TR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\sv-SE
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pt-PT
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pt-BR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pl-PL
2013-05-31 00:14:21 ----D---- C:\Windows\system32\nl-NL
2013-05-31 00:14:21 ----D---- C:\Windows\system32\ko-KR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\it-IT
2013-05-31 00:14:21 ----D---- C:\Windows\system32\hu-HU
2013-05-31 00:14:21 ----D---- C:\Windows\system32\fr-FR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\fi-FI
2013-05-31 00:14:21 ----D---- C:\Windows\system32\es-ES
2013-05-31 00:14:21 ----D---- C:\Windows\system32\el-GR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\de-DE
2013-05-31 00:14:20 ----D---- C:\Windows\system32\zh-CN
2013-05-31 00:14:20 ----D---- C:\Windows\system32\ru-RU
2013-05-31 00:14:20 ----D---- C:\Windows\system32\nb-NO
2013-05-31 00:14:20 ----D---- C:\Windows\system32\ja-JP
2013-05-31 00:14:20 ----D---- C:\Windows\system32\da-DK
2013-05-31 00:14:19 ----D---- C:\Windows\AppPatch
2013-05-31 00:09:13 ----D---- C:\Windows\system32\catroot2
2013-05-30 23:58:47 ----A---- C:\Windows\hms_odpocet.ini
2013-05-30 23:51:49 ----D---- C:\Windows\debug
2013-05-30 23:50:06 ----RD---- C:\Program Files
2013-05-30 23:42:30 ----D---- C:\Windows\Prefetch
2013-05-30 23:41:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-05-30 23:32:50 ----D---- C:\ProgramData\Microsoft Help
2013-05-30 23:28:10 ----D---- C:\Program Files (x86)\Nokia
2013-05-30 23:21:26 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-05-30 23:07:52 ----D---- C:\Windows\Minidump
2013-05-30 22:56:49 ----D---- C:\Program Files (x86)\Adobe
2013-05-29 17:59:24 ----D---- C:\Windows\system32\NDF
2013-05-03 16:15:58 ----A---- C:\Windows\system32\MRT.exe
2013-05-02 02:06:08 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 62496]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2011-12-26 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-11-18 526392]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 38288]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2011-08-04 187632]
R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2013-05-25 168288]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-10-18 2957544]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys [2011-12-26 349416]
S3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x64; C:\Windows\system32\DRIVERS\Apfiltr.sys [2011-11-24 304760]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys []
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-11-01 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-11-01 27136]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-11-01 171008]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [2011-07-20 44032]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [2010-06-16 37888]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-11-01 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2012-12-14 621008]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-31 878368]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-19 1259296]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-30 256904]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-30 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-11-30 718888]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-02 1255736]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://www.stahuj.centrum.cz/utility_a_ ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte na Search (hledat)
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

linda_23
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 31 bře 2009 18:33

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#3 Příspěvek od linda_23 »

# AdwCleaner v2.301 - Log vytvooen 31/05/2013 v 22:10:43
# Aktualizováno 16/05/2013 Xplode
# Operaení systém : Windows 7 Ultimate Service Pack 1 (64 bits)
# Uživatel : Linda - NO1-PC
# Spuštin systém : Normální
# Spuštino z : C:\Users\Linda\Desktop\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Nalezeno : C:\Program Files (x86)\FunWebProducts
Složka Nalezeno : C:\ProgramData\ICQ\ICQToolbar
Složka Nalezeno : C:\ProgramData\Tencent

***** [Registry] *****

Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Klíe Nalezeno : HKLM\Software\Fun Web Products
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Klíe Nalezeno : HKLM\Software\MyWebSearch
Klíe Nalezeno : HKLM\Software\TENCENT
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467E-B8D4-7786EDA79AE0}
Klíe Nalezeno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry jsou eisté.

-\\ Mozilla Firefox v21.0 (en-US)

Soubor : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1w1xydni.default\prefs.js

[OK] Soubor je eistý.

-\\ Google Chrome v27.0.1453.94

Soubor : C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [7176 octets] - [31/05/2013 22:10:43]

########## EOF - C:\AdwCleaner[R1].txt - [7236 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#4 Příspěvek od Rudy »

Spusťte znovu ADWCleaner a klikněte na >Delete< (smazat). Vložte nový log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

linda_23
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 31 bře 2009 18:33

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#5 Příspěvek od linda_23 »

# AdwCleaner v2.301 - Log vytvooen 31/05/2013 v 22:35:59
# Aktualizováno 16/05/2013 Xplode
# Operaení systém : Windows 7 Ultimate Service Pack 1 (64 bits)
# Uživatel : Linda - NO1-PC
# Spuštin systém : Normální
# Spuštino z : C:\Users\Linda\Desktop\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Vymazáno : C:\Program Files (x86)\FunWebProducts
Složka Vymazáno : C:\ProgramData\ICQ\ICQToolbar
Složka Vymazáno : C:\ProgramData\Tencent

***** [Registry] *****

Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Klíe Vymazáno : HKLM\Software\Fun Web Products
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Klíe Vymazáno : HKLM\Software\MyWebSearch
Klíe Vymazáno : HKLM\Software\TENCENT
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467E-B8D4-7786EDA79AE0}
Klíe Vymazáno : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry jsou eisté.

-\\ Mozilla Firefox v21.0 (en-US)

Soubor : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1w1xydni.default\prefs.js

[OK] Soubor je eistý.

-\\ Google Chrome v27.0.1453.94

Soubor : C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [7225 octets] - [31/05/2013 22:10:43]
AdwCleaner[S1].txt - [7234 octets] - [31/05/2013 22:35:59]

########## EOF - C:\AdwCleaner[S1].txt - [7294 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#6 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

linda_23
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 31 bře 2009 18:33

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#7 Příspěvek od linda_23 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Linda at 2013-05-31 22:56:39
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 20 GB (41%) free of 50 GB
Total RAM: 2047 MB (31% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:56:44, on 31.5.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16576)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\DelayLoad.exe
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Asc.exe
C:\Program Files\trend micro\Linda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: ???????@Mail.Ru - {8984B388-A5BB-4DF7-B274-77B879E179DB} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: GomPicker - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Program Files (x86)\GRETECH\GomPicker\GomPickerBHO.dll
O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Advanced SystemCare Ultimate] "C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4076065141-316484736-1245102644-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4076065141-316484736-1245102644-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) - IOBit - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9425 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
"C:\Program Files (x86)\Internet Download Manager\IDMan.exe" /onboot
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\DelayLoad.exe" /DelayLoad
"C:\Users\Linda\AppData\Local\Temp\Rar$EX00.321\UniKeyNT.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Asc.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Users\Linda\Downloads\Programs\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1w1xydni.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.202 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.202 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2013-04-30 400704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-03-19 6305912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2013-04-30 364352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-03-19 4529272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL [2012-12-10 655744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0181C6E-9218-4792-9F3C-E8DF52B2F1AC}]
GretechBHO Class - C:\Program Files (x86)\GRETECH\GomPicker\GomPickerBHO.dll [2011-06-21 2529912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-10-17 13307496]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 4035152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"IDMan"=C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2013-05-27 3581816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\DellTPad\Apoint.exe [2011-11-24 392048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverScanner]
C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe delay 20000 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\No 1\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\No 1\AppData\Local\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2013-05-27 3581816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe -quiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Network balancing]
c:\users\no 1\appdata\roaming\svchost.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent]
C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [2011-12-14 190768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe -onlytray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCKeeper]
C:\Program Files\ZeoBIT\PCKeeper\PCKeeper.exe /autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerSuite]
C:\PROGRA~2\Uniblue\POWERS~1\launcher.exe delay 20000 -m []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\SbieCtrl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniKey]
C:\Users\No 1\AppData\Local\Temp\Rar$EX00.382\UniKeyNT.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-04-04 843712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-05-31 22:35:59 ----A---- C:\AdwCleaner[S1].txt
2013-05-31 22:20:32 ----D---- C:\Users\Linda\AppData\Roaming\WinRAR
2013-05-31 22:10:43 ----A---- C:\AdwCleaner[R1].txt
2013-05-31 20:18:06 ----D---- C:\Users\Linda\AppData\Roaming\Skype
2013-05-31 20:15:51 ----D---- C:\Users\Linda\AppData\Roaming\IDM
2013-05-31 20:15:51 ----D---- C:\Users\Linda\AppData\Roaming\DMCache
2013-05-31 20:15:47 ----D---- C:\Program Files (x86)\Google
2013-05-31 20:01:05 ----D---- C:\Users\Linda\AppData\Roaming\IObit
2013-05-31 19:52:31 ----D---- C:\Users\Linda\AppData\Roaming\Mozilla
2013-05-31 19:52:11 ----D---- C:\Users\Linda\AppData\Roaming\ESET
2013-05-31 19:51:22 ----D---- C:\Users\Linda\AppData\Roaming\Adobe
2013-05-31 19:51:06 ----D---- C:\Users\Linda\AppData\Roaming\Identities
2013-05-31 19:50:54 ----SD---- C:\Users\Linda\AppData\Roaming\Microsoft
2013-05-31 19:50:54 ----D---- C:\Users\Linda\AppData\Roaming\Media Center Programs
2013-05-31 19:50:54 ----D---- C:\Users\Linda\AppData\Roaming\Macromedia
2013-05-31 19:18:43 ----D---- C:\ProgramData\.mono
2013-05-31 19:12:26 ----D---- C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
2013-05-31 19:12:18 ----D---- C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
2013-05-31 19:12:03 ----D---- C:\Program Files (x86)\IObit
2013-05-31 18:55:20 ----D---- C:\ProgramData\IDM
2013-05-31 18:55:16 ----D---- C:\Program Files (x86)\Internet Download Manager
2013-05-31 18:36:48 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2013-05-31 18:25:27 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-05-31 18:25:19 ----D---- C:\ProgramData\NVIDIA
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvvsvc.exe
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvsvcr.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvsvc64.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvshext.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvmctray.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvcpl.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-05-30 23:59:55 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-05-30 23:59:55 ----A---- C:\Windows\system32\elshyph.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\url.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\wininet.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\webcheck.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\urlmon.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\url.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-05-30 23:59:52 ----A---- C:\Windows\system32\msrating.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\msls31.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\mshtmled.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\licmgr10.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\jsproxy.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\inseng.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iesetup.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iertutil.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iernonce.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iedkcs32.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ieapfltr.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ieapfltr.dat
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ie4uinit.exe
2013-05-30 23:59:52 ----A---- C:\Windows\system32\icardie.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\dxtrans.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\dxtmsft.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\wextract.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\vbscript.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\pngfilt.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\occache.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshtmler.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshtml.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshta.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeedssync.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeeds.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\jscript9.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\jscript.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\imgutil.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iexpress.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\ieUnatt.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\ieui.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iesysprep.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iepeers.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-05-30 23:59:50 ----A---- C:\Windows\system32\ieframe.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-30 23:54:25 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2013-05-30 23:54:25 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2013-05-30 23:54:24 ----A---- C:\Windows\system32\XpsPrint.dll
2013-05-30 23:54:24 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-05-30 23:54:23 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2013-05-30 23:54:23 ----A---- C:\Windows\system32\WMPhoto.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\dxgi.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\d3d10warp.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\d2d1.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2013-05-30 23:54:21 ----A---- C:\Windows\system32\FntCache.dll
2013-05-30 23:54:21 ----A---- C:\Windows\system32\DWrite.dll
2013-05-30 23:54:20 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2013-05-30 23:54:20 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d11.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10level9.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10core.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10_1.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10.dll
2013-05-30 23:54:19 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2013-05-30 23:54:19 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2013-05-30 23:54:19 ----A---- C:\Windows\system32\UIAnimation.dll
2013-05-30 23:36:58 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-05-30 23:36:58 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-05-30 23:36:58 ----A---- C:\Windows\system32\atmlib.dll
2013-05-30 23:36:58 ----A---- C:\Windows\system32\atmfd.dll
2013-05-30 22:38:58 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-05-30 22:38:58 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-30 22:38:58 ----A---- C:\Windows\system32\cdd.dll
2013-05-30 22:38:53 ----A---- C:\Windows\system32\mstscax.dll
2013-05-30 22:38:52 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-05-30 22:38:50 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-05-30 22:38:50 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-05-30 22:38:50 ----A---- C:\Windows\system32\tsgqec.dll
2013-05-30 22:38:50 ----A---- C:\Windows\system32\aaclient.dll
2013-05-30 22:38:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-05-30 22:38:37 ----A---- C:\Windows\system32\tzres.dll
2013-05-30 22:38:23 ----A---- C:\Windows\system32\win32spl.dll
2013-05-30 22:38:22 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-05-30 22:38:21 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-05-30 22:38:13 ----A---- C:\Windows\system32\shell32.dll
2013-05-30 22:38:10 ----A---- C:\Windows\SYSWOW64\shell32.dll
2013-05-30 22:38:09 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2013-05-30 22:38:09 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-05-30 22:38:09 ----A---- C:\Windows\system32\shdocvw.dll
2013-05-30 22:38:09 ----A---- C:\Windows\system32\consent.exe
2013-05-30 22:38:09 ----A---- C:\Windows\system32\authui.dll
2013-05-30 22:38:08 ----A---- C:\Windows\system32\appinfo.dll
2013-05-30 22:37:19 ----A---- C:\Windows\system32\schannel.dll
2013-05-30 22:37:19 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-05-30 22:37:19 ----A---- C:\Windows\system32\drivers\cng.sys
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-05-30 22:37:18 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdrmemptylst.exe
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdpwsx.dll
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdpcorekmts.dll
2013-05-30 22:37:15 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-05-30 22:37:12 ----A---- C:\Windows\system32\win32k.sys
2013-05-30 22:37:10 ----A---- C:\Windows\system32\msxml6.dll
2013-05-30 22:37:10 ----A---- C:\Windows\system32\msxml3.dll
2013-05-30 22:37:09 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-05-30 22:37:09 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-05-30 22:37:08 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2013-05-30 22:37:08 ----A---- C:\Windows\system32\msxml3r.dll
2013-05-30 22:36:09 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-05-30 22:36:09 ----A---- C:\Windows\system32\dpnet.dll
2013-05-30 22:36:08 ----A---- C:\Windows\system32\ncrypt.dll
2013-05-30 22:36:07 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-05-30 22:36:06 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-05-30 22:36:06 ----A---- C:\Windows\system32\wintrust.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\wow64win.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\winsrv.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\KernelBase.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\kernel32.dll
2013-05-30 22:36:00 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-05-30 22:36:00 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-05-30 22:36:00 ----A---- C:\Windows\system32\conhost.exe
2013-05-30 22:35:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 22:35:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-05-30 22:35:59 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-05-30 22:35:59 ----A---- C:\Windows\system32\wow64.dll
2013-05-30 22:35:59 ----A---- C:\Windows\system32\ntvdm64.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 22:35:58 ----A---- C:\Windows\system32\wow64cpu.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-05-30 22:35:57 ----A---- C:\Windows\SYSWOW64\user.exe
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\netio.sys
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-05-30 22:35:44 ----A---- C:\Windows\system32\rdpcorets.dll
2013-05-30 22:35:44 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2013-05-30 22:34:38 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2013-05-30 22:34:38 ----A---- C:\Windows\system32\kerberos.dll
2013-05-30 22:34:36 ----A---- C:\Windows\system32\synceng.dll
2013-05-30 22:34:35 ----A---- C:\Windows\SYSWOW64\synceng.dll
2013-05-30 22:34:28 ----A---- C:\Windows\system32\taskhost.exe
2013-05-30 22:34:27 ----A---- C:\Windows\system32\browser.dll
2013-05-30 22:34:26 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2013-05-30 22:34:26 ----A---- C:\Windows\SYSWOW64\browcli.dll
2013-05-30 22:34:26 ----A---- C:\Windows\system32\netapi32.dll
2013-05-30 22:34:26 ----A---- C:\Windows\system32\browcli.dll
2013-05-30 22:34:23 ----A---- C:\Windows\system32\localspl.dll
2013-05-30 22:34:16 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-05-30 22:34:12 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-05-30 22:34:11 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-05-30 22:34:10 ----A---- C:\Windows\system32\smss.exe
2013-05-30 22:34:10 ----A---- C:\Windows\system32\csrsrv.dll
2013-05-30 22:34:09 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-05-30 22:33:53 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2013-05-30 22:33:48 ----A---- C:\Windows\system32\cdosys.dll
2013-05-30 22:33:17 ----A---- C:\Windows\system32\crypt32.dll
2013-05-30 22:33:16 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-05-30 22:33:16 ----A---- C:\Windows\system32\cryptsvc.dll
2013-05-30 22:33:16 ----A---- C:\Windows\system32\cryptnet.dll
2013-05-30 22:33:15 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-05-30 22:33:15 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wups2.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wucltux.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wuaueng.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wuauclt.exe
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wups.dll
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wudriver.dll
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wuapi.dll
2013-05-30 22:15:33 ----A---- C:\Windows\system32\wuwebv.dll
2013-05-30 22:15:33 ----A---- C:\Windows\system32\wuapp.exe
2013-05-27 06:42:50 ----A---- C:\Windows\system32\drivers\idmwfp.sys

======List of files/folders modified in the last 1 month======

2013-05-31 22:56:43 ----D---- C:\Program Files\trend micro
2013-05-31 22:56:37 ----D---- C:\Windows\Temp
2013-05-31 22:54:28 ----D---- C:\Windows\system32\config
2013-05-31 22:49:22 ----D---- C:\Windows
2013-05-31 22:38:29 ----RD---- C:\Users
2013-05-31 22:36:14 ----RD---- C:\Program Files (x86)
2013-05-31 22:36:14 ----HD---- C:\ProgramData
2013-05-31 20:20:04 ----SHD---- C:\Windows\Installer
2013-05-31 20:20:04 ----SHD---- C:\Config.Msi
2013-05-31 20:15:52 ----D---- C:\Windows\Tasks
2013-05-31 20:15:52 ----D---- C:\Windows\system32\Tasks
2013-05-31 19:51:22 ----D---- C:\Windows\inf
2013-05-31 19:51:02 ----SHD---- C:\$Recycle.Bin
2013-05-31 19:12:18 ----D---- C:\ProgramData\IObit
2013-05-31 19:12:00 ----D---- C:\Windows\winsxs
2013-05-31 18:57:14 ----D---- C:\Windows\system32\drivers
2013-05-31 18:55:18 ----D---- C:\Windows\SysWOW64
2013-05-31 18:47:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-05-31 18:46:37 ----D---- C:\ProgramData\Systweak
2013-05-31 18:46:35 ----D---- C:\Windows\System32
2013-05-31 18:46:26 ----D---- C:\Windows\Microsoft.NET
2013-05-31 18:46:25 ----RSD---- C:\Windows\assembly
2013-05-31 18:46:16 ----D---- C:\Windows\Panther
2013-05-31 18:46:13 ----D---- C:\Windows\Logs
2013-05-31 18:38:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-05-31 18:38:11 ----D---- C:\Windows\system32\cs-CZ
2013-05-31 18:32:02 ----D---- C:\ProgramData\Yahoo!
2013-05-31 18:32:02 ----D---- C:\Program Files (x86)\Yahoo!
2013-05-31 18:25:27 ----D---- C:\Program Files\NVIDIA Corporation
2013-05-31 18:25:26 ----D---- C:\Temp
2013-05-31 18:24:57 ----D---- C:\Windows\Help
2013-05-31 18:21:52 ----D---- C:\Windows\system32\catroot
2013-05-31 18:21:49 ----D---- C:\Windows\system32\DriverStore
2013-05-31 18:13:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-05-31 18:08:17 ----D---- C:\ProgramData\Skype
2013-05-31 18:08:04 ----RD---- C:\Program Files (x86)\Skype
2013-05-31 18:08:01 ----D---- C:\Program Files (x86)\Common Files
2013-05-31 18:02:51 ----SHD---- C:\System Volume Information
2013-05-31 17:48:16 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-31 00:14:26 ----D---- C:\Program Files\Internet Explorer
2013-05-31 00:14:26 ----D---- C:\Program Files (x86)\Internet Explorer
2013-05-31 00:14:25 ----D---- C:\Windows\SYSWOW64\migration
2013-05-31 00:14:25 ----D---- C:\Windows\SYSWOW64\en-US
2013-05-31 00:14:24 ----D---- C:\Windows\system32\migration
2013-05-31 00:14:24 ----D---- C:\Windows\system32\en-US
2013-05-31 00:14:24 ----D---- C:\Windows\PolicyDefinitions
2013-05-31 00:14:22 ----RSD---- C:\Windows\Fonts
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-TW
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-HK
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-CN
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\tr-TR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\sv-SE
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ru-RU
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pt-PT
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pt-BR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pl-PL
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\nl-NL
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\nb-NO
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ko-KR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ja-JP
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\it-IT
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\hu-HU
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\fr-FR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\fi-FI
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\es-ES
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\el-GR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\de-DE
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\da-DK
2013-05-31 00:14:21 ----D---- C:\Windows\system32\zh-TW
2013-05-31 00:14:21 ----D---- C:\Windows\system32\zh-HK
2013-05-31 00:14:21 ----D---- C:\Windows\system32\tr-TR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\sv-SE
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pt-PT
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pt-BR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pl-PL
2013-05-31 00:14:21 ----D---- C:\Windows\system32\nl-NL
2013-05-31 00:14:21 ----D---- C:\Windows\system32\ko-KR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\it-IT
2013-05-31 00:14:21 ----D---- C:\Windows\system32\hu-HU
2013-05-31 00:14:21 ----D---- C:\Windows\system32\fr-FR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\fi-FI
2013-05-31 00:14:21 ----D---- C:\Windows\system32\es-ES
2013-05-31 00:14:21 ----D---- C:\Windows\system32\el-GR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\de-DE
2013-05-31 00:14:20 ----D---- C:\Windows\system32\zh-CN
2013-05-31 00:14:20 ----D---- C:\Windows\system32\ru-RU
2013-05-31 00:14:20 ----D---- C:\Windows\system32\nb-NO
2013-05-31 00:14:20 ----D---- C:\Windows\system32\ja-JP
2013-05-31 00:14:20 ----D---- C:\Windows\system32\da-DK
2013-05-31 00:14:19 ----D---- C:\Windows\AppPatch
2013-05-31 00:09:13 ----D---- C:\Windows\system32\catroot2
2013-05-30 23:58:47 ----A---- C:\Windows\hms_odpocet.ini
2013-05-30 23:51:49 ----D---- C:\Windows\debug
2013-05-30 23:50:06 ----RD---- C:\Program Files
2013-05-30 23:42:30 ----D---- C:\Windows\Prefetch
2013-05-30 23:41:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-05-30 23:32:50 ----D---- C:\ProgramData\Microsoft Help
2013-05-30 23:28:10 ----D---- C:\Program Files (x86)\Nokia
2013-05-30 23:21:26 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-05-30 23:07:52 ----D---- C:\Windows\Minidump
2013-05-30 22:56:49 ----D---- C:\Program Files (x86)\Adobe
2013-05-29 17:59:24 ----D---- C:\Windows\system32\NDF
2013-05-03 16:15:58 ----A---- C:\Windows\system32\MRT.exe
2013-05-02 02:06:08 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 62496]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2011-12-26 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-11-18 526392]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 38288]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2011-08-04 187632]
R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2013-05-25 168288]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-10-18 2957544]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys [2011-12-26 349416]
S3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x64; C:\Windows\system32\DRIVERS\Apfiltr.sys [2011-11-24 304760]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys []
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-11-01 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-11-01 27136]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-11-01 171008]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [2011-07-20 44032]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [2010-06-16 37888]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-11-01 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2012-12-14 621008]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-31 878368]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-19 1259296]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-30 256904]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-30 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-11-30 718888]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-02 1255736]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#8 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\Skype\Toolbars
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4076065141-316484736-1245102644-1000UA.job
C:\ProgramData\.mono
C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

linda_23
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 31 bře 2009 18:33

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#9 Příspěvek od linda_23 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Linda at 2013-05-31 23:24:45
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 20 GB (40%) free of 50 GB
Total RAM: 2047 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:24:48, on 31.5.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16576)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\DelayLoad.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Linda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: GomPicker - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Program Files (x86)\GRETECH\GomPicker\GomPickerBHO.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Advanced SystemCare Ultimate] "C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [UniKey] C:\Users\Linda\AppData\Local\Temp\Rar$EX00.321\UniKeyNT.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4076065141-316484736-1245102644-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4076065141-316484736-1245102644-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) - IOBit - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9797 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {C55CBD7F-A16E-4979-BF40-76704F0E2C8D}
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe"
C:\Windows\Explorer.EXE
taskeng.exe {105155F4-2A84-48CE-B757-3E6D75A243C8}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
"C:\Program Files (x86)\Internet Download Manager\IDMan.exe" /onboot
"C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\DelayLoad.exe" /DelayLoad
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3744.0.1938085773\392752373" --supports-dual-gpus=false --gpu-vendor-id=0x10de --gpu-device-id=0x01d3 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.783 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --instant-process --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3744.2.657023413\408646881" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3744.3.986235299\810873978" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3744.4.2082350937\423681998" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3744.5.1316032560\100592938" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.15.14_0\IDMGCExt.dll" --lang=cs --channel="3744.6.188612012\123520128" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\Plugin/ASCPlugin_Protect.dll" --lang=cs --channel="3744.7.901298863\704190000" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DefaultControl/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Padding2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/12/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/SpdyCwnd/cwndMin16/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_54/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --disable-accelerated-2d-canvas --channel="3744.8.1412437939\1326275969" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Linda\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\1w1xydni.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.202 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.202 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2013-04-30 400704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2013-04-30 364352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL [2012-12-10 655744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0181C6E-9218-4792-9F3C-E8DF52B2F1AC}]
GretechBHO Class - C:\Program Files (x86)\GRETECH\GomPicker\GomPickerBHO.dll [2011-06-21 2529912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-10-17 13307496]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 4035152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"IDMan"=C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2013-05-27 3581816]
"UniKey"=C:\Users\Linda\AppData\Local\Temp\Rar$EX00.321\UniKeyNT.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\DellTPad\Apoint.exe [2011-11-24 392048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverScanner]
C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe delay 20000 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\No 1\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\No 1\AppData\Local\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2013-05-27 3581816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe -quiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Network balancing]
c:\users\no 1\appdata\roaming\svchost.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent]
C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [2011-12-14 190768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe -onlytray []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCKeeper]
C:\Program Files\ZeoBIT\PCKeeper\PCKeeper.exe /autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerSuite]
C:\PROGRA~2\Uniblue\POWERS~1\launcher.exe delay 20000 -m []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\SbieCtrl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniKey]
C:\Users\No 1\AppData\Local\Temp\Rar$EX00.382\UniKeyNT.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-04-04 843712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-05-31 23:13:16 ----D---- C:\_OTM
2013-05-31 22:35:59 ----A---- C:\AdwCleaner[S1].txt
2013-05-31 22:20:32 ----D---- C:\Users\Linda\AppData\Roaming\WinRAR
2013-05-31 22:10:43 ----A---- C:\AdwCleaner[R1].txt
2013-05-31 20:18:06 ----D---- C:\Users\Linda\AppData\Roaming\Skype
2013-05-31 20:15:51 ----D---- C:\Users\Linda\AppData\Roaming\IDM
2013-05-31 20:15:51 ----D---- C:\Users\Linda\AppData\Roaming\DMCache
2013-05-31 20:15:47 ----D---- C:\Program Files (x86)\Google
2013-05-31 20:01:05 ----D---- C:\Users\Linda\AppData\Roaming\IObit
2013-05-31 19:52:31 ----D---- C:\Users\Linda\AppData\Roaming\Mozilla
2013-05-31 19:52:11 ----D---- C:\Users\Linda\AppData\Roaming\ESET
2013-05-31 19:51:22 ----D---- C:\Users\Linda\AppData\Roaming\Adobe
2013-05-31 19:51:06 ----D---- C:\Users\Linda\AppData\Roaming\Identities
2013-05-31 19:50:54 ----SD---- C:\Users\Linda\AppData\Roaming\Microsoft
2013-05-31 19:50:54 ----D---- C:\Users\Linda\AppData\Roaming\Media Center Programs
2013-05-31 19:50:54 ----D---- C:\Users\Linda\AppData\Roaming\Macromedia
2013-05-31 19:12:03 ----D---- C:\Program Files (x86)\IObit
2013-05-31 18:55:20 ----D---- C:\ProgramData\IDM
2013-05-31 18:55:16 ----D---- C:\Program Files (x86)\Internet Download Manager
2013-05-31 18:36:48 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2013-05-31 18:25:27 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2013-05-31 18:25:19 ----D---- C:\ProgramData\NVIDIA
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvvsvc.exe
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvsvcr.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvsvc64.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvshext.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvmctray.dll
2013-05-31 18:25:01 ----A---- C:\Windows\system32\nvcpl.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-05-30 23:59:55 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-05-30 23:59:55 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-05-30 23:59:55 ----A---- C:\Windows\system32\elshyph.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-05-30 23:59:54 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\url.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-05-30 23:59:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\wininet.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\webcheck.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\urlmon.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\url.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-05-30 23:59:52 ----A---- C:\Windows\system32\msrating.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\msls31.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\mshtmled.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\licmgr10.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\jsproxy.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\inseng.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iesetup.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iertutil.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iernonce.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\iedkcs32.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ieapfltr.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ieapfltr.dat
2013-05-30 23:59:52 ----A---- C:\Windows\system32\ie4uinit.exe
2013-05-30 23:59:52 ----A---- C:\Windows\system32\icardie.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\dxtrans.dll
2013-05-30 23:59:52 ----A---- C:\Windows\system32\dxtmsft.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\wextract.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\vbscript.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\pngfilt.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\occache.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshtmler.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshtml.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\mshta.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeedssync.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\msfeeds.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\jscript9.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\jscript.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\imgutil.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iexpress.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\ieUnatt.exe
2013-05-30 23:59:51 ----A---- C:\Windows\system32\ieui.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iesysprep.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\iepeers.dll
2013-05-30 23:59:51 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-05-30 23:59:50 ----A---- C:\Windows\system32\ieframe.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-30 23:54:26 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-30 23:54:25 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-30 23:54:25 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2013-05-30 23:54:25 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2013-05-30 23:54:24 ----A---- C:\Windows\system32\XpsPrint.dll
2013-05-30 23:54:24 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2013-05-30 23:54:23 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2013-05-30 23:54:23 ----A---- C:\Windows\system32\WMPhoto.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2013-05-30 23:54:22 ----A---- C:\Windows\SYSWOW64\d3d10core.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\dxgi.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\d3d10warp.dll
2013-05-30 23:54:22 ----A---- C:\Windows\system32\d2d1.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecsExt.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2013-05-30 23:54:21 ----A---- C:\Windows\SYSWOW64\d3d10.dll
2013-05-30 23:54:21 ----A---- C:\Windows\system32\FntCache.dll
2013-05-30 23:54:21 ----A---- C:\Windows\system32\DWrite.dll
2013-05-30 23:54:20 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2013-05-30 23:54:20 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d11.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10level9.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10core.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10_1core.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10_1.dll
2013-05-30 23:54:20 ----A---- C:\Windows\system32\d3d10.dll
2013-05-30 23:54:19 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2013-05-30 23:54:19 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2013-05-30 23:54:19 ----A---- C:\Windows\system32\UIAnimation.dll
2013-05-30 23:36:58 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-05-30 23:36:58 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-05-30 23:36:58 ----A---- C:\Windows\system32\atmlib.dll
2013-05-30 23:36:58 ----A---- C:\Windows\system32\atmfd.dll
2013-05-30 22:38:58 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-05-30 22:38:58 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-30 22:38:58 ----A---- C:\Windows\system32\cdd.dll
2013-05-30 22:38:53 ----A---- C:\Windows\system32\mstscax.dll
2013-05-30 22:38:52 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-05-30 22:38:50 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-05-30 22:38:50 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-05-30 22:38:50 ----A---- C:\Windows\system32\tsgqec.dll
2013-05-30 22:38:50 ----A---- C:\Windows\system32\aaclient.dll
2013-05-30 22:38:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-05-30 22:38:37 ----A---- C:\Windows\system32\tzres.dll
2013-05-30 22:38:23 ----A---- C:\Windows\system32\win32spl.dll
2013-05-30 22:38:22 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-05-30 22:38:21 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-05-30 22:38:13 ----A---- C:\Windows\system32\shell32.dll
2013-05-30 22:38:10 ----A---- C:\Windows\SYSWOW64\shell32.dll
2013-05-30 22:38:09 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2013-05-30 22:38:09 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-05-30 22:38:09 ----A---- C:\Windows\system32\shdocvw.dll
2013-05-30 22:38:09 ----A---- C:\Windows\system32\consent.exe
2013-05-30 22:38:09 ----A---- C:\Windows\system32\authui.dll
2013-05-30 22:38:08 ----A---- C:\Windows\system32\appinfo.dll
2013-05-30 22:37:19 ----A---- C:\Windows\system32\schannel.dll
2013-05-30 22:37:19 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-05-30 22:37:19 ----A---- C:\Windows\system32\drivers\cng.sys
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-05-30 22:37:18 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-05-30 22:37:18 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdrmemptylst.exe
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdpwsx.dll
2013-05-30 22:37:16 ----A---- C:\Windows\system32\rdpcorekmts.dll
2013-05-30 22:37:15 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-05-30 22:37:12 ----A---- C:\Windows\system32\win32k.sys
2013-05-30 22:37:10 ----A---- C:\Windows\system32\msxml6.dll
2013-05-30 22:37:10 ----A---- C:\Windows\system32\msxml3.dll
2013-05-30 22:37:09 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-05-30 22:37:09 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-05-30 22:37:08 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2013-05-30 22:37:08 ----A---- C:\Windows\system32\msxml3r.dll
2013-05-30 22:36:09 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-05-30 22:36:09 ----A---- C:\Windows\system32\dpnet.dll
2013-05-30 22:36:08 ----A---- C:\Windows\system32\ncrypt.dll
2013-05-30 22:36:07 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-05-30 22:36:06 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-05-30 22:36:06 ----A---- C:\Windows\system32\wintrust.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\wow64win.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\winsrv.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\KernelBase.dll
2013-05-30 22:36:01 ----A---- C:\Windows\system32\kernel32.dll
2013-05-30 22:36:00 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-05-30 22:36:00 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-05-30 22:36:00 ----A---- C:\Windows\system32\conhost.exe
2013-05-30 22:35:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 22:35:59 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-05-30 22:35:59 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-05-30 22:35:59 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-05-30 22:35:59 ----A---- C:\Windows\system32\wow64.dll
2013-05-30 22:35:59 ----A---- C:\Windows\system32\ntvdm64.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-05-30 22:35:58 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 22:35:58 ----A---- C:\Windows\system32\wow64cpu.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 22:35:57 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-05-30 22:35:57 ----A---- C:\Windows\SYSWOW64\user.exe
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\netio.sys
2013-05-30 22:35:46 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-05-30 22:35:44 ----A---- C:\Windows\system32\rdpcorets.dll
2013-05-30 22:35:44 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2013-05-30 22:34:38 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2013-05-30 22:34:38 ----A---- C:\Windows\system32\kerberos.dll
2013-05-30 22:34:36 ----A---- C:\Windows\system32\synceng.dll
2013-05-30 22:34:35 ----A---- C:\Windows\SYSWOW64\synceng.dll
2013-05-30 22:34:28 ----A---- C:\Windows\system32\taskhost.exe
2013-05-30 22:34:27 ----A---- C:\Windows\system32\browser.dll
2013-05-30 22:34:26 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2013-05-30 22:34:26 ----A---- C:\Windows\SYSWOW64\browcli.dll
2013-05-30 22:34:26 ----A---- C:\Windows\system32\netapi32.dll
2013-05-30 22:34:26 ----A---- C:\Windows\system32\browcli.dll
2013-05-30 22:34:23 ----A---- C:\Windows\system32\localspl.dll
2013-05-30 22:34:16 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-05-30 22:34:12 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-05-30 22:34:11 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-05-30 22:34:10 ----A---- C:\Windows\system32\smss.exe
2013-05-30 22:34:10 ----A---- C:\Windows\system32\csrsrv.dll
2013-05-30 22:34:09 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-05-30 22:33:53 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2013-05-30 22:33:48 ----A---- C:\Windows\system32\cdosys.dll
2013-05-30 22:33:17 ----A---- C:\Windows\system32\crypt32.dll
2013-05-30 22:33:16 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-05-30 22:33:16 ----A---- C:\Windows\system32\cryptsvc.dll
2013-05-30 22:33:16 ----A---- C:\Windows\system32\cryptnet.dll
2013-05-30 22:33:15 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-05-30 22:33:15 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wups2.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wucltux.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wuaueng.dll
2013-05-30 22:15:53 ----A---- C:\Windows\system32\wuauclt.exe
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wups.dll
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wudriver.dll
2013-05-30 22:15:45 ----A---- C:\Windows\system32\wuapi.dll
2013-05-30 22:15:33 ----A---- C:\Windows\system32\wuwebv.dll
2013-05-30 22:15:33 ----A---- C:\Windows\system32\wuapp.exe
2013-05-27 06:42:50 ----A---- C:\Windows\system32\drivers\idmwfp.sys

======List of files/folders modified in the last 1 month======

2013-05-31 23:24:47 ----D---- C:\Program Files\trend micro
2013-05-31 23:24:43 ----D---- C:\Windows\Temp
2013-05-31 23:23:35 ----D---- C:\Windows\Microsoft.NET
2013-05-31 23:23:05 ----RSD---- C:\Windows\assembly
2013-05-31 23:18:28 ----D---- C:\Windows\system32\config
2013-05-31 23:15:06 ----D---- C:\Windows
2013-05-31 23:14:57 ----D---- C:\Windows\debug
2013-05-31 23:13:18 ----HD---- C:\ProgramData
2013-05-31 23:13:18 ----D---- C:\Windows\Tasks
2013-05-31 23:13:17 ----RD---- C:\Program Files (x86)\Skype
2013-05-31 22:38:29 ----RD---- C:\Users
2013-05-31 22:36:14 ----RD---- C:\Program Files (x86)
2013-05-31 20:20:04 ----SHD---- C:\Windows\Installer
2013-05-31 20:20:04 ----SHD---- C:\Config.Msi
2013-05-31 20:15:52 ----D---- C:\Windows\system32\Tasks
2013-05-31 19:51:22 ----D---- C:\Windows\inf
2013-05-31 19:51:02 ----SHD---- C:\$Recycle.Bin
2013-05-31 19:12:18 ----D---- C:\ProgramData\IObit
2013-05-31 19:12:00 ----D---- C:\Windows\winsxs
2013-05-31 18:57:14 ----D---- C:\Windows\system32\drivers
2013-05-31 18:55:18 ----D---- C:\Windows\SysWOW64
2013-05-31 18:47:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-05-31 18:46:37 ----D---- C:\ProgramData\Systweak
2013-05-31 18:46:35 ----D---- C:\Windows\System32
2013-05-31 18:46:16 ----D---- C:\Windows\Panther
2013-05-31 18:46:13 ----D---- C:\Windows\Logs
2013-05-31 18:38:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-05-31 18:38:11 ----D---- C:\Windows\system32\cs-CZ
2013-05-31 18:32:02 ----D---- C:\ProgramData\Yahoo!
2013-05-31 18:32:02 ----D---- C:\Program Files (x86)\Yahoo!
2013-05-31 18:25:27 ----D---- C:\Program Files\NVIDIA Corporation
2013-05-31 18:25:26 ----D---- C:\Temp
2013-05-31 18:24:57 ----D---- C:\Windows\Help
2013-05-31 18:21:52 ----D---- C:\Windows\system32\catroot
2013-05-31 18:21:49 ----D---- C:\Windows\system32\DriverStore
2013-05-31 18:13:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-05-31 18:08:17 ----D---- C:\ProgramData\Skype
2013-05-31 18:08:01 ----D---- C:\Program Files (x86)\Common Files
2013-05-31 18:02:51 ----SHD---- C:\System Volume Information
2013-05-31 17:48:16 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-31 00:14:26 ----D---- C:\Program Files\Internet Explorer
2013-05-31 00:14:26 ----D---- C:\Program Files (x86)\Internet Explorer
2013-05-31 00:14:25 ----D---- C:\Windows\SYSWOW64\migration
2013-05-31 00:14:25 ----D---- C:\Windows\SYSWOW64\en-US
2013-05-31 00:14:24 ----D---- C:\Windows\system32\migration
2013-05-31 00:14:24 ----D---- C:\Windows\system32\en-US
2013-05-31 00:14:24 ----D---- C:\Windows\PolicyDefinitions
2013-05-31 00:14:22 ----RSD---- C:\Windows\Fonts
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-TW
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-HK
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\zh-CN
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\tr-TR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\sv-SE
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ru-RU
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pt-PT
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pt-BR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\pl-PL
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\nl-NL
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\nb-NO
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ko-KR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\ja-JP
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\it-IT
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\hu-HU
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\fr-FR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\fi-FI
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\es-ES
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\el-GR
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\de-DE
2013-05-31 00:14:22 ----D---- C:\Windows\SYSWOW64\da-DK
2013-05-31 00:14:21 ----D---- C:\Windows\system32\zh-TW
2013-05-31 00:14:21 ----D---- C:\Windows\system32\zh-HK
2013-05-31 00:14:21 ----D---- C:\Windows\system32\tr-TR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\sv-SE
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pt-PT
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pt-BR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\pl-PL
2013-05-31 00:14:21 ----D---- C:\Windows\system32\nl-NL
2013-05-31 00:14:21 ----D---- C:\Windows\system32\ko-KR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\it-IT
2013-05-31 00:14:21 ----D---- C:\Windows\system32\hu-HU
2013-05-31 00:14:21 ----D---- C:\Windows\system32\fr-FR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\fi-FI
2013-05-31 00:14:21 ----D---- C:\Windows\system32\es-ES
2013-05-31 00:14:21 ----D---- C:\Windows\system32\el-GR
2013-05-31 00:14:21 ----D---- C:\Windows\system32\de-DE
2013-05-31 00:14:20 ----D---- C:\Windows\system32\zh-CN
2013-05-31 00:14:20 ----D---- C:\Windows\system32\ru-RU
2013-05-31 00:14:20 ----D---- C:\Windows\system32\nb-NO
2013-05-31 00:14:20 ----D---- C:\Windows\system32\ja-JP
2013-05-31 00:14:20 ----D---- C:\Windows\system32\da-DK
2013-05-31 00:14:19 ----D---- C:\Windows\AppPatch
2013-05-31 00:09:13 ----D---- C:\Windows\system32\catroot2
2013-05-30 23:58:47 ----A---- C:\Windows\hms_odpocet.ini
2013-05-30 23:50:06 ----RD---- C:\Program Files
2013-05-30 23:42:30 ----D---- C:\Windows\Prefetch
2013-05-30 23:41:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-05-30 23:32:50 ----D---- C:\ProgramData\Microsoft Help
2013-05-30 23:28:10 ----D---- C:\Program Files (x86)\Nokia
2013-05-30 23:21:26 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-05-30 23:07:52 ----D---- C:\Windows\Minidump
2013-05-30 22:56:49 ----D---- C:\Program Files (x86)\Adobe
2013-05-29 17:59:24 ----D---- C:\Windows\system32\NDF
2013-05-03 16:15:58 ----A---- C:\Windows\system32\MRT.exe
2013-05-02 02:06:08 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2011-08-04 62496]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2011-12-26 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-11-18 526392]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2011-08-04 38288]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2011-08-04 187632]
R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2013-05-25 168288]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-10-18 2957544]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys [2011-12-26 349416]
S3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x64; C:\Windows\system32\DRIVERS\Apfiltr.sys [2011-11-24 304760]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys []
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-11-01 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-11-01 27136]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-11-01 171008]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [2011-07-20 44032]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [2010-06-16 37888]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-11-01 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2012-12-14 621008]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-09-22 974944]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-31 878368]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-19 1259296]
R2 TeamViewer7;TeamViewer 7; C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-30 256904]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-30 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-11-30 718888]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-02 1255736]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#10 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Linda.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Dopručuji odinstalovat AdvancedSystemCare. Tento čínský šmejd v rukou laika dokáže poškodit systém.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

linda_23
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 31 bře 2009 18:33

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#11 Příspěvek od linda_23 »

Tak jsem udělala vše co jste říkal. Odinstalovala jsem AdvancedSystemCare. Teď RAM běží na 800 Mb když nic nedělám a počítač je pořád strochu pomalý :) Jo a chtěla bych se zeptat jaký program byste doporučil na optimalizace počítače. Děkuji :D

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#12 Příspěvek od Rudy »

Na optimalizaci postačí CCleaner: http://forum.viry.cz/viewtopic.php?f=46&t=7478 . Ještě můžete defragmentovat disk.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Babis
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 31 kvě 2013 16:58

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#13 Příspěvek od Babis »

Zdravím, můžu se zeptat, jak ASC poškozuje systém? Už ho dost dlouho používám a musím říct, že jsem spokojený, tak mě zajímá, co přesně bych mohl udělat špatně.
EDIT: Omlouvám se, že takto zasahuji do cizího topicu, ještě navíc HJT, ale připadá mi zbytečné zakládat vlastní topic.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119527
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu. RAM vždy běží na 1GB!

#14 Příspěvek od Rudy »

Babis píše:Zdravím, můžu se zeptat, jak ASC poškozuje systém? Už ho dost dlouho používám a musím říct, že jsem spokojený, tak mě zajímá, co přesně bych mohl udělat špatně.
EDIT: Omlouvám se, že takto zasahuji do cizího topicu, ještě navíc HJT, ale připadá mi zbytečné zakládat vlastní topic.
Zdravím!
Pokud máte dotaz, měl byste si založit vlastní téma. Nicméně vám odpovím. Hledá neexistující problémy balamutí usera, aby si koupil doplňky, či placené programy, co by měl vyčistit nevyčistí a právě hledáním neexistujících problémů si neznalý user poškodí systém. Zkrátka je to soft, bez něhož může být klidně "na živu". Projděte si fórum a uvidíte sám.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět