Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s virem

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Momoum
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 kvě 2013 14:51

Problém s virem

#1 Příspěvek od Momoum »

Dobrý den, prosím o kontrolu logu, mám podezření na vir v NB. Děkuji předem :)

Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2014-07-16 20:54:44
Microsoft Windows 7 Home Premium
System drive C: has 400 GB (93%) free of 432 GB
Total RAM: 4091 MB (61% free)

HijackThis download failed

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 1957200
\??\C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\windows\SysWOW64\PnkBstrA.exe
C:\windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
atieclxx
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Users\Lenovo\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\USB Camera\VM331_STI.EXE"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2136.0.59180495\1787967435" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2136.1.1321919855\773924811" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2136.2.415770660\801877763" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2136.3.758760087\248412303" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=gpu-process --channel="2136.4.1489678697\423106510" --no-sandbox --lang=en-US --log-severity=disable --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,9,19 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.0.0 --lang=en-US --log-severity=disable /prefetch:822062411

"taskhost.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2660.0.1790499366\1911344556" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_77/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --enable-software-compositing --channel="2660.1.1407420018\1183728251" /prefetch:673131151
"C:\Users\Lenovo\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k WerSvcGroup

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-27 10775584]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2010-04-27 2040352]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-01-07 1894696]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [2010-04-12 4462496]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2010-03-18 7056800]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-02-24 5581888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08 21446272]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"Spotify"=C:\Users\Lenovo\AppData\Roaming\Spotify\Spotify.exe [2014-07-08 6189624]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-03 98304]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331_STI.EXE [2009-09-15 536576]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
"VeriFaceManager"=C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [2010-08-28 3122528]
"UCam_Menu"=C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"YouCam Mirror Tray icon"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2010-03-03 171104]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-04 218408]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-16 20:54:45 ----D---- C:\Program Files\trend micro
2014-07-16 20:54:43 ----D---- C:\rsit
2014-07-11 21:45:28 ----A---- C:\windows\SYSWOW64\xactengine2_8.dll
2014-07-11 21:45:28 ----A---- C:\windows\system32\xactengine2_8.dll
2014-07-11 21:45:27 ----A---- C:\windows\SYSWOW64\x3daudio1_2.dll
2014-07-11 21:45:27 ----A---- C:\windows\system32\x3daudio1_2.dll
2014-07-11 21:45:26 ----A---- C:\windows\SYSWOW64\d3dx10_34.dll
2014-07-11 21:45:26 ----A---- C:\windows\SYSWOW64\D3DCompiler_34.dll
2014-07-11 21:45:26 ----A---- C:\windows\system32\d3dx10_34.dll
2014-07-11 21:45:26 ----A---- C:\windows\system32\D3DCompiler_34.dll
2014-07-11 21:45:25 ----A---- C:\windows\SYSWOW64\d3dx9_34.dll
2014-07-11 21:45:25 ----A---- C:\windows\system32\d3dx9_34.dll
2014-07-11 21:45:24 ----A---- C:\windows\SYSWOW64\xinput1_3.dll
2014-07-11 21:45:24 ----A---- C:\windows\SYSWOW64\xactengine2_7.dll
2014-07-11 21:45:24 ----A---- C:\windows\system32\xinput1_3.dll
2014-07-11 21:45:24 ----A---- C:\windows\system32\xactengine2_7.dll
2014-07-11 21:45:23 ----A---- C:\windows\SYSWOW64\d3dx10_33.dll
2014-07-11 21:45:23 ----A---- C:\windows\SYSWOW64\D3DCompiler_33.dll
2014-07-11 21:45:23 ----A---- C:\windows\system32\d3dx10_33.dll
2014-07-11 21:45:23 ----A---- C:\windows\system32\D3DCompiler_33.dll
2014-07-11 21:45:22 ----A---- C:\windows\SYSWOW64\d3dx9_33.dll
2014-07-11 21:45:22 ----A---- C:\windows\system32\d3dx9_33.dll
2014-07-11 21:45:21 ----A---- C:\windows\SYSWOW64\xactengine2_6.dll
2014-07-11 21:45:21 ----A---- C:\windows\system32\xactengine2_6.dll
2014-07-11 21:45:20 ----A---- C:\windows\SYSWOW64\xactengine2_5.dll
2014-07-11 21:45:20 ----A---- C:\windows\SYSWOW64\d3dx10.dll
2014-07-11 21:45:20 ----A---- C:\windows\system32\xactengine2_5.dll
2014-07-11 21:45:20 ----A---- C:\windows\system32\d3dx10.dll
2014-07-11 21:45:19 ----A---- C:\windows\SYSWOW64\d3dx9_32.dll
2014-07-11 21:45:19 ----A---- C:\windows\system32\d3dx9_32.dll
2014-07-11 21:45:18 ----A---- C:\windows\SYSWOW64\xactengine2_4.dll
2014-07-11 21:45:18 ----A---- C:\windows\SYSWOW64\x3daudio1_1.dll
2014-07-11 21:45:18 ----A---- C:\windows\system32\xactengine2_4.dll
2014-07-11 21:45:18 ----A---- C:\windows\system32\x3daudio1_1.dll
2014-07-11 21:45:17 ----A---- C:\windows\SYSWOW64\xactengine2_3.dll
2014-07-11 21:45:17 ----A---- C:\windows\SYSWOW64\d3dx9_31.dll
2014-07-11 21:45:17 ----A---- C:\windows\system32\xactengine2_3.dll
2014-07-11 21:45:17 ----A---- C:\windows\system32\d3dx9_31.dll
2014-07-11 21:45:16 ----A---- C:\windows\SYSWOW64\xinput1_2.dll
2014-07-11 21:45:16 ----A---- C:\windows\system32\xinput1_2.dll
2014-07-11 21:45:15 ----A---- C:\windows\SYSWOW64\xactengine2_2.dll
2014-07-11 21:45:15 ----A---- C:\windows\system32\xactengine2_2.dll
2014-07-11 21:45:13 ----A---- C:\windows\SYSWOW64\xinput1_1.dll
2014-07-11 21:45:13 ----A---- C:\windows\system32\xinput1_1.dll
2014-07-11 21:45:12 ----A---- C:\windows\SYSWOW64\xactengine2_1.dll
2014-07-11 21:45:12 ----A---- C:\windows\system32\xactengine2_1.dll
2014-07-11 21:45:07 ----A---- C:\windows\SYSWOW64\d3dx9_30.dll
2014-07-11 21:45:07 ----A---- C:\windows\system32\d3dx9_30.dll
2014-07-11 21:45:04 ----A---- C:\windows\SYSWOW64\xactengine2_0.dll
2014-07-11 21:45:04 ----A---- C:\windows\SYSWOW64\x3daudio1_0.dll
2014-07-11 21:45:04 ----A---- C:\windows\system32\xactengine2_0.dll
2014-07-11 21:45:04 ----A---- C:\windows\system32\x3daudio1_0.dll
2014-07-11 21:45:03 ----A---- C:\windows\SYSWOW64\d3dx9_29.dll
2014-07-11 21:45:03 ----A---- C:\windows\SYSWOW64\d3dx9_28.dll
2014-07-11 21:45:03 ----A---- C:\windows\system32\d3dx9_29.dll
2014-07-11 21:45:03 ----A---- C:\windows\system32\d3dx9_28.dll
2014-07-11 21:45:01 ----A---- C:\windows\SYSWOW64\d3dx9_27.dll
2014-07-11 21:45:01 ----A---- C:\windows\system32\d3dx9_27.dll
2014-07-11 21:45:00 ----A---- C:\windows\SYSWOW64\d3dx9_26.dll
2014-07-11 21:45:00 ----A---- C:\windows\system32\d3dx9_26.dll
2014-07-11 21:44:59 ----A---- C:\windows\SYSWOW64\d3dx9_25.dll
2014-07-11 21:44:59 ----A---- C:\windows\system32\d3dx9_25.dll
2014-07-11 21:44:58 ----A---- C:\windows\SYSWOW64\d3dx9_24.dll
2014-07-11 21:44:58 ----A---- C:\windows\system32\d3dx9_24.dll
2014-07-11 21:43:18 ----A---- C:\windows\SYSWOW64\PnkBstrB.exe
2014-07-11 21:43:15 ----A---- C:\windows\SYSWOW64\PnkBstrA.exe
2014-07-11 21:43:12 ----A---- C:\windows\game.ini
2014-07-11 21:28:00 ----D---- C:\Program Files (x86)\Activision
2014-07-11 21:26:29 ----D---- C:\Users\Lenovo\AppData\Roaming\Macromedia
2014-07-08 16:19:16 ----D---- C:\Users\Lenovo\AppData\Roaming\Spotify
2014-07-05 18:00:03 ----SHD---- C:\System Volume Information
2014-07-05 18:00:03 ----ASH---- C:\pagefile.sys
2014-07-05 17:59:58 ----ASH---- C:\hiberfil.sys
2014-07-05 16:51:59 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2014-07-05 16:50:28 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\PresentationHostProxy.dll
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\PresentationHost.exe
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\netfxperf.dll
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\mscoree.dll
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\dfshim.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\PresentationHostProxy.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\PresentationHost.exe
2014-07-05 16:48:25 ----A---- C:\windows\system32\netfxperf.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\mscoree.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\dfshim.dll
2014-07-05 16:37:26 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2014-07-05 16:37:18 ----RD---- C:\Program Files (x86)\Skype
2014-07-05 16:37:15 ----D---- C:\ProgramData\Skype
2014-07-05 16:30:55 ----N---- C:\windows\system32\MpSigStub.exe
2014-07-05 16:27:54 ----D---- C:\Program Files (x86)\Google
2014-07-05 16:24:49 ----D---- C:\Users\Lenovo\AppData\Roaming\ESET
2014-07-05 16:23:34 ----D---- C:\ProgramData\ESET
2014-07-05 16:23:34 ----D---- C:\Program Files\ESET
2014-07-05 16:07:07 ----D---- C:\Users\Lenovo\AppData\Roaming\ATI
2014-07-05 16:06:20 ----D---- C:\Users\Lenovo\AppData\Roaming\Identities
2014-07-05 16:06:17 ----SHD---- C:\$RECYCLE.BIN
2014-07-05 16:06:05 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2014-07-05 16:06:05 ----D---- C:\Users\Lenovo\AppData\Roaming\Media Center Programs
2014-07-05 16:05:50 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-07-05 16:05:21 ----D---- C:\Program Files (x86)\Windows Live SkyDrive
2014-07-05 16:05:03 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2014-07-05 16:04:54 ----D---- C:\Program Files (x86)\Microsoft
2014-07-05 16:02:27 ----SHD---- C:\Recovery

======List of files/folders modified in the last 1 month======

2014-07-16 20:54:46 ----D---- C:\windows\Temp
2014-07-16 20:54:45 ----RD---- C:\Program Files
2014-07-16 20:07:40 ----D---- C:\windows\system32\config
2014-07-16 20:07:34 ----D---- C:\windows\winsxs
2014-07-16 19:59:23 ----D---- C:\windows\system32\catroot2
2014-07-16 19:59:23 ----D---- C:\windows\system32\catroot
2014-07-16 19:53:28 ----D---- C:\windows\System32
2014-07-16 19:53:27 ----D---- C:\windows\inf
2014-07-16 19:53:27 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-07-16 19:53:03 ----D---- C:\windows\rescache
2014-07-16 19:49:06 ----D---- C:\ProgramData\VeriFace
2014-07-15 20:57:09 ----D---- C:\Program Files\Windows Sidebar
2014-07-15 20:57:09 ----D---- C:\Program Files\Windows Media Player
2014-07-15 20:57:09 ----D---- C:\Program Files\Windows Mail
2014-07-15 20:57:09 ----D---- C:\Program Files\Internet Explorer
2014-07-15 20:57:08 ----D---- C:\Program Files\Windows Photo Viewer
2014-07-15 20:57:08 ----D---- C:\Program Files\Windows Journal
2014-07-15 20:57:08 ----D---- C:\Program Files\Windows Defender
2014-07-15 20:57:08 ----D---- C:\Program Files\Common Files\System
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Windows Sidebar
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Windows Media Player
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Windows Mail
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\winrm
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\slmgr
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\sk-SK
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\migwiz
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\en
2014-07-15 20:57:07 ----D---- C:\windows\servicing
2014-07-15 20:57:07 ----D---- C:\windows\ehome
2014-07-15 20:57:07 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2014-07-15 20:57:07 ----D---- C:\Program Files (x86)\Windows Defender
2014-07-15 20:57:03 ----D---- C:\windows\SYSWOW64\en-US
2014-07-15 20:57:03 ----D---- C:\windows\SYSWOW64\drivers\en-US
2014-07-15 20:57:03 ----D---- C:\windows\SYSWOW64\drivers
2014-07-15 20:57:00 ----D---- C:\windows\SYSWOW64\WCN
2014-07-15 20:57:00 ----D---- C:\windows\SYSWOW64\DriverStore
2014-07-15 20:57:00 ----D---- C:\windows\SYSWOW64\Dism
2014-07-15 20:56:56 ----D---- C:\windows\SYSWOW64\wbem
2014-07-15 20:56:56 ----D---- C:\windows\SYSWOW64\Printing_Admin_Scripts
2014-07-15 20:56:56 ----D---- C:\Windows
2014-07-15 20:56:55 ----D---- C:\windows\PolicyDefinitions
2014-07-15 20:56:55 ----D---- C:\windows\en-US
2014-07-15 20:56:54 ----D---- C:\windows\system32\winrm
2014-07-15 20:56:54 ----D---- C:\windows\system32\sysprep
2014-07-15 20:56:54 ----D---- C:\windows\system32\slmgr
2014-07-15 20:56:54 ----D---- C:\windows\system32\sk-SK
2014-07-15 20:56:54 ----D---- C:\windows\system32\oobe
2014-07-15 20:56:54 ----D---- C:\windows\system32\migwiz
2014-07-15 20:56:54 ----D---- C:\windows\system32\en
2014-07-15 20:56:54 ----D---- C:\windows\system32\Boot
2014-07-15 20:56:49 ----D---- C:\windows\system32\en-US
2014-07-15 20:56:42 ----D---- C:\windows\system32\WCN
2014-07-15 20:56:42 ----D---- C:\windows\system32\DriverStore
2014-07-15 20:56:42 ----D---- C:\windows\system32\drivers\en-US
2014-07-15 20:56:42 ----D---- C:\windows\system32\drivers
2014-07-15 20:56:42 ----D---- C:\windows\system32\Dism
2014-07-15 20:56:38 ----D---- C:\windows\system32\Printing_Admin_Scripts
2014-07-15 20:56:37 ----D---- C:\windows\system32\wbem
2014-07-15 20:56:17 ----D---- C:\Program Files\DVD Maker
2014-07-15 20:55:54 ----D---- C:\windows\Speech
2014-07-14 09:38:43 ----D---- C:\windows\system32\wdi
2014-07-13 14:09:04 ----D---- C:\windows\Logs
2014-07-13 13:59:03 ----D---- C:\windows\Prefetch
2014-07-11 21:45:28 ----D---- C:\windows\SysWOW64
2014-07-11 21:45:12 ----RSD---- C:\windows\assembly
2014-07-11 21:45:08 ----D---- C:\windows\Microsoft.NET
2014-07-11 21:43:14 ----D---- C:\windows\system32\LogFiles
2014-07-11 21:43:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-07-11 21:43:08 ----SHD---- C:\windows\Installer
2014-07-11 21:28:00 ----RD---- C:\Program Files (x86)
2014-07-09 21:06:56 ----SD---- C:\ProgramData\Microsoft
2014-07-08 20:54:14 ----D---- C:\windows\system32\NDF
2014-07-05 18:01:44 ----D---- C:\windows\debug
2014-07-05 16:55:29 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-07-05 16:55:29 ----D---- C:\windows\system32\cs-CZ
2014-07-05 16:48:19 ----D---- C:\windows\SoftwareDistribution
2014-07-05 16:37:21 ----D---- C:\Program Files (x86)\Common Files
2014-07-05 16:37:15 ----HD---- C:\ProgramData
2014-07-05 16:27:57 ----D---- C:\windows\Tasks
2014-07-05 16:27:57 ----D---- C:\windows\system32\Tasks
2014-07-05 16:12:02 ----D---- C:\ProgramData\McAfee
2014-07-05 16:11:31 ----D---- C:\Program Files\Common Files
2014-07-05 16:06:04 ----RD---- C:\Users
2014-07-05 16:05:57 ----D---- C:\Program Files (x86)\Windows Live

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2009-08-24 16440]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2010-01-15 39008]
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 44120]
R1 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 62136]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2013-09-17 220232]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2009-10-19 28176]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 6402560]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 188928]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl664.sys [2010-02-02 3058168]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2010-04-27 2357024]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-01-07 302128]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11280]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-16 79376]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2010-03-12 242720]
S3 vm331avs;Digital Camera 1; C:\windows\System32\Drivers\vm331avs.sys [2009-11-09 207232]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 151656]
S3 wsvd;wsvd; C:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-03-03 202752]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2009-08-11 864032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-02-24 1343408]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2014-07-11 66872]
R2 PnkBstrB;PnkBstrB; C:\windows\syswow64\PnkBstrB.exe [2014-07-11 103736]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-05 116648]
S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-05 116648]
S3 IGRS;IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s virem

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Momoum
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 kvě 2013 14:51

Re: Problém s virem

#3 Příspěvek od Momoum »

Zde je log:

# AdwCleaner v3.215 - Report created 16/07/2014 at 21:18:24
# Updated 09/07/2014 by Xplode
# Operating System : Windows 7 Home Premium (64 bits)
# Username : Lenovo - LENOVO-PC
# Running from : C:\Users\Lenovo\Desktop\adwcleaner_3.215.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7600.16385


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [618 octets] - [16/07/2014 21:18:24]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [677 octets] ##########




# AdwCleaner v3.215 - Report created 16/07/2014 at 21:26:38
# Updated 09/07/2014 by Xplode
# Operating System : Windows 7 Home Premium (64 bits)
# Username : Lenovo - LENOVO-PC
# Running from : C:\Users\Lenovo\Desktop\adwcleaner_3.215.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7600.16385


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [756 octets] - [16/07/2014 21:18:24]
AdwCleaner[S0].txt - [678 octets] - [16/07/2014 21:26:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [737 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s virem

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:

:files
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files (x86)\Windows Live\Toolbar
C:\windows\SYSWOW64\mscoree.dll

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]

:services
SeaPort

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Momoum
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 kvě 2013 14:51

Re: Problém s virem

#5 Příspěvek od Momoum »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2014-07-16 22:24:26
Microsoft Windows 7 Home Premium
System drive C: has 400 GB (93%) free of 432 GB
Total RAM: 4091 MB (63% free)


======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 3199520
\??\C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
taskeng.exe {92F6AF56-8962-48A3-A763-62EEFD104B5B}
atieclxx
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\windows\Explorer.EXE
C:\windows\SysWOW64\PnkBstrB.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\servicing\TrustedInstaller.exe
C:\windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Users\Lenovo\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\USB Camera\VM331_STI.EXE"
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe"
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\windows\system32\sppsvc.exe
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2872.0.1309884895\1385084218" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2872.1.2019161096\334657022" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2872.2.1847738166\690830521" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=renderer --js-flags=--harmony-proxies --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="2872.3.213814169\1849584774" /prefetch:673131151
"C:\Users\Lenovo\AppData\Roaming\Spotify\Data\SpotifyHelper.exe" --type=gpu-process --channel="2872.4.898623313\1596540788" --no-sandbox --lang=en-US --log-severity=disable --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,9,19 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.0.0 --lang=en-US --log-severity=disable /prefetch:822062411
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\Lenovo\Desktop\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-27 10775584]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2010-04-27 2040352]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-01-07 1894696]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [2010-04-12 4462496]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2010-03-18 7056800]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-02-24 5581888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08 21446272]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"Spotify"=C:\Users\Lenovo\AppData\Roaming\Spotify\Spotify.exe [2014-07-08 6189624]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-03 98304]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331_STI.EXE [2009-09-15 536576]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
"VeriFaceManager"=C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [2010-08-28 3122528]
"UCam_Menu"=C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"YouCam Mirror Tray icon"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2010-03-03 171104]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-04 218408]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-16 22:18:20 ----D---- C:\_OTM
2014-07-16 21:18:12 ----D---- C:\AdwCleaner
2014-07-16 20:54:45 ----D---- C:\Program Files\trend micro
2014-07-16 20:54:43 ----D---- C:\rsit
2014-07-11 21:45:28 ----A---- C:\windows\SYSWOW64\xactengine2_8.dll
2014-07-11 21:45:28 ----A---- C:\windows\system32\xactengine2_8.dll
2014-07-11 21:45:27 ----A---- C:\windows\SYSWOW64\x3daudio1_2.dll
2014-07-11 21:45:27 ----A---- C:\windows\system32\x3daudio1_2.dll
2014-07-11 21:45:26 ----A---- C:\windows\SYSWOW64\d3dx10_34.dll
2014-07-11 21:45:26 ----A---- C:\windows\SYSWOW64\D3DCompiler_34.dll
2014-07-11 21:45:26 ----A---- C:\windows\system32\d3dx10_34.dll
2014-07-11 21:45:26 ----A---- C:\windows\system32\D3DCompiler_34.dll
2014-07-11 21:45:25 ----A---- C:\windows\SYSWOW64\d3dx9_34.dll
2014-07-11 21:45:25 ----A---- C:\windows\system32\d3dx9_34.dll
2014-07-11 21:45:24 ----A---- C:\windows\SYSWOW64\xinput1_3.dll
2014-07-11 21:45:24 ----A---- C:\windows\SYSWOW64\xactengine2_7.dll
2014-07-11 21:45:24 ----A---- C:\windows\system32\xinput1_3.dll
2014-07-11 21:45:24 ----A---- C:\windows\system32\xactengine2_7.dll
2014-07-11 21:45:23 ----A---- C:\windows\SYSWOW64\d3dx10_33.dll
2014-07-11 21:45:23 ----A---- C:\windows\SYSWOW64\D3DCompiler_33.dll
2014-07-11 21:45:23 ----A---- C:\windows\system32\d3dx10_33.dll
2014-07-11 21:45:23 ----A---- C:\windows\system32\D3DCompiler_33.dll
2014-07-11 21:45:22 ----A---- C:\windows\SYSWOW64\d3dx9_33.dll
2014-07-11 21:45:22 ----A---- C:\windows\system32\d3dx9_33.dll
2014-07-11 21:45:21 ----A---- C:\windows\SYSWOW64\xactengine2_6.dll
2014-07-11 21:45:21 ----A---- C:\windows\system32\xactengine2_6.dll
2014-07-11 21:45:20 ----A---- C:\windows\SYSWOW64\xactengine2_5.dll
2014-07-11 21:45:20 ----A---- C:\windows\SYSWOW64\d3dx10.dll
2014-07-11 21:45:20 ----A---- C:\windows\system32\xactengine2_5.dll
2014-07-11 21:45:20 ----A---- C:\windows\system32\d3dx10.dll
2014-07-11 21:45:19 ----A---- C:\windows\SYSWOW64\d3dx9_32.dll
2014-07-11 21:45:19 ----A---- C:\windows\system32\d3dx9_32.dll
2014-07-11 21:45:18 ----A---- C:\windows\SYSWOW64\xactengine2_4.dll
2014-07-11 21:45:18 ----A---- C:\windows\SYSWOW64\x3daudio1_1.dll
2014-07-11 21:45:18 ----A---- C:\windows\system32\xactengine2_4.dll
2014-07-11 21:45:18 ----A---- C:\windows\system32\x3daudio1_1.dll
2014-07-11 21:45:17 ----A---- C:\windows\SYSWOW64\xactengine2_3.dll
2014-07-11 21:45:17 ----A---- C:\windows\SYSWOW64\d3dx9_31.dll
2014-07-11 21:45:17 ----A---- C:\windows\system32\xactengine2_3.dll
2014-07-11 21:45:17 ----A---- C:\windows\system32\d3dx9_31.dll
2014-07-11 21:45:16 ----A---- C:\windows\SYSWOW64\xinput1_2.dll
2014-07-11 21:45:16 ----A---- C:\windows\system32\xinput1_2.dll
2014-07-11 21:45:15 ----A---- C:\windows\SYSWOW64\xactengine2_2.dll
2014-07-11 21:45:15 ----A---- C:\windows\system32\xactengine2_2.dll
2014-07-11 21:45:13 ----A---- C:\windows\SYSWOW64\xinput1_1.dll
2014-07-11 21:45:13 ----A---- C:\windows\system32\xinput1_1.dll
2014-07-11 21:45:12 ----A---- C:\windows\SYSWOW64\xactengine2_1.dll
2014-07-11 21:45:12 ----A---- C:\windows\system32\xactengine2_1.dll
2014-07-11 21:45:07 ----A---- C:\windows\SYSWOW64\d3dx9_30.dll
2014-07-11 21:45:07 ----A---- C:\windows\system32\d3dx9_30.dll
2014-07-11 21:45:04 ----A---- C:\windows\SYSWOW64\xactengine2_0.dll
2014-07-11 21:45:04 ----A---- C:\windows\SYSWOW64\x3daudio1_0.dll
2014-07-11 21:45:04 ----A---- C:\windows\system32\xactengine2_0.dll
2014-07-11 21:45:04 ----A---- C:\windows\system32\x3daudio1_0.dll
2014-07-11 21:45:03 ----A---- C:\windows\SYSWOW64\d3dx9_29.dll
2014-07-11 21:45:03 ----A---- C:\windows\SYSWOW64\d3dx9_28.dll
2014-07-11 21:45:03 ----A---- C:\windows\system32\d3dx9_29.dll
2014-07-11 21:45:03 ----A---- C:\windows\system32\d3dx9_28.dll
2014-07-11 21:45:01 ----A---- C:\windows\SYSWOW64\d3dx9_27.dll
2014-07-11 21:45:01 ----A---- C:\windows\system32\d3dx9_27.dll
2014-07-11 21:45:00 ----A---- C:\windows\SYSWOW64\d3dx9_26.dll
2014-07-11 21:45:00 ----A---- C:\windows\system32\d3dx9_26.dll
2014-07-11 21:44:59 ----A---- C:\windows\SYSWOW64\d3dx9_25.dll
2014-07-11 21:44:59 ----A---- C:\windows\system32\d3dx9_25.dll
2014-07-11 21:44:58 ----A---- C:\windows\SYSWOW64\d3dx9_24.dll
2014-07-11 21:44:58 ----A---- C:\windows\system32\d3dx9_24.dll
2014-07-11 21:43:18 ----A---- C:\windows\SYSWOW64\PnkBstrB.exe
2014-07-11 21:43:15 ----A---- C:\windows\SYSWOW64\PnkBstrA.exe
2014-07-11 21:43:12 ----A---- C:\windows\game.ini
2014-07-11 21:28:00 ----D---- C:\Program Files (x86)\Activision
2014-07-11 21:26:29 ----D---- C:\Users\Lenovo\AppData\Roaming\Macromedia
2014-07-08 16:19:16 ----D---- C:\Users\Lenovo\AppData\Roaming\Spotify
2014-07-05 18:00:03 ----SHD---- C:\System Volume Information
2014-07-05 18:00:03 ----ASH---- C:\pagefile.sys
2014-07-05 17:59:58 ----ASH---- C:\hiberfil.sys
2014-07-05 16:51:59 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2014-07-05 16:50:28 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\PresentationHostProxy.dll
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\PresentationHost.exe
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\netfxperf.dll
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\mscoree.dll
2014-07-05 16:48:25 ----A---- C:\windows\SYSWOW64\dfshim.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\PresentationHostProxy.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\PresentationHost.exe
2014-07-05 16:48:25 ----A---- C:\windows\system32\netfxperf.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\mscoree.dll
2014-07-05 16:48:25 ----A---- C:\windows\system32\dfshim.dll
2014-07-05 16:37:26 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2014-07-05 16:37:18 ----RD---- C:\Program Files (x86)\Skype
2014-07-05 16:37:15 ----D---- C:\ProgramData\Skype
2014-07-05 16:30:55 ----N---- C:\windows\system32\MpSigStub.exe
2014-07-05 16:27:54 ----D---- C:\Program Files (x86)\Google
2014-07-05 16:24:49 ----D---- C:\Users\Lenovo\AppData\Roaming\ESET
2014-07-05 16:23:34 ----D---- C:\ProgramData\ESET
2014-07-05 16:23:34 ----D---- C:\Program Files\ESET
2014-07-05 16:07:07 ----D---- C:\Users\Lenovo\AppData\Roaming\ATI
2014-07-05 16:06:20 ----D---- C:\Users\Lenovo\AppData\Roaming\Identities
2014-07-05 16:06:17 ----SHD---- C:\$RECYCLE.BIN
2014-07-05 16:06:05 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2014-07-05 16:06:05 ----D---- C:\Users\Lenovo\AppData\Roaming\Media Center Programs
2014-07-05 16:05:50 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-07-05 16:05:21 ----D---- C:\Program Files (x86)\Windows Live SkyDrive
2014-07-05 16:05:03 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2014-07-05 16:04:54 ----D---- C:\Program Files (x86)\Microsoft
2014-07-05 16:02:27 ----SHD---- C:\Recovery

======List of files/folders modified in the last 1 month======

2014-07-16 22:24:28 ----D---- C:\windows\Temp
2014-07-16 22:24:11 ----D---- C:\windows\System32
2014-07-16 22:24:11 ----D---- C:\windows\inf
2014-07-16 22:24:11 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-07-16 22:21:13 ----D---- C:\ProgramData\VeriFace
2014-07-16 22:20:16 ----D---- C:\windows\system32\config
2014-07-16 22:18:23 ----D---- C:\Program Files (x86)\Windows Live
2014-07-16 22:18:22 ----D---- C:\windows\Tasks
2014-07-16 21:27:57 ----D---- C:\windows\system32\catroot2
2014-07-16 20:54:45 ----RD---- C:\Program Files
2014-07-16 20:07:34 ----D---- C:\windows\winsxs
2014-07-16 19:59:23 ----D---- C:\windows\system32\catroot
2014-07-16 19:53:03 ----D---- C:\windows\rescache
2014-07-15 20:57:09 ----D---- C:\Program Files\Windows Sidebar
2014-07-15 20:57:09 ----D---- C:\Program Files\Windows Media Player
2014-07-15 20:57:09 ----D---- C:\Program Files\Windows Mail
2014-07-15 20:57:09 ----D---- C:\Program Files\Internet Explorer
2014-07-15 20:57:08 ----D---- C:\Program Files\Windows Photo Viewer
2014-07-15 20:57:08 ----D---- C:\Program Files\Windows Journal
2014-07-15 20:57:08 ----D---- C:\Program Files\Windows Defender
2014-07-15 20:57:08 ----D---- C:\Program Files\Common Files\System
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Windows Sidebar
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Windows Media Player
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Windows Mail
2014-07-15 20:57:08 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\winrm
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\slmgr
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\sk-SK
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\migwiz
2014-07-15 20:57:07 ----D---- C:\windows\SYSWOW64\en
2014-07-15 20:57:07 ----D---- C:\windows\servicing
2014-07-15 20:57:07 ----D---- C:\windows\ehome
2014-07-15 20:57:07 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2014-07-15 20:57:07 ----D---- C:\Program Files (x86)\Windows Defender
2014-07-15 20:57:03 ----D---- C:\windows\SYSWOW64\en-US
2014-07-15 20:57:03 ----D---- C:\windows\SYSWOW64\drivers\en-US
2014-07-15 20:57:03 ----D---- C:\windows\SYSWOW64\drivers
2014-07-15 20:57:00 ----D---- C:\windows\SYSWOW64\WCN
2014-07-15 20:57:00 ----D---- C:\windows\SYSWOW64\DriverStore
2014-07-15 20:57:00 ----D---- C:\windows\SYSWOW64\Dism
2014-07-15 20:56:56 ----D---- C:\windows\SYSWOW64\wbem
2014-07-15 20:56:56 ----D---- C:\windows\SYSWOW64\Printing_Admin_Scripts
2014-07-15 20:56:56 ----D---- C:\Windows
2014-07-15 20:56:55 ----D---- C:\windows\PolicyDefinitions
2014-07-15 20:56:55 ----D---- C:\windows\en-US
2014-07-15 20:56:54 ----D---- C:\windows\system32\winrm
2014-07-15 20:56:54 ----D---- C:\windows\system32\sysprep
2014-07-15 20:56:54 ----D---- C:\windows\system32\slmgr
2014-07-15 20:56:54 ----D---- C:\windows\system32\sk-SK
2014-07-15 20:56:54 ----D---- C:\windows\system32\oobe
2014-07-15 20:56:54 ----D---- C:\windows\system32\migwiz
2014-07-15 20:56:54 ----D---- C:\windows\system32\en
2014-07-15 20:56:54 ----D---- C:\windows\system32\Boot
2014-07-15 20:56:49 ----D---- C:\windows\system32\en-US
2014-07-15 20:56:42 ----D---- C:\windows\system32\WCN
2014-07-15 20:56:42 ----D---- C:\windows\system32\DriverStore
2014-07-15 20:56:42 ----D---- C:\windows\system32\drivers\en-US
2014-07-15 20:56:42 ----D---- C:\windows\system32\drivers
2014-07-15 20:56:42 ----D---- C:\windows\system32\Dism
2014-07-15 20:56:38 ----D---- C:\windows\system32\Printing_Admin_Scripts
2014-07-15 20:56:37 ----D---- C:\windows\system32\wbem
2014-07-15 20:56:17 ----D---- C:\Program Files\DVD Maker
2014-07-15 20:55:54 ----D---- C:\windows\Speech
2014-07-14 09:38:43 ----D---- C:\windows\system32\wdi
2014-07-13 14:09:04 ----D---- C:\windows\Logs
2014-07-13 13:59:03 ----D---- C:\windows\Prefetch
2014-07-11 21:45:28 ----D---- C:\windows\SysWOW64
2014-07-11 21:45:12 ----RSD---- C:\windows\assembly
2014-07-11 21:45:08 ----D---- C:\windows\Microsoft.NET
2014-07-11 21:43:14 ----D---- C:\windows\system32\LogFiles
2014-07-11 21:43:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-07-11 21:43:08 ----SHD---- C:\windows\Installer
2014-07-11 21:28:00 ----RD---- C:\Program Files (x86)
2014-07-09 21:06:56 ----SD---- C:\ProgramData\Microsoft
2014-07-08 20:54:14 ----D---- C:\windows\system32\NDF
2014-07-05 18:01:44 ----D---- C:\windows\debug
2014-07-05 16:55:29 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-07-05 16:55:29 ----D---- C:\windows\system32\cs-CZ
2014-07-05 16:48:19 ----D---- C:\windows\SoftwareDistribution
2014-07-05 16:37:21 ----D---- C:\Program Files (x86)\Common Files
2014-07-05 16:37:15 ----HD---- C:\ProgramData
2014-07-05 16:27:57 ----D---- C:\windows\system32\Tasks
2014-07-05 16:12:02 ----D---- C:\ProgramData\McAfee
2014-07-05 16:11:31 ----D---- C:\Program Files\Common Files
2014-07-05 16:06:04 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2009-08-24 16440]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2010-01-15 39008]
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 44120]
R1 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 62136]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2013-09-17 220232]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2009-10-19 28176]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 6402560]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 188928]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl664.sys [2010-02-02 3058168]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2010-04-27 2357024]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-01-07 302128]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11280]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-16 79376]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2010-03-12 242720]
S3 vm331avs;Digital Camera 1; C:\windows\System32\Drivers\vm331avs.sys [2009-11-09 207232]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 151656]
S3 wsvd;wsvd; C:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-03-03 202752]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2009-08-11 864032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-02-24 1343408]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2014-07-11 66872]
R2 PnkBstrB;PnkBstrB; C:\windows\syswow64\PnkBstrB.exe [2014-07-11 103736]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-05 116648]
S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-05 116648]
S3 IGRS;IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s virem

#6 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. PC by již mělo být čisté.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Momoum
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 12 kvě 2013 14:51

Re: Problém s virem

#7 Příspěvek od Momoum »

Děkuji a zase někdy Na shledanou :)

Problém byl už vyřešen, vše funguje normálně. Ještě jednou díky a můžete :closed: :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s virem

#8 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět