Podezření na vir: 3590F75ABA9E...(zzzzz..) Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod jerabina » 17 kvě 2015 21:36

Neboj se, v sekci BSOD tě provedou stejně jako tady :-)
Podíváme, co se v počítači změnilo:

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit Farbar Recovery Scan Tool (FRST)
32bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
64bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
a ulož jej na plochu. ,pak spusť FRST jako správce
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Reklama
PhR
Level 3
Level 3
Příspěvky: 448
Registrován: duben 12
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod PhR » 17 kvě 2015 21:42

FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-04-2015 01 (ATTENTION: ====> FRST version is 18 days old and could be outdated)
Ran by ASUS (administrator) on ASUS-PC on 17-05-2015 21:40:01
Running from C:\Users\ASUS\Desktop
Loaded Profiles: ASUS (Available profiles: ASUS)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Glarysoft Ltd) D:\Glary Utilities 5\SoftwareUpdate.exe
(Glarysoft Ltd) D:\Glary Utilities 5\x64\Win64ShellLink.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-11] (Avast Software s.r.o.)
HKU\S-1-5-21-233904950-2367353388-1579625358-1000\...\Run: [GUDelayStartup] => D:\Glary Utilities 5\StartupManager.exe [37152 2015-05-11] (Glarysoft Ltd)
HKU\S-1-5-21-233904950-2367353388-1579625358-1000\...\Run: [GoogleChromeAutoLaunch_D5DDF34FE692FC2EA1B8968615A3C02A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [812872 2015-05-05] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-07] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-01] (Avast Software s.r.o.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-01] (Avast Software s.r.o.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelogx64.dll [2015-04-23] (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll [2015-04-23] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-12]

Chrome:
=======
CHR Profile: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Steam inventory helper) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2015-05-16]
CHR Extension: (LoungeDestroyer) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghahcnmfjfckcedfajbhekgknjdplfcl [2015-05-16]
CHR Extension: (AdBlock) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-05-16]
CHR Extension: (No Name) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21]
CHR Extension: (Avast Online Security) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-16]
CHR Extension: (No Name) - C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-07] (Avast Software s.r.o.)
S4 celavimushost; C:\Program Files (x86)\CEVO\CSGO Client Beta\CelavimusClientHelper.exe [124632 2015-04-07] (altPUG LLC)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [1931632 2015-05-16] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-05-16] ()
S4 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-03-10] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.)
R2 RzSurroundVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [4250624 2015-02-03] (A-Volute) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-05-07] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-07] ()
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2015-05-16] (Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-04-30] (REALiX(tm))
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [129312 2015-04-30] (Intel Corporation)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-02-05] (NVIDIA Corporation)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-12-30] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-03-10] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2015-03-03] (Razer, Inc.)
R3 RZSURROUNDVADService; C:\Windows\System32\drivers\RzSurroundVAD.sys [40640 2015-02-09] (Windows (R) Win 7 DDK provider)
U3 AppMgmt; %SystemRoot%\system32\svchost.exe -k netsvcs
U2 CscService; No ImagePath
U3 PeerDistSvc; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-17 21:40 - 2015-05-17 21:40 - 00010203 _____ () C:\Users\ASUS\Desktop\FRST.txt
2015-05-17 21:39 - 2015-05-17 21:40 - 00000000 ____D () C:\FRST
2015-05-17 21:02 - 2015-05-17 21:02 - 572552352 _____ () C:\Windows\MEMORY.DMP
2015-05-17 21:02 - 2015-05-17 21:02 - 00266320 _____ () C:\Windows\Minidump\051715-21528-01.dmp
2015-05-17 11:06 - 2015-05-17 11:06 - 00000748 _____ () C:\Windows\PFRO.log
2015-05-17 01:00 - 2015-05-17 21:02 - 00000112 _____ () C:\Windows\setupact.log
2015-05-17 01:00 - 2015-05-17 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-16 17:51 - 2015-05-16 17:51 - 00001724 _____ () C:\Users\Public\Desktop\Defraggler.lnk
2015-05-16 17:51 - 2015-05-16 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2015-05-16 17:51 - 2015-05-16 17:51 - 00000000 ____D () C:\Program Files\Defraggler
2015-05-16 17:48 - 2015-05-16 17:49 - 04532776 _____ (Piriform Ltd) C:\Users\ASUS\Downloads\dfsetup219.exe
2015-05-16 17:43 - 2015-05-16 17:44 - 00001486 _____ () C:\DelFix.txt
2015-05-16 17:33 - 2015-05-16 17:33 - 00000000 ____D () C:\ProgramData\GlarySoft
2015-05-16 17:30 - 2015-05-16 17:30 - 00020160 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys
2015-05-16 17:30 - 2015-05-16 17:30 - 00003264 _____ () C:\Windows\System32\Tasks\GlaryInitialize 5
2015-05-16 17:30 - 2015-05-16 17:30 - 00002928 _____ () C:\Windows\System32\Tasks\GU5SkipUAC
2015-05-16 17:30 - 2015-05-16 17:30 - 00000595 _____ () C:\Users\Public\Desktop\Glary Utilities 5.lnk
2015-05-16 17:30 - 2015-05-16 17:30 - 00000595 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\GlarySoft
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\DiskDefrag
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2015-05-16 17:29 - 2015-05-16 17:29 - 15086472 _____ () C:\Users\ASUS\Downloads\gu5setup.exe
2015-05-16 13:45 - 2015-05-16 13:45 - 00000000 ____D () C:\Users\ASUS\AppData\Local\4A Games
2015-05-16 13:30 - 2015-05-16 13:30 - 00013177 _____ () C:\Users\ASUS\Desktop\Ovládací panel NVIDIA – zástupce.lnk
2015-05-16 10:56 - 2015-05-16 10:56 - 00000000 ____D () C:\Users\ASUS\AppData\Local\ESN
2015-05-16 10:50 - 2015-05-16 10:50 - 01640200 _____ () C:\Users\ASUS\Downloads\battlelog-web-plugins_2.7.0_160_R2 (1).exe
2015-05-16 10:33 - 2015-05-16 16:37 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2015-05-16 10:27 - 2015-05-16 10:57 - 00000000 ____D () C:\Users\ASUS\Documents\Battlefield 3
2015-05-16 10:27 - 2015-05-16 10:27 - 01640200 _____ () C:\Users\ASUS\Downloads\battlelog-web-plugins_2.7.0_160_R2.exe
2015-05-16 03:20 - 2015-05-16 03:20 - 00000849 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2015-05-16 03:20 - 2015-05-16 03:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2015-05-16 02:14 - 2015-05-16 02:14 - 00000000 __SHD () C:\Users\ASUS\AppData\Local\EmieUserList
2015-05-16 02:14 - 2015-05-16 02:14 - 00000000 __SHD () C:\Users\ASUS\AppData\Local\EmieSiteList
2015-05-16 02:14 - 2015-05-16 02:14 - 00000000 __SHD () C:\Users\ASUS\AppData\Local\EmieBrowserModeList
2015-05-16 02:10 - 2015-05-16 10:38 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\Origin
2015-05-16 02:10 - 2015-05-16 10:27 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Origin
2015-05-16 02:09 - 2015-05-17 18:51 - 00000000 ____D () C:\ProgramData\Origin
2015-05-16 02:09 - 2015-05-16 02:09 - 00000524 _____ () C:\Users\Public\Desktop\Origin.lnk
2015-05-16 02:09 - 2015-05-16 02:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-05-16 02:08 - 2015-05-16 02:09 - 17110336 _____ (Electronic Arts, Inc.) C:\Users\ASUS\Downloads\OriginThinSetup.exe
2015-05-16 01:42 - 2015-05-16 01:42 - 00000221 _____ () C:\Users\ASUS\Desktop\Call of Duty Modern Warfare 3.url
2015-05-15 23:30 - 2015-05-16 17:53 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\IObit
2015-05-15 23:30 - 2015-05-16 17:50 - 00000000 ____D () C:\ProgramData\IObit
2015-05-15 23:03 - 2015-05-15 23:03 - 30993712 _____ (Riot Games) C:\Users\ASUS\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014 (1).exe
2015-05-14 18:33 - 2015-05-14 18:33 - 00007047 _____ () C:\Users\ASUS\Downloads\MW2---MW3-Config-von-Nesko.rar
2015-05-14 15:46 - 2015-05-14 15:46 - 00000221 _____ () C:\Users\ASUS\Desktop\Call of Duty Modern Warfare 3 - Multiplayer.url
2015-05-12 18:31 - 2015-05-12 18:31 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2015-05-12 18:31 - 2015-05-12 18:31 - 00000000 ____D () C:\Program Files\Realtek
2015-05-12 18:29 - 2015-05-12 18:29 - 72113152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2015-05-12 18:29 - 2015-05-12 18:29 - 12975360 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 12834736 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 05804772 _____ () C:\Windows\system32\Drivers\rtvienna.dat
2015-05-12 18:29 - 2015-05-12 18:29 - 05615552 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 05234952 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 04664792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2015-05-12 18:29 - 2015-05-12 18:29 - 03218800 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 02907864 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 02846936 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 02702040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2015-05-12 18:29 - 2015-05-12 18:29 - 02530520 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 02421480 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 02162992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 02101848 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 01990874 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-05-12 18:29 - 2015-05-12 18:29 - 01736408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 01413776 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 01313904 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 01303256 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 01104040 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00995120 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00979280 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00947760 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00943784 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00906800 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00871856 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00856992 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00837776 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00734376 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00662784 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00654480 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00631000 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00582056 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00544400 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.DLL
2015-05-12 18:29 - 2015-05-12 18:29 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00454288 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00435344 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00369296 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00329360 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00329360 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00250536 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00213432 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaemaxapo64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00168816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00162224 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2015-05-12 18:29 - 2015-05-12 18:29 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2015-05-12 18:28 - 2015-05-12 18:29 - 14048512 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 07087448 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 06242576 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 03182104 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 02789808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 02041432 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01939800 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01933584 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01559744 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01499984 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01360640 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 01136728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00922880 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00663296 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00560328 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00501184 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00487360 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00415680 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00336144 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00315736 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00306288 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00284944 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00261464 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00109848 _____ () C:\Windows\system32\AcpiServiceVnA64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2015-05-12 18:28 - 2015-05-12 18:28 - 00096568 _____ () C:\Windows\system32\audioLibVc.dll
2015-05-12 18:24 - 2015-05-16 17:50 - 00000000 ____D () C:\Program Files (x86)\IObit
2015-05-12 18:24 - 2015-05-15 20:18 - 00000713 _____ () C:\Users\Public\Desktop\Driver Booster 2.lnk
2015-05-12 18:22 - 2015-05-12 18:23 - 11247792 _____ (IObit ) C:\Users\ASUS\Downloads\driver_booster_setup (1).exe
2015-05-12 18:22 - 2015-05-12 18:22 - 07412008 _____ (IObit ) C:\Users\ASUS\Downloads\smart-defrag-setup (1).exe
2015-05-10 11:45 - 2015-05-10 11:45 - 00000000 ____D () C:\Users\ASUS\Documents\4A Games
2015-05-09 23:16 - 2015-05-09 23:16 - 00000221 _____ () C:\Users\ASUS\Desktop\Metro 2033.url
2015-05-07 21:01 - 2015-05-07 21:01 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-05-07 21:01 - 2015-05-07 21:01 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-05-06 19:08 - 2015-05-06 19:09 - 02933962 _____ () C:\Users\ASUS\Downloads\THOMAYEROVÁ_VY_32_INOVACE_12_01_20 (1).pptx
2015-05-01 02:39 - 2015-05-01 02:39 - 00002125 _____ () C:\Users\Public\Desktop\Razer Game Booster.lnk
2015-04-30 12:27 - 2015-04-30 12:27 - 01795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2015-04-30 12:27 - 2015-04-30 12:27 - 00129312 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
2015-04-30 12:27 - 2015-04-30 12:27 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2015-04-30 12:26 - 2015-04-30 12:26 - 00977624 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2015-04-30 12:26 - 2015-04-30 12:26 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2015-04-30 11:59 - 2015-04-30 11:59 - 22768704 _____ (Razer Inc. ) C:\Users\ASUS\Downloads\RazerCortexSetup_5.4.15.0 (1).exe
2015-04-30 11:56 - 2015-04-30 11:57 - 41954352 _____ (Razer Inc. ) C:\Users\ASUS\Downloads\RazerGameBoosterSetup_4.2.45.0.exe
2015-04-30 11:42 - 2015-05-16 17:32 - 00003178 _____ () C:\Windows\System32\Tasks\Driver Booster Scan
2015-04-30 11:42 - 2015-05-16 17:32 - 00003122 _____ () C:\Windows\System32\Tasks\Driver Booster Update
2015-04-30 11:42 - 2015-05-16 17:32 - 00002820 _____ () C:\Windows\System32\Tasks\Driver Booster SkipUAC (ASUS)
2015-04-30 11:42 - 2015-05-12 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
2015-04-30 11:42 - 2015-04-30 11:42 - 00026528 _____ (REALiX(tm)) C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS
2015-04-30 11:41 - 2015-01-10 15:32 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
2015-04-30 11:41 - 2014-06-04 15:17 - 00034080 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2015-04-30 11:40 - 2015-04-30 11:41 - 06112584 _____ (IObit ) C:\Users\ASUS\Downloads\game-assistant2-beta.exe
2015-04-30 11:40 - 2015-04-30 11:40 - 07428536 _____ (IObit ) C:\Users\ASUS\Downloads\smart-defrag-setup.exe
2015-04-30 11:39 - 2015-04-30 11:40 - 11247792 _____ (IObit ) C:\Users\ASUS\Downloads\driver_booster_setup.exe
2015-04-30 11:19 - 2015-04-30 11:20 - 02101248 _____ (Farbar) C:\Users\ASUS\Desktop\FRST64.exe
2015-04-30 11:16 - 2015-05-15 23:53 - 00000000 ____D () C:\Users\ASUS\Downloads\backups
2015-04-30 10:06 - 2015-04-30 10:08 - 00000000 ____D () C:\Users\ASUS\Documents\Heroes of the Storm
2015-04-30 10:05 - 2015-04-30 10:05 - 00000682 _____ () C:\Users\Public\Desktop\Heroes of the Storm.lnk
2015-04-30 10:05 - 2015-04-30 10:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
2015-04-22 21:55 - 2015-04-22 21:55 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2015-04-22 21:50 - 2015-04-22 21:51 - 00638976 _____ () C:\Users\ASUS\Downloads\Detection.msi
2015-04-21 17:25 - 2015-05-10 19:17 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\TS3Client
2015-04-21 17:24 - 2015-04-21 17:24 - 28115400 _____ (TeamSpeak Systems GmbH) C:\Users\ASUS\Downloads\TeamSpeak3-Client-win32-3.0.16.exe
2015-04-21 17:24 - 2015-04-21 17:24 - 00001162 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-04-21 17:24 - 2015-04-21 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-04-21 17:24 - 2015-04-21 17:24 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2015-04-18 10:50 - 2015-04-18 10:50 - 00011374 _____ () C:\Users\ASUS\Documents\cc_20150418_104959.reg
2015-04-17 19:43 - 2015-04-08 22:32 - 00560968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-04-17 19:39 - 2015-04-09 02:58 - 31570064 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 30397072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 25375048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 24053576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 17176128 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 15818528 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 15716232 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 14006752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 12852784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 11380728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 10423952 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-04-17 19:39 - 2015-04-09 02:58 - 02896528 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 02573456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 01086424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 00927440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-04-17 19:39 - 2015-04-09 02:58 - 00175880 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-04-17 19:39 - 2015-04-09 02:58 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-04-17 18:42 - 2012-08-22 15:46 - 01763688 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco64.dll
2015-04-17 18:42 - 2012-08-22 15:46 - 01482600 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco64.dll
2015-04-17 18:31 - 2015-04-17 18:33 - 183340160 _____ (NVIDIA Corporation) C:\Users\ASUS\Downloads\306.02-desktop-win8-win7-winvista-64bit-english-beta.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-17 21:16 - 2015-03-13 18:27 - 01752217 _____ () C:\Windows\WindowsUpdate.log
2015-05-17 21:11 - 2009-07-14 06:45 - 00014240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-17 21:11 - 2009-07-14 06:45 - 00014240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-17 21:10 - 2015-03-11 19:50 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-17 21:02 - 2015-03-12 17:57 - 00000000 ____D () C:\Windows\Minidump
2015-05-17 21:02 - 2015-03-09 18:21 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-17 21:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-17 21:00 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-05-17 19:59 - 2015-03-11 22:36 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Battle.net
2015-05-17 18:06 - 2015-03-12 08:23 - 00348672 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-05-17 18:06 - 2015-03-12 00:00 - 00348672 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-05-17 18:06 - 2015-03-12 00:00 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-05-17 17:32 - 2015-03-14 02:06 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2015-05-17 17:31 - 2015-03-11 22:36 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-05-17 11:06 - 2015-03-12 22:21 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-05-16 16:44 - 2015-03-09 17:57 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-16 13:38 - 2015-04-02 13:22 - 00000000 ____D () C:\Users\ASUS\AppData\Local\CrashDumps
2015-05-16 12:44 - 2015-03-11 20:15 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2015-05-16 10:58 - 2015-03-12 00:00 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-05-16 03:19 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-16 02:21 - 2015-03-14 19:12 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-16 01:42 - 2015-03-11 19:52 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-05-15 23:48 - 2015-03-27 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2015-05-15 23:27 - 2015-03-14 15:32 - 00000000 ___RD () C:\Users\ASUS\Desktop\Plocha
2015-05-15 18:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-11 20:07 - 2015-03-09 17:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-11 20:07 - 2015-03-09 17:45 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-05-11 14:09 - 2015-04-05 00:09 - 00000000 ____D () C:\ProgramData\ProductData
2015-05-07 21:01 - 2015-03-12 22:21 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-05-07 21:01 - 2015-03-12 22:21 - 00272248 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-05-07 21:01 - 2015-03-12 22:21 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-05-07 21:01 - 2015-03-12 22:21 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-05-07 21:01 - 2015-03-12 22:21 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-05-07 21:01 - 2015-03-12 22:21 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-05-07 21:01 - 2015-03-12 22:21 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-05-07 21:00 - 2015-03-12 22:21 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-05-04 17:03 - 2009-07-14 07:08 - 00032564 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-01 02:40 - 2015-04-02 01:18 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Razer_Inc
2015-05-01 02:40 - 2015-03-20 20:09 - 00000000 ____D () C:\Users\ASUS\AppData\Local\Razer
2015-05-01 02:39 - 2015-03-20 20:08 - 00000000 ____D () C:\ProgramData\Razer
2015-05-01 02:39 - 2015-03-20 20:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-05-01 02:39 - 2015-03-20 20:08 - 00000000 ____D () C:\Program Files (x86)\Razer
2015-04-30 12:26 - 2015-03-09 17:45 - 00107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2015-04-30 12:13 - 2015-03-09 16:49 - 00000000 ____D () C:\Windows\Panther
2015-04-30 11:23 - 2015-03-09 17:55 - 00003956 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-04-30 11:23 - 2015-03-09 17:55 - 00003704 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-04-30 11:18 - 2015-03-14 17:05 - 00000000 ____D () C:\Windows\pss
2015-04-30 10:06 - 2015-03-11 22:36 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-04-30 08:35 - 2015-03-15 17:16 - 00000000 ____D () C:\Users\ASUS\AppData\Roaming\Skype
2015-04-28 06:44 - 2009-07-14 17:18 - 00759432 _____ () C:\Windows\system32\perfh005.dat
2015-04-28 06:44 - 2009-07-14 17:18 - 00195712 _____ () C:\Windows\system32\perfc005.dat
2015-04-28 06:44 - 2009-07-14 07:13 - 01731420 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-17 20:14 - 2015-04-16 18:40 - 00000000 ____D () C:\Users\ASUS\AppData\Local\NVIDIA Corporation
2015-04-17 20:14 - 2015-03-25 14:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-04-17 20:14 - 2015-03-09 18:20 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-04-17 20:14 - 2015-03-09 18:20 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-04-17 20:14 - 2015-03-09 18:15 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-17 14:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-15 14:25

==================== End Of Log ============================
GeForce GT 630 2GB
I5-3550 3,30GHz
4GB RAM
W7 HP

PhR
Level 3
Level 3
Příspěvky: 448
Registrován: duben 12
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod PhR » 17 kvě 2015 21:43

Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-04-2015 01
Ran by ASUS at 2015-05-17 21:40:46
Running from C:\Users\ASUS\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-233904950-2367353388-1579625358-500 - Administrator - Disabled)
ASUS (S-1-5-21-233904950-2367353388-1579625358-1000 - Administrator - Enabled) => C:\Users\ASUS
Guest (S-1-5-21-233904950-2367353388-1579625358-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.7.0 - EA Digital Illusions CE AB)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward)
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
CEVO CS:GO Client Beta version 1.0 (HKLM-x32\...\CEVO CS:GO Client Beta_is1) (Version: 1.0 - )
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform)
Driver Booster 2.3 (HKLM-x32\...\Driver Booster_is1) (Version: 2.3 - IObit)
Glary Utilities 5.25 (HKLM-x32\...\Glary Utilities 5) (Version: 5.25.0.44 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel® Chipset Device Software (x32 Version: 10.0.24 - Intel(R) Corporation) Hidden
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.2.6.1 - IObit)
Logitech Gaming Software 8.58 (HKLM\...\Logitech Gaming Software) (Version: 8.58.177 - Logitech Inc.)
Malwarebytes Anti-Malware verze 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 CSY Language Pack (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MSI Afterburner 4.1.0 (HKLM-x32\...\Afterburner) (Version: 4.1.0 - MSI Co., LTD)
NVIDIA Ovladač 3D Vision 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 350.12 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 349.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 349.95 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0324 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0324 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.12.2862 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{c38b75ca-6796-40ee-a6df-a8d19c128d94}) (Version: latest - ppy Pty Ltd)
Ovládací panel NVIDIA 350.12 (Version: 350.12 - NVIDIA Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.2.45.0 - Razer Inc.)
Razer Surround (HKLM-x32\...\Razer Surround) (Version: 1.05.14 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.24735 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.91.1119.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7487 - Realtek Semiconductor Corp.)
Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
System Requirements Lab Detection (HKLM-x32\...\{BD3AE453-BBFB-47C0-8999-7D1CB0188BA5}) (Version: 6.1.4.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points =========================

16-05-2015 17:43:52 End of disinfection

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-04-04 18:21 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0DEEDB81-FAD0-430B-B2BB-7CD84A722667} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {1171B713-7E5D-4F9E-9A38-7E91D228C29D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-09] (Google Inc.)
Task: {20C1CEAF-4C4A-4B9C-BA46-9C49206D5D93} - System32\Tasks\Driver Booster Update => D:\Driver Booster\AutoUpdate.exe [2015-04-28] (IObit)
Task: {249E1741-6B6D-4637-8FBD-523476EF97A6} - System32\Tasks\Driver Booster Scan => D:\Driver Booster\Scheduler.exe [2015-04-07] (IObit)
Task: {24F9EF00-2796-4B5A-B3FD-732124EC3480} - System32\Tasks\Driver Booster SkipUAC (ASUS) => D:\Driver Booster\DriverBooster.exe [2015-04-28] (IObit)
Task: {4CF5D3BD-0715-44BB-9346-1380E430CB9E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-05-07] (Avast Software s.r.o.)
Task: {4E8E3DF4-F1D4-4529-9AC3-C7D1B4C64C2E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {6B29E9BC-1D32-4BDE-8C28-91909A5D12CD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-09] (Google Inc.)
Task: {A4254A9A-4D1E-4AF2-8A7C-CD9F3DA4403F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {A898B72F-2DDC-44E9-AB95-80A07EB21798} - System32\Tasks\GlaryInitialize 5 => D:\Glary Utilities 5\Initialize.exe [2015-05-11] (Glarysoft Ltd)
Task: {BB44A540-60B5-49A9-9FCC-E147F663147C} - System32\Tasks\GU5SkipUAC => D:\Glary Utilities 5\Integrator.exe [2015-05-11] (Glarysoft Ltd)
Task: {EF9EAA70-9A78-4D22-BB11-9C8EC9FDE45E} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {F7C125CC-4D99-4EBB-AF12-F4C11393C93E} - \Uninstaller_SkipUac_ASUS No Task File <==== ATTENTION

==================== Loaded Modules (whitelisted) ==============

2015-03-09 18:20 - 2015-04-08 23:30 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-03-12 00:00 - 2015-05-16 10:58 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-05-07 21:01 - 2015-05-07 21:01 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-05-07 21:00 - 2015-05-07 21:00 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-05-17 19:09 - 2015-05-17 19:09 - 02929664 _____ () C:\Program Files\AVAST Software\Avast\defs\15051701\algo.dll
2015-03-12 22:21 - 2015-03-12 22:21 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-03-09 18:14 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-03-11 19:50 - 2015-04-16 19:40 - 00776192 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-03-11 19:50 - 2015-04-23 04:16 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-03-11 19:50 - 2015-04-23 04:16 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-03-11 19:50 - 2015-04-23 04:16 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2015-03-11 19:50 - 2015-05-15 03:58 - 02396352 _____ () C:\Program Files (x86)\Steam\video.dll
2015-03-11 19:50 - 2014-12-01 23:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2015-03-11 19:50 - 2014-12-01 23:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2015-03-11 19:50 - 2014-12-01 23:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2015-03-11 19:50 - 2014-12-01 23:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2015-03-11 19:50 - 2014-12-01 23:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2015-03-11 19:50 - 2015-05-15 03:57 - 00703168 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-03-11 19:50 - 2015-05-11 21:01 - 36302728 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2015-05-14 07:13 - 2015-05-11 21:01 - 08958344 _____ () C:\Program Files (x86)\Steam\bin\pdf.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Users\ASUS\Downloads\ccsetup503.exe:$CmdTcID
AlternateDataStreams: C:\Users\ASUS\Downloads\ccsetup503.exe:$CmdZnID

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-233904950-2367353388-1579625358-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: celavimushost => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: LiveUpdateSvc => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: Razer Game Scanner Service => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: GoogleChromeAutoLaunch_D5DDF34FE692FC2EA1B8968615A3C02A => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: Launch LCore => C:\Program Files\Logitech Gaming Software\LCore.exe /minimized

==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [{0442FAC1-E956-4812-8769-DFFEAF3458F7}] => (Allow) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
FirewallRules: [{0512ABC4-DEE9-447E-A45C-7F317F9DBA87}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{4E0564D0-314C-42F8-9C42-B5198C82F8D9}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{4FCA019C-5407-4285-A69E-16A7DBC5CD66}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{583385A7-C0DB-4CDF-AB65-935E3F83490E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{2436C7B4-10A8-49F9-85C0-6BBF4016A0D5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{8254662A-4091-45E8-93F9-4079CEBCC14C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{593242CB-D0CF-4C5F-A502-3D806BB1C33C}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{B91D9DD8-BEA4-4BE6-920B-C9DE5651F070}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [TCP Query User{E463B666-EAAA-4EBF-A144-F8506AC1A3EC}D:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) D:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [UDP Query User{63963D4B-5F7E-4941-BFCD-73D0C0438EFD}D:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe] => (Allow) D:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe
FirewallRules: [{62B23D2C-872B-47F7-955E-0AC2CCDA5848}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{A353B882-535D-4EF1-8F79-4ADAA186C554}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{74240C58-55D6-41B3-ABD7-067A2D5259CC}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{4A8F9B70-29B3-43A5-90D6-A474C81F7DAF}C:\games\counter-strike\hl.exe] => (Allow) C:\games\counter-strike\hl.exe
FirewallRules: [UDP Query User{18176B39-B9D0-4F02-8132-B27E39B9B647}C:\games\counter-strike\hl.exe] => (Allow) C:\games\counter-strike\hl.exe
FirewallRules: [{70EAA59D-F8FA-4911-8300-ABF9304929D9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTE.EXE
FirewallRules: [{68B53BB5-6B51-4C38-90D5-03786B7087B2}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTE.EXE
FirewallRules: [TCP Query User{7042BD8D-C7C5-46E0-BCD0-EB5C31EB5CB2}D:\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) D:\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{67CB1594-ACD9-44D0-84F5-9957D9662EDB}D:\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) D:\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe
FirewallRules: [{896B3392-0C97-4EE4-81FF-3B8EC2DAFA90}] => (Allow) D:\SteamLibrary\steamapps\common\Metro 2033\metro2033.exe
FirewallRules: [{AD2D18DC-3DF2-40F7-85B6-4B390304A9E7}] => (Allow) D:\SteamLibrary\steamapps\common\Metro 2033\metro2033.exe
FirewallRules: [{3EB32A62-C678-491F-B234-9CB3206B97CE}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{D62A0558-F470-443A-8331-4A382A7E6B9D}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{A2D713A1-63FF-441D-B2BC-C75BE19BBA5A}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
FirewallRules: [{5F5550A6-F97C-4D88-B383-B0BF2D178C42}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
FirewallRules: [{6B568B33-26CC-49B8-BC84-ACF249F0642E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{37DA825A-44EE-46D0-9056-C2EE9C588647}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{C8557E79-E851-4C02-A1C5-6B2A167F1920}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B7D4C072-DBF5-4138-9C68-DFDD1155DEB5}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{2E8AD0BB-BA85-42B7-BA33-009C813EF50D}] => (Allow) D:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{0D2243D3-F3BD-44CC-998D-C3EEE3FC87DD}] => (Allow) D:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{A7DEE1B0-3B60-40C0-83E6-0E3208F88D3C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{7F2B462C-01E5-4F76-9D01-457CBE5D0485}D:\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe] => (Allow) D:\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{59C65B1B-1B0D-409D-A967-8E41663F663F}D:\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe] => (Allow) D:\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/17/2015 06:48:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program rads_user_kernel.exe verze 0.0.0.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 48c08

Čas spuštění: 01d090c144bf9f67

Čas ukončení: 55

Cesta k aplikaci: D:\RADS\system\rads_user_kernel.exe

ID hlášení: 8d9041d4-fcb4-11e4-802b-60a44c5075e6

Error: (05/17/2015 06:04:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program main.exe verze 4.2.45.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 39ec4

Čas spuštění: 01d090ba3d145641

Čas ukončení: 105

Cesta k aplikaci: C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

ID hlášení:

Error: (05/17/2015 11:38:36 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program bf3.exe verze 1.6.0.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 904

Čas spuštění: 01d09084a44ab49a

Čas ukončení: 391

Cesta k aplikaci: D:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe

ID hlášení:

Error: (05/16/2015 01:38:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Název chybujícího modulu: d3d11.dll, verze: 6.2.9200.16570, časové razítko: 0x5153774d
Kód výjimky: 0xc0000005
Posun chyby: 0x0008ee8b
ID chybujícího procesu: 0x1dd8
Čas spuštění chybující aplikace: 0xbf3.exe0
Cesta k chybující aplikaci: bf3.exe1
Cesta k chybujícímu modulu: bf3.exe2
ID zprávy: bf3.exe3

Error: (05/16/2015 01:30:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: nvcplui.exe, verze: 8.1.770.0, časové razítko: 0x55259889
Název chybujícího modulu: nvcplui.exe, verze: 8.1.770.0, časové razítko: 0x55259889
Kód výjimky: 0x40000015
Posun chyby: 0x00000000001c9259
ID chybujícího procesu: 0x1e94
Čas spuštění chybující aplikace: 0xnvcplui.exe0
Cesta k chybující aplikaci: nvcplui.exe1
Cesta k chybujícímu modulu: nvcplui.exe2
ID zprávy: nvcplui.exe3

Error: (05/16/2015 00:43:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program main.exe verze 4.2.45.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 1bf0

Čas spuštění: 01d08fc50079ebfc

Čas ukončení: 122

Cesta k aplikaci: C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

ID hlášení: 55702b91-fbb8-11e4-8d92-60a44c5075e6

Error: (05/16/2015 00:42:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: main.exe, verze: 4.2.45.0, časové razítko: 0x5316ea5b
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.18798, časové razítko: 0x5507b485
Kód výjimky: 0xe0434352
Posun chyby: 0x0000c42d
ID chybujícího procesu: 0x1984
Čas spuštění chybující aplikace: 0xmain.exe0
Cesta k chybující aplikaci: main.exe1
Cesta k chybujícímu modulu: main.exe2
ID zprávy: main.exe3

Error: (05/16/2015 00:42:52 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: main.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: Microsoft.VisualBasic.ApplicationServices.CantStartSingleInstanceException
Zásobník:
na Microsoft.VisualBasic.ApplicationServices.WindowsFormsApplicationBase.Run(System.String[])
na Razer.Kel.GUI.Startup.Main(System.String[])

Error: (05/16/2015 11:15:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Název chybujícího modulu: d3d11.dll, verze: 6.2.9200.16570, časové razítko: 0x5153774d
Kód výjimky: 0xc0000005
Posun chyby: 0x000a6583
ID chybujícího procesu: 0x1690
Čas spuštění chybující aplikace: 0xbf3.exe0
Cesta k chybující aplikaci: bf3.exe1
Cesta k chybujícímu modulu: bf3.exe2
ID zprávy: bf3.exe3

Error: (05/16/2015 11:10:22 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko: 0x511c9356
Název chybujícího modulu: d3d11.dll, verze: 6.2.9200.16570, časové razítko: 0x5153774d
Kód výjimky: 0xc0000005
Posun chyby: 0x0008ee8b
ID chybujícího procesu: 0xc34
Čas spuštění chybující aplikace: 0xbf3.exe0
Cesta k chybující aplikaci: bf3.exe1
Cesta k chybujícímu modulu: bf3.exe2
ID zprávy: bf3.exe3


System errors:
=============
Error: (05/17/2015 09:03:40 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: WMPNetworkSvc0x80004005

Error: (05/17/2015 09:03:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
cdrom

Error: (05/17/2015 09:02:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba LiveUpdate neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (05/17/2015 09:02:42 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x000000d1 (0x000000000058012a, 0x000000000000000e, 0x0000000000000000, 0xfffff88004a67a47)C:\Windows\MEMORY.DMP051715-21528-01

Error: (05/17/2015 09:02:39 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (20:59:59, ‎17.‎5.‎2015) bylo neočekávané.

Error: (05/17/2015 03:08:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba SSDP Discovery neuspěla při spuštění v důsledku následující chyby:
%%1053

Error: (05/17/2015 03:08:05 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby SSDPSRV bylo dosaženo časového limitu (30000 ms).

Error: (05/17/2015 03:08:05 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: WMPNetworkSvc0x80004005

Error: (05/17/2015 03:07:35 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby upnphost bylo dosaženo časového limitu (30000 ms).

Error: (05/17/2015 03:07:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba SSDP Discovery neuspěla při spuštění v důsledku následující chyby:
%%1053


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3550 CPU @ 3.30GHz
Percentage of memory in use: 25%
Total physical RAM: 4032.14 MB
Available physical RAM: 2995 MB
Total Pagefile: 8062.48 MB
Available Pagefile: 6659.93 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:97.6 GB) (Free:57.2 GB) NTFS
Drive d: () (Fixed) (Total:368.07 GB) (Free:304.24 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 66689C17)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=97.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=368.1 GB) - (Type=07 NTFS)

==================== End Of Log ============================
GeForce GT 630 2GB
I5-3550 3,30GHz
4GB RAM
W7 HP

mople71
Level 3.5
Level 3.5
Příspěvky: 662
Registrován: listopad 14
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod mople71 » 17 kvě 2015 21:58

Ty tam máš CCleaner, Glary Utilities a IObit... a divíš se, že se to seká... Aha. :D

PhR
Level 3
Level 3
Příspěvky: 448
Registrován: duben 12
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod PhR » 17 kvě 2015 22:02

CCleaner - nevím co je na něm špatně :S
IObit - jen driver booster
Glary Utilities - to stejné co ccleaner

Navíc nic z toho nemívám spuštěné na pozadí nebo tak.

E: Ale Glary Utilities stejně dávám pryč, možná to zapřičinuje ten bsod
GeForce GT 630 2GB
I5-3550 3,30GHz
4GB RAM
W7 HP

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod jerabina » 17 kvě 2015 22:05

Odinstaluj prosím vše od IObitu(driver booster je přesně to, co likviduje systém) a Glary Utilities(absolutně nemá smysl, akorát víc zanáší počítač). CCleaner si klidně ponechej, nahradí oba zmíněné.
Tyto programy ani nemusíš mít spuštěné na pozadí, stačí, když je použiješ jednou za čas, aby to nebylo OK ..
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

mople71
Level 3.5
Level 3.5
Příspěvky: 662
Registrován: listopad 14
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod mople71 » 17 kvě 2015 22:06

Oddělej je všechny a OS reinstaluj, má v sobě fatální chyby. A už nikdy tyhle "tweakery" neinstaluj. ;)

PhR
Level 3
Level 3
Příspěvky: 448
Registrován: duben 12
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod PhR » 17 kvě 2015 22:06

Obojí pryč, ccleaner si můžu nechat když nebudu čistit registry doufám?
GeForce GT 630 2GB
I5-3550 3,30GHz
4GB RAM
W7 HP

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod jerabina » 17 kvě 2015 22:07

Ano, samozřejmě. Za chvíli zde postnu fixlist pro FRST.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod jerabina » 17 kvě 2015 22:30

Vypni trvale Windows Defender.

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:

HKU\S-1-5-21-233904950-2367353388-1579625358-1000\...\Run: [GUDelayStartup] => D:\Glary Utilities 5\StartupManager.exe [37152 2015-05-11] (Glarysoft Ltd)
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 7

S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2015-05-16] (Glarysoft Ltd)

U2 CscService; No ImagePath
U3 PeerDistSvc; No ImagePath

C:\Program Files (x86)\IObit\LiveUpdate\
C:\ProgramData\GlarySoft
C:\Windows\System32\Tasks\GlaryInitialize 5
C:\Windows\System32\Tasks\GU5SkipUAC
C:\Users\Public\Desktop\Glary Utilities 5.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
C:\Users\ASUS\AppData\Roaming\GlarySoft
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
C:\Users\ASUS\Downloads\gu5setup.exe
C:\ProgramData\IObit
C:\Users\ASUS\AppData\Roaming\IObit
C:\Windows\system32\IObitSmartDefragExtension.dll
C:\Windows\system32\SmartDefragBootTime.exe
C:\Users\ASUS\Downloads\game-assistant2-beta.exe
C:\Users\ASUS\Downloads\smart-defrag-setup.exe
C:\Users\ASUS\Downloads\driver_booster_setup.exe
C:\Windows\System32\Tasks\Driver Booster SkipUAC
C:\Windows\System32\Tasks\Driver Booster Update
C:\Windows\System32\Tasks\Driver Booster Scan
C:\Users\ASUS\Downloads\RazerGameBoosterSetup_4.2.45.0.exe
C:\Users\ASUS\Downloads\RazerCortexSetup_5.4.15.0 (1).exe

C:\Windows\Tasks\*.job
Task: {1171B713-7E5D-4F9E-9A38-7E91D228C29D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-09] (Google Inc.)
Task: {20C1CEAF-4C4A-4B9C-BA46-9C49206D5D93} - System32\Tasks\Driver Booster Update => D:\Driver Booster\AutoUpdate.exe [2015-04-28] (IObit)
Task: {249E1741-6B6D-4637-8FBD-523476EF97A6} - System32\Tasks\Driver Booster Scan => D:\Driver Booster\Scheduler.exe [2015-04-07] (IObit)
Task: {24F9EF00-2796-4B5A-B3FD-732124EC3480} - System32\Tasks\Driver Booster SkipUAC (ASUS) => D:\Driver Booster\DriverBooster.exe [2015-04-28] (IObit)
Task: {6B29E9BC-1D32-4BDE-8C28-91909A5D12CD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-09] (Google Inc.)
Task: {A898B72F-2DDC-44E9-AB95-80A07EB21798} - System32\Tasks\GlaryInitialize 5 => D:\Glary Utilities 5\Initialize.exe [2015-05-11] (Glarysoft Ltd)
Task: {BB44A540-60B5-49A9-9FCC-E147F663147C} - System32\Tasks\GU5SkipUAC => D:\Glary Utilities 5\Integrator.exe [2015-05-11] (Glarysoft Ltd)
Task: {F7C125CC-4D99-4EBB-AF12-F4C11393C93E} - \Uninstaller_SkipUac_ASUS No Task File <==== ATTENTION

AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Users\ASUS\Downloads\ccsetup503.exe:$CmdTcID
AlternateDataStreams: C:\Users\ASUS\Downloads\ccsetup503.exe:$CmdZnID


CMD: bitsadmin /reset /allusers

EmptyTemp:
End


(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt

Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

PhR
Level 3
Level 3
Příspěvky: 448
Registrován: duben 12
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod PhR » 18 kvě 2015 07:26

Fixlog
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by ASUS at 2015-05-17 22:34:54 Run:1
Running from C:\Users\ASUS\Desktop
Loaded Profiles: ASUS (Available profiles: ASUS)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKU\S-1-5-21-233904950-2367353388-1579625358-1000\...\Run: [GUDelayStartup] => D:\Glary Utilities 5\StartupManager.exe [37152 2015-05-11] (Glarysoft Ltd)
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 7

S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]

R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2015-05-16] (Glarysoft Ltd)

U2 CscService; No ImagePath
U3 PeerDistSvc; No ImagePath

C:\Program Files (x86)\IObit\LiveUpdate\
C:\ProgramData\GlarySoft
C:\Windows\System32\Tasks\GlaryInitialize 5
C:\Windows\System32\Tasks\GU5SkipUAC
C:\Users\Public\Desktop\Glary Utilities 5.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
C:\Users\ASUS\AppData\Roaming\GlarySoft
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
C:\Users\ASUS\Downloads\gu5setup.exe
C:\ProgramData\IObit
C:\Users\ASUS\AppData\Roaming\IObit
C:\Windows\system32\IObitSmartDefragExtension.dll
C:\Windows\system32\SmartDefragBootTime.exe
C:\Users\ASUS\Downloads\game-assistant2-beta.exe
C:\Users\ASUS\Downloads\smart-defrag-setup.exe
C:\Users\ASUS\Downloads\driver_booster_setup.exe
C:\Windows\System32\Tasks\Driver Booster SkipUAC
C:\Windows\System32\Tasks\Driver Booster Update
C:\Windows\System32\Tasks\Driver Booster Scan
C:\Users\ASUS\Downloads\RazerGameBoosterSetup_4.2.45.0.exe
C:\Users\ASUS\Downloads\RazerCortexSetup_5.4.15.0 (1).exe

C:\Windows\Tasks\*.job
Task: {1171B713-7E5D-4F9E-9A38-7E91D228C29D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-09] (Google Inc.)
Task: {20C1CEAF-4C4A-4B9C-BA46-9C49206D5D93} - System32\Tasks\Driver Booster Update => D:\Driver Booster\AutoUpdate.exe [2015-04-28] (IObit)
Task: {249E1741-6B6D-4637-8FBD-523476EF97A6} - System32\Tasks\Driver Booster Scan => D:\Driver Booster\Scheduler.exe [2015-04-07] (IObit)
Task: {24F9EF00-2796-4B5A-B3FD-732124EC3480} - System32\Tasks\Driver Booster SkipUAC (ASUS) => D:\Driver Booster\DriverBooster.exe [2015-04-28] (IObit)
Task: {6B29E9BC-1D32-4BDE-8C28-91909A5D12CD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-09] (Google Inc.)
Task: {A898B72F-2DDC-44E9-AB95-80A07EB21798} - System32\Tasks\GlaryInitialize 5 => D:\Glary Utilities 5\Initialize.exe [2015-05-11] (Glarysoft Ltd)
Task: {BB44A540-60B5-49A9-9FCC-E147F663147C} - System32\Tasks\GU5SkipUAC => D:\Glary Utilities 5\Integrator.exe [2015-05-11] (Glarysoft Ltd)
Task: {F7C125CC-4D99-4EBB-AF12-F4C11393C93E} - \Uninstaller_SkipUac_ASUS No Task File <==== ATTENTION

AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Users\ASUS\Downloads\ccsetup503.exe:$CmdTcID
AlternateDataStreams: C:\Users\ASUS\Downloads\ccsetup503.exe:$CmdZnID


CMD: bitsadmin /reset /allusers

EmptyTemp:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-233904950-2367353388-1579625358-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GUDelayStartup => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
LiveUpdateSvc => Service deleted successfully.
GUBootStartup => Unable to stop service
GUBootStartup => Error deleting Service
CscService => Service deleted successfully.
PeerDistSvc => Service deleted successfully.
"C:\Program Files (x86)\IObit\LiveUpdate" => File/Directory not found.
C:\ProgramData\GlarySoft => Moved successfully.
"C:\Windows\System32\Tasks\GlaryInitialize 5" => File/Directory not found.
"C:\Windows\System32\Tasks\GU5SkipUAC" => File/Directory not found.
"C:\Users\Public\Desktop\Glary Utilities 5.lnk" => File/Directory not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk" => File/Directory not found.
C:\Users\ASUS\AppData\Roaming\GlarySoft => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5" => File/Directory not found.
C:\Users\ASUS\Downloads\gu5setup.exe => Moved successfully.
C:\ProgramData\IObit => Moved successfully.
C:\Users\ASUS\AppData\Roaming\IObit => Moved successfully.
C:\Windows\system32\IObitSmartDefragExtension.dll => Moved successfully.
C:\Windows\system32\SmartDefragBootTime.exe => Moved successfully.
C:\Users\ASUS\Downloads\game-assistant2-beta.exe => Moved successfully.
C:\Users\ASUS\Downloads\smart-defrag-setup.exe => Moved successfully.
C:\Users\ASUS\Downloads\driver_booster_setup.exe => Moved successfully.
"C:\Windows\System32\Tasks\Driver Booster SkipUAC" => File/Directory not found.
"C:\Windows\System32\Tasks\Driver Booster Update" => File/Directory not found.
"C:\Windows\System32\Tasks\Driver Booster Scan" => File/Directory not found.
C:\Users\ASUS\Downloads\RazerGameBoosterSetup_4.2.45.0.exe => Moved successfully.
C:\Users\ASUS\Downloads\RazerCortexSetup_5.4.15.0 (1).exe => Moved successfully.
"C:\Windows\Tasks\*.job" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1171B713-7E5D-4F9E-9A38-7E91D228C29D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1171B713-7E5D-4F9E-9A38-7E91D228C29D}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20C1CEAF-4C4A-4B9C-BA46-9C49206D5D93} => Key not found.
C:\Windows\System32\Tasks\Driver Booster Update not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{249E1741-6B6D-4637-8FBD-523476EF97A6} => Key not found.
C:\Windows\System32\Tasks\Driver Booster Scan not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{24F9EF00-2796-4B5A-B3FD-732124EC3480}" => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24F9EF00-2796-4B5A-B3FD-732124EC3480}" => Key Deleted successfully.
C:\Windows\System32\Tasks\Driver Booster SkipUAC (ASUS) => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (ASUS)" => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6B29E9BC-1D32-4BDE-8C28-91909A5D12CD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B29E9BC-1D32-4BDE-8C28-91909A5D12CD}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A898B72F-2DDC-44E9-AB95-80A07EB21798} => Key not found.
C:\Windows\System32\Tasks\GlaryInitialize 5 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GlaryInitialize 5 => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB44A540-60B5-49A9-9FCC-E147F663147C} => Key not found.
C:\Windows\System32\Tasks\GU5SkipUAC not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GU5SkipUAC => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F7C125CC-4D99-4EBB-AF12-F4C11393C93E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F7C125CC-4D99-4EBB-AF12-F4C11393C93E}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_ASUS => Key not found.
C:\Windows\system32\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Windows\SysWOW64\poqexec.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\ASUS\Downloads\ccsetup503.exe => ":$CmdTcID" ADS removed successfully.
C:\Users\ASUS\Downloads\ccsetup503.exe => ":$CmdZnID" ADS removed successfully.

========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========

EmptyTemp: => Removed 621.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog 22:35:17 ====
GeForce GT 630 2GB
I5-3550 3,30GHz
4GB RAM
W7 HP

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Podezření na vir: 3590F75ABA9E...(zzzzz..)

Příspěvekod Orcus » 18 kvě 2015 17:54

Jak to vypadá nyní?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 56 hostů