Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Sám se mi zapíná prohlížeč na YT a nějaké weby

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Gbelik
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 17 úno 2018 17:08

Sám se mi zapíná prohlížeč na YT a nějaké weby

#1 Příspěvek od Gbelik »

Dobrý den , nedávno jsem si něco nainstaloval a stím se mi nainstaloval nějaký ruský prohlížeč a do chromu se mi dalo nějaké vyhledávání , obě jsem smazal , ale stane se že samovolně se mi zapne Google a hodí mě to na nějaký web či video na Youtube bez toho abych něco udělal .

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files (x86)\iobit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(IObit) C:\Program Files (x86)\iobit\Advanced SystemCare\ASCTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(IObit) C:\Program Files (x86)\iobit\IObit Uninstaller\UninstallMonitor.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(BitTorrent Inc.) C:\Users\Jindra\AppData\Roaming\uTorrent\uTorrent.exe
(BitTorrent Inc.) C:\Users\Jindra\AppData\Roaming\uTorrent\updates\3.5.1_44332\utorrentie.exe
(BitTorrent Inc.) C:\Users\Jindra\AppData\Roaming\uTorrent\updates\3.5.1_44332\utorrentie.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
() C:\Windows\ERUNT.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2017-12-23] (AVAST Software)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2022688 2016-04-26] (IObit)
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe [16004784 2017-12-06] ()
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\RunOnce: [Application Restart #2] => C:\Program Files (x86)\Black Desert Online\DGCefBrowser.exe --type=renderer --no-sandbox --lang=en-US --lang=en-US --log-file=Debug.log --log-severity=disable --disable-accelerated-2d-canvas --disable (the data entry has 146 more characters).
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {618c0df7-cc4e-11e7-a1a9-50e54942a6ce} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {c0a9f494-9ad0-11e7-80dc-50e54942a6ce} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {c0a9f499-9ad0-11e7-80dc-50e54942a6ce} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {c0a9f4b1-9ad0-11e7-80dc-50e54942a6ce} - F:\HiSuiteDownLoader.exe
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{047DFA43-B026-4D1F-BABD-2FBD80C3E431}: [DhcpNameServer] 10.0.0.138

Internet Explorer:
==================
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-1603485170-3323181878-2894952063-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7BAF151C8F-2249-43FF-9545-FF989A2AC1BD%7D&gp=811142
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\iobit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2018-01-06] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2018-01-06] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2018-01-06] (Oracle Corporation)
BHO-x32: Search@Mail.Ru -> {8E8F97CD-60B5-456F-A201-73065652D099} -> C:\Users\Jindra\AppData\Local\Mail.Ru\Sputnik\ie_addon_dll.dll [2018-02-16] (Mail.Ru)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2018-01-06] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - No File

FireFox:
========
FF DefaultProfile: uhauyfkc.default
FF ProfilePath: C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default [2018-02-17]
FF user.js: detected! => C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\user.js [2017-08-14]
FF Homepage: Mozilla\Firefox\Profiles\uhauyfkc.default -> hxxps://www.seznam.cz/
FF Extension: (Bing Search) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\bingsearch.full@microsoft.com.xpi [2016-11-18] [Legacy]
FF Extension: (Firefox Hotfix) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\firefox-hotfix@mozilla.org.xpi [2017-01-12] [Legacy]
FF Extension: (???????? ???????? Mail.Ru) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\homepage@mail.ru.xpi [2018-02-16]
FF Extension: (Mail.Ru) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\search@mail.ru.xpi [2018-02-16]
FF Extension: (?????) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.xpi [2018-02-16]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\features\{0d8d0e6f-f05e-4f4b-b995-620fadb10e41}\malware-remediation@mozilla.org.xpi [2017-01-12] [Legacy]
FF SearchPlugin: C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\searchplugins\bing-.xml [2016-11-18]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2018-01-06] ()
FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2018-01-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2018-01-06] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2018-01-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2018-01-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2018-01-06] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1603485170-3323181878-2894952063-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jindra\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)

Chrome:
=======
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=811138"
CHR NewTab: Default -> Not-active:"chrome-extension://lhemechcanjmilllmccjbjldonmnnjjj/visual-bookmarks.html", Active:"chrome-extension://alnhfcfhjaopeigkhbhhcpgkocmaejpm/start/index.html"
CHR Profile: C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default [2018-02-17]
CHR Extension: (Prezentace) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Assassin's Creed Wallpapers HD New Tab Themes) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnhfcfhjaopeigkhbhhcpgkocmaejpm [2017-12-20]
CHR Extension: (Dokumenty) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Disk Google) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-14]
CHR Extension: (YouTube) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-14]
CHR Extension: (Adobe Acrobat) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-01-31]
CHR Extension: (Avast SafePrice) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2018-02-16]
CHR Extension: (Tabulky) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-16]
CHR Extension: (AdBlock) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-02-17]
CHR Extension: (Avast Online Security) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-13]
CHR Extension: (???????? ???????? Mail.Ru) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnif [2018-02-16] *Smazáno
CHR Extension: (AntiGameOrigin v6) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfaofnlkooiapdmkbppmpgmjmhkolaeb [2017-12-19]
CHR Extension: (?????????? ???????? Mail.Ru) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhemechcanjmilllmccjbjldonmnnjjj [2018-02-16] *Smazáno
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-14]
CHR Extension: (Chrome Media Router) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-15]
CHR Profile: C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\System Profile [2018-02-17]
CHR HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2017-12-23] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2017-12-23] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1494024 2017-10-01] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-02-07] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [383016 2017-11-05] (EasyAntiCheat Ltd)
S3 HnGSteamService; D:\Steam hry\steamapps\common\Heroes & Generals\hngservice.exe [777000 2018-02-15] (Reto-Moto ApS)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-07-26] () [File not signed]
S3 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960160 2016-04-22] (IObit)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123104 2017-11-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-12-12] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2016-10-20] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AR9271; C:\Windows\System32\DRIVERS\athuwx.sys [2224160 2012-08-30] (Atheros Communications, Inc.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [192944 2018-02-16] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2017-12-23] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2017-12-23] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2017-12-23] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2017-12-23] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [190440 2018-02-16] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-02-16] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-09-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146648 2018-02-16] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-02-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-02-16] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-02-16] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [459952 2018-02-16] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [205464 2018-02-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [379448 2018-02-16] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-04-04] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-04-04] (Disc Soft Ltd)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2017-07-26] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-11-18] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2017-07-26] (Huawei Technologies Co., Ltd.)
S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-08-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [48064 2017-08-18] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation)
S1 prodrv06; C:\Windows\SysWOW64\drivers\prodrv06.sys [52128 2003-10-10] (Protection Technology) [File not signed]
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [62720 2003-10-10] (Protection Technology) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [6944 2003-09-06] (Protection Technology) [File not signed]
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4832 2003-09-06] (Protection Technology) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2016-05-14] ()
R1 SPVDPort; C:\Windows\System32\DRIVERS\spvdbus.sys [99768 2016-11-03] ()
R1 SPVVEngine; C:\Windows\system32\Drivers\spvve.sys [248760 2016-11-03] ()
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] ()
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [151184 2016-03-10] (MBB)
U3 aho81anz; no ImagePath
S3 cpuz138; \??\C:\Users\Jindra\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION
S3 DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-02-17 17:19 - 2018-02-17 17:19 - 001329152 _____ C:\Users\Jindra\Downloads\RSITx64.exe
2018-02-17 17:19 - 2018-02-17 17:19 - 001329152 _____ C:\Users\Jindra\Downloads\RSITx64 (3).exe
2018-02-17 17:19 - 2018-02-17 17:19 - 001222144 _____ C:\Users\Jindra\Downloads\RSITx64 (2).exe
2018-02-17 17:19 - 2018-02-17 17:19 - 001222144 _____ C:\Users\Jindra\Downloads\RSITx64 (1).exe
2018-02-17 17:18 - 2018-02-17 17:20 - 000024910 _____ C:\Users\Jindra\Downloads\FRST.txt
2018-02-17 17:15 - 2018-02-17 17:18 - 000000000 ____D C:\FRST
2018-02-17 17:14 - 2018-02-17 17:14 - 002403840 _____ (Farbar) C:\Users\Jindra\Downloads\FRST64.exe
2018-02-17 13:33 - 2018-02-17 13:33 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\Google
2018-02-17 10:51 - 2018-02-17 10:51 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\KK Game Studio
2018-02-16 21:45 - 2018-02-17 10:51 - 000000000 ____D C:\Users\Jindra\Downloads\3DMGAME-Freeman.Guerrilla.Warfare.v0.102.Cracked-3DM
2018-02-16 21:45 - 2018-02-16 21:45 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\Unity
2018-02-16 21:45 - 2018-02-16 21:45 - 000000000 ____D C:\Users\Jindra\AppData\Local\Unity
2018-02-16 21:44 - 2018-02-16 21:46 - 000000000 ____D C:\Users\Jindra\AppData\Local\Lite
2018-02-16 21:44 - 2018-02-16 21:44 - 000528261 _____ ( ) C:\Users\Jindra\Downloads\Freeman.Guerrilla.Warfare.v0.102.Cracked-3DM.torre.exe
2018-02-16 21:44 - 2018-02-16 21:44 - 000021973 _____ C:\Users\Jindra\Downloads\Freeman.Guerrilla.Warfare.v0.102.Cracked-3DM.torrent
2018-02-16 21:43 - 2018-02-16 21:43 - 000037928 _____ C:\Users\Jindra\Downloads\The.Next.Car.Game.Pre-Alpha.v0.212037.torrent
2018-02-16 21:42 - 2018-02-16 21:46 - 000000000 ____D C:\Users\Jindra\AppData\Local\Mail.Ru *Smazáno
2018-02-16 21:42 - 2018-02-16 21:46 - 000000000 ____D C:\Program Files (x86)\Mail.Ru *Smazáno
2018-02-16 21:42 - 2018-02-16 21:45 - 000000000 ____D C:\ProgramData\Mail.Ru *Smazáno
2018-02-16 21:42 - 2018-02-16 21:42 - 000003604 _____ C:\Windows\System32\Tasks\kotcatkcomksz
2018-02-16 21:03 - 2018-02-16 21:03 - 000380768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-02-11 23:30 - 2018-02-11 23:34 - 000000683 _____ C:\Users\Jindra\Desktop\Nový textový dokument (2).txt
2018-02-09 21:53 - 2018-02-09 21:53 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossout
2018-02-09 20:42 - 2018-02-09 20:42 - 000000222 _____ C:\Users\Jindra\Desktop\Crossout.url
2018-02-07 20:20 - 2018-02-07 20:20 - 000000222 _____ C:\Users\Jindra\Desktop\Heroes & Generals.url
2018-02-05 21:21 - 2018-02-05 21:23 - 195687134 _____ C:\Users\Jindra\Downloads\mafia_freeride_1.0_by_majo-213.rar
2018-02-05 20:51 - 2018-02-05 20:51 - 000000000 ____D C:\ProgramData\SWCUTemp
2018-02-04 14:16 - 2013-10-16 19:01 - 074480478 _____ C:\Users\Jindra\Desktop\US Army Modification v0.6.e4mod
2018-02-04 14:13 - 2018-02-04 14:15 - 074251947 _____ C:\Users\Jindra\Downloads\us_army_mod_v0-6_by_Hoppah.zip
2018-02-04 14:13 - 2011-04-28 00:11 - 080186292 _____ C:\Users\Jindra\Desktop\NYMod_V1.01.e4mod
2018-02-04 14:10 - 2018-02-04 14:12 - 080130757 _____ C:\Users\Jindra\Downloads\New_York_Mod_V1.01.zip
2018-01-31 18:00 - 2018-01-31 18:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WizardWorks
2018-01-31 17:09 - 2018-01-31 17:09 - 000000000 ____D C:\Users\Jindra\AppData\Local\Quadriga Games
2018-01-31 16:53 - 2018-01-31 16:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deep Silver
2018-01-29 17:37 - 2018-01-29 17:37 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\Promotion Software GmbH
2018-01-28 21:05 - 2018-01-28 21:06 - 000290095 _____ C:\Users\Jindra\Desktop\Nadávky.rar
2018-01-25 18:46 - 2018-01-25 19:53 - 000000221 _____ C:\Users\Jindra\Desktop\Mount & Blade Warband.url
2018-01-20 16:33 - 2018-01-20 16:35 - 000000000 ____D C:\Users\Jindra\Desktop\RimWorld

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-02-17 17:20 - 2016-05-14 19:52 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\uTorrent
2018-02-17 12:25 - 2016-05-14 08:35 - 000000000 ____D C:\ProgramData\NVIDIA
2018-02-17 10:45 - 2016-05-14 21:05 - 000000000 ____D C:\Users\Jindra\AppData\Local\CrashDumps
2018-02-17 05:43 - 2016-05-16 16:19 - 000000000 ____D C:\Program Files (x86)\Steam
2018-02-17 03:20 - 2009-07-14 05:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-02-17 03:20 - 2009-07-14 05:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-02-16 21:42 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-02-16 21:42 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-02-16 21:40 - 2018-01-12 07:28 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\uTorrent
2018-02-16 21:04 - 2017-03-09 15:02 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2018-02-16 21:03 - 2017-11-16 14:43 - 000192944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000459952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000379448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000205464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000146648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000110328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-02-16 21:02 - 2017-12-23 12:10 - 000190440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-02-16 21:02 - 2016-05-15 12:04 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-02-16 20:43 - 2017-12-07 15:46 - 000003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:46 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:45 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:44 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:44 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:44 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:44 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-12-07 15:44 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-16 20:43 - 2017-08-14 16:34 - 000003088 _____ C:\Windows\System32\Tasks\{8A11E3C5-0E41-4D89-91EF-C5C8C0FC1D19}
2018-02-16 20:43 - 2017-08-14 15:57 - 000003162 _____ C:\Windows\System32\Tasks\{3B0E6B7F-5CFE-4E51-97E2-A4E6C3BD6488}
2018-02-16 20:43 - 2017-03-16 15:13 - 000003894 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1463310646
2018-02-16 20:43 - 2016-05-15 12:04 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2018-02-16 20:43 - 2016-05-15 07:39 - 000002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Jindra
2018-02-16 20:43 - 2016-05-14 21:39 - 000003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-02-16 20:43 - 2016-05-14 21:39 - 000003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-02-16 20:42 - 2018-01-06 21:02 - 000004408 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-02-16 20:42 - 2017-06-05 14:30 - 000003260 _____ C:\Windows\System32\Tasks\DRPNPS
2018-02-16 20:42 - 2017-04-17 12:05 - 000003452 _____ C:\Windows\System32\Tasks\DriverPack Notifier
2018-02-16 20:42 - 2016-05-15 07:39 - 000002872 _____ C:\Windows\System32\Tasks\ASC9_SkipUac_Jindra
2018-02-16 20:42 - 2016-05-14 21:33 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-16 17:45 - 2017-10-24 19:55 - 000000000 ____D C:\Users\Jindra\Documents\Assassin's Creed Unity
2018-02-15 15:41 - 2016-05-14 21:33 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-02-14 15:44 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-02-10 20:10 - 2016-05-16 16:35 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\TS3Client
2018-02-09 17:15 - 2010-11-21 10:27 - 000671834 _____ C:\Windows\system32\perfh005.dat
2018-02-09 17:15 - 2010-11-21 10:27 - 000142430 _____ C:\Windows\system32\perfc005.dat
2018-02-09 17:15 - 2009-07-14 06:13 - 001591974 _____ C:\Windows\system32\PerfStringBackup.INI
2018-02-08 16:57 - 2016-05-13 14:26 - 000000000 ____D C:\Users\Jindra
2018-02-08 09:15 - 2016-10-28 15:03 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\Heroes and Generals
2018-02-05 20:49 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-05 19:58 - 2016-05-15 07:39 - 000000000 ____D C:\ProgramData\ProductData
2018-02-03 14:32 - 2017-01-12 17:01 - 000000000 ____D C:\Users\Jindra\Desktop\hry
2018-02-01 09:53 - 2016-05-14 19:46 - 000000000 ___HD C:\Users\Jindra\AppData\Roaming\DAEMON Tools Lite
2018-01-31 17:54 - 2016-05-13 14:29 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-01-29 16:10 - 2017-12-03 17:49 - 000000000 ____D C:\Users\Jindra\AppData\Local\Arma 3
2018-01-27 22:17 - 2016-11-12 12:38 - 000000000 ____D C:\Users\Jindra\Documents\Mount&Blade Warband Savegames
2018-01-18 13:46 - 2017-12-03 17:49 - 000000000 ____D C:\Users\Jindra\Documents\Arma 3

==================== Files in the root of some directories =======

2017-07-16 23:56 - 2017-08-14 16:10 - 000004564 _____ () C:\Users\Jindra\AppData\Roaming\downloads.json
2016-09-15 16:02 - 2016-09-16 12:22 - 000007595 _____ () C:\Users\Jindra\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-02-16 21:41 - 2018-02-16 21:41 - 002575544 _____ () C:\Users\Jindra\AppData\Local\Temp\x4x70ntvzv.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-02-07 18:10

==================== End of FRST.txt =======================


A ještě bych poprosil jestli tam neni něco podezřelého nebo tak.
Děkuji za odpovědi.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#2 Příspěvek od Rudy »

Zdravím!
Dal jste log bez hlavičky. Ta je pro nás také důležitá. Jinak spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gbelik
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 17 úno 2018 17:08

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#3 Příspěvek od Gbelik »

Omlouvám se

Zde je je zbytek

***** [ Folders ] *****

PUP.Optional.AdvancedSystemCare, C:\ProgramData\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\ProgramData\Application Data\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\All Users\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\Jindra\AppData\LocalLow\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\Jindra\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\ProgramData\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\ProgramData\Application Data\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\All Users\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\Jindra\AppData\LocalLow\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\Jindra\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.Legacy, C:\ProgramData\IObit\ASCDownloader
PUP.Optional.Legacy, C:\ProgramData\Application Data\IObit\ASCDownloader
PUP.Optional.Legacy, C:\Users\All Users\IObit\ASCDownloader
PUP.Optional.Legacy, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare
PUP.Optional.Reimage, C:\Program Files\Reimage
PUP.Optional.Mail.Ru, C:\Windows\System32\config\systemprofile\AppData\Local\Mail.Ru
PUP.Optional.Mail.Ru, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Mail.Ru
PUP.Optional.DriverPack, C:\Program Files (x86)\DriverPack Notifier
PUP.Optional.DriverPack, C:\Users\Jindra\AppData\Roaming\DriverPack Notifier
PUP.Optional.DriverPack, C:\Users\Jindra\AppData\Roaming\DRPSu
PUP.Optional.DriverAgentPlus, C:\ProgramData\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\ProgramData\Application Data\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\Users\All Users\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\Users\Jindra\AppData\Roaming\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\ProgramData\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\ProgramData\Application Data\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\Users\All Users\DriverAgentPlus
PUP.Optional.DriverAgentPlus, C:\Users\Jindra\AppData\Roaming\DriverAgentPlus


***** [ Files ] *****

PUP.Optional.AdvancedSystemCare, C:\Users\All Users\Desktop\Advanced SystemCare 9.lnk
PUP.Optional.AdvancedSystemCare, C:\Users\Public\Desktop\Advanced SystemCare 9.lnk
PUP.Optional.AdvancedSystemCare, C:\Windows\SysNative\REGISTRYDEFRAGBOOTTIME.EXE
PUP.Optional.Legacy, C:\Users\Jindra\Favorites\Mail.Ru.url
PUP.Optional.Legacy, C:\Users\Jindra\Favorites\Mail.Ru Агент - используй для общения!.url
PUP.Optional.Reimage, C:\Windows\Reimage.ini
PUP.Optional.Mail.Ru, C:\Users\Jindra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk


***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

PUP.Optional.Legacy, C:\Users\Jindra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk - url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811144"
PUP.Optional.Legacy, C:\Users\Jindra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk - url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811144"


***** [ Tasks ] *****

PUP.Optional.AdvancedSystemCare, ASC9_PerformanceMonitor
PUP.Optional.Legacy, Driver Booster Scheduler
PUP.Optional.DriverPack, DriverPack Notifier


***** [ Registry ] *****

PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IOBIT\ASC
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IObit\RealTimeProtector
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IObit\ASC
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
PUP.Optional.AdvancedSystemCare, [Value] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Microsoft\Windows\CurrentVersion\Run | Advanced SystemCare 9
PUP.Optional.AdvancedSystemCare, [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run | Advanced SystemCare 9
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\dt soft\daemon tools toolbar
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare_is1
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
PUP.Optional.Conduit, [Key] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Conduit
PUP.Optional.Conduit, [Key] - HKCU\Software\Conduit
PUP.Optional.Reimage, [Key] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
PUP.Optional.Reimage, [Key] - HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
PUP.Optional.Reimage, [Key] - HKLM\SOFTWARE\Reimage
PUP.Optional.Reimage, [Key] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Reimage
PUP.Optional.Reimage, [Key] - HKCU\Software\Reimage
PUP.Optional.Mail.Ru, [Key] - HKLM\SOFTWARE\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\AppDataLow\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKCU\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKCU\Software\AppDataLow\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKCU\Software\Google\Chrome\NativeMessagingHosts\ru.mail.go.ext_info_host
PUP.Optional.Mail.Ru, [Key] - HKCU\Software\Mozilla\NativeMessagingHosts\ru.mail.go.ext_info_host
PUP.Optional.DriverPack, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverPack Notifier
PUP.Optional.DriverPack, [Key] - HKLM\SOFTWARE\drpsu
PUP.Optional.DriverPack, [Key] - HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\drpsu
PUP.Optional.DriverPack, [Key] - HKCU\Software\drpsu


***** [ Firefox (and derivatives) ] *****

PUP.Optional.Legacy, Plugin found: Домашняя страница Mail.Ru -
PUP.Optional.Legacy, Plugin found: Поиск Mail.Ru -
PUP.Optional.Mail.Ru, Plugin found: __MSG_extName__ -
PUP.Optional.Mail.Ru, Plugin found: __MSG_extName__ -


***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#4 Příspěvek od Rudy »

V ADW ještě klikněte na mazání, restartujte a pak dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gbelik
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 17 úno 2018 17:08

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#5 Příspěvek od Gbelik »

(IObit) C:\Program Files (x86)\iobit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(IObit) C:\Program Files (x86)\iobit\IObit Uninstaller\BigUpgrade_IU.exe
(IObit) C:\Program Files (x86)\iobit\IObit Uninstaller\UninstallMonitor.exe
(IObit) C:\Program Files (x86)\iobit\Advanced SystemCare\ASCTray.exe
() C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [243496 2018-02-16] (AVAST Software)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2022688 2016-04-26] (IObit)
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe [16004784 2017-12-06] ()
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\RunOnce: [Application Restart #2] => C:\Program Files (x86)\Black Desert Online\DGCefBrowser.exe --type=renderer --no-sandbox --lang=en-US --lang=en-US --log-file=Debug.log --log-severity=disable --disable-accelerated-2d-canvas --disable (the data entry has 146 more characters).
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {618c0df7-cc4e-11e7-a1a9-50e54942a6ce} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {c0a9f494-9ad0-11e7-80dc-50e54942a6ce} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {c0a9f499-9ad0-11e7-80dc-50e54942a6ce} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\...\MountPoints2: {c0a9f4b1-9ad0-11e7-80dc-50e54942a6ce} - F:\HiSuiteDownLoader.exe
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{047DFA43-B026-4D1F-BABD-2FBD80C3E431}: [DhcpNameServer] 10.0.0.138

Internet Explorer:
==================
HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-1603485170-3323181878-2894952063-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7BAF151C8F-2249-43FF-9545-FF989A2AC1BD%7D&gp=811142
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\iobit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2018-01-06] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-02-16] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2018-01-06] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2018-01-06] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-02-16] (AVAST Software)
BHO-x32: Search@Mail.Ru -> {8E8F97CD-60B5-456F-A201-73065652D099} -> No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2018-01-06] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - No File

FireFox:
========
FF DefaultProfile: uhauyfkc.default
FF ProfilePath: C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default [2018-02-17]
FF user.js: detected! => C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\user.js [2017-08-14]
FF Homepage: Mozilla\Firefox\Profiles\uhauyfkc.default -> hxxps://www.seznam.cz/
FF Extension: (Bing Search) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\bingsearch.full@microsoft.com.xpi [2016-11-18] [Legacy]
FF Extension: (Firefox Hotfix) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\firefox-hotfix@mozilla.org.xpi [2017-01-12] [Legacy]
FF Extension: (Домашняя страница Mail.Ru) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\homepage@mail.ru.xpi [2018-02-16]
FF Extension: (Mail.Ru) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\search@mail.ru.xpi [2018-02-16]
FF Extension: (Пульт) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\Extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.xpi [2018-02-16]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\features\{0d8d0e6f-f05e-4f4b-b995-620fadb10e41}\malware-remediation@mozilla.org.xpi [2017-01-12] [Legacy]
FF SearchPlugin: C:\Users\Jindra\AppData\Roaming\Mozilla\Firefox\Profiles\uhauyfkc.default\searchplugins\bing-.xml [2016-11-18]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2018-01-06] ()
FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2018-01-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2018-01-06] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2018-01-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2018-01-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2018-01-06] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1603485170-3323181878-2894952063-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jindra\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)

Chrome:
=======
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=811138"
CHR NewTab: Default -> Not-active:"chrome-extension://lhemechcanjmilllmccjbjldonmnnjjj/visual-bookmarks.html", Active:"chrome-extension://alnhfcfhjaopeigkhbhhcpgkocmaejpm/start/index.html"
CHR Profile: C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default [2018-02-17]
CHR Extension: (Prezentace) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Assassin's Creed Wallpapers HD New Tab Themes) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnhfcfhjaopeigkhbhhcpgkocmaejpm [2017-12-20]
CHR Extension: (Dokumenty) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Disk Google) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-14]
CHR Extension: (YouTube) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-14]
CHR Extension: (Adobe Acrobat) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-01-31]
CHR Extension: (Avast SafePrice) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2018-02-16]
CHR Extension: (Tabulky) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-16]
CHR Extension: (AdBlock) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-02-17]
CHR Extension: (Avast Online Security) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-13]
CHR Extension: (AntiGameOrigin v6) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfaofnlkooiapdmkbppmpgmjmhkolaeb [2017-12-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-14]
CHR Extension: (Chrome Media Router) - C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-15]
CHR Profile: C:\Users\Jindra\AppData\Local\Google\Chrome\User Data\System Profile [2018-02-17]
CHR HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1603485170-3323181878-2894952063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7564512 2018-02-16] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [300600 2018-02-16] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1494024 2017-10-01] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-02-07] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [383016 2017-11-05] (EasyAntiCheat Ltd)
S3 HnGSteamService; D:\Steam hry\steamapps\common\Heroes & Generals\hngservice.exe [777000 2018-02-15] (Reto-Moto ApS)
S3 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-07-26] () [File not signed]
S3 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960160 2016-04-22] (IObit)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123104 2017-11-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-12-12] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2016-10-20] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AR9271; C:\Windows\System32\DRIVERS\athuwx.sys [2224160 2012-08-30] (Atheros Communications, Inc.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [192944 2018-02-16] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2017-12-23] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2017-12-23] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2017-12-23] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2017-12-23] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [190440 2018-02-16] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-02-16] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-09-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146648 2018-02-16] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-02-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-02-16] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-02-16] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [459952 2018-02-16] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [205464 2018-02-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [379448 2018-02-16] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-04-04] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-04-04] (Disc Soft Ltd)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2017-07-26] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-11-18] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2017-07-26] (Huawei Technologies Co., Ltd.)
S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-08-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [48064 2017-08-18] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation)
S1 prodrv06; C:\Windows\SysWOW64\drivers\prodrv06.sys [52128 2003-10-10] (Protection Technology) [File not signed]
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [62720 2003-10-10] (Protection Technology) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [6944 2003-09-06] (Protection Technology) [File not signed]
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4832 2003-09-06] (Protection Technology) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2016-05-14] ()
R1 SPVDPort; C:\Windows\System32\DRIVERS\spvdbus.sys [99768 2016-11-03] ()
R1 SPVVEngine; C:\Windows\system32\Drivers\spvve.sys [248760 2016-11-03] ()
S3 t_mouse.sys; C:\Windows\System32\DRIVERS\t_mouse.sys [6144 2012-12-19] ()
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [151184 2016-03-10] (MBB)
U3 a6pdv6v3; no ImagePath
S3 cpuz138; \??\C:\Users\Jindra\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION
S3 DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-02-17 20:02 - 2018-02-17 20:03 - 000023066 _____ C:\Users\Jindra\Downloads\FRST.txt
2018-02-17 20:01 - 2018-02-17 20:01 - 002403840 _____ (Farbar) C:\Users\Jindra\Downloads\FRST64.exe
2018-02-17 18:25 - 2018-02-17 19:50 - 000000000 ____D C:\AdwCleaner
2018-02-17 18:22 - 2018-02-17 18:23 - 008222496 _____ (Malwarebytes) C:\Users\Jindra\Downloads\adwcleaner_7.0.8.0.exe
2018-02-17 17:23 - 2018-02-17 17:24 - 000074798 _____ C:\Users\Jindra\Desktop\Addition.txt
2018-02-17 17:23 - 2018-02-17 17:24 - 000036850 _____ C:\Users\Jindra\Desktop\FRST.txt
2018-02-17 17:15 - 2018-02-17 20:02 - 000000000 ____D C:\FRST
2018-02-17 13:33 - 2018-02-17 13:33 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\Google
2018-02-17 10:51 - 2018-02-17 10:51 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\KK Game Studio
2018-02-16 21:45 - 2018-02-17 10:51 - 000000000 ____D C:\Users\Jindra\Downloads\3DMGAME-Freeman.Guerrilla.Warfare.v0.102.Cracked-3DM
2018-02-16 21:45 - 2018-02-16 21:45 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\Unity
2018-02-16 21:45 - 2018-02-16 21:45 - 000000000 ____D C:\Users\Jindra\AppData\Local\Unity
2018-02-16 21:44 - 2018-02-16 21:46 - 000000000 ____D C:\Users\Jindra\AppData\Local\Lite
2018-02-16 21:42 - 2018-02-17 19:25 - 000003604 _____ C:\Windows\System32\Tasks\kotcatkcomksz
2018-02-16 21:03 - 2018-02-16 21:03 - 000380768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-02-11 23:30 - 2018-02-11 23:34 - 000000683 _____ C:\Users\Jindra\Desktop\Nový textový dokument (2).txt
2018-02-09 21:53 - 2018-02-09 21:53 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossout
2018-02-09 20:42 - 2018-02-09 20:42 - 000000222 _____ C:\Users\Jindra\Desktop\Crossout.url
2018-02-07 20:20 - 2018-02-07 20:20 - 000000222 _____ C:\Users\Jindra\Desktop\Heroes & Generals.url
2018-02-04 14:16 - 2013-10-16 19:01 - 074480478 _____ C:\Users\Jindra\Desktop\US Army Modification v0.6.e4mod
2018-02-04 14:13 - 2011-04-28 00:11 - 080186292 _____ C:\Users\Jindra\Desktop\NYMod_V1.01.e4mod
2018-01-31 18:00 - 2018-01-31 18:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WizardWorks
2018-01-31 17:09 - 2018-01-31 17:09 - 000000000 ____D C:\Users\Jindra\AppData\Local\Quadriga Games
2018-01-31 16:53 - 2018-01-31 16:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deep Silver
2018-01-29 17:37 - 2018-01-29 17:37 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\Promotion Software GmbH
2018-01-28 21:05 - 2018-01-28 21:06 - 000290095 _____ C:\Users\Jindra\Desktop\Nadávky.rar
2018-01-25 18:46 - 2018-01-25 19:53 - 000000221 _____ C:\Users\Jindra\Desktop\Mount & Blade Warband.url
2018-01-20 16:33 - 2018-01-20 16:35 - 000000000 ____D C:\Users\Jindra\Desktop\RimWorld

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-02-17 20:03 - 2009-07-14 05:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-02-17 20:03 - 2009-07-14 05:45 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-02-17 20:01 - 2016-05-14 08:35 - 000000000 ____D C:\ProgramData\NVIDIA
2018-02-17 19:56 - 2016-05-15 07:39 - 000000000 ____D C:\ProgramData\ProductData
2018-02-17 19:55 - 2017-10-24 19:55 - 000000000 ____D C:\Users\Jindra\Documents\Assassin's Creed Unity
2018-02-17 19:54 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-17 19:52 - 2016-05-16 16:19 - 000000000 ____D C:\Program Files (x86)\Steam
2018-02-17 19:26 - 2017-12-07 15:46 - 000003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-12-07 15:46 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-12-07 15:44 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-12-07 15:44 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-12-07 15:44 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-12-07 15:44 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-12-07 15:44 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:26 - 2017-08-14 16:34 - 000003088 _____ C:\Windows\System32\Tasks\{8A11E3C5-0E41-4D89-91EF-C5C8C0FC1D19}
2018-02-17 19:26 - 2017-08-14 15:57 - 000003162 _____ C:\Windows\System32\Tasks\{3B0E6B7F-5CFE-4E51-97E2-A4E6C3BD6488}
2018-02-17 19:26 - 2017-03-16 15:13 - 000003894 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1463310646
2018-02-17 19:26 - 2016-05-15 12:04 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2018-02-17 19:26 - 2016-05-15 07:39 - 000002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Jindra
2018-02-17 19:25 - 2018-01-06 21:02 - 000004408 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-02-17 19:25 - 2017-12-07 15:45 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-02-17 19:25 - 2017-06-05 14:30 - 000003260 _____ C:\Windows\System32\Tasks\DRPNPS
2018-02-17 19:25 - 2017-04-17 12:05 - 000003452 _____ C:\Windows\System32\Tasks\DriverPack Notifier
2018-02-17 19:25 - 2016-05-15 07:39 - 000002872 _____ C:\Windows\System32\Tasks\ASC9_SkipUac_Jindra
2018-02-17 19:25 - 2016-05-14 21:39 - 000003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-02-17 19:25 - 2016-05-14 21:39 - 000003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-02-17 19:25 - 2016-05-14 21:33 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-17 18:24 - 2016-05-14 19:52 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\uTorrent
2018-02-17 10:45 - 2016-05-14 21:05 - 000000000 ____D C:\Users\Jindra\AppData\Local\CrashDumps
2018-02-16 21:42 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-02-16 21:42 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-02-16 21:04 - 2017-03-09 15:02 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2018-02-16 21:03 - 2017-11-16 14:43 - 000192944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000459952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000379448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000205464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000146648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000110328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-02-16 21:03 - 2016-05-15 12:04 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-02-16 21:02 - 2017-12-23 12:10 - 000190440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-02-16 21:02 - 2016-05-15 12:04 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-02-15 15:41 - 2016-05-14 21:33 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-02-14 15:44 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-02-10 20:10 - 2016-05-16 16:35 - 000000000 ____D C:\Users\Jindra\AppData\Roaming\TS3Client
2018-02-09 17:15 - 2010-11-21 10:27 - 000671834 _____ C:\Windows\system32\perfh005.dat
2018-02-09 17:15 - 2010-11-21 10:27 - 000142430 _____ C:\Windows\system32\perfc005.dat
2018-02-09 17:15 - 2009-07-14 06:13 - 001591974 _____ C:\Windows\system32\PerfStringBackup.INI
2018-02-08 16:57 - 2016-05-13 14:26 - 000000000 ____D C:\Users\Jindra
2018-02-08 09:15 - 2016-10-28 15:03 - 000000000 ____D C:\Users\Jindra\AppData\LocalLow\Heroes and Generals
2018-02-03 14:32 - 2017-01-12 17:01 - 000000000 ____D C:\Users\Jindra\Desktop\hry
2018-02-01 09:53 - 2016-05-14 19:46 - 000000000 ___HD C:\Users\Jindra\AppData\Roaming\DAEMON Tools Lite
2018-01-31 17:54 - 2016-05-13 14:29 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-01-29 16:10 - 2017-12-03 17:49 - 000000000 ____D C:\Users\Jindra\AppData\Local\Arma 3
2018-01-27 22:17 - 2016-11-12 12:38 - 000000000 ____D C:\Users\Jindra\Documents\Mount&Blade Warband Savegames
2018-01-18 13:46 - 2017-12-03 17:49 - 000000000 ____D C:\Users\Jindra\Documents\Arma 3

==================== Files in the root of some directories =======

2017-07-16 23:56 - 2017-08-14 16:10 - 000004564 _____ () C:\Users\Jindra\AppData\Roaming\downloads.json
2016-09-15 16:02 - 2016-09-16 12:22 - 000007595 _____ () C:\Users\Jindra\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-02-16 21:41 - 2018-02-16 21:41 - 002575544 _____ () C:\Users\Jindra\AppData\Local\Temp\x4x70ntvzv.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-02-07 18:10

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#6 Příspěvek od Rudy »

Rudy píše:Zdravím!
Dal jste log bez hlavičky. Ta je pro nás také důležitá.
Kde je hlavička logu?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gbelik
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 17 úno 2018 17:08

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#7 Příspěvek od Gbelik »

Myslíte toto ? :

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.02.2018
Ran by Jindra (administrator) on JINDRA-PC (17-02-2018 20:02:19)
Running from C:\Users\Jindra\Downloads
Loaded Profiles: Jindra (Available Profiles: Jindra)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

----------------------------------------------------

# AdwCleaner 7.0.8.0 - Logfile created on Sat Feb 17 17:26:39 2018
# Updated on 2018/08/02 by Malwarebytes
# Database: 02-16-2018.1
# Running on Windows 7 Ultimate (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

PUP.Optional.AdvancedSystemCare, AdvancedSystemCareService9

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#8 Příspěvek od Rudy »

Ano, toto. Váš OS je legální?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gbelik
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 17 úno 2018 17:08

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#9 Příspěvek od Gbelik »

Bohužel neni

Gbelik
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 17 úno 2018 17:08

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#10 Příspěvek od Gbelik »

jinak pro dodatek , ten chrome se mi zapíná pravidelně a myslím že cca po 25-40 minutách . ( nejčastěji na webové hry )

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Sám se mi zapíná prohlížeč na YT a nějaké weby

#11 Příspěvek od Rudy »

Gbelik píše:Bohužel neni
Pak je mi líto, ale nemohu pokračovat. Viz pravidla: https://forum.viry.cz/viewtopic.php?f=12&t=115512 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět