Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Nabouraný mail.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
neb251
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 02 čer 2019 18:15

Nabouraný mail.

#1 Příspěvek od neb251 »

Zdravím a prosím o pomoc. Někdo mi zřejmě hacknul mailový účet společně se hrou Heartstone. Do tohoto fora sem se musel znovu zaregistrovat. Změnil na obou účtech přihlašovací údaje. Prosím o konrolu logu. Doufám že se mi podaří dát celou tu pohromu nějak dopořádku. Hlavně ten mejl... :-(

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-06-2019
Ran by z (administrator) on Z-PC (MEDIONPC MS-7616) (02-06-2019 19:25:03)
Running from C:\Users\z\Desktop\viry
Loaded Profiles: z (Available Profiles: z)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Canon INC.) [File not signed] C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe
(CANON INC.) [File not signed] C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe
(CÍGLER SOFTWARE, a.s. -> Solitea Česká republika, a.s.) C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe
(Corel Corporation -> WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Corel Corporation -> WinZip) [File not signed] C:\Program Files\WinZip\WZUpdateNotifier.exe
(Fractalis Software) [File not signed] C:\Program Files (x86)\Fractalis Software\Display Stix 2.1.1\dstix.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Microsoft Corporation) [File not signed] C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Nokia -> Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia -> Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
(Nokia -> Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Seznam.cz, a.s. -> ) C:\Users\z\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Seznam.cz, a.s. -> ) C:\Users\z\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(WinZip Computing LLC -> WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] (Samsung Electronics CO., LTD. -> )
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [262024 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2047744 2017-12-14] (Corel Corporation -> WinZip) [File not signed]
HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [123848 2017-12-14] (Corel Corporation -> WinZip Computing, S.L.)
HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436416 2017-12-14] (WinZip Computing LLC -> WinZip Computing, S.L.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318128 2016-08-25] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Tanks] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3139936 2018-06-25] (Wargaming.net Limited -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\z\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [109808 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Warships] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3140384 2018-09-26] (Wargaming PCL -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia -> Nokia)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [S3AutomaticSTART] => C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe [16584080 2018-09-19] (CÍGLER SOFTWARE, a.s. -> Solitea Česká republika, a.s.)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [S3Automatic] => C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe [16584080 2018-09-19] (CÍGLER SOFTWARE, a.s. -> Solitea Česká republika, a.s.)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [Display Stix - System tray] => C:\Program Files (x86)\Fractalis Software\Display Stix 2.1.1\dstix.exe [241664 2004-01-12] (Fractalis Software) [File not signed]
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [53646912 2019-05-24] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe [16256240 2018-03-12] (A FOUR TECH CO., LTD. -> )
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46506040 2019-04-09] (Google LLC -> )
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [BitTorrent] => C:\Users\z\AppData\Roaming\BitTorrent\BitTorrent.exe [1744064 2019-01-27] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [18630056 2018-09-10] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [AutoStart PC Studio] => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NewPCStudio.exe
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Warships (1)] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3140384 2018-09-26] (Wargaming PCL -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Warships (2)] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3140384 2018-09-26] (Wargaming PCL -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [AvastBrowserAutoLaunch_8A75A33FF14ADA301D337A774A4D2AE2] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1958568 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Warships (3)] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3140384 2018-09-26] (Wargaming PCL -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Warships (4)] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3140384 2018-09-26] (Wargaming PCL -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Warships (5)] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3140384 2018-09-26] (Wargaming PCL -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Tanks (1)] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3139936 2018-06-25] (Wargaming.net Limited -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\Run: [World of Tanks (2)] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3139936 2018-06-25] (Wargaming.net Limited -> Wargaming.net)
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\MountPoints2: {a6b56dad-10ed-11e8-bb5b-406186f3ca2c} - L:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\MountPoints2: {a6b56e07-10ed-11e8-bb5b-406186f3ca2c} - L:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\MountPoints2: {a6b56e95-10ed-11e8-bb5b-406186f3ca2c} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\MountPoints2: {c97fa000-b0d2-11e8-ba4a-406186f3ca2c} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\MountPoints2: {c97fa099-b0d2-11e8-ba4a-406186f3ca2c} - G:\HiSuiteDownLoader.exe
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\...\MountPoints2: {e540c1b8-0817-11e9-a66c-406186f3ca2c} - G:\HiSuiteDownLoader.exe
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\74.0.1376.131\Installer\chrmstp.exe [2019-05-28] (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2019-04-16]
ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Service Manager.lnk [2018-11-08]
ShortcutTarget: Service Manager.lnk -> C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation) [File not signed]
Startup: C:\Users\z\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2017-10-15]
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.) [File not signed]
BootExecute: autocheck autochk * aswBoot.exe /A:"C:" /A:"* STARTUP" /L:"1029" /heur:80 /RA:fix /pup /archives /IA:0 /KBD:4 /dir:"C:\Program Files\AVAST Software\Avast"
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {03DEDE1B-3135-435F-9CCB-5CBE4F0BEA05} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {08451931-D9E4-4E1A-9CC1-94C4743339D1} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1958568 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
Task: {16041FE2-E3AF-4198-A448-58F17551F8E8} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2047744 2017-12-14] (Corel Corporation -> WinZip) [File not signed]
Task: {1795E962-86E3-4986-8520-19A8108D0627} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [728000 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2684E38C-42C5-408A-93E3-3C092126A763} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1542080 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {29D41162-6FDB-4C00-A4B0-5EDEEDA015C3} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1958568 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
Task: {4694F59E-0DEF-4F23-8951-F280CC6823D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-05-15] (Google Inc -> Google Inc.)
Task: {4E37BE0E-6239-4887-B5AD-D2CA655D5387} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
Task: {530DAA1B-347C-41BF-A0EE-29BE51586E25} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436160 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7B50510F-5B8E-4A03-8458-871BB8CCAE8E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {7C82A0FC-DB47-48AF-8671-81060A649A89} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [960448 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8BF99741-E089-4E94-8CB2-339BA7C9C0C2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-05-15] (Google Inc -> Google Inc.)
Task: {A84D7D33-7557-43B2-9FE6-0DF22BBCBC6D} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
Task: {B1757E5E-F130-4A64-B62C-4C8C32EB3BC9} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B3ED7286-26B9-4259-BAF6-E4E2D2C12B3B} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [655296 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C94F4587-4195-4A2C-8990-999AC9819F1F} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2934152 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
Task: {CACF1AA7-3FBF-4C77-8F4B-407C96D194D2} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [655296 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CC114D12-C144-4A60-AA64-17A8D3818B9E} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [728000 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CE599264-E537-4915-8A72-B2C187231DB6} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2380088 2019-04-16] (AVAST Software s.r.o. -> AVAST Software)
Task: {D3485FE8-E4AF-4BB0-A207-987A0156998A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [272384 2018-03-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {E38E4449-CA0D-41E4-B2AB-3E96B63D550C} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {F18F62D8-B0ED-4DE0-968C-D4F46FB8E14E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [13797712 2018-09-10] (Piriform Ltd -> Piriform Ltd)
Task: {F9445811-6DD8-4934-8308-34660396CADC} - System32\Tasks\Avast Cleanup Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [1659000 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{98F090C1-CD88-465B-A020-FE5D7514E463}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{F408DB05-22DB-451A-805A-2F3D98469521}: [DhcpNameServer] 192.168.42.129

Internet Explorer:
==================
HKU\S-1-5-21-2836580553-618681296-1798274236-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {029E627B-4F0E-4BC2-9D99-5A632F12D8BA} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {12BCDD8A-A4FF-4522-8A86-AE072D8E276C} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {4BC1E21B-C94A-4ACF-B430-110DB047D74F} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {5FE6E04A-8D1D-4B07-88F3-1542B04DBA8A} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {73AB0EBA-4D4A-4BB5-B6C4-10E175DC36ED} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {79D8FC62-FC99-42C2-B37A-CB359E317642} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {992E3C3E-84AC-4F45-9FA2-39013E14BE57} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {CA1C1DCB-0E11-48F0-8045-4D37E85EC537} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_28314
SearchScopes: HKU\S-1-5-21-2836580553-618681296-1798274236-1000 -> {D99472A1-FF86-4CBF-BB7A-62531DFE0DD9} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_28314
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1474483233675
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

FireFox:
========
FF DefaultProfile: cprwhjtg.default
FF ProfilePath: C:\Users\z\AppData\Roaming\Mozilla\Firefox\Profiles\cprwhjtg.default [2019-06-02]
FF Extension: (Avast Online Security) - C:\Users\z\AppData\Roaming\Mozilla\Firefox\Profiles\cprwhjtg.default\Extensions\wrc@avast.com.xpi [2019-05-28]
FF Extension: (ImTranslator: Překladač, Slovník, Hlas) - C:\Users\z\AppData\Roaming\Mozilla\Firefox\Profiles\cprwhjtg.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2019-05-29]
FF Extension: (Video DownloadHelper) - C:\Users\z\AppData\Roaming\Mozilla\Firefox\Profiles\cprwhjtg.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2019-05-30]
FF Extension: (No Name) - C:\Users\z\AppData\Roaming\Mozilla\Firefox\Profiles\cprwhjtg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-05-09]
FF Extension: (YouTube Flash Video Player) - C:\Users\z\AppData\Roaming\Mozilla\Firefox\Profiles\cprwhjtg.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2018-01-20]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll [2018-03-04] (Adobe Systems Incorporated -> )
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (Garmin International, Inc. -> GARMIN Corp.)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll [2018-03-04] (Adobe Systems Incorporated -> )
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (Garmin International, Inc. -> GARMIN Corp.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-02-08] (NVIDIA CORPORATION -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-02-08] (NVIDIA CORPORATION -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-03] (Adobe Inc. -> Adobe Systems Inc.)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6844776 2019-05-28] (AVAST Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [409224 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\74.0.1376.131\elevation_service.exe [1079424 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
R2 CleanupPSvc; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [10267576 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-10-22] (Huawei Technologies Co., Ltd. -> ) [File not signed]
R2 MSSQLSERVER; C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [7520337 2002-12-17] (Microsoft Corporation) [File not signed]
S3 MSSQLServerADHelper; C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [66112 2002-12-17] (Microsoft Corporation) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
S3 SQLSERVERAGENT; C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [311872 2002-12-17] (Microsoft Corporation) [File not signed]
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11665136 2019-01-16] (TeamViewer GmbH -> TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [37104 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [207448 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [262496 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [205848 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [61472 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [279120 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42288 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [167872 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [112312 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [87944 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1030784 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [477584 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [225096 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [385880 2019-05-30] (AVAST Software s.r.o. -> AVAST Software)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2018-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-10-22] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 nmwcd; C:\Windows\System32\drivers\ccdcmbx64.sys [19968 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbox64.sys [27136 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation -> NVIDIA Corporation)
S3 pccsmcfd; C:\Windows\System32\DRIVERS\pccsmcfdx64.sys [26112 2012-06-11] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
R3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [187392 2009-06-10] (Microsoft Windows -> Realtek Corporation )
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [9216 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
U5 usbser; C:\Windows\System32\Drivers\usbser.sys [33280 2018-10-22] (Microsoft Windows -> Microsoft Corporation)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2012-01-09] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-06-02 19:24 - 2019-06-02 19:25 - 000000000 ____D C:\FRST
2019-06-02 19:22 - 2019-06-02 19:25 - 000000000 ____D C:\Users\z\Desktop\viry
2019-05-31 10:03 - 2019-05-31 10:03 - 000368036 _____ C:\Users\z\Desktop\Skenování1419.pdf
2019-05-30 12:30 - 2019-05-30 12:30 - 295618832 _____ C:\Users\z\Downloads\taky-vymetas-komin-sousedce-hlasuj-540p.mp4
2019-05-30 12:20 - 2019-05-30 12:21 - 305672174 _____ C:\Users\z\Downloads\delej-mrdej-brzy-se-vrati-domu-starej-4k-540p.mp4
2019-05-29 08:17 - 2019-05-29 08:18 - 371249620 _____ C:\Users\z\Downloads\milf-dvojcata-a-navic-jednovajecny-540p.mp4
2019-05-27 18:42 - 2019-05-29 09:24 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-05-27 18:39 - 2019-05-27 18:39 - 000363400 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2019-05-27 18:30 - 2019-05-27 18:25 - 000207184 _____ C:\Users\z\Desktop\narozky_50.zip
2019-05-27 18:25 - 2019-05-27 18:25 - 000207184 _____ C:\Users\z\Downloads\narozky_50.zip
2019-05-27 18:16 - 2019-06-02 18:39 - 000001306 _____ C:\Users\Public\Desktop\Skype.lnk
2019-05-27 18:12 - 2019-05-27 18:15 - 000308656 _____ C:\Windows\system32\FNTCACHE.DAT
2019-05-20 04:43 - 2019-05-20 04:43 - 000000991 _____ C:\Users\Public\Desktop\HiSuite.lnk
2019-05-20 04:43 - 2019-05-20 04:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite
2019-05-20 04:43 - 2018-10-22 05:15 - 000287232 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_quusbnet.sys
2019-05-20 04:43 - 2018-10-22 05:15 - 000226560 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_quusbmdm.sys
2019-05-20 04:43 - 2018-10-22 05:15 - 000127360 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_cdcacm.sys
2019-05-20 04:43 - 2018-10-22 05:15 - 000116864 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_usbdev.sys
2019-05-20 04:43 - 2018-10-22 05:15 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2019-05-20 04:43 - 2018-10-22 05:15 - 000018944 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbccgpfilter.sys
2019-05-20 04:42 - 2019-05-20 04:43 - 000000000 ____D C:\Program Files (x86)\HiSuite
2019-05-18 18:52 - 2019-05-18 18:52 - 000068774 _____ C:\Users\z\Desktop\document.pdf
2019-05-17 09:27 - 2019-05-17 09:27 - 000020650 _____ C:\Users\z\Desktop\Charlie_The_Bomber_+Tom_Jegr_and_Gang.pdf
2019-05-17 07:54 - 2019-05-17 07:55 - 294821663 _____ C:\Users\z\Downloads\automaticka-sukaci-linka-540p.mp4
2019-05-11 11:08 - 2019-05-11 11:08 - 000001742 _____ C:\Users\Public\Desktop\Webium's Modpack.lnk
2019-05-11 11:07 - 2019-05-11 11:07 - 124183207 _____ (myWOTmods.com ) C:\Users\z\Downloads\webium-WOT-1.5.0.0_modpack-installer-v00.exe
2019-05-09 12:15 - 2019-05-09 12:15 - 002390850 _____ C:\Users\z\Desktop\Vsechno_bylo_jinak-Viktor_Suvorov.pdf
2019-05-03 19:04 - 2019-05-03 19:03 - 000109530 _____ C:\Users\z\Downloads\Tisk_CP.pdf

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-06-02 19:04 - 2016-09-26 08:52 - 000000000 ____D C:\Users\z\AppData\Local\Battle.net
2019-06-02 18:48 - 2016-09-18 21:59 - 000000000 ____D C:\ProgramData\NVIDIA
2019-06-02 18:48 - 2009-07-14 06:45 - 000021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-06-02 18:48 - 2009-07-14 06:45 - 000021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-06-02 18:47 - 2016-11-18 07:11 - 000000000 ____D C:\Users\z\AppData\LocalLow\Mozilla
2019-06-02 18:46 - 2016-10-30 12:27 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2019-06-02 18:46 - 2016-09-22 19:46 - 000000000 ____D C:\Users\z\AppData\Roaming\Samsung
2019-06-02 18:45 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2019-06-02 18:39 - 2018-03-04 12:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-06-02 18:38 - 2016-09-22 19:55 - 000000000 ____D C:\Users\z\AppData\Roaming\BitTorrent
2019-06-02 18:35 - 2018-05-15 19:19 - 000000000 ___RD C:\Users\z\Disk Google
2019-06-02 18:34 - 2017-12-25 12:00 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-06-02 18:33 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-06-02 18:31 - 2016-09-22 20:17 - 000000000 ____D C:\ProgramData\AVAST Software
2019-06-02 08:05 - 2016-09-26 08:50 - 000000000 ____D C:\Users\z\AppData\Roaming\Battle.net
2019-06-02 07:05 - 2016-09-26 08:51 - 000000000 ____D C:\Program Files (x86)\Battle.net
2019-05-31 08:54 - 2016-09-26 08:59 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2019-05-30 20:46 - 2016-09-22 20:05 - 000000000 ____D C:\Users\z\AppData\Roaming\vlc
2019-05-30 20:06 - 2018-05-15 19:14 - 000003386 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-05-30 20:06 - 2018-05-15 19:14 - 000003258 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-05-30 20:06 - 2018-04-15 13:22 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-05-30 20:06 - 2018-04-15 13:22 - 000002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2019-05-30 20:06 - 2018-03-04 12:09 - 000003380 _____ C:\Windows\System32\Tasks\WinZip Update Notifier
2019-05-30 20:06 - 2017-10-17 11:17 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:17 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:17 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:16 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:16 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:16 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:16 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2017-10-17 11:16 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-05-30 20:06 - 2016-10-21 08:47 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-05-30 20:06 - 2016-09-22 20:18 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2019-05-30 10:40 - 2016-09-22 20:18 - 000385880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2019-05-30 08:20 - 2011-04-12 10:34 - 000686650 _____ C:\Windows\system32\perfh005.dat
2019-05-30 08:20 - 2011-04-12 10:34 - 000148824 _____ C:\Windows\system32\perfc005.dat
2019-05-30 08:20 - 2009-07-14 07:13 - 001636058 _____ C:\Windows\system32\PerfStringBackup.INI
2019-05-29 09:32 - 2017-03-03 00:23 - 000004168 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2019-05-29 09:24 - 2016-12-06 10:00 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-05-28 20:00 - 2019-04-17 19:00 - 000003732 _____ C:\Windows\System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2019-05-28 20:00 - 2019-04-17 19:00 - 000003150 _____ C:\Windows\System32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2019-05-28 20:00 - 2018-04-05 10:54 - 000002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2019-05-28 19:23 - 2016-12-27 21:37 - 000000000 ____D C:\Users\z\Downloads\torenty
2019-05-27 19:01 - 2016-10-21 08:46 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-05-27 18:39 - 2018-10-23 08:21 - 000042288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2019-05-27 18:39 - 2017-12-22 10:20 - 000279120 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2019-05-27 18:39 - 2016-09-22 20:18 - 000477584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2019-05-27 18:39 - 2016-09-22 20:18 - 000225096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2019-05-27 18:39 - 2016-09-22 20:18 - 000167872 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2019-05-27 18:39 - 2016-09-22 20:18 - 000112312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2019-05-27 18:39 - 2016-09-22 20:18 - 000087944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2019-05-27 18:38 - 2019-01-16 18:40 - 000262496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2019-05-27 18:38 - 2019-01-16 18:40 - 000205848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2019-05-27 18:38 - 2019-01-16 18:40 - 000061472 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2019-05-27 18:38 - 2019-01-16 18:40 - 000037104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2019-05-27 18:38 - 2017-11-18 05:26 - 000207448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2019-05-27 18:38 - 2016-09-22 20:18 - 001030784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2019-05-20 04:44 - 2018-02-14 15:11 - 000000000 ____D C:\Users\z\AppData\Local\Hisuite
2019-05-19 15:20 - 2016-09-22 22:39 - 000000000 ____D C:\Users\z\AppData\Local\CrashDumps
2019-05-18 21:44 - 2016-09-22 23:25 - 000000000 ____D C:\Users\z\dwhelper
2019-05-17 13:09 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2019-05-17 09:34 - 2016-11-16 15:02 - 000000000 ____D C:\Users\z\Documents\HOKNA
2019-05-11 11:08 - 2016-09-22 20:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\webium's modpack

==================== Files in the root of some directories =======

2016-09-22 20:04 - 2016-09-22 20:04 - 031717016 _____ () C:\Users\z\Instalaca.exe

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)


LastRegBack: 2019-06-02 00:15
==================== End of FRST.txt ============================

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Nabouraný mail.

#2 Příspěvek od Conder »

Ahoj :)

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
  • Nechaj zaskrtnute vsetky nalezy
  • Klikni na Cisteni a opravy (Clean and Repair) a potvrd restart PC teraz
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah sem skopiruj
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

neb251
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 02 čer 2019 18:15

Re: Nabouraný mail.

#3 Příspěvek od neb251 »

Díky za rychlou nápovědu. Jsou tam dva tak doufám že tenhle je ten správnej. :thumbsup:

# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-05-27.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 06-02-2019
# Duration: 00:00:05
# OS: Windows 7 Home Premium
# Cleaned: 7
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Users\Public\Documents\Downloaded Installers
Deleted C:\Users\z\AppData\Roaming\Seznam.cz

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cz.seznam.software.szndesktop
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SeznamInstall
Deleted HKCU\Software\Mozilla\NativeMessagingHosts\sznpp_nm
Deleted HKCU\Software\Seznam.cz
Deleted HKLM\Software\Wow6432Node\SlimWare Utilities Inc

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1783 octets] - [02/06/2019 20:00:05]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

neb251
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 02 čer 2019 18:15

Re: Nabouraný mail.

#4 Příspěvek od neb251 »

pro jistotu ještě ten druhej :-)

# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-05-27.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 06-02-2019
# Duration: 00:00:43
# OS: Windows 7 Home Premium
# Scanned: 27501
# Detected: 7


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy C:\Users\Public\Documents\Downloaded Installers
PUP.Optional.Seznam.cz C:\Users\z\AppData\Roaming\Seznam.cz

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Seznam.cz HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cz.seznam.software.szndesktop
PUP.Optional.Seznam.cz HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SeznamInstall
PUP.Optional.Seznam.cz HKCU\Software\Mozilla\NativeMessagingHosts\sznpp_nm
PUP.Optional.Seznam.cz HKCU\Software\Seznam.cz
PUP.Optional.SlimCleanerPlus HKLM\Software\Wow6432Node\SlimWare Utilities Inc

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Nabouraný mail.

#5 Příspěvek od Conder »

:arrow: Poprosim o obidva nove logy z FRST.
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Odpovědět