Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o pomoc zavirovaný počítač aniž jsem chtěl

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#1 Příspěvek od honzikuh »

Stahnul jsem program android data recovery a nainstalovalo se mi mnoho čínských programů něco už jsem odstranil, ale jednu chvíli mne to blokovalo přístup na net

Logfile of random's system information tool 1.10 (written by random/random)
Run by Honza at 2015-08-06 19:39:56
Microsoft Windows 8.1 Pro s aplikací Media Center
System drive C: has 17 GB (8%) free of 205 GB
Total RAM: 8190 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:40:08, on 6.8.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCTray.exe
C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\plugins\QMNetMon\QQPCNetFlow.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCRealTimeSpeedup.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Users\Honza\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
C:\IQIYI Video\Common\QyKernel.exe
C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files (x86)\Rising\RSD\popwndexe.exe
C:\PROGRAM FILES (X86)\RISING\RAV\RSTRAY.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\qmspeedupplugin\phonerocket\dock_5.7.0.2\QQPCPhoneDock.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Program Files\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91072394_hao_pg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91072394_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://127.0.0.1:8088/ppsva.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O2 - BHO: °®ĆćŇŐÖúĘÖ - {FB4F6285-4C32-49F2-950F-A5998F9CEC6C} - C:\IQIYI Video\Common\Accelerator\IEHelper.dll
O4 - HKLM\..\Run: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ QQPCTray] "C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCTRAY.EXE" /regrun /qqrepair
O4 - HKLM\..\Run: [RSDTRAY] "C:\Program Files (x86)\Rising\RSD\popwndexe.exe"
O4 - HKLM\..\Run: [RavTRAY] "C:\Program Files (x86)\Rising\RAV\RSTRAY.EXE" -system
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [EPSON Stylus DX6000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S9473.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [LightShot] C:\Users\Honza\AppData\Local\Skillbrains\lightshot\Lightshot.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\baidu\baidu.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_290685FDE340642E7CB9D7EEDFD9E05D] "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
O4 - HKCU\..\Run: [HCDNClient] "C:\IQIYI Video\Common\QyKernel.exe" -shell_start
O4 - Startup: MEGAsync.lnk = Honza\AppData\Local\MEGAsync\MEGAsync.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - C:\Program Files (x86)\BitSpirit\bsurl.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Správce zabezpečení účtů 1.89.6 (appmgmts) - Unknown owner - C:\Users\Honza\AppData\Local\Sprvcezabezpeen\mssip32.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Check Service (fchk32) - Unknown owner - C:\Program Files\fchk32\fchk32.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: QQPCMgr RTP Service (QQPCRTP) - Tencent - C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCRTP.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Rsd Service (RsMgrSvc) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe
O23 - Service: Rav Service (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RAV\ravmond.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\WINDOWS\SysWOW64\ssins.exe
O23 - Service: TAOFrame - Tencent - C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TAOFrame.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12454 bytes

======Listing Processes======






wininit.exe
winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCRTP.exe" -r
"C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe"
"C:\Program Files (x86)\Rising\RAV\ravmond.exe"
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
atieclxx
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Users\Honza\AppData\Local\Sprvcezabezpeen\mssip32.exe" /s
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {2e7716f6-c6f3-4d93-bc458ee52f9c70c0}
"C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE"
"C:\Program Files\fchk32\fchk32.exe" /s iid=1635197 did=Missing sid= ref= id=d0f6f818f2a1d17efd9b0808f594377ce756bec89bf99f9b5ed6e4070c950c6f
taskhostex.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCTray.exe" /elevated /regrun
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
C:\WINDOWS\SysWOW64\ssins.exe
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\WINDOWS\system32\GWX\GWX.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" -Embedding
"C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\plugins\QMNetMon\QQPCNetFlow.exe" /regrun /elevated
"C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCRealTimeSpeedup.exe"
"C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TAOFrame.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\WinFast\WFDTV\WFWIZ.exe"
"C:\Users\Honza\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe"
"C:\IQIYI Video\Common\QyKernel.exe" -shell_start
"C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe"
"C:\Program Files\WinFast\WFDTV\DTVSchdl.exe"
"C:\Program Files (x86)\Rising\RSD\popwndexe.exe"
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\PROGRAM FILES (X86)\RISING\RAV\RSTRAY.EXE" -system
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.mystartsearch.com/?type=sc&t ... XX5QE1ZRYB
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --on-initialized-event-handle=420 --parent-handle=424
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5264.0.1592705627\2133745280" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6819 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.200.1062.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoId/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5264.3.1704254493\303056937" --font-cache-shared-handle=3176 /prefetch:673131151
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://www.mystartsearch.com/?type=sc&t ... XX5QE1ZRYB
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoId/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5264.7.1108491407\1710684068" --font-cache-shared-handle=5476 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoId/*RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5264.9.644922067\1930854093" --font-cache-shared-handle=4040 /prefetch:673131151

"C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
"C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\qmspeedupplugin\phonerocket\dock_5.7.0.2\QQPCPhoneDock.exe" update
"C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe" lng=1029
"C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe" "/base-dir=C:\Program Files (x86)\ESET\ESET Online Scanner" /lang=1029 /as
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Users\Honza\Downloads\RSITx64.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.malwarebytes.org/restorebro ... XX5QE1ZRYB"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@iqiyi.com/npclient]
"Description"=iQiyi Browser Plugin
"Path"=C:\IQIYI Video\LStyle\npclient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@iqiyi.com/npWebPlayer]
"Description"=pps-webplayer-plugin
"Path"=C:\IQIYI Video\LStyle\npWebPlayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/QQPCMgr]
"Description"=QQPCMgr Detector
"Path"=C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\npQMExtensionsMozilla.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rising.com.cn/nprising]
"Description"=
"Path"=C:\Program Files (x86)\Rising\RAV\nprising.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iqiyi.com/npclient]
"Description"=iQiyi Browser Plugin
"Path"=C:\IQIYI Video\LStyle\npclient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iqiyi.com/npWebPlayer]
"Description"=pps-webplayer-plugin
"Path"=C:\IQIYI Video\LStyle\npWebPlayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll


C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\searchplugins\
firmycz.xml
yahoo.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}]
电脑管家网页防火墙 - C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TSWebMon64.dat [2015-08-06 413536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-12 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-12 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}]
°®ĆćŇŐÖúĘÖ - C:\IQIYI Video\Common\Accelerator\IEHelper.dll [2015-04-29 326760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-05-09 13672152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2015-06-20 22012688]
"EPSON Stylus DX6000"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBIE.EXE [2007-10-05 213504]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2013-01-09 2916352]
"LightShot"=C:\Users\Honza\AppData\Local\Skillbrains\lightshot\Lightshot.exe [2014-11-18 226560]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-02-26 31344744]
"apphide"=C:\Program Files (x86)\baidu\baidu.exe []
"GoogleChromeAutoLaunch_290685FDE340642E7CB9D7EEDFD9E05D"=C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window []
"HCDNClient"=C:\IQIYI Video\Common\QyKernel.exe [2015-05-12 576104]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"iSkysoft Helper Compact.exe"=C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2014-08-05 2014208]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2014-03-04 103936]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-02-06 170496]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2015-06-17 421888]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-07-15 767176]
" QQPCTray"=C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCTRAY.EXE [2015-08-06 355296]
"RSDTRAY"=C:\Program Files (x86)\Rising\RSD\popwndexe.exe [2012-09-25 126808]
"RavTRAY"=C:\Program Files (x86)\Rising\RAV\RSTRAY.EXE [2014-05-15 111000]

C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-06 19:39:56 ----D---- C:\rsit
2015-08-06 19:39:02 ----D---- C:\Program Files (x86)\ESET
2015-08-06 19:29:22 ----A---- C:\WINDOWS\SYSWOW64\drivers\TS888x64.sys
2015-08-06 19:28:58 ----D---- C:\ProgramData\TXQMPC
2015-08-06 19:21:34 ----A---- C:\Users\Honza\AppData\Roaming\NQZOkL1VwF88UD.exe.lnk
2015-08-06 19:21:33 ----A---- C:\Users\Honza\AppData\Roaming\JaxnO0pi8PWQ.exe.lnk
2015-08-06 19:21:09 ----A---- C:\MAMB.txt
2015-08-06 19:19:46 ----D---- C:\ProgramData\KingSoft
2015-08-06 19:16:37 ----RSH---- C:\rising.ini
2015-08-06 19:16:36 ----RD---- C:\RavBin
2015-08-06 19:16:36 ----N---- C:\WINDOWS\SYSWOW64\vpatch.dll
2015-08-06 19:16:30 ----N---- C:\WINDOWS\SYSWOW64\ravext.dll
2015-08-06 19:16:30 ----N---- C:\WINDOWS\SYSWOW64\bsmain.exe
2015-08-06 19:16:30 ----N---- C:\WINDOWS\system32\ravext64.dll
2015-08-06 19:16:24 ----N---- C:\WINDOWS\system32\drivers\sysmon.sys
2015-08-06 19:16:24 ----N---- C:\WINDOWS\system32\drivers\rsutils.sys
2015-08-06 19:16:24 ----N---- C:\WINDOWS\system32\drivers\rsndisp.sys
2015-08-06 19:15:36 ----D---- C:\Program Files (x86)\Rising
2015-08-06 19:15:35 ----D---- C:\ProgramData\Rising
2015-08-06 19:14:51 ----A---- C:\WINDOWS\system32\drivers\TAOAccelerator64.sys
2015-08-06 19:14:47 ----D---- C:\Program Files\Common Files\Tencent
2015-08-06 19:14:32 ----A---- C:\WINDOWS\system32\drivers\TAOKernel64.sys
2015-08-06 19:14:30 ----A---- C:\WINDOWS\system32\drivers\TFsFltX64.sys
2015-08-06 19:13:39 ----D---- C:\Program Files (x86)\Tencent
2015-08-06 19:13:35 ----D---- C:\Users\Honza\AppData\Roaming\Tencent
2015-08-06 19:13:33 ----D---- C:\ProgramData\Tencent
2015-08-06 18:45:59 ----D---- C:\ProgramData\Systweak
2015-08-06 18:45:46 ----A---- C:\WINDOWS\system32\sasnative64.exe
2015-08-06 18:45:33 ----A---- C:\WINDOWS\system32\roboot64.exe
2015-08-06 18:45:18 ----D---- C:\Users\Honza\AppData\Roaming\systweak
2015-08-06 18:40:02 ----D---- C:\IQIYI Video
2015-08-06 18:39:00 ----D---- C:\Program Files (x86)\2ca13b38-0996-461b-8076-e78d4d2854b0
2015-08-06 18:38:42 ----D---- C:\Program Files (x86)\globalUpdate
2015-08-06 18:37:58 ----A---- C:\WINDOWS\prleth.sys
2015-08-06 18:37:58 ----A---- C:\WINDOWS\hgfs.sys
2015-08-06 18:27:50 ----D---- C:\Program Files\fchk32
2015-08-06 18:27:15 ----D---- C:\ProgramData\FonePaw
2015-08-06 18:27:10 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2015-08-06 18:15:25 ----D---- C:\TenorshareData
2015-08-05 05:21:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-02 19:55:01 ----D---- C:\Program Files (x86)\Android Data Recovery
2015-08-02 19:36:49 ----D---- C:\Program Files (x86)\Tenorshare Android Data Recovery
2015-08-02 06:27:35 ----D---- C:\ProgramData\ATI
2015-08-01 15:34:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-08-01 15:34:04 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-01 15:34:03 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-08-01 15:34:02 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-08-01 15:34:02 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-16 04:12:26 ----A---- C:\WINDOWS\system32\amdave64.dll
2015-07-16 04:12:24 ----A---- C:\WINDOWS\SYSWOW64\amdave32.dll
2015-07-16 04:12:20 ----A---- C:\WINDOWS\system32\amdmiracast.dll
2015-07-16 04:12:18 ----A---- C:\WINDOWS\system32\amdhcp64.dll
2015-07-16 04:12:14 ----A---- C:\WINDOWS\system32\atimpc64.dll
2015-07-16 04:12:12 ----A---- C:\WINDOWS\SYSWOW64\atimpc32.dll
2015-07-16 04:12:02 ----A---- C:\WINDOWS\system32\amdpcom64.dll
2015-07-16 04:12:00 ----A---- C:\WINDOWS\SYSWOW64\amdpcom32.dll
2015-07-16 04:11:52 ----A---- C:\WINDOWS\system32\atiu9p64.dll
2015-07-16 04:11:10 ----A---- C:\WINDOWS\system32\atiumd6a.dll
2015-07-16 04:11:06 ----A---- C:\WINDOWS\system32\atiumd64.dll
2015-07-16 04:09:00 ----A---- C:\WINDOWS\system32\drivers\amdacpksd.sys
2015-07-16 04:06:36 ----A---- C:\WINDOWS\system32\drivers\atikmdag.sys
2015-07-16 04:01:52 ----A---- C:\WINDOWS\system32\clinfo.exe
2015-07-16 04:01:46 ----A---- C:\WINDOWS\system32\amdocl64.dll
2015-07-16 04:00:38 ----A---- C:\WINDOWS\SYSWOW64\amdocl.dll
2015-07-16 03:59:34 ----A---- C:\WINDOWS\system32\OpenCL.dll
2015-07-16 03:59:32 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2015-07-16 03:58:02 ----A---- C:\WINDOWS\system32\amdocl12cl64.dll
2015-07-16 03:57:54 ----A---- C:\WINDOWS\SYSWOW64\amdocl12cl.dll
2015-07-16 03:35:18 ----A---- C:\WINDOWS\system32\mantle64.dll
2015-07-16 03:35:14 ----A---- C:\WINDOWS\SYSWOW64\mantle32.dll
2015-07-16 03:35:08 ----A---- C:\WINDOWS\system32\amdmantle64.dll
2015-07-16 03:30:36 ----A---- C:\WINDOWS\SYSWOW64\amdmantle32.dll
2015-07-16 03:29:20 ----A---- C:\WINDOWS\system32\amdhdl64.dll
2015-07-16 03:29:18 ----A---- C:\WINDOWS\SYSWOW64\amdhdl32.dll
2015-07-16 03:28:36 ----A---- C:\WINDOWS\system32\atio6axx.dll
2015-07-16 03:26:58 ----A---- C:\WINDOWS\system32\mantleaxl64.dll
2015-07-16 03:26:56 ----A---- C:\WINDOWS\SYSWOW64\mantleaxl32.dll
2015-07-16 03:25:04 ----A---- C:\WINDOWS\system32\amdmmcl6.dll
2015-07-16 03:25:02 ----A---- C:\WINDOWS\SYSWOW64\amdmmcl.dll
2015-07-16 03:22:52 ----A---- C:\WINDOWS\SYSWOW64\atioglxx.dll
2015-07-16 03:21:48 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2015-07-16 03:21:46 ----A---- C:\WINDOWS\SYSWOW64\aticalrt.dll
2015-07-16 03:21:46 ----A---- C:\WINDOWS\system32\aticalrt64.dll
2015-07-16 03:21:44 ----A---- C:\WINDOWS\system32\aticalcl64.dll
2015-07-16 03:21:42 ----A---- C:\WINDOWS\SYSWOW64\aticalcl.dll
2015-07-16 03:21:38 ----A---- C:\WINDOWS\system32\aticaldd64.dll
2015-07-16 03:20:46 ----A---- C:\WINDOWS\SYSWOW64\aticaldd.dll
2015-07-16 03:17:30 ----A---- C:\WINDOWS\system32\atidemgy.dll
2015-07-16 03:17:28 ----A---- C:\WINDOWS\system32\atieah64.exe
2015-07-16 03:17:26 ----A---- C:\WINDOWS\SYSWOW64\atieah32.exe
2015-07-16 03:17:26 ----A---- C:\WINDOWS\system32\amdgfxinfo64.dll
2015-07-16 03:17:24 ----A---- C:\WINDOWS\SYSWOW64\amdgfxinfo32.dll
2015-07-16 03:17:24 ----A---- C:\WINDOWS\system32\atimuixx.dll
2015-07-16 03:17:22 ----A---- C:\WINDOWS\system32\atieclxx.exe
2015-07-16 03:17:14 ----A---- C:\WINDOWS\system32\atiesrxx.exe
2015-07-16 03:17:00 ----A---- C:\WINDOWS\system32\atitmm64.dll
2015-07-16 03:15:04 ----A---- C:\WINDOWS\system32\atisamu64.dll
2015-07-16 03:15:00 ----A---- C:\WINDOWS\SYSWOW64\atisamu32.dll
2015-07-16 03:14:04 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2015-07-16 03:13:40 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2015-07-16 03:13:36 ----A---- C:\WINDOWS\SYSWOW64\atiadlxy.dll
2015-07-16 03:13:36 ----A---- C:\WINDOWS\SYSWOW64\atiadlxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\SYSWOW64\atiglpxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\system32\atiglpxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\system32\atig6pxx.dll
2015-07-16 03:13:30 ----A---- C:\WINDOWS\system32\atig6txx.dll
2015-07-16 03:13:28 ----A---- C:\WINDOWS\SYSWOW64\atigktxx.dll
2015-07-16 03:13:26 ----A---- C:\WINDOWS\system32\drivers\atikmpag.sys
2015-07-16 03:12:08 ----A---- C:\WINDOWS\system32\hsa-thunk64.dll
2015-07-16 03:12:06 ----A---- C:\WINDOWS\SYSWOW64\hsa-thunk.dll
2015-07-15 17:33:02 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 17:33:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 17:32:59 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\certcli.dll
2015-07-15 17:32:32 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 17:32:31 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 17:32:31 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 17:32:24 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 17:32:24 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 17:31:31 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 17:31:31 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 17:31:30 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 17:31:24 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-07-15 17:31:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 17:31:22 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-15 17:30:25 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-15 17:30:25 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-15 17:30:24 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-15 17:30:19 ----AC---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-15 17:30:18 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-15 17:30:16 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 17:30:15 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2015-07-15 17:30:09 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-15 17:30:07 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-07-15 17:30:06 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2015-07-15 17:30:06 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 17:29:41 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2015-07-15 17:29:39 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-15 17:29:37 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 17:29:25 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2015-07-15 17:29:25 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2015-07-15 17:29:25 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 17:29:23 ----A---- C:\WINDOWS\system32\drivers\storvsp.sys
2015-07-15 17:29:06 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 17:29:04 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-07-15 17:28:50 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 17:28:48 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-07-15 17:28:28 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 17:28:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-07-15 17:28:21 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 17:28:15 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 17:28:15 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 17:28:14 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-07-15 17:28:10 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2015-07-15 17:28:10 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 17:28:06 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-15 17:28:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2015-07-15 17:28:01 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 17:28:00 ----A---- C:\WINDOWS\system32\apphelp.dll
2015-07-15 17:27:59 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-07-15 17:27:59 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-15 12:20:38 ----A---- C:\WINDOWS\system32\drivers\AtihdWB6.sys
2015-07-15 12:20:38 ----A---- C:\WINDOWS\system32\DelayAPO.dll
2015-07-13 17:19:34 ----A---- C:\WINDOWS\system32\amde31a.dat
2015-07-13 17:19:20 ----A---- C:\WINDOWS\system32\ativce03.dat
2015-07-10 18:24:49 ----HD---- C:\$Windows.~BT
2015-07-10 09:40:10 ----A---- C:\WINDOWS\system32\amdicdxx.dat

======List of files/folders modified in the last 1 month======

2015-08-06 19:40:09 ----D---- C:\WINDOWS\Prefetch
2015-08-06 19:40:03 ----D---- C:\Program Files\trend micro
2015-08-06 19:39:02 ----RD---- C:\Program Files (x86)
2015-08-06 19:36:36 ----D---- C:\WINDOWS\system32\Tasks
2015-08-06 19:34:24 ----D---- C:\WINDOWS\Temp
2015-08-06 19:30:59 ----D---- C:\WINDOWS\system32\catroot
2015-08-06 19:29:53 ----HD---- C:\ProgramData
2015-08-06 19:29:22 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-08-06 19:26:39 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 19:25:44 ----D---- C:\Users\Honza\AppData\Roaming\Seznam.cz
2015-08-06 19:25:42 ----D---- C:\Program Files (x86)\Seznam.cz
2015-08-06 19:25:41 ----D---- C:\WINDOWS\Tasks
2015-08-06 19:22:51 ----RSD---- C:\WINDOWS\Fonts
2015-08-06 19:22:50 ----D---- C:\Program Files (x86)\Adobe
2015-08-06 19:20:25 ----D---- C:\Windows
2015-08-06 19:16:36 ----D---- C:\WINDOWS\SysWOW64
2015-08-06 19:16:30 ----RD---- C:\WINDOWS\System32
2015-08-06 19:16:24 ----D---- C:\WINDOWS\system32\drivers
2015-08-06 19:14:47 ----D---- C:\Program Files\Common Files
2015-08-06 19:14:29 ----D---- C:\Program Files (x86)\Common Files
2015-08-06 19:00:55 ----SHD---- C:\WINDOWS\Installer
2015-08-06 19:00:16 ----D---- C:\WINDOWS\system32\sru
2015-08-06 18:53:53 ----SHD---- C:\Config.Msi
2015-08-06 18:53:37 ----SHD---- C:\System Volume Information
2015-08-06 18:52:48 ----RD---- C:\Program Files
2015-08-06 18:40:38 ----SHD---- C:\$RECYCLE.BIN
2015-08-06 18:35:55 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-06 18:28:38 ----SD---- C:\Users\Honza\AppData\Roaming\Microsoft
2015-08-06 18:27:51 ----D---- C:\WINDOWS\system32\drivers\etc
2015-08-06 18:27:14 ----RSD---- C:\WINDOWS\assembly
2015-08-06 18:11:17 ----D---- C:\WINDOWS\Inf
2015-08-06 16:18:20 ----HD---- C:\Program Files\WindowsApps
2015-08-06 16:18:19 ----D---- C:\WINDOWS\AppReadiness
2015-08-06 16:18:02 ----D---- C:\WINDOWS\system32\config
2015-08-05 06:05:03 ----D---- C:\WINDOWS\Microsoft.NET
2015-08-03 19:38:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-02 19:42:46 ----SD---- C:\ProgramData\Microsoft
2015-08-02 19:38:15 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-02 19:37:59 ----D---- C:\Program Files\DIFX
2015-08-02 06:25:22 ----D---- C:\WINDOWS\WinSxS
2015-08-01 15:59:12 ----DC---- C:\WINDOWS\Panther
2015-08-01 15:46:59 ----D---- C:\WINDOWS\Logs
2015-08-01 15:42:26 ----D---- C:\Program Files\AMD
2015-08-01 15:41:56 ----D---- C:\ProgramData\AMD
2015-08-01 15:33:54 ----D---- C:\WINDOWS\CbsTemp
2015-08-01 15:29:41 ----D---- C:\AMD
2015-08-01 15:24:56 ----SD---- C:\WINDOWS\system32\GWX
2015-07-17 19:02:27 ----D---- C:\WINDOWS\rescache
2015-07-16 07:32:33 ----D---- C:\WINDOWS\apppatch
2015-07-16 07:32:32 ----D---- C:\WINDOWS\system32\cs-CZ
2015-07-16 07:32:32 ----D---- C:\WINDOWS\PolicyDefinitions
2015-07-16 07:32:31 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-16 07:32:30 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-16 07:32:30 ----RD---- C:\WINDOWS\ToastData
2015-07-16 07:32:29 ----D---- C:\WINDOWS\WinStore
2015-07-16 07:32:29 ----D---- C:\WINDOWS\system32\wbem
2015-07-16 07:32:29 ----D---- C:\WINDOWS\system32\appraiser
2015-07-16 07:32:29 ----D---- C:\Program Files\Internet Explorer
2015-07-16 07:32:29 ----D---- C:\Program Files (x86)\Internet Explorer
2015-07-16 06:51:26 ----D---- C:\ProgramData\Microsoft Help
2015-07-16 06:39:44 ----D---- C:\WINDOWS\system32\MRT
2015-07-16 06:39:04 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-07-16 04:12:16 ----A---- C:\WINDOWS\SYSWOW64\amdhcp32.dll
2015-07-16 04:11:58 ----A---- C:\WINDOWS\system32\atiuxp64.dll
2015-07-16 04:11:56 ----A---- C:\WINDOWS\SYSWOW64\atiuxpag.dll
2015-07-16 04:11:52 ----A---- C:\WINDOWS\SYSWOW64\atiu9pag.dll
2015-07-16 04:11:48 ----A---- C:\WINDOWS\system32\aticfx64.dll
2015-07-16 04:11:44 ----A---- C:\WINDOWS\SYSWOW64\aticfx32.dll
2015-07-16 04:11:38 ----A---- C:\WINDOWS\system32\atidxx64.dll
2015-07-16 04:11:34 ----A---- C:\WINDOWS\SYSWOW64\atidxx32.dll
2015-07-16 04:11:26 ----A---- C:\WINDOWS\SYSWOW64\atiumdva.dll
2015-07-16 04:11:18 ----A---- C:\WINDOWS\SYSWOW64\atiumdag.dll
2015-07-16 03:12:52 ----A---- C:\WINDOWS\system32\coinst_15.20.dll
2015-07-15 17:27:55 ----D---- C:\WINDOWS\system32\catroot2
2015-07-13 23:10:13 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-07-08 20:37:57 ----D---- C:\Program Files (x86)\TeamViewer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 DSFKSVCS;@oem67.inf,%DSFKSVCS.DeviceDesc%;Kernel Services for DSF; C:\WINDOWS\System32\drivers\dsfksvcs.sys [2010-02-08 676232]
R0 dsfroot;@oem68.inf,%dsfroot.SVCDESC%;root enumerated bus driver; C:\WINDOWS\System32\drivers\dsfroot.sys [2010-02-08 35832]
R0 speedfan;speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sysmon;sysmon; C:\WINDOWS\system32\DRIVERS\sysmon.sys [2014-09-10 119344]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-31 59728]
R1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QMUdisk64.sys [2015-04-17 62264]
R1 rsutils;rsutils; C:\WINDOWS\system32\DRIVERS\rsutils.sys [2014-08-15 69336]
R1 TAOKernelDriver;Tencent Auto Optimize Platform.; C:\WINDOWS\System32\Drivers\TAOKernel64.sys [2015-08-06 174392]
R1 TSCPM;TSCPM; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\tscpm64.sys [2015-08-06 42296]
R1 TSSysKit;TSSysKit; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TSSysKit64.sys [2015-08-06 87352]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 QQSysMonX64;QQSysMonX64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQSysMonX64.sys [2015-08-06 127800]
R2 TAOAccelerator;Tencent TAOAccelerator driver.; \??\C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys [2015-08-06 99640]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-07-16 21622272]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-07-16 665088]
R3 AtiHDAudioService;@oem129.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWB6.sys [2015-07-15 102912]
R3 CX88VID;@oem40.inf,%CX23880.DeviceDesc%;WinFast CX2388x AvStream Driver; C:\WINDOWS\system32\drivers\cxavsvid.sys [2007-09-19 469248]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
R3 RTL8168;@oem98.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-11-26 838872]
R3 TFsFlt;TFsFlt; C:\WINDOWS\system32\Drivers\TFsFltX64.sys [2015-08-06 87864]
R3 TS888x64;TS888x64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TS888x64.sys [2015-08-06 28984]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2013-03-08 58536]
S0 amdkmafd;@oem120.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S1 TSDefenseBt;TSDefenseBt; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TSDefenseBT64.sys [2015-08-06 28472]
S3 61883;@61883.inf,%61883_Unit.ServiceDesc%;61883 Unit Device; C:\WINDOWS\System32\drivers\61883.sys [2013-08-22 59904]
S3 AndnetBus;@oem108.inf,%LGSI.Service.Desc%;LGE Mobile USB Composite Device; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [2015-01-21 20992]
S3 AndNetDiag;@oem103.inf,%Lgsi.Service.Name%;LGE AndroidNet USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [2015-01-26 30720]
S3 ANDNetModem;@oem105.inf,%LGSI.Service.Name%;LGE AndroidNet USB Modem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [2015-01-26 37376]
S3 athur;@oem99.inf,%ATHR.Service.DispName%;Qualcomm Atheros AR9271 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athuw8x.sys [2013-06-02 2919936]
S3 Avc;@avc.inf,%Avc.ServiceDesc%;AVC Device; C:\WINDOWS\System32\drivers\avc.sys [2013-08-22 48000]
S3 bthav;@oem83.inf,%AVFilter.SvcDesc%;Bluetooth AV Profile; C:\WINDOWS\system32\drivers\bthav.sys [2008-07-10 40448]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
S3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter_hs.sys []
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 MSDV;@msdv.inf,%DVCR.Capture%;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2013-08-22 51584]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys []
S3 OlyCamComm;@oem60.inf,%OlyUsbDesc%;OLYMPUS USB Communication Device; C:\WINDOWS\system32\DRIVERS\OlyCamComm.sys [2009-09-09 24208]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\RtsUCcid.sys [2009-08-10 50176]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-07-16 246784]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-07-15 344064]
R2 appmgmts;Správce zabezpečení účtů 1.89.6; C:\Users\Honza\AppData\Local\Sprvcezabezpeen\mssip32.exe [2015-08-06 38400]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [2007-01-11 126464]
R2 fchk32;Check Service; C:\Program Files\fchk32\fchk32.exe [2015-08-06 379392]
R2 QQPCRTP;QQPCMgr RTP Service; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\QQPCRTP.exe [2015-08-06 297608]
R2 RsMgrSvc;Rsd Service; C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [2014-09-02 179992]
R2 RsRavMon;Rav Service; C:\Program Files (x86)\Rising\RAV\ravmond.exe [2014-05-15 277552]
R2 ssinstall;SInstalátor; C:\WINDOWS\SysWOW64\ssins.exe [2014-12-12 2324216]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2014-11-28 5419792]
R3 TAOFrame;TAOFrame; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16066.216\TAOFrame.exe [2015-08-06 293728]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\WINDOWS\ehome\ehRecvr.exe [2013-09-30 697856]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\WINDOWS\ehome\ehsched.exe [2013-09-30 176128]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc []
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-05 148136]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-16 268976]
S4 DfSdkS;Defragmentation-Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control\Dfsdks.exe [2009-08-24 544768]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\WINDOWS\system32\svchost.exe [2014-10-29 38792]
S4 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#3 Příspěvek od honzikuh »

Moc děkuji za rychlou reakci


# AdwCleaner v4.208 - Log vytvořen 06/08/2015 v 21:33:09
# Aktualizováno 09/07/2015 by Xplode
# Databáze : 2015-08-01.1 [Server]
# Operační system : Windows 8.1 Pro with Media Center (x64)
# Uživatelské jméno : Honza - HONZA-PC
# Spuštěno z : C:\Users\Honza\Desktop\adwcleaner_4.208.exe
# Nastavení : Čištění

***** [ Služby ] *****

[#] Služba Smazáno : globalUpdate
[#] Služba Smazáno : globalUpdatem
Služba Smazáno : TSDefenseBt
Služba Smazáno : TSSysKit
[#] Služba Smazáno : QMUdisk
Služba Smazáno : TS888x64
Služba Smazáno : QQSysMonX64
Služba Smazáno : TSCPM
Služba Smazáno : TFsFlt
Služba Smazáno : vToolbarUpdater18.8.0

***** [ Soubory / Složky ] *****

Složka Smazáno : C:\IQIYI Video
Složka Smazáno : C:\ProgramData\AVG Secure Search
Složka Smazáno : C:\ProgramData\AVG Security Toolbar
Složka Smazáno : C:\ProgramData\Systweak
Složka Smazáno : C:\ProgramData\IQIYI Video
Složka Smazáno : C:\ProgramData\tencent
Složka Smazáno : C:\ProgramData\TXQMPC
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\Program Files (x86)\Zrychleni Pocitace
Složka Smazáno : C:\Program Files (x86)\tencent
Složka Smazáno : C:\Program Files (x86)\Common Files\AVG Secure Search
Složka Smazáno : C:\Program Files (x86)\Common Files\tencent
Složka Smazáno : C:\Users\Honza\AppData\Local\Temp\tencent
Složka Smazáno : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\tencent
[!] Složka Smazáno : C:\Program Files\Common Files\tencent
Složka Smazáno : C:\Users\Honza\AppData\Local\globalUpdate
Složka Smazáno : C:\Users\Honza\AppData\Local\SysassistByHotWheel
Složka Smazáno : C:\Users\Honza\AppData\Roaming\Systweak
Složka Smazáno : C:\Users\Honza\AppData\Roaming\IQIYI Video
Složka Smazáno : C:\Users\Honza\AppData\Roaming\tencent
Složka Smazáno : C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\Extensions\Avg@toolbar
Složka Smazáno : C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Soubor Smazáno : C:\WINDOWS\shost.bin
Soubor Smazáno : C:\WINDOWS\SysWOW64\drivers\TS888x64.sys
Soubor Smazáno : C:\WINDOWS\System32\roboot64.exe
Soubor Smazáno : C:\WINDOWS\System32\sasnative64.exe
Soubor Smazáno : C:\WINDOWS\System32\drivers\TFsFltX64.sys
Soubor Smazáno : C:\Users\Honza\AppData\Roaming\dDpwrzaKlBCJZjYV1QfPG3
Soubor Smazáno : C:\Users\Honza\AppData\Roaming\NQZOkL1VwF88UD
Soubor Smazáno : C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\searchplugins\avg-secure-search.xml
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
Soubor Smazáno : C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\searchplugins\yahoo.xml
Soubor Smazáno : C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.istartsurf.com_0.localstorage
Soubor Smazáno : C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.istartsurf.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage
Soubor Smazáno : C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****

Zástupce Vyléčeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Zástupce Vyléčeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
Zástupce Vyléčeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Zástupce Vyléčeno : C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Zástupce Vyléčeno : C:\Users\Honza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Zástupce Vyléčeno : C:\Users\Honza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Zástupce Vyléčeno : C:\Users\Honza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Klíč Smazáno : HKLM\SOFTWARE\Classes\S
Klíč Smazáno : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Klíč Smazáno : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Klíč Smazáno : HKCU\Software\Mozilla\Extends
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
Klíč Smazáno : HKLM\SOFTWARE\CLASSES\METNSD
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
Hodnota Smazáno : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
Hodnota Smazáno : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
Hodnota Smazáno : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
Klíč Smazáno : HKCU\Software\MozillaPlugins\@iqiyi.com/npWebPlayer
Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\@iqiyi.com/npWebPlayer
Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\@iqiyi.com/npclient
Hodnota Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [HCDNClient]
Klíč Smazáno : HKLM\SOFTWARE\Classes\qygameclient
Klíč Smazáno : HKLM\SOFTWARE\Classes\HCDNProxy
Klíč Smazáno : HKLM\SOFTWARE\9bdfbdae-e8a9-4f81-b458-aa1e7bbe8857
Klíč Smazáno : HKLM\SOFTWARE\adc22f00-8df9-4d4b-bad4-fc7edd899716
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{307B3CDB-9EE3-4137-9D18-F9AD6537ECEB}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{C43F0D7D-78F0-47B8-954C-8FB36960B785}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C43F0D7D-78F0-47B8-954C-8FB36960B785}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{B6360BD3-5CD0-40D3-BD87-DAFF37889F50}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{E1D75F62-CBBD-45C7-9D1D-6B5ECEC2E006}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{E6F928E4-B672-4F3A-8CA2-53C4259235DE}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6BE0FB-8B18-4DFC-959F-233651CC4D7F}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAC94FEE-45B4-4FD4-9EEA-D8978EC96C6E}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{5CD76C57-6893-478A-B776-47E7C82504BE}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Klíč Smazáno : HKCU\Software\AnyProtect
Klíč Smazáno : HKCU\Software\APN PIP
Klíč Smazáno : HKCU\Software\AskPartnerNetwork
Klíč Smazáno : HKCU\Software\GlobalUpdate
Klíč Smazáno : HKCU\Software\HomeTab
Klíč Smazáno : HKCU\Software\InstalledBrowserExtensions
Klíč Smazáno : HKCU\Software\simplytech
Klíč Smazáno : HKCU\Software\systweak
Klíč Smazáno : HKCU\Software\Tutorials
Klíč Smazáno : HKCU\Software\WajIEnhance
Klíč Smazáno : HKCU\Software\WajIntEnhance
Klíč Smazáno : HKCU\Software\rttasks
Klíč Smazáno : HKCU\Software\SearchProtectWS
Klíč Smazáno : HKCU\Software\Crossbrowse
Klíč Smazáno : HKCU\Software\Appscion
Klíč Smazáno : HKCU\Software\Linkey
Klíč Smazáno : HKCU\Software\YorkNewCin
Klíč Smazáno : HKCU\Software\HighDefAction
Klíč Smazáno : HKCU\Software\ArenaHD
Klíč Smazáno : HKCU\Software\Avg Secure Update
Klíč Smazáno : HKCU\Software\Kromtech
Klíč Smazáno : HKCU\Software\QyGameClient
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKLM\SOFTWARE\Conduit
Klíč Smazáno : HKLM\SOFTWARE\GlobalUpdate
Klíč Smazáno : HKLM\SOFTWARE\InstalledBrowserExtensions
Klíč Smazáno : HKLM\SOFTWARE\SearchProtect
Klíč Smazáno : HKLM\SOFTWARE\systweak
Klíč Smazáno : HKLM\SOFTWARE\SpeedBit
Klíč Smazáno : HKLM\SOFTWARE\AIM Toolbar
Klíč Smazáno : HKLM\SOFTWARE\searchult
Klíč Smazáno : HKU\.DEFAULT\Software\Goobzo
Klíč Smazáno : HKU\.DEFAULT\Software\Avg Secure Update
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean-Pro_is1
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IQIYI Video
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Klíč Smazáno : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Data Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840

Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v39.0 (x86 cs)

[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("browser.search.searchengine.alias", "istartsurf");
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("browser.search.searchengine.iconURL", "hxxp://www.istartsurf.com/web/favicon.ico");
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("browser.search.searchengine.name", "istartsurf");
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("browser.search.searchengine.url", "hxxp://www.istartsurf.com/web/?type=dspp&ts=14 ... XX5QE1ZRYB&[...]
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2[...]
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("extensions.quick_start.enable_search1", false);
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[i13gmfne.default-1416118578905\prefs.js] - Řádek Smazáno : user_pref("plugin.state.npconduitfirefoxplugin", 0);

-\\ Google Chrome v44.0.2403.130

[C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.istartsurf.com/web/?type=dspp&ts=14 ... earchTerms}
[C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.istartsurf.com/web/?type=dspp&ts=14 ... earchTerms}
[C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] :
[C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Startup_URLs] : 26593CCC95D57E45C04A98D50773A0E008075A3E1AF46B11256A1D953763273F"},"software_reporter":{"prompt_reason":"81068E4D9EAA2B61C0CD1596D5AF0694AD2D985D210CFD0DD5EEF718FB82D4F2","prompt_seed":"2808DC83CB3929568D0585E1C047B83393BA426BE6C0E937C93B1314474A7B78","prompt_version":"CEEE36151697EE62CB4B1EB165745393106C2C0D9A7D9CCA91CCB3BA1F8FE6AF"},"sync":{"remaining_rollback_tries":"B836F9102239226233438265AF65A002EF658A555F40D2F4722DCE514160EC9A"}},"super_mac":"9D8CB218F65CF04572BFB7BF69339FA955F98511E7FC527E4A6C23F455E35DB3"},"session":{"restore_on_startup":4,"startup_urls":["hxxp://www.seznam.cz/","hxxp://www.istartsurf. ... XX5QE1ZRYB

*************************

AdwCleaner[R0].txt - [27648 bytů] - [06/08/2015 21:29:25]
AdwCleaner[S0].txt - [20548 bytů] - [06/08/2015 21:33:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20607 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#5 Příspěvek od honzikuh »

Je to všechno odinstalované :D


Logfile of random's system information tool 1.10 (written by random/random)
Run by Honza at 2015-08-07 05:24:07
Microsoft Windows 8.1 Pro s aplikací Media Center
System drive C: has 15 GB (8%) free of 205 GB
Total RAM: 8190 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:24:11, on 7.8.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Users\Honza\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [EPSON Stylus DX6000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S9473.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [LightShot] C:\Users\Honza\AppData\Local\Skillbrains\lightshot\Lightshot.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\baidu\baidu.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_290685FDE340642E7CB9D7EEDFD9E05D] "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - Startup: MEGAsync.lnk = Honza\AppData\Local\MEGAsync\MEGAsync.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - C:\Program Files (x86)\BitSpirit\bsurl.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Správce zabezpečení účtů 1.89.6 (appmgmts) - Unknown owner - C:\Users\Honza\AppData\Local\Sprvcezabezpeen\mssip32.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Check Service (fchk32) - Unknown owner - C:\Program Files\fchk32\fchk32.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\WINDOWS\SysWOW64\ssins.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 10684 bytes

======Listing Processes======




c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-e7e8-723575af5350 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"

wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe"
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Users\Honza\AppData\Local\Sprvcezabezpeen\mssip32.exe" /s
"C:\Program Files (x86)\AVG\AVG2015\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE"
"C:\Program Files\fchk32\fchk32.exe" /s iid=1635197 did=Missing sid= ref= id=d0f6f818f2a1d17efd9b0808f594377ce756bec89bf99f9b5ed6e4070c950c6f
dashost.exe {857a3158-ed41-469e-91a9b4a0dc072630}
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\SysWOW64\ssins.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
taskeng.exe {20DC64FE-D84D-47AC-9656-0B22F4CAAA38}
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\WinFast\WFDTV\WFWIZ.exe"
"C:\Users\Honza\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe"
"C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe"
"C:\Program Files\WinFast\WFDTV\DTVSchdl.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
ctfmon.exe
"C:\WINDOWS\system32\GWX\GWX.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --on-initialized-event-handle=420 --parent-handle=424
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5920.0.493992714\1311736288" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6819 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.200.1062.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Default/BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5920.1.376826025\1871699865" --font-cache-shared-handle=1980 /prefetch:673131151
taskhost.exe $(Arg0)
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5920.4.24405843\1302065552" --font-cache-shared-handle=3980 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="5920.5.1424200052\362845502" --font-cache-shared-handle=2520 /prefetch:673131151

C:\WINDOWS\system32\rundll32.exe aepdu.dll,AePduRunUpdate -nolegacy
"C:\Users\Honza\Downloads\RSITx64.exe"


======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://mysearch.avg.com/?cid={6FE679CB ... 2015-08-06 21:09:30&v=4.1.5.143&pid=wtu&sg=&sap=hp"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rising.com.cn/nprising]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iqiyi.com/npclient]
"Description"=iQiyi Browser Plugin
"Path"=C:\IQIYI Video\LStyle\npclient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iqiyi.com/npWebPlayer]
"Description"=pps-webplayer-plugin
"Path"=C:\IQIYI Video\LStyle\npWebPlayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll


C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\searchplugins\
firmycz.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-12 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-12 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-05-09 13672152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2015-06-20 22012688]
"EPSON Stylus DX6000"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBIE.EXE [2007-10-05 213504]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2013-01-09 2916352]
"LightShot"=C:\Users\Honza\AppData\Local\Skillbrains\lightshot\Lightshot.exe [2014-11-18 226560]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-02-26 31344744]
"apphide"=C:\Program Files (x86)\baidu\baidu.exe []
"GoogleChromeAutoLaunch_290685FDE340642E7CB9D7EEDFD9E05D"=C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window []
"cz.seznam.software.autoupdate"=C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"iSkysoft Helper Compact.exe"=C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2014-08-05 2014208]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2014-03-04 103936]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-02-06 170496]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2015-06-17 421888]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-07-15 767176]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2015-07-31 3780520]

C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-06 21:29:23 ----D---- C:\AdwCleaner
2015-08-06 21:09:22 ----D---- C:\Program Files\AVG Web TuneUp
2015-08-06 21:09:16 ----D---- C:\ProgramData\AVG Web TuneUp
2015-08-06 21:09:14 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-08-06 21:06:23 ----D---- C:\Users\Honza\AppData\Roaming\AVG2015
2015-08-06 21:05:46 ----D---- C:\Program Files\Common Files\AV
2015-08-06 21:05:04 ----D---- C:\Users\Honza\AppData\Roaming\TuneUp Software
2015-08-06 21:03:22 ----HD---- C:\$AVG
2015-08-06 21:03:21 ----D---- C:\ProgramData\AVG2015
2015-08-06 21:02:28 ----D---- C:\Program Files (x86)\AVG
2015-08-06 20:58:41 ----D---- C:\ProgramData\MFAData
2015-08-06 19:39:56 ----D---- C:\rsit
2015-08-06 19:39:02 ----D---- C:\Program Files (x86)\ESET
2015-08-06 19:21:09 ----A---- C:\MAMB.txt
2015-08-06 19:19:46 ----D---- C:\ProgramData\KingSoft
2015-08-06 19:16:36 ----RD---- C:\RavBin
2015-08-06 19:16:36 ----N---- C:\WINDOWS\SYSWOW64\vpatch.dll
2015-08-06 19:15:36 ----D---- C:\Program Files (x86)\Rising
2015-08-06 19:15:35 ----D---- C:\ProgramData\Rising
2015-08-06 18:39:00 ----D---- C:\Program Files (x86)\2ca13b38-0996-461b-8076-e78d4d2854b0
2015-08-06 18:37:58 ----A---- C:\WINDOWS\prleth.sys
2015-08-06 18:37:58 ----A---- C:\WINDOWS\hgfs.sys
2015-08-06 18:27:50 ----D---- C:\Program Files\fchk32
2015-08-06 18:27:15 ----D---- C:\ProgramData\FonePaw
2015-08-06 18:15:25 ----D---- C:\TenorshareData
2015-08-05 05:21:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-02 19:55:01 ----D---- C:\Program Files (x86)\Android Data Recovery
2015-08-02 19:36:49 ----D---- C:\Program Files (x86)\Tenorshare Android Data Recovery
2015-08-02 06:27:35 ----D---- C:\ProgramData\ATI
2015-08-01 15:34:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-08-01 15:34:04 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-01 15:34:03 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-08-01 15:34:02 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-08-01 15:34:02 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-28 11:02:14 ----A---- C:\WINDOWS\system32\drivers\avgidsdrivera.sys
2015-07-28 11:01:38 ----A---- C:\WINDOWS\system32\drivers\avgmfx64.sys
2015-07-16 04:12:26 ----A---- C:\WINDOWS\system32\amdave64.dll
2015-07-16 04:12:24 ----A---- C:\WINDOWS\SYSWOW64\amdave32.dll
2015-07-16 04:12:20 ----A---- C:\WINDOWS\system32\amdmiracast.dll
2015-07-16 04:12:18 ----A---- C:\WINDOWS\system32\amdhcp64.dll
2015-07-16 04:12:14 ----A---- C:\WINDOWS\system32\atimpc64.dll
2015-07-16 04:12:12 ----A---- C:\WINDOWS\SYSWOW64\atimpc32.dll
2015-07-16 04:12:02 ----A---- C:\WINDOWS\system32\amdpcom64.dll
2015-07-16 04:12:00 ----A---- C:\WINDOWS\SYSWOW64\amdpcom32.dll
2015-07-16 04:11:52 ----A---- C:\WINDOWS\system32\atiu9p64.dll
2015-07-16 04:11:10 ----A---- C:\WINDOWS\system32\atiumd6a.dll
2015-07-16 04:11:06 ----A---- C:\WINDOWS\system32\atiumd64.dll
2015-07-16 04:09:00 ----A---- C:\WINDOWS\system32\drivers\amdacpksd.sys
2015-07-16 04:06:36 ----A---- C:\WINDOWS\system32\drivers\atikmdag.sys
2015-07-16 04:01:52 ----A---- C:\WINDOWS\system32\clinfo.exe
2015-07-16 04:01:46 ----A---- C:\WINDOWS\system32\amdocl64.dll
2015-07-16 04:00:38 ----A---- C:\WINDOWS\SYSWOW64\amdocl.dll
2015-07-16 03:59:34 ----A---- C:\WINDOWS\system32\OpenCL.dll
2015-07-16 03:59:32 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2015-07-16 03:58:02 ----A---- C:\WINDOWS\system32\amdocl12cl64.dll
2015-07-16 03:57:54 ----A---- C:\WINDOWS\SYSWOW64\amdocl12cl.dll
2015-07-16 03:35:18 ----A---- C:\WINDOWS\system32\mantle64.dll
2015-07-16 03:35:14 ----A---- C:\WINDOWS\SYSWOW64\mantle32.dll
2015-07-16 03:35:08 ----A---- C:\WINDOWS\system32\amdmantle64.dll
2015-07-16 03:30:36 ----A---- C:\WINDOWS\SYSWOW64\amdmantle32.dll
2015-07-16 03:29:20 ----A---- C:\WINDOWS\system32\amdhdl64.dll
2015-07-16 03:29:18 ----A---- C:\WINDOWS\SYSWOW64\amdhdl32.dll
2015-07-16 03:28:36 ----A---- C:\WINDOWS\system32\atio6axx.dll
2015-07-16 03:26:58 ----A---- C:\WINDOWS\system32\mantleaxl64.dll
2015-07-16 03:26:56 ----A---- C:\WINDOWS\SYSWOW64\mantleaxl32.dll
2015-07-16 03:25:04 ----A---- C:\WINDOWS\system32\amdmmcl6.dll
2015-07-16 03:25:02 ----A---- C:\WINDOWS\SYSWOW64\amdmmcl.dll
2015-07-16 03:22:52 ----A---- C:\WINDOWS\SYSWOW64\atioglxx.dll
2015-07-16 03:21:48 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2015-07-16 03:21:46 ----A---- C:\WINDOWS\SYSWOW64\aticalrt.dll
2015-07-16 03:21:46 ----A---- C:\WINDOWS\system32\aticalrt64.dll
2015-07-16 03:21:44 ----A---- C:\WINDOWS\system32\aticalcl64.dll
2015-07-16 03:21:42 ----A---- C:\WINDOWS\SYSWOW64\aticalcl.dll
2015-07-16 03:21:38 ----A---- C:\WINDOWS\system32\aticaldd64.dll
2015-07-16 03:20:46 ----A---- C:\WINDOWS\SYSWOW64\aticaldd.dll
2015-07-16 03:17:30 ----A---- C:\WINDOWS\system32\atidemgy.dll
2015-07-16 03:17:28 ----A---- C:\WINDOWS\system32\atieah64.exe
2015-07-16 03:17:26 ----A---- C:\WINDOWS\SYSWOW64\atieah32.exe
2015-07-16 03:17:26 ----A---- C:\WINDOWS\system32\amdgfxinfo64.dll
2015-07-16 03:17:24 ----A---- C:\WINDOWS\SYSWOW64\amdgfxinfo32.dll
2015-07-16 03:17:24 ----A---- C:\WINDOWS\system32\atimuixx.dll
2015-07-16 03:17:22 ----A---- C:\WINDOWS\system32\atieclxx.exe
2015-07-16 03:17:14 ----A---- C:\WINDOWS\system32\atiesrxx.exe
2015-07-16 03:17:00 ----A---- C:\WINDOWS\system32\atitmm64.dll
2015-07-16 03:15:04 ----A---- C:\WINDOWS\system32\atisamu64.dll
2015-07-16 03:15:00 ----A---- C:\WINDOWS\SYSWOW64\atisamu32.dll
2015-07-16 03:14:04 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2015-07-16 03:13:40 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2015-07-16 03:13:36 ----A---- C:\WINDOWS\SYSWOW64\atiadlxy.dll
2015-07-16 03:13:36 ----A---- C:\WINDOWS\SYSWOW64\atiadlxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\SYSWOW64\atiglpxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\system32\atiglpxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\system32\atig6pxx.dll
2015-07-16 03:13:30 ----A---- C:\WINDOWS\system32\atig6txx.dll
2015-07-16 03:13:28 ----A---- C:\WINDOWS\SYSWOW64\atigktxx.dll
2015-07-16 03:13:26 ----A---- C:\WINDOWS\system32\drivers\atikmpag.sys
2015-07-16 03:12:08 ----A---- C:\WINDOWS\system32\hsa-thunk64.dll
2015-07-16 03:12:06 ----A---- C:\WINDOWS\SYSWOW64\hsa-thunk.dll
2015-07-15 17:33:02 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 17:33:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 17:32:59 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\certcli.dll
2015-07-15 17:32:32 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 17:32:31 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 17:32:31 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 17:32:24 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 17:32:24 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 17:31:31 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 17:31:31 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 17:31:30 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 17:31:24 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-07-15 17:31:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 17:31:22 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-15 17:30:25 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-15 17:30:25 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-15 17:30:24 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-15 17:30:19 ----AC---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-15 17:30:18 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-15 17:30:16 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 17:30:15 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2015-07-15 17:30:09 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-15 17:30:07 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-07-15 17:30:06 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2015-07-15 17:30:06 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 17:29:41 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2015-07-15 17:29:39 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-15 17:29:37 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 17:29:25 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2015-07-15 17:29:25 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2015-07-15 17:29:25 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 17:29:23 ----A---- C:\WINDOWS\system32\drivers\storvsp.sys
2015-07-15 17:29:06 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 17:29:04 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-07-15 17:28:50 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 17:28:48 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-07-15 17:28:28 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 17:28:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-07-15 17:28:21 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 17:28:15 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 17:28:15 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 17:28:14 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-07-15 17:28:10 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2015-07-15 17:28:10 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 17:28:06 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-15 17:28:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2015-07-15 17:28:01 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 17:28:00 ----A---- C:\WINDOWS\system32\apphelp.dll
2015-07-15 17:27:59 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-07-15 17:27:59 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-15 12:20:38 ----A---- C:\WINDOWS\system32\drivers\AtihdWB6.sys
2015-07-15 12:20:38 ----A---- C:\WINDOWS\system32\DelayAPO.dll
2015-07-13 17:19:34 ----A---- C:\WINDOWS\system32\amde31a.dat
2015-07-13 17:19:20 ----A---- C:\WINDOWS\system32\ativce03.dat
2015-07-10 18:24:49 ----HD---- C:\$Windows.~BT
2015-07-10 09:40:10 ----A---- C:\WINDOWS\system32\amdicdxx.dat
2015-07-10 07:31:52 ----A---- C:\WINDOWS\system32\drivers\avgwfpa.sys
2015-07-09 07:11:56 ----A---- C:\WINDOWS\system32\drivers\avgfwd6a.sys

======List of files/folders modified in the last 1 month======

2015-08-07 05:24:09 ----D---- C:\Program Files\trend micro
2015-08-07 05:23:39 ----D---- C:\WINDOWS\Temp
2015-08-07 05:19:31 ----D---- C:\WINDOWS\system32\sru
2015-08-06 21:59:11 ----D---- C:\WINDOWS\Prefetch
2015-08-06 21:58:46 ----D---- C:\Users\Honza\AppData\Roaming\Seznam.cz
2015-08-06 21:35:40 ----RD---- C:\WINDOWS\System32
2015-08-06 21:35:40 ----D---- C:\Program Files\Common Files
2015-08-06 21:33:24 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-08-06 21:33:24 ----D---- C:\WINDOWS\system32\drivers
2015-08-06 21:33:24 ----D---- C:\Windows
2015-08-06 21:33:15 ----D---- C:\Program Files (x86)\Common Files
2015-08-06 21:33:14 ----RD---- C:\Program Files (x86)
2015-08-06 21:33:14 ----HD---- C:\ProgramData
2015-08-06 21:14:13 ----D---- C:\WINDOWS\system32\Tasks
2015-08-06 21:10:50 ----D---- C:\WINDOWS\Tasks
2015-08-06 21:09:22 ----RD---- C:\Program Files
2015-08-06 21:06:02 ----SHD---- C:\WINDOWS\Installer
2015-08-06 21:06:01 ----SHD---- C:\Config.Msi
2015-08-06 21:04:57 ----HD---- C:\WINDOWS\ELAMBKUP
2015-08-06 21:04:39 ----D---- C:\WINDOWS\Inf
2015-08-06 21:04:35 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-06 21:03:39 ----D---- C:\WINDOWS\SysWOW64
2015-08-06 20:55:04 ----D---- C:\WINDOWS\AppReadiness
2015-08-06 19:44:41 ----HD---- C:\Program Files\WindowsApps
2015-08-06 19:30:59 ----D---- C:\WINDOWS\system32\catroot
2015-08-06 19:26:39 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 19:25:42 ----D---- C:\Program Files (x86)\Seznam.cz
2015-08-06 19:22:51 ----RSD---- C:\WINDOWS\Fonts
2015-08-06 19:22:50 ----D---- C:\Program Files (x86)\Adobe
2015-08-06 18:53:37 ----SHD---- C:\System Volume Information
2015-08-06 18:40:38 ----SHD---- C:\$RECYCLE.BIN
2015-08-06 18:35:55 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-06 18:28:38 ----SD---- C:\Users\Honza\AppData\Roaming\Microsoft
2015-08-06 18:27:51 ----D---- C:\WINDOWS\system32\drivers\etc
2015-08-06 18:27:14 ----RSD---- C:\WINDOWS\assembly
2015-08-06 16:18:02 ----D---- C:\WINDOWS\system32\config
2015-08-05 06:05:03 ----D---- C:\WINDOWS\Microsoft.NET
2015-08-03 19:38:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-02 19:42:46 ----SD---- C:\ProgramData\Microsoft
2015-08-02 19:37:59 ----D---- C:\Program Files\DIFX
2015-08-02 06:25:22 ----D---- C:\WINDOWS\WinSxS
2015-08-01 15:59:12 ----DC---- C:\WINDOWS\Panther
2015-08-01 15:46:59 ----D---- C:\WINDOWS\Logs
2015-08-01 15:42:26 ----D---- C:\Program Files\AMD
2015-08-01 15:41:56 ----D---- C:\ProgramData\AMD
2015-08-01 15:33:54 ----D---- C:\WINDOWS\CbsTemp
2015-08-01 15:29:41 ----D---- C:\AMD
2015-08-01 15:24:56 ----SD---- C:\WINDOWS\system32\GWX
2015-07-17 19:02:27 ----D---- C:\WINDOWS\rescache
2015-07-16 07:32:33 ----D---- C:\WINDOWS\apppatch
2015-07-16 07:32:32 ----D---- C:\WINDOWS\system32\cs-CZ
2015-07-16 07:32:32 ----D---- C:\WINDOWS\PolicyDefinitions
2015-07-16 07:32:31 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-16 07:32:30 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-16 07:32:30 ----RD---- C:\WINDOWS\ToastData
2015-07-16 07:32:29 ----D---- C:\WINDOWS\WinStore
2015-07-16 07:32:29 ----D---- C:\WINDOWS\system32\wbem
2015-07-16 07:32:29 ----D---- C:\WINDOWS\system32\appraiser
2015-07-16 07:32:29 ----D---- C:\Program Files\Internet Explorer
2015-07-16 07:32:29 ----D---- C:\Program Files (x86)\Internet Explorer
2015-07-16 06:51:26 ----D---- C:\ProgramData\Microsoft Help
2015-07-16 06:39:44 ----D---- C:\WINDOWS\system32\MRT
2015-07-16 06:39:04 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-07-16 04:12:16 ----A---- C:\WINDOWS\SYSWOW64\amdhcp32.dll
2015-07-16 04:11:58 ----A---- C:\WINDOWS\system32\atiuxp64.dll
2015-07-16 04:11:56 ----A---- C:\WINDOWS\SYSWOW64\atiuxpag.dll
2015-07-16 04:11:52 ----A---- C:\WINDOWS\SYSWOW64\atiu9pag.dll
2015-07-16 04:11:48 ----A---- C:\WINDOWS\system32\aticfx64.dll
2015-07-16 04:11:44 ----A---- C:\WINDOWS\SYSWOW64\aticfx32.dll
2015-07-16 04:11:38 ----A---- C:\WINDOWS\system32\atidxx64.dll
2015-07-16 04:11:34 ----A---- C:\WINDOWS\SYSWOW64\atidxx32.dll
2015-07-16 04:11:26 ----A---- C:\WINDOWS\SYSWOW64\atiumdva.dll
2015-07-16 04:11:18 ----A---- C:\WINDOWS\SYSWOW64\atiumdag.dll
2015-07-16 03:12:52 ----A---- C:\WINDOWS\system32\coinst_15.20.dll
2015-07-15 17:27:55 ----D---- C:\WINDOWS\system32\catroot2
2015-07-13 23:10:13 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-07-08 20:37:57 ----D---- C:\Program Files (x86)\TeamViewer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\WINDOWS\system32\DRIVERS\avgidsha.sys [2015-05-12 253408]
R0 Avgloga;AVG Logging Driver; C:\WINDOWS\system32\DRIVERS\avgloga.sys [2015-05-07 378336]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx64.sys [2015-07-28 245680]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx64.sys [2015-03-20 40928]
R0 DSFKSVCS;@oem67.inf,%DSFKSVCS.DeviceDesc%;Kernel Services for DSF; C:\WINDOWS\System32\drivers\dsfksvcs.sys [2010-02-08 676232]
R0 dsfroot;@oem68.inf,%dsfroot.SVCDESC%;root enumerated bus driver; C:\WINDOWS\System32\drivers\dsfroot.sys [2010-02-08 35832]
R0 speedfan;speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-31 59728]
R1 Avgdiska;AVG Disk Driver; C:\WINDOWS\system32\DRIVERS\avgdiska.sys [2015-03-11 162784]
R1 Avgfwfd;@oem170.inf,%AvgfwfdService_Desc%;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwd6a.sys [2015-07-09 77760]
R1 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdrivera.sys [2015-07-28 312752]
R1 Avgldx64;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx64.sys [2015-06-16 259040]
R1 Avgwfpa;AVG Firewall Driver; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys [2015-07-10 296896]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-07-16 21622272]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-07-16 665088]
R3 AtiHDAudioService;@oem129.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWB6.sys [2015-07-15 102912]
R3 CX88VID;@oem40.inf,%CX23880.DeviceDesc%;WinFast CX2388x AvStream Driver; C:\WINDOWS\system32\drivers\cxavsvid.sys [2007-09-19 469248]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
R3 RTL8168;@oem98.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-11-26 838872]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2013-03-08 58536]
S0 amdkmafd;@oem120.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\WINDOWS\system32\DRIVERS\avgboota.sys [2015-03-27 21152]
S3 61883;@61883.inf,%61883_Unit.ServiceDesc%;61883 Unit Device; C:\WINDOWS\System32\drivers\61883.sys [2013-08-22 59904]
S3 AndnetBus;@oem108.inf,%LGSI.Service.Desc%;LGE Mobile USB Composite Device; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [2015-01-21 20992]
S3 AndNetDiag;@oem103.inf,%Lgsi.Service.Name%;LGE AndroidNet USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [2015-01-26 30720]
S3 ANDNetModem;@oem105.inf,%LGSI.Service.Name%;LGE AndroidNet USB Modem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [2015-01-26 37376]
S3 athur;@oem99.inf,%ATHR.Service.DispName%;Qualcomm Atheros AR9271 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athuw8x.sys [2013-06-02 2919936]
S3 Avc;@avc.inf,%Avc.ServiceDesc%;AVC Device; C:\WINDOWS\System32\drivers\avc.sys [2013-08-22 48000]
S3 bthav;@oem83.inf,%AVFilter.SvcDesc%;Bluetooth AV Profile; C:\WINDOWS\system32\drivers\bthav.sys [2008-07-10 40448]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
S3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter_hs.sys []
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 MSDV;@msdv.inf,%DVCR.Capture%;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2013-08-22 51584]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys []
S3 OlyCamComm;@oem60.inf,%OlyUsbDesc%;OLYMPUS USB Communication Device; C:\WINDOWS\system32\DRIVERS\OlyCamComm.sys [2009-09-09 24208]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\RtsUCcid.sys [2009-08-10 50176]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-07-16 246784]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-07-15 344064]
R2 appmgmts;Správce zabezpečení účtů 1.89.6; C:\Users\Honza\AppData\Local\Sprvcezabezpeen\mssip32.exe [2015-08-06 38400]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-07-31 1560592]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-07-31 3633576]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-07-31 335656]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [2007-01-11 126464]
R2 fchk32;Check Service; C:\Program Files\fchk32\fchk32.exe [2015-08-06 379392]
R2 ssinstall;SInstalátor; C:\WINDOWS\SysWOW64\ssins.exe [2014-12-12 2324216]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2014-11-28 5419792]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\WINDOWS\ehome\ehRecvr.exe [2013-09-30 697856]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\WINDOWS\ehome\ehsched.exe [2013-09-30 176128]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-05 148136]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-16 268976]
S4 DfSdkS;Defragmentation-Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control\Dfsdks.exe [2009-08-24 544768]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\WINDOWS\system32\svchost.exe [2014-10-29 38792]
S4 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]

-----------------EOF-----------------

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#6 Příspěvek od honzikuh »

Ranní nález AVG

http://prntscr.com/81ryxz

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#7 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\baidu
C:\Program Files\fchk32
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"apphide"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:services
fchk32

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#8 Příspěvek od honzikuh »

Provedeno

Logfile of random's system information tool 1.10 (written by random/random)
Run by Honza at 2015-08-07 19:09:30
Microsoft Windows 8.1 Pro s aplikací Media Center
System drive C: has 20 GB (10%) free of 205 GB
Total RAM: 8190 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:09:32, on 7.8.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Users\Honza\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_BzVqASLW90uzABlD4jc2fP0kEitVrcQAJPeT5uSZBXuYR4EvjaFXauthpG38tqGQ4eZwnXbWf1mcQnombTqLGBspJtm1Bywz8r_-L1gxxJIqLPO9EWgTFdbtLvSbP8xbWqX-8KcCXiBOpJ872ccRjeVlCHUB0&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_BzVqASLW90uzABlD4jc2fP0kEitVrcQAJPeT5uSZBXuYR4EvjaFXauthpG38tqGQ4eZwnXbWf1mcQnombTqLGBspJtm1Bywz8r_-L1gxxJIqLPO9EWgTFdbtLvSbP8xbWqX-8KcCXiBOpJ872ccRjeVlCHUB0&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_BzVqASLW90uzABlD4jc2fP0kEitVrcQAJPeT5uSZBXuYR4EvjaFXauthpG38tqGQ4eZwnXbWf1mcQnombTqLGBspJtm1Bywz8r_-L1gxxJIqLPO9EWgTFdbtLvSbP8xbWqX-8KcCXiBOpJ872ccRjeVlCHUB0&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_BzVqASLW90uzABlD4jc2fP0kEitVrcQAJPeT5uSZBXuYR4EvjaFXauthpG38tqGQ4eZwnXbWf1mcQnoVpPyn7kNTvLEAxPwoTgJLAvTt4hUAUwneu8xGtmSUgug2TGbWw22hfgvKLMWFJkC45-RpuHTI-lr3u
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_BzVqASLW90uzABlD4jc2fP0kEitVrcQAJPeT5uSZBXuYR4EvjaFXauthpG38tqGQ4eZwnXbWf1mcQnombTqLGBspJtm1Bywz8r_-L1gxxJIqLPO9EWgTFdbtLvSbP8xbWqX-8KcCXiBOpJ872ccRjeVlCHUB0&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [EPSON Stylus DX6000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S9473.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [LightShot] C:\Users\Honza\AppData\Local\Skillbrains\lightshot\Lightshot.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_290685FDE340642E7CB9D7EEDFD9E05D] "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - Startup: MEGAsync.lnk = Honza\AppData\Local\MEGAsync\MEGAsync.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - C:\Program Files (x86)\BitSpirit\bsurl.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\ProgramData\ExtTag\4dnjrrjq.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: ExtTag service (ExtTag) - Unknown owner - C:\ProgramData\ExtTag\ExtTag (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\WINDOWS\SysWOW64\ssins.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 11573 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe"
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
atieclxx
C:\WINDOWS\system32\svchost.exe -k NetworkService

C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {0fe71fed-e69e-4def-bd1bcb2dcfdb822b}
"C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE"
C:\ProgramData\ExtTag\ExtTag
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\SysWOW64\ssins.exe
taskeng.exe {B4B977CF-3152-435F-860B-6824E01769E0}
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\08072015_190018.log
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
C:\ProgramData\ExtTag\ggr3jcgq.exe regname Stpro.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\system32\GWX\GWX.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\WinFast\WFDTV\WFWIZ.exe"
"C:\Users\Honza\AppData\Local\Skillbrains\lightshot\5.1.4.41\Lightshot.exe"
"C:\Program Files\WinFast\WFDTV\DTVSchdl.exe"
"C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe"
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 588 592 600 65536 596
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" %SNP%
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --on-initialized-event-handle=444 --parent-handle=448
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4504.0.765022472\966136526" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6819 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.200.1062.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Default/BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledTimeLossDetection/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="4504.1.367633479\2119972776" --font-cache-shared-handle=1920 /prefetch:673131151
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledTimeLossDetection/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="4504.5.1289022627\2016860378" --font-cache-shared-handle=4612 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4504.6.1095623721\2076658834" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/*EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledTimeLossDetection/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_49/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_14/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --channel="4504.7.1017275294\1752751246" --font-cache-shared-handle=4608 /prefetch:673131151
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
rundll32.exe WSClient.dll,RefreshBannedAppsList
"C:\Users\Honza\Downloads\RSITx64.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "C:\ProgramData\ExtTags\ff.HP"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rising.com.cn/nprising]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iqiyi.com/npclient]
"Description"=iQiyi Browser Plugin
"Path"=C:\IQIYI Video\LStyle\npclient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iqiyi.com/npWebPlayer]
"Description"=pps-webplayer-plugin
"Path"=C:\IQIYI Video\LStyle\npWebPlayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll


C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\i13gmfne.default-1416118578905\searchplugins\
firmycz.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-12 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-12 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-05-09 13672152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2015-06-20 22012688]
"EPSON Stylus DX6000"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBIE.EXE [2007-10-05 213504]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2013-01-09 2916352]
"LightShot"=C:\Users\Honza\AppData\Local\Skillbrains\lightshot\Lightshot.exe [2014-11-18 226560]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-02-26 31344744]
"GoogleChromeAutoLaunch_290685FDE340642E7CB9D7EEDFD9E05D"=C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window []
"cz.seznam.software.autoupdate"=C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"iSkysoft Helper Compact.exe"=C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2014-08-05 2014208]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2014-03-04 103936]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-02-06 170496]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2015-06-17 421888]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-07-15 767176]

C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Honza\AppData\Local\MEGAsync\MEGAsync.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\ProgramData\ExtTag\1s4qip2x.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-07 19:00:18 ----D---- C:\_OTM
2015-08-07 18:51:53 ----D---- C:\ProgramData\ExtTags
2015-08-07 18:50:49 ----D---- C:\ProgramData\ExtTag
2015-08-06 21:29:23 ----D---- C:\AdwCleaner
2015-08-06 21:09:22 ----D---- C:\Program Files\AVG Web TuneUp
2015-08-06 21:09:16 ----D---- C:\ProgramData\AVG Web TuneUp
2015-08-06 21:09:14 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-08-06 21:05:46 ----D---- C:\Program Files\Common Files\AV
2015-08-06 21:05:04 ----D---- C:\Users\Honza\AppData\Roaming\TuneUp Software
2015-08-06 20:58:41 ----D---- C:\ProgramData\MFAData
2015-08-06 19:39:56 ----D---- C:\rsit
2015-08-06 19:39:02 ----D---- C:\Program Files (x86)\ESET
2015-08-06 19:21:09 ----A---- C:\MAMB.txt
2015-08-06 19:19:46 ----D---- C:\ProgramData\KingSoft
2015-08-06 19:16:36 ----RD---- C:\RavBin
2015-08-06 19:16:36 ----N---- C:\WINDOWS\SYSWOW64\vpatch.dll
2015-08-06 19:15:36 ----D---- C:\Program Files (x86)\Rising
2015-08-06 19:15:35 ----D---- C:\ProgramData\Rising
2015-08-06 18:39:00 ----D---- C:\Program Files (x86)\2ca13b38-0996-461b-8076-e78d4d2854b0
2015-08-06 18:37:58 ----A---- C:\WINDOWS\prleth.sys
2015-08-06 18:37:58 ----A---- C:\WINDOWS\hgfs.sys
2015-08-06 18:27:15 ----D---- C:\ProgramData\FonePaw
2015-08-06 18:15:25 ----D---- C:\TenorshareData
2015-08-05 05:21:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-02 19:55:01 ----D---- C:\Program Files (x86)\Android Data Recovery
2015-08-02 19:36:49 ----D---- C:\Program Files (x86)\Tenorshare Android Data Recovery
2015-08-02 06:27:35 ----D---- C:\ProgramData\ATI
2015-08-01 15:34:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-08-01 15:34:04 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-08-01 15:34:03 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-08-01 15:34:02 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-08-01 15:34:02 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-07-16 04:12:26 ----A---- C:\WINDOWS\system32\amdave64.dll
2015-07-16 04:12:24 ----A---- C:\WINDOWS\SYSWOW64\amdave32.dll
2015-07-16 04:12:20 ----A---- C:\WINDOWS\system32\amdmiracast.dll
2015-07-16 04:12:18 ----A---- C:\WINDOWS\system32\amdhcp64.dll
2015-07-16 04:12:14 ----A---- C:\WINDOWS\system32\atimpc64.dll
2015-07-16 04:12:12 ----A---- C:\WINDOWS\SYSWOW64\atimpc32.dll
2015-07-16 04:12:02 ----A---- C:\WINDOWS\system32\amdpcom64.dll
2015-07-16 04:12:00 ----A---- C:\WINDOWS\SYSWOW64\amdpcom32.dll
2015-07-16 04:11:52 ----A---- C:\WINDOWS\system32\atiu9p64.dll
2015-07-16 04:11:10 ----A---- C:\WINDOWS\system32\atiumd6a.dll
2015-07-16 04:11:06 ----A---- C:\WINDOWS\system32\atiumd64.dll
2015-07-16 04:09:00 ----A---- C:\WINDOWS\system32\drivers\amdacpksd.sys
2015-07-16 04:06:36 ----A---- C:\WINDOWS\system32\drivers\atikmdag.sys
2015-07-16 04:01:52 ----A---- C:\WINDOWS\system32\clinfo.exe
2015-07-16 04:01:46 ----A---- C:\WINDOWS\system32\amdocl64.dll
2015-07-16 04:00:38 ----A---- C:\WINDOWS\SYSWOW64\amdocl.dll
2015-07-16 03:59:34 ----A---- C:\WINDOWS\system32\OpenCL.dll
2015-07-16 03:59:32 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2015-07-16 03:58:02 ----A---- C:\WINDOWS\system32\amdocl12cl64.dll
2015-07-16 03:57:54 ----A---- C:\WINDOWS\SYSWOW64\amdocl12cl.dll
2015-07-16 03:35:18 ----A---- C:\WINDOWS\system32\mantle64.dll
2015-07-16 03:35:14 ----A---- C:\WINDOWS\SYSWOW64\mantle32.dll
2015-07-16 03:35:08 ----A---- C:\WINDOWS\system32\amdmantle64.dll
2015-07-16 03:30:36 ----A---- C:\WINDOWS\SYSWOW64\amdmantle32.dll
2015-07-16 03:29:20 ----A---- C:\WINDOWS\system32\amdhdl64.dll
2015-07-16 03:29:18 ----A---- C:\WINDOWS\SYSWOW64\amdhdl32.dll
2015-07-16 03:28:36 ----A---- C:\WINDOWS\system32\atio6axx.dll
2015-07-16 03:26:58 ----A---- C:\WINDOWS\system32\mantleaxl64.dll
2015-07-16 03:26:56 ----A---- C:\WINDOWS\SYSWOW64\mantleaxl32.dll
2015-07-16 03:25:04 ----A---- C:\WINDOWS\system32\amdmmcl6.dll
2015-07-16 03:25:02 ----A---- C:\WINDOWS\SYSWOW64\amdmmcl.dll
2015-07-16 03:22:52 ----A---- C:\WINDOWS\SYSWOW64\atioglxx.dll
2015-07-16 03:21:48 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2015-07-16 03:21:46 ----A---- C:\WINDOWS\SYSWOW64\aticalrt.dll
2015-07-16 03:21:46 ----A---- C:\WINDOWS\system32\aticalrt64.dll
2015-07-16 03:21:44 ----A---- C:\WINDOWS\system32\aticalcl64.dll
2015-07-16 03:21:42 ----A---- C:\WINDOWS\SYSWOW64\aticalcl.dll
2015-07-16 03:21:38 ----A---- C:\WINDOWS\system32\aticaldd64.dll
2015-07-16 03:20:46 ----A---- C:\WINDOWS\SYSWOW64\aticaldd.dll
2015-07-16 03:17:30 ----A---- C:\WINDOWS\system32\atidemgy.dll
2015-07-16 03:17:28 ----A---- C:\WINDOWS\system32\atieah64.exe
2015-07-16 03:17:26 ----A---- C:\WINDOWS\SYSWOW64\atieah32.exe
2015-07-16 03:17:26 ----A---- C:\WINDOWS\system32\amdgfxinfo64.dll
2015-07-16 03:17:24 ----A---- C:\WINDOWS\SYSWOW64\amdgfxinfo32.dll
2015-07-16 03:17:24 ----A---- C:\WINDOWS\system32\atimuixx.dll
2015-07-16 03:17:22 ----A---- C:\WINDOWS\system32\atieclxx.exe
2015-07-16 03:17:14 ----A---- C:\WINDOWS\system32\atiesrxx.exe
2015-07-16 03:17:00 ----A---- C:\WINDOWS\system32\atitmm64.dll
2015-07-16 03:15:04 ----A---- C:\WINDOWS\system32\atisamu64.dll
2015-07-16 03:15:00 ----A---- C:\WINDOWS\SYSWOW64\atisamu32.dll
2015-07-16 03:14:04 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2015-07-16 03:13:40 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2015-07-16 03:13:36 ----A---- C:\WINDOWS\SYSWOW64\atiadlxy.dll
2015-07-16 03:13:36 ----A---- C:\WINDOWS\SYSWOW64\atiadlxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\SYSWOW64\atiglpxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\system32\atiglpxx.dll
2015-07-16 03:13:32 ----A---- C:\WINDOWS\system32\atig6pxx.dll
2015-07-16 03:13:30 ----A---- C:\WINDOWS\system32\atig6txx.dll
2015-07-16 03:13:28 ----A---- C:\WINDOWS\SYSWOW64\atigktxx.dll
2015-07-16 03:13:26 ----A---- C:\WINDOWS\system32\drivers\atikmpag.sys
2015-07-16 03:12:08 ----A---- C:\WINDOWS\system32\hsa-thunk64.dll
2015-07-16 03:12:06 ----A---- C:\WINDOWS\SYSWOW64\hsa-thunk.dll
2015-07-15 17:33:02 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 17:33:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-07-15 17:32:59 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\msv1_0.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2015-07-15 17:32:58 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-07-15 17:32:57 ----A---- C:\WINDOWS\system32\certcli.dll
2015-07-15 17:32:32 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 17:32:31 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 17:32:31 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-07-15 17:32:27 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-07-15 17:32:26 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 17:32:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-07-15 17:32:24 ----A---- C:\WINDOWS\system32\wups2.dll
2015-07-15 17:32:24 ----A---- C:\WINDOWS\system32\wups.dll
2015-07-15 17:31:31 ----A---- C:\WINDOWS\system32\wininet.dll
2015-07-15 17:31:31 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-07-15 17:31:30 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\ieui.dll
2015-07-15 17:31:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-07-15 17:31:27 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-07-15 17:31:26 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\system32\msrating.dll
2015-07-15 17:31:25 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-07-15 17:31:24 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-07-15 17:31:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\jscript.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-07-15 17:31:23 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-07-15 17:31:22 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\invagent.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 17:30:26 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-07-15 17:30:25 ----A---- C:\WINDOWS\system32\devinv.dll
2015-07-15 17:30:25 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-07-15 17:30:24 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\sermouse.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\mouclass.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\kbdhid.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\kbdclass.sys
2015-07-15 17:30:20 ----AC---- C:\WINDOWS\system32\drivers\i8042prt.sys
2015-07-15 17:30:19 ----AC---- C:\WINDOWS\system32\drivers\mouhid.sys
2015-07-15 17:30:18 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-07-15 17:30:16 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 17:30:15 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2015-07-15 17:30:09 ----A---- C:\WINDOWS\system32\shell32.dll
2015-07-15 17:30:07 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-07-15 17:30:06 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2015-07-15 17:30:06 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 17:29:41 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2015-07-15 17:29:39 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2015-07-15 17:29:37 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\system32\WSShared.dll
2015-07-15 17:29:37 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\system32\msi.dll
2015-07-15 17:29:26 ----A---- C:\WINDOWS\system32\authui.dll
2015-07-15 17:29:25 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2015-07-15 17:29:25 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2015-07-15 17:29:25 ----A---- C:\WINDOWS\system32\msiexec.exe
2015-07-15 17:29:23 ----A---- C:\WINDOWS\system32\drivers\storvsp.sys
2015-07-15 17:29:06 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-07-15 17:29:04 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-07-15 17:28:50 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-07-15 17:28:48 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-07-15 17:28:28 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-07-15 17:28:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-07-15 17:28:21 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-07-15 17:28:20 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-07-15 17:28:15 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 17:28:15 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-07-15 17:28:14 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-07-15 17:28:10 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2015-07-15 17:28:10 ----A---- C:\WINDOWS\system32\ole32.dll
2015-07-15 17:28:06 ----A---- C:\WINDOWS\system32\fhcpl.dll
2015-07-15 17:28:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2015-07-15 17:28:01 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 17:28:00 ----A---- C:\WINDOWS\system32\apphelp.dll
2015-07-15 17:27:59 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-07-15 17:27:59 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-07-15 12:20:38 ----A---- C:\WINDOWS\system32\drivers\AtihdWB6.sys
2015-07-15 12:20:38 ----A---- C:\WINDOWS\system32\DelayAPO.dll
2015-07-13 17:19:34 ----A---- C:\WINDOWS\system32\amde31a.dat
2015-07-13 17:19:20 ----A---- C:\WINDOWS\system32\ativce03.dat
2015-07-10 18:24:49 ----HD---- C:\$Windows.~BT
2015-07-10 09:40:10 ----A---- C:\WINDOWS\system32\amdicdxx.dat

======List of files/folders modified in the last 1 month======

2015-08-07 19:09:31 ----D---- C:\Program Files\trend micro
2015-08-07 19:08:56 ----D---- C:\WINDOWS\Prefetch
2015-08-07 19:06:10 ----D---- C:\WINDOWS\Temp
2015-08-07 19:05:44 ----SHD---- C:\Config.Msi
2015-08-07 19:05:44 ----RD---- C:\Program Files (x86)
2015-08-07 19:05:44 ----HD---- C:\ProgramData
2015-08-07 19:00:18 ----RD---- C:\Program Files
2015-08-07 19:00:18 ----D---- C:\WINDOWS\Tasks
2015-08-07 19:00:01 ----D---- C:\WINDOWS\system32\sru
2015-08-07 18:59:23 ----SHD---- C:\WINDOWS\Installer
2015-08-07 18:58:51 ----D---- C:\WINDOWS\system32\drivers
2015-08-07 18:58:43 ----D---- C:\WINDOWS\Inf
2015-08-07 18:57:38 ----SHD---- C:\System Volume Information
2015-08-07 18:53:04 ----D---- C:\WINDOWS\system32\Tasks
2015-08-07 05:51:56 ----D---- C:\WINDOWS\Microsoft.NET
2015-08-07 05:32:26 ----D---- C:\WINDOWS\system32\catroot
2015-08-06 21:58:46 ----D---- C:\Users\Honza\AppData\Roaming\Seznam.cz
2015-08-06 21:35:40 ----RD---- C:\WINDOWS\System32
2015-08-06 21:35:40 ----D---- C:\Program Files\Common Files
2015-08-06 21:33:24 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-08-06 21:33:24 ----D---- C:\Windows
2015-08-06 21:33:15 ----D---- C:\Program Files (x86)\Common Files
2015-08-06 21:04:57 ----HD---- C:\WINDOWS\ELAMBKUP
2015-08-06 21:04:35 ----D---- C:\WINDOWS\system32\DriverStore
2015-08-06 21:03:39 ----D---- C:\WINDOWS\SysWOW64
2015-08-06 20:55:04 ----D---- C:\WINDOWS\AppReadiness
2015-08-06 19:44:41 ----HD---- C:\Program Files\WindowsApps
2015-08-06 19:26:39 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-06 19:25:42 ----D---- C:\Program Files (x86)\Seznam.cz
2015-08-06 19:22:51 ----RSD---- C:\WINDOWS\Fonts
2015-08-06 19:22:50 ----D---- C:\Program Files (x86)\Adobe
2015-08-06 18:40:38 ----SHD---- C:\$RECYCLE.BIN
2015-08-06 18:35:55 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-06 18:28:38 ----SD---- C:\Users\Honza\AppData\Roaming\Microsoft
2015-08-06 18:27:51 ----D---- C:\WINDOWS\system32\drivers\etc
2015-08-06 18:27:14 ----RSD---- C:\WINDOWS\assembly
2015-08-06 16:18:02 ----D---- C:\WINDOWS\system32\config
2015-08-03 19:38:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-02 19:42:46 ----SD---- C:\ProgramData\Microsoft
2015-08-02 19:37:59 ----D---- C:\Program Files\DIFX
2015-08-02 06:25:22 ----D---- C:\WINDOWS\WinSxS
2015-08-01 15:59:12 ----DC---- C:\WINDOWS\Panther
2015-08-01 15:46:59 ----D---- C:\WINDOWS\Logs
2015-08-01 15:42:26 ----D---- C:\Program Files\AMD
2015-08-01 15:41:56 ----D---- C:\ProgramData\AMD
2015-08-01 15:33:54 ----D---- C:\WINDOWS\CbsTemp
2015-08-01 15:29:41 ----D---- C:\AMD
2015-08-01 15:24:56 ----SD---- C:\WINDOWS\system32\GWX
2015-07-17 19:02:27 ----D---- C:\WINDOWS\rescache
2015-07-16 07:32:33 ----D---- C:\WINDOWS\apppatch
2015-07-16 07:32:32 ----D---- C:\WINDOWS\system32\cs-CZ
2015-07-16 07:32:32 ----D---- C:\WINDOWS\PolicyDefinitions
2015-07-16 07:32:31 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-07-16 07:32:30 ----SD---- C:\WINDOWS\system32\CompatTel
2015-07-16 07:32:30 ----RD---- C:\WINDOWS\ToastData
2015-07-16 07:32:29 ----D---- C:\WINDOWS\WinStore
2015-07-16 07:32:29 ----D---- C:\WINDOWS\system32\wbem
2015-07-16 07:32:29 ----D---- C:\WINDOWS\system32\appraiser
2015-07-16 07:32:29 ----D---- C:\Program Files\Internet Explorer
2015-07-16 07:32:29 ----D---- C:\Program Files (x86)\Internet Explorer
2015-07-16 06:51:26 ----D---- C:\ProgramData\Microsoft Help
2015-07-16 06:39:44 ----D---- C:\WINDOWS\system32\MRT
2015-07-16 06:39:04 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-07-16 04:12:16 ----A---- C:\WINDOWS\SYSWOW64\amdhcp32.dll
2015-07-16 04:11:58 ----A---- C:\WINDOWS\system32\atiuxp64.dll
2015-07-16 04:11:56 ----A---- C:\WINDOWS\SYSWOW64\atiuxpag.dll
2015-07-16 04:11:52 ----A---- C:\WINDOWS\SYSWOW64\atiu9pag.dll
2015-07-16 04:11:48 ----A---- C:\WINDOWS\system32\aticfx64.dll
2015-07-16 04:11:44 ----A---- C:\WINDOWS\SYSWOW64\aticfx32.dll
2015-07-16 04:11:38 ----A---- C:\WINDOWS\system32\atidxx64.dll
2015-07-16 04:11:34 ----A---- C:\WINDOWS\SYSWOW64\atidxx32.dll
2015-07-16 04:11:26 ----A---- C:\WINDOWS\SYSWOW64\atiumdva.dll
2015-07-16 04:11:18 ----A---- C:\WINDOWS\SYSWOW64\atiumdag.dll
2015-07-16 03:12:52 ----A---- C:\WINDOWS\system32\coinst_15.20.dll
2015-07-15 17:27:55 ----D---- C:\WINDOWS\system32\catroot2
2015-07-13 23:10:13 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-07-08 20:37:57 ----D---- C:\Program Files (x86)\TeamViewer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 DSFKSVCS;@oem67.inf,%DSFKSVCS.DeviceDesc%;Kernel Services for DSF; C:\WINDOWS\System32\drivers\dsfksvcs.sys [2010-02-08 676232]
R0 dsfroot;@oem68.inf,%dsfroot.SVCDESC%;root enumerated bus driver; C:\WINDOWS\System32\drivers\dsfroot.sys [2010-02-08 35832]
R0 speedfan;speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-31 59728]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-07-16 21622272]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-07-16 665088]
R3 AtiHDAudioService;@oem129.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWB6.sys [2015-07-15 102912]
R3 CX88VID;@oem40.inf,%CX23880.DeviceDesc%;WinFast CX2388x AvStream Driver; C:\WINDOWS\system32\drivers\cxavsvid.sys [2007-09-19 469248]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
R3 RTL8168;@oem98.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-11-26 838872]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2013-03-08 58536]
S0 amdkmafd;@oem120.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S3 61883;@61883.inf,%61883_Unit.ServiceDesc%;61883 Unit Device; C:\WINDOWS\System32\drivers\61883.sys [2013-08-22 59904]
S3 AndnetBus;@oem108.inf,%LGSI.Service.Desc%;LGE Mobile USB Composite Device; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [2015-01-21 20992]
S3 AndNetDiag;@oem103.inf,%Lgsi.Service.Name%;LGE AndroidNet USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [2015-01-26 30720]
S3 ANDNetModem;@oem105.inf,%LGSI.Service.Name%;LGE AndroidNet USB Modem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [2015-01-26 37376]
S3 athur;@oem99.inf,%ATHR.Service.DispName%;Qualcomm Atheros AR9271 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athuw8x.sys [2013-06-02 2919936]
S3 Avc;@avc.inf,%Avc.ServiceDesc%;AVC Device; C:\WINDOWS\System32\drivers\avc.sys [2013-08-22 48000]
S3 bthav;@oem83.inf,%AVFilter.SvcDesc%;Bluetooth AV Profile; C:\WINDOWS\system32\drivers\bthav.sys [2008-07-10 40448]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
S3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter_hs.sys []
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 MSDV;@msdv.inf,%DVCR.Capture%;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2013-08-22 51584]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys []
S3 OlyCamComm;@oem60.inf,%OlyUsbDesc%;OLYMPUS USB Communication Device; C:\WINDOWS\system32\DRIVERS\OlyCamComm.sys [2009-09-09 24208]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\RtsUCcid.sys [2009-08-10 50176]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\System32\drivers\usbscan.sys [2014-10-29 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-07-16 246784]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-07-15 344064]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [2007-01-11 126464]
R2 ExtTag;ExtTag service; C:\ProgramData\ExtTag\ExtTag []
R2 ssinstall;SInstalátor; C:\WINDOWS\SysWOW64\ssins.exe [2014-12-12 2324216]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2014-11-28 5419792]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\WINDOWS\ehome\ehRecvr.exe [2013-09-30 697856]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\WINDOWS\ehome\ehsched.exe [2013-09-30 176128]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-19 107912]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-05 148136]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-16 268976]
S4 DfSdkS;Defragmentation-Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control\Dfsdks.exe [2009-08-24 544768]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\WINDOWS\system32\svchost.exe [2014-10-29 38792]
S4 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#9 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Honza.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73 ... VlCHUB0&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73 ... VlCHUB0&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73 ... VlCHUB0&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F. ... puHTI-lr3u
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73 ... VlCHUB0&q={searchTerms}
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#10 Příspěvek od honzikuh »

Hotovo :D

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#11 Příspěvek od Rudy »

Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#12 Příspěvek od honzikuh »

Nastala změna obrovská , adwcleaner_4.208 odinstaloval všechno co nešlo, a ráno AVG našlo jen 1 objekt .Počkám ještě 24 hodin, ale vypadá že je všechno díky Vám zase v pořádku :|

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#13 Příspěvek od Rudy »

OK. Dejte zítra vědět a já to tu uzavřu. Zatím není zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

honzikuh
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 328
Registrován: 20 říj 2007 12:11

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#14 Příspěvek od honzikuh »

Moc moc děkuju, vypadá to čisté i 24 hodinách používání, :| :closed:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc zavirovaný počítač aniž jsem chtěl

#15 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno