Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

iStartSurf

Návody, recenze, diskuze, řešení problémů

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Wratan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 srp 2014 17:39

iStartSurf

#1 Příspěvek od Wratan »

Zdravím, dnes se mi v nb vyskytla tato potvůrka, kterou jsem si tam zatáhl pravděpodobně neopatrným stažením torrentu z neověřeného zdroje. Neustále běží na pozadí a tváří se jako program a při spuštění prohlížeče mi otevírá další záložku se štítkem IStartSurf. Snažil jsem se na internetu najít něco bližšího a pravděpodobně se jedná o nějakou stejnojmennou havěť, ale nevím si s ní rady jak jí odstranit, aby mi nezpomalovala prohlížeč a neohrožovala bezpečnost prohlížení.. Předem děkuji za radu :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: iStartSurf

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Pro zacatek dejte log z FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Wratan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 srp 2014 17:39

Re: iStartSurf

#3 Příspěvek od Wratan »

Doufám, že přikládám správný log. :)

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-08-2014
Ran by Vratislav (administrator) on VRATISLAV-PC on 07-08-2014 19:33:14
Running from C:\Users\Vratislav\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
() C:\Program Files (x86)\SupTab\HpUI.exe
() C:\Program Files (x86)\SupTab\Loader32.exe
() C:\Program Files (x86)\SupTab\Loader64.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-17] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-07] (AVAST Software)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKU\S-1-5-21-857389507-1624657458-2295153863-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... R2674R2674
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... R2674R2674
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... R2674R2674
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... R2674R2674
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... R2674R2674
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll No File
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-31]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/", "hxxp://www.istartsurf.com/?type=hp&ts=14074217 ... R2674R2674"
CHR Extension: (Dokumenty Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-31]
CHR Extension: (Disk Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-31]
CHR Extension: (YouTube) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-31]
CHR Extension: (Vyhledávání Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-31]
CHR Extension: (ssave net) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi [2014-04-21]
CHR Extension: (avast! Online Security) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-10-31]
CHR Extension: (Peněženka Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-31]
CHR Extension: (Quick start) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-08-07]
CHR Extension: (Gmail) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-31]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-07]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-07]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-03-26] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-07] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [694784 2014-08-07] (Cherished Technololgy LIMITED) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-18] ()
S2 Update trolatunt; "C:\Program Files (x86)\trolatunt\updatetrolatunt.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-07] ()
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-12-02] (Duplex Secure Ltd.)
U3 a0ab31re; C:\Windows\System32\Drivers\a0ab31re.sys [0 ] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-07 19:33 - 2014-08-07 19:33 - 00017784 _____ () C:\Users\Vratislav\Desktop\FRST.txt
2014-08-07 19:32 - 2014-08-07 19:33 - 00000000 ____D () C:\FRST
2014-08-07 19:32 - 2014-08-07 19:32 - 02094080 _____ (Farbar) C:\Users\Vratislav\Desktop\FRST64.exe
2014-08-07 18:43 - 2014-08-07 18:43 - 545128340 _____ () C:\Windows\MEMORY.DMP
2014-08-07 18:43 - 2014-08-07 18:43 - 00262144 _____ () C:\Windows\Minidump\080714-32417-01.dmp
2014-08-07 18:36 - 2014-08-07 18:36 - 00000000 ____D () C:\Windows\ERUNT
2014-08-07 16:54 - 2014-08-07 16:54 - 00000000 _____ () C:\autoexec.bat
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieUserList
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieSiteList
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-08-07 16:52 - 2014-08-07 18:37 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-08-07 16:39 - 2014-08-07 18:43 - 00000168 _____ () C:\Windows\setupact.log
2014-08-07 16:39 - 2014-08-07 16:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-07 16:38 - 2014-08-07 16:38 - 00004580 _____ () C:\Windows\PFRO.log
2014-08-07 16:36 - 2014-08-07 16:36 - 00029236 _____ () C:\Users\Vratislav\Documents\cc_20140807_163629.reg
2014-08-07 16:29 - 2014-08-07 16:29 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-08-07 16:29 - 2014-08-07 16:29 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-08-07 16:29 - 2014-08-07 16:29 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-08-07 16:28 - 2014-08-07 16:37 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Seznam.cz
2014-08-07 16:28 - 2014-08-07 16:37 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-08-07 16:28 - 2014-08-07 16:31 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CatalinaGroup
2014-08-07 16:28 - 2014-08-07 16:28 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\MaxiGet Download Manager
2014-08-07 16:27 - 2014-08-07 16:38 - 00000000 ____D () C:\Program Files (x86)\trolatunt
2014-08-07 13:11 - 2014-08-07 13:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-07 13:11 - 2014-08-07 13:11 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-31 15:28 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-31 15:28 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-07-31 15:28 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-31 15:28 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-07-31 15:28 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-07-31 15:28 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-07-31 15:28 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-07-31 15:28 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-07-31 15:28 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-07-20 10:48 - 2014-07-20 10:48 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CrashRpt
2014-07-20 10:22 - 2014-07-28 14:37 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\wf-launcher
2014-07-20 10:22 - 2014-07-28 14:21 - 00000000 ____D () C:\ProgramData\GFACE
2014-07-18 17:18 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-18 17:17 - 2014-07-18 17:17 - 00004114 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 17:17 - 2014-07-18 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-18 17:17 - 2014-07-11 03:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-18 17:17 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-18 17:17 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-10 16:22 - 2014-07-12 09:50 - 00000000 ____D () C:\Users\Vratislav\Desktop\Shiro2_Client_2014
2014-07-09 16:06 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 16:06 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 16:06 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 16:06 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 16:06 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 16:06 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 16:06 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 16:06 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 16:06 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 16:06 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 16:06 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 16:06 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 16:06 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 16:06 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 16:06 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 16:06 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 16:06 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 16:06 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 16:06 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 16:06 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 16:06 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 16:06 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 16:06 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 16:06 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 16:06 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 16:06 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 16:06 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 16:06 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 16:06 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 16:06 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 16:06 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 16:06 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 16:06 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 16:06 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 16:06 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 16:06 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 16:06 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 16:06 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 16:06 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 16:06 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 16:05 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 16:05 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 16:05 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 16:05 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 16:05 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 16:05 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 16:05 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 16:05 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 16:05 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 16:05 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 16:05 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 16:05 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 16:05 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 16:05 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 16:05 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 16:05 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 16:05 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 16:05 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 16:05 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 16:05 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 16:05 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 16:05 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 16:05 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 16:05 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 16:05 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 16:05 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 16:03 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 16:03 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 16:03 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-07 19:33 - 2014-08-07 19:33 - 00017784 _____ () C:\Users\Vratislav\Desktop\FRST.txt
2014-08-07 19:33 - 2014-08-07 19:32 - 00000000 ____D () C:\FRST
2014-08-07 19:32 - 2014-08-07 19:32 - 02094080 _____ (Farbar) C:\Users\Vratislav\Desktop\FRST64.exe
2014-08-07 19:32 - 2013-10-31 18:49 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Skype
2014-08-07 19:05 - 2013-10-31 18:25 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-07 18:58 - 2013-10-31 18:41 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-07 18:50 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-07 18:50 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-07 18:46 - 2013-10-31 17:33 - 01166705 _____ () C:\Windows\WindowsUpdate.log
2014-08-07 18:43 - 2014-08-07 18:43 - 545128340 _____ () C:\Windows\MEMORY.DMP
2014-08-07 18:43 - 2014-08-07 18:43 - 00262144 _____ () C:\Windows\Minidump\080714-32417-01.dmp
2014-08-07 18:43 - 2014-08-07 16:39 - 00000168 _____ () C:\Windows\setupact.log
2014-08-07 18:43 - 2014-06-08 11:01 - 00000000 ____D () C:\Windows\Minidump
2014-08-07 18:43 - 2013-10-31 18:25 - 00000954 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-07 18:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-07 18:37 - 2014-08-07 16:52 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-08-07 18:36 - 2014-08-07 18:36 - 00000000 ____D () C:\Windows\ERUNT
2014-08-07 16:54 - 2014-08-07 16:54 - 00000000 _____ () C:\autoexec.bat
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieUserList
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieSiteList
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-08-07 16:42 - 2013-10-31 17:34 - 00001393 _____ () C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-07 16:39 - 2014-08-07 16:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-07 16:38 - 2014-08-07 16:38 - 00004580 _____ () C:\Windows\PFRO.log
2014-08-07 16:38 - 2014-08-07 16:27 - 00000000 ____D () C:\Program Files (x86)\trolatunt
2014-08-07 16:37 - 2014-08-07 16:28 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Seznam.cz
2014-08-07 16:37 - 2014-08-07 16:28 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-08-07 16:36 - 2014-08-07 16:36 - 00029236 _____ () C:\Users\Vratislav\Documents\cc_20140807_163629.reg
2014-08-07 16:33 - 2014-05-30 10:59 - 00000000 ____D () C:\ProgramData\Origin
2014-08-07 16:33 - 2013-10-31 21:09 - 00000000 ___RD () C:\Users\Vratislav\Desktop\Hry
2014-08-07 16:32 - 2013-10-31 18:52 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-07 16:32 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-07 16:31 - 2014-08-07 16:28 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CatalinaGroup
2014-08-07 16:31 - 2013-10-31 17:38 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-07 16:30 - 2014-05-13 09:04 - 00000000 ____D () C:\Program Files (x86)\Phenomedia AG
2014-08-07 16:29 - 2014-08-07 16:29 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-08-07 16:29 - 2014-08-07 16:29 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-08-07 16:29 - 2014-08-07 16:29 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-08-07 16:29 - 2014-05-13 09:09 - 00000000 ____D () C:\Phenomedia AG
2014-08-07 16:28 - 2014-08-07 16:28 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\MaxiGet Download Manager
2014-08-07 16:20 - 2013-10-31 22:18 - 00000000 ____D () C:\Users\Vratislav\Downloads\Gameforge Live
2014-08-07 14:25 - 2013-10-31 18:36 - 00000000 ____D () C:\Users\Vratislav\Desktop\Programy
2014-08-07 13:12 - 2013-10-31 18:11 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-07 13:11 - 2014-08-07 13:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-07 13:11 - 2014-08-07 13:11 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-07 13:11 - 2013-12-29 00:16 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-08-07 13:11 - 2013-11-13 09:40 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-07 13:11 - 2013-10-31 18:11 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-07 13:11 - 2013-10-31 18:11 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-07 12:50 - 2013-10-31 18:48 - 00000000 ____D () C:\ProgramData\Skype
2014-08-07 12:48 - 2013-10-31 20:53 - 00000000 ___RD () C:\Users\Vratislav\Desktop\Filmy
2014-08-06 23:20 - 2013-11-16 12:41 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\uTorrent
2014-08-06 22:00 - 2011-04-12 10:34 - 00668790 _____ () C:\Windows\system32\perfh005.dat
2014-08-06 22:00 - 2011-04-12 10:34 - 00141418 _____ () C:\Windows\system32\perfc005.dat
2014-08-06 22:00 - 2009-07-14 07:13 - 01583214 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-06 12:39 - 2013-11-04 11:39 - 00000000 ____D () C:\Temp
2014-08-01 10:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-29 18:52 - 2014-03-05 16:29 - 00000000 ____D () C:\Users\Vratislav\Desktop\Seriály
2014-07-28 15:41 - 2013-12-13 19:58 - 00072192 ___SH () C:\Users\Vratislav\Documents\Thumbs.db
2014-07-28 14:37 - 2014-07-20 10:22 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\wf-launcher
2014-07-28 14:21 - 2014-07-20 10:22 - 00000000 ____D () C:\ProgramData\GFACE
2014-07-25 15:59 - 2013-10-31 18:49 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-07-20 10:48 - 2014-07-20 10:48 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CrashRpt
2014-07-18 17:18 - 2013-11-02 22:46 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-18 17:17 - 2014-07-18 17:17 - 00004114 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 17:17 - 2014-07-18 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-18 17:17 - 2013-11-02 22:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-12 09:50 - 2014-07-10 16:22 - 00000000 ____D () C:\Users\Vratislav\Desktop\Shiro2_Client_2014
2014-07-11 03:02 - 2014-07-18 17:17 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-11 02:56 - 2014-07-18 17:18 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-11 02:56 - 2014-07-18 17:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-11 02:55 - 2014-07-18 17:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-09 21:50 - 2009-07-14 06:45 - 00419872 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 21:48 - 2014-05-06 16:27 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-09 21:48 - 2011-04-12 10:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 21:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-09 21:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 17:41 - 2013-11-01 11:47 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 17:39 - 2013-11-01 11:46 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 16:08 - 2013-11-20 23:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

Some content of TEMP:
====================
C:\Users\Vratislav\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Vratislav\AppData\Local\Temp\SHSetup.exe
C:\Users\Vratislav\AppData\Local\Temp\trolatuntSetup.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9712.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9713.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9714.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9715.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9716.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9717.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9728.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT9729.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT972A.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\UNT972B.tmp.exe
C:\Users\Vratislav\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-07 13:46

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: iStartSurf

#4 Příspěvek od vyosek »

:arrow: Log je v poradku

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Wratan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 srp 2014 17:39

Re: iStartSurf

#5 Příspěvek od Wratan »

JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Vratislav on źt 07.08.2014 at 23:10:21,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dttoolbar.toolbandobj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dttoolbar.toolbandobj.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 07.08.2014 at 23:22:38,20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Wratan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 srp 2014 17:39

Re: iStartSurf

#6 Příspěvek od Wratan »

S tím AdwCleanerem mám problém, proběhne Scan vše v pořádku, ale když dám Clean ten proběhne jen do poloviny a poté se objeví chybová hláška s tím, že program přestal pracovat.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: iStartSurf

#7 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Wratan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 srp 2014 17:39

Re: iStartSurf

#8 Příspěvek od Wratan »

Zoek log Nechci soudit podle prvotních dojmů, ale řekl bych že verbež je odstraněna, zmizela celá složka kde ten program byl dokonce se už ani nespouští dole na liště a při spuštění prohlížeče se nic dalšího neobjevuje..


Zoek.exe v5.0.0.0 Updated 04-August-2014
Tool run by Vratislav on p  08.08.2014 at 11:38:40,19.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Vratislav\Desktop\zoek\zoek.scr [Scan all users] [Script inserted]

==== System Restore Info ======================

8.8.2014 11:52:45 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~3\InstallMate deleted
C:\Users\Vratislav\AppData\Local\MaxiGet Download Manager deleted
C:\Users\Vratislav\Searches deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
"C:\PROGRA~3\186e7649c6c80a54\{7DD5E91C-3864-77EC-7635-D14910C2A03E}" deleted
"C:\PROGRA~3\186e7649c6c80a54\{7DD5E91C-3864-77EC-7635-D14910C2A03E}.old" deleted
"C:\PROGRA~3\186e7649c6c80a54" deleted
"C:\Users\Vratislav\AppData\Roaming\Vso" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [07.08.2014 13:11]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[07.08.2014 13:11]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14.07.2014 18:22]

ssave net - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
ssave net - Vratislav\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi
avast Online Security - Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
ssave net - Vratislav\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi

==== Chromium Startpages ======================

C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com/",
"startup_urls": [ "http://www.google.com/" ],


==== Chrome Fix ======================

C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Vratislav\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully
C:\Users\Vratislav\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gapghbnkalnnjlbaekkedlcpacefpomi deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"

==== Reset Google Chrome ======================

C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vratislav\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Vratislav\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=86 folders=32 669843 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Vratislav\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\VRATIS~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on p  08.08.2014 at 12:27:30,87 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: iStartSurf

#9 Příspěvek od vyosek »

Poprosim o novy log z FRST a docistime zbytecky
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Wratan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 07 srp 2014 17:39

Re: iStartSurf

#10 Příspěvek od Wratan »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-08-2014 01
Ran by Vratislav (administrator) on VRATISLAV-PC on 09-08-2014 22:26:58
Running from C:\Users\Vratislav\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-17] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-07] (AVAST Software)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKU\S-1-5-21-857389507-1624657458-2295153863-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-31]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Dokumenty Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-31]
CHR Extension: (Disk Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-31]
CHR Extension: (YouTube) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-31]
CHR Extension: (Vyhledávání Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-31]
CHR Extension: (Peněženka Google) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-31]
CHR Extension: (Gmail) - C:\Users\Vratislav\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-31]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-07]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-03-26] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-07] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-18] ()

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-07] ()
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-12-02] (Duplex Secure Ltd.)
U3 acm60fbq; C:\Windows\System32\Drivers\acm60fbq.sys [0 ] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-09 22:26 - 2014-08-09 22:26 - 00013233 _____ () C:\Users\Vratislav\Desktop\FRST.txt
2014-08-09 22:26 - 2014-08-09 22:26 - 00000000 ____D () C:\Users\Vratislav\Desktop\FRST-OlderVersion
2014-08-09 22:22 - 2014-08-09 22:26 - 33685914 _____ () C:\Users\Vratislav\Desktop\Assassins-Creed-2-Brotherhood-CZ-titulky-ISO.rar.6822863971942093231.part
2014-08-08 12:12 - 2014-02-13 23:59 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-08 11:52 - 2014-08-08 12:27 - 00010290 _____ () C:\zoek-results.log
2014-08-08 11:35 - 2014-08-08 12:27 - 00000000 ____D () C:\zoek_backup
2014-08-07 23:24 - 2014-08-07 23:39 - 00000000 ____D () C:\AdwCleaner
2014-08-07 19:32 - 2014-08-09 22:27 - 00000000 ____D () C:\FRST
2014-08-07 19:32 - 2014-08-09 22:26 - 02093568 _____ (Farbar) C:\Users\Vratislav\Desktop\FRST64.exe
2014-08-07 18:43 - 2014-08-07 18:43 - 545128340 _____ () C:\Windows\MEMORY.DMP
2014-08-07 18:43 - 2014-08-07 18:43 - 00262144 _____ () C:\Windows\Minidump\080714-32417-01.dmp
2014-08-07 18:36 - 2014-08-07 18:36 - 00000000 ____D () C:\Windows\ERUNT
2014-08-07 16:54 - 2014-08-07 16:54 - 00000000 _____ () C:\autoexec.bat
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieUserList
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieSiteList
2014-08-07 16:52 - 2014-08-07 18:37 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-08-07 16:39 - 2014-08-09 18:06 - 00000672 _____ () C:\Windows\setupact.log
2014-08-07 16:39 - 2014-08-07 16:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-07 16:38 - 2014-08-08 12:27 - 00005138 _____ () C:\Windows\PFRO.log
2014-08-07 16:36 - 2014-08-07 16:36 - 00029236 _____ () C:\Users\Vratislav\Documents\cc_20140807_163629.reg
2014-08-07 16:28 - 2014-08-07 16:37 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Seznam.cz
2014-08-07 16:28 - 2014-08-07 16:37 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-08-07 16:28 - 2014-08-07 16:31 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CatalinaGroup
2014-08-07 13:11 - 2014-08-07 13:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-07 13:11 - 2014-08-07 13:11 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-31 15:28 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-31 15:28 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-07-31 15:28 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-07-31 15:28 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-31 15:28 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-07-31 15:28 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-07-31 15:28 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-07-31 15:28 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-07-31 15:28 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-07-31 15:28 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-07-20 10:48 - 2014-07-20 10:48 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CrashRpt
2014-07-20 10:22 - 2014-07-28 14:37 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\wf-launcher
2014-07-20 10:22 - 2014-07-28 14:21 - 00000000 ____D () C:\ProgramData\GFACE
2014-07-18 17:18 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-18 17:17 - 2014-07-18 17:17 - 00004114 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 17:17 - 2014-07-18 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-18 17:17 - 2014-07-11 03:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-18 17:17 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-18 17:17 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-10 16:22 - 2014-07-12 09:50 - 00000000 ____D () C:\Users\Vratislav\Desktop\Shiro2_Client_2014

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-09 22:27 - 2014-08-09 22:26 - 00013233 _____ () C:\Users\Vratislav\Desktop\FRST.txt
2014-08-09 22:27 - 2014-08-07 19:32 - 00000000 ____D () C:\FRST
2014-08-09 22:27 - 2013-10-31 21:09 - 00000000 ___RD () C:\Users\Vratislav\Desktop\Hry
2014-08-09 22:26 - 2014-08-09 22:26 - 00000000 ____D () C:\Users\Vratislav\Desktop\FRST-OlderVersion
2014-08-09 22:26 - 2014-08-09 22:22 - 33685914 _____ () C:\Users\Vratislav\Desktop\Assassins-Creed-2-Brotherhood-CZ-titulky-ISO.rar.6822863971942093231.part
2014-08-09 22:26 - 2014-08-07 19:32 - 02093568 _____ (Farbar) C:\Users\Vratislav\Desktop\FRST64.exe
2014-08-09 22:23 - 2013-10-31 18:49 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Skype
2014-08-09 22:23 - 2013-10-31 18:41 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-09 22:05 - 2013-10-31 18:25 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-09 18:14 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-09 18:14 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-09 18:06 - 2014-08-07 16:39 - 00000672 _____ () C:\Windows\setupact.log
2014-08-09 18:06 - 2013-10-31 18:25 - 00000954 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-09 18:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-09 15:29 - 2013-10-31 17:33 - 01243321 _____ () C:\Windows\WindowsUpdate.log
2014-08-09 10:28 - 2013-11-13 09:40 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-08 20:12 - 2014-01-06 19:27 - 00000000 ____D () C:\Users\Vratislav\Desktop\Výzva 21dní+trenink
2014-08-08 15:28 - 2011-04-12 10:34 - 00668790 _____ () C:\Windows\system32\perfh005.dat
2014-08-08 15:28 - 2011-04-12 10:34 - 00141418 _____ () C:\Windows\system32\perfc005.dat
2014-08-08 15:28 - 2009-07-14 07:13 - 01583214 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-08 13:45 - 2013-10-31 22:18 - 00000000 ____D () C:\Users\Vratislav\Downloads\Gameforge Live
2014-08-08 12:27 - 2014-08-08 11:52 - 00010290 _____ () C:\zoek-results.log
2014-08-08 12:27 - 2014-08-08 11:35 - 00000000 ____D () C:\zoek_backup
2014-08-08 12:27 - 2014-08-07 16:38 - 00005138 _____ () C:\Windows\PFRO.log
2014-08-08 12:08 - 2013-10-31 17:33 - 00000000 ____D () C:\Users\Vratislav
2014-08-07 23:39 - 2014-08-07 23:24 - 00000000 ____D () C:\AdwCleaner
2014-08-07 18:43 - 2014-08-07 18:43 - 545128340 _____ () C:\Windows\MEMORY.DMP
2014-08-07 18:43 - 2014-08-07 18:43 - 00262144 _____ () C:\Windows\Minidump\080714-32417-01.dmp
2014-08-07 18:43 - 2014-06-08 11:01 - 00000000 ____D () C:\Windows\Minidump
2014-08-07 18:37 - 2014-08-07 16:52 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-08-07 18:36 - 2014-08-07 18:36 - 00000000 ____D () C:\Windows\ERUNT
2014-08-07 16:54 - 2014-08-07 16:54 - 00000000 _____ () C:\autoexec.bat
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieUserList
2014-08-07 16:53 - 2014-08-07 16:53 - 00000000 __SHD () C:\Users\Vratislav\AppData\Local\EmieSiteList
2014-08-07 16:42 - 2013-10-31 17:34 - 00001393 _____ () C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-07 16:39 - 2014-08-07 16:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-07 16:37 - 2014-08-07 16:28 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Seznam.cz
2014-08-07 16:37 - 2014-08-07 16:28 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-08-07 16:36 - 2014-08-07 16:36 - 00029236 _____ () C:\Users\Vratislav\Documents\cc_20140807_163629.reg
2014-08-07 16:33 - 2014-05-30 10:59 - 00000000 ____D () C:\ProgramData\Origin
2014-08-07 16:32 - 2013-10-31 18:52 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-07 16:32 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-07 16:31 - 2014-08-07 16:28 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CatalinaGroup
2014-08-07 16:31 - 2013-10-31 17:38 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-07 16:30 - 2014-05-13 09:04 - 00000000 ____D () C:\Program Files (x86)\Phenomedia AG
2014-08-07 16:29 - 2014-05-13 09:09 - 00000000 ____D () C:\Phenomedia AG
2014-08-07 14:25 - 2013-10-31 18:36 - 00000000 ____D () C:\Users\Vratislav\Desktop\Programy
2014-08-07 13:12 - 2013-10-31 18:11 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-07 13:11 - 2014-08-07 13:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-07 13:11 - 2014-08-07 13:11 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-07 13:11 - 2013-12-29 00:16 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-07 13:11 - 2013-10-31 18:11 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-07 13:11 - 2013-10-31 18:11 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-07 12:50 - 2013-10-31 18:48 - 00000000 ____D () C:\ProgramData\Skype
2014-08-07 12:48 - 2013-10-31 20:53 - 00000000 ___RD () C:\Users\Vratislav\Desktop\Filmy
2014-08-06 23:20 - 2013-11-16 12:41 - 00000000 ____D () C:\Users\Vratislav\AppData\Roaming\uTorrent
2014-08-06 12:39 - 2013-11-04 11:39 - 00000000 ____D () C:\Temp
2014-08-01 10:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-29 18:52 - 2014-03-05 16:29 - 00000000 ____D () C:\Users\Vratislav\Desktop\Seriály
2014-07-28 15:41 - 2013-12-13 19:58 - 00072192 ___SH () C:\Users\Vratislav\Documents\Thumbs.db
2014-07-28 14:37 - 2014-07-20 10:22 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\wf-launcher
2014-07-28 14:21 - 2014-07-20 10:22 - 00000000 ____D () C:\ProgramData\GFACE
2014-07-25 15:59 - 2013-10-31 18:49 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-07-20 10:48 - 2014-07-20 10:48 - 00000000 ____D () C:\Users\Vratislav\AppData\Local\CrashRpt
2014-07-18 17:18 - 2013-11-02 22:46 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-18 17:17 - 2014-07-18 17:17 - 00004114 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 17:17 - 2014-07-18 17:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-18 17:17 - 2013-11-02 22:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-12 09:50 - 2014-07-10 16:22 - 00000000 ____D () C:\Users\Vratislav\Desktop\Shiro2_Client_2014
2014-07-11 03:02 - 2014-07-18 17:17 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-11 02:56 - 2014-07-18 17:18 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-11 02:56 - 2014-07-18 17:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-11 02:55 - 2014-07-18 17:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-07 13:46

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: iStartSurf

#11 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
    HKU\S-1-5-21-857389507-1624657458-2295153863-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
    
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
    SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
    Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
    
    FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
    
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
    
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
    C:\Program Files (x86)\Skype\Toolbars
    
    S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
    S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
    C:\Program Files\Enigma Software Group
    
    2014-08-09 22:26 - 2014-08-09 22:26 - 00013233 _____ () C:\Users\Vratislav\Desktop\FRST.txt
    2014-08-09 22:26 - 2014-08-09 22:26 - 00000000 ____D () C:\Users\Vratislav\Desktop\FRST-OlderVersion
    2014-08-08 12:12 - 2014-02-13 23:59 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2014-08-08 11:52 - 2014-08-08 12:27 - 00010290 _____ () C:\zoek-results.log
    2014-08-08 11:35 - 2014-08-08 12:27 - 00000000 ____D () C:\zoek_backup
    2014-08-07 23:24 - 2014-08-07 23:39 - 00000000 ____D () C:\AdwCleaner
    2014-08-07 19:32 - 2014-08-09 22:27 - 00000000 ____D () C:\FRST
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět