Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu.

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
morar
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 212
Registrován: 01 kvě 2007 16:35
Bydliště: Bzenec

Prosím o kontrolu.

#1 Příspěvek od morar »

Ahoj.
Prosím o kontrolu.
Zdědil jsem PC po synovi a zdá se mi zpomalené. Nevím co tady všechno prováděl :?: Projel jsem ho ADWCLEANER a smazal jsem co našel. Přikládám log. Ještě přikládám log z RSIT.
Předem děkuji.



# AdwCleaner v6.030 - Log soubor vytvořen 15/11/2016 na 18:14:16
# Aktualizováno dne 19/10/2016 z Malwarebytes
# Databáze : 2016-11-15.1 [Server]
# Operační systém : Windows 10 Pro (X86)
# Uživatelské jméno : Marek - MAREK-PC
# Beží od : C:\Users\Marek\Desktop\adwcleaner_6.030.exe
# Mod: Čištění
# Podpora : hxxps://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Adresáře ] *****



***** [ Soubory ] *****

[-] Soubor smazán:C:\WINDOWS\Reimage.ini


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Klíč smazán:HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Klíč smazán:HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\Software\Reimage
[-] Klíč smazán:HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[#] Klíč smazán po restartování:HKCU\Software\Reimage
[#] Klíč smazán po restartování:HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[-] Klíč smazán:HKLM\SOFTWARE\Reimage
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [10314 Bajtů] - [17/11/2015 20:36:36]
C:\AdwCleaner\AdwCleaner[C2].txt - [2990 Bajtů] - [26/10/2016 21:52:05]
C:\AdwCleaner\AdwCleaner[C3].txt - [1387 Bajtů] - [05/11/2016 10:41:02]
C:\AdwCleaner\AdwCleaner[C4].txt - [2204 Bajtů] - [15/11/2016 18:14:16]
C:\AdwCleaner\AdwCleaner[S1].txt - [9889 Bajtů] - [17/11/2015 20:32:49]
C:\AdwCleaner\AdwCleaner[S2].txt - [3114 Bajtů] - [26/10/2016 21:46:23]
C:\AdwCleaner\AdwCleaner[S3].txt - [1708 Bajtů] - [05/11/2016 10:39:13]
C:\AdwCleaner\AdwCleaner[S4].txt - [2842 Bajtů] - [15/11/2016 18:12:36]

########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [2574 Bajtů] ##########



Logfile of random's system information tool 1.10 (written by random/random)
Run by Marek at 2016-11-15 18:21:59
Microsoft Windows 10 Pro
System drive C: has 409 GB (86%) free of 476 GB
Total RAM: 3455 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:22:12, on 15.11.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
C:\Users\Marek\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\LG Software\LG Smart Share\Update\SmartShareTray.exe
C:\Program Files\LG Software\LG Smart Share\DMS\SmartShareDMS.exe
C:\Program Files\LG Software\LG Smart Share\DMR\SmartShareDMR.exe
C:\Program Files\LG Software\LG Smart Share\DMC\Aggregation.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Marek\Downloads\RSIT.exe
C:\Program Files\trend micro\Marek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8118
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Marek\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O23 - Service: @oem4.inf,%AEADISRV.SvcDesc%;Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\WINDOWS\system32\AEADISRV.EXE
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Comodo - C:\Program Files\Comodo\Dragon\dragon_updater.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Death to Spies Drivers Auto Removal (pr2apc6b) (pr2apc6b) - Cenega Czech - C:\WINDOWS\system32\pr2apc6b.exe
O23 - Service: Samsung UPD Utility Service (SamsungUPDUtilSvc) - Unknown owner - C:\Windows\system32\SecUPDUtilSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 4757 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player PPAPI Notifier.job - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\j9igrqbx.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2008-01-02 1302528]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-26 7408312]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2007-12-06 3637248]
"CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2012-03-09 350072]
"Zune Launcher"=C:\Program Files\Zune\ZuneLauncher.exe [2011-08-05 159456]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2015-06-18 3576664]
"OneDrive"=C:\Users\Marek\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-10-26 633024]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-11-07 7048408]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-11-15 18:21:59 ----D---- C:\rsit
2016-11-15 18:21:59 ----D---- C:\Program Files\trend micro
2016-11-06 08:50:40 ----D---- C:\Users\Marek\AppData\Roaming\Easeware
2016-11-05 10:27:02 ----D---- C:\Program Files\Comodo
2016-11-05 10:26:35 ----A---- C:\WINDOWS\system32\msvcr71.dll
2016-11-05 10:26:35 ----A---- C:\WINDOWS\system32\mfc71.dll
2016-10-30 16:37:56 ----D---- C:\ProgramData\LG Software
2016-10-30 16:37:15 ----D---- C:\WINDOWS\system32\SSFilter
2016-10-30 16:37:15 ----A---- C:\WINDOWS\system32\av_proxy.dll
2016-10-30 16:37:15 ----A---- C:\WINDOWS\system32\av_dll.dll
2016-10-30 16:37:06 ----D---- C:\Program Files\LG Software
2016-10-30 16:36:18 ----D---- C:\ProgramData\Package Cache
2016-10-26 21:05:01 ----D---- C:\Program Files\Common Files\Skype
2016-10-26 21:01:32 ----D---- C:\ProgramData\Gaijin
2016-10-26 18:43:57 ----D---- C:\Program Files\Mozilla Firefox
2016-10-26 18:00:37 ----HD---- C:\$WINDOWS.~BT

======List of files/folders modified in the last 1 month======

2016-11-15 18:21:59 ----RD---- C:\Program Files
2016-11-15 18:21:26 ----D---- C:\WINDOWS\System32
2016-11-15 18:21:26 ----D---- C:\WINDOWS\INF
2016-11-15 18:21:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-15 18:20:51 ----D---- C:\WINDOWS\Temp
2016-11-15 18:18:55 ----D---- C:\Windows
2016-11-15 18:15:03 ----D---- C:\WINDOWS\system32\sru
2016-11-15 18:14:24 ----D---- C:\WINDOWS\Prefetch
2016-11-15 18:14:16 ----D---- C:\AdwCleaner
2016-11-15 18:05:13 ----D---- C:\WINDOWS\debug
2016-11-15 17:56:51 ----D---- C:\WINDOWS\system32\drivers
2016-11-15 17:11:59 ----D---- C:\WINDOWS\system32\Macromed
2016-11-15 13:02:28 ----HD---- C:\Program Files\WindowsApps
2016-11-15 12:55:28 ----D---- C:\WINDOWS\AppReadiness
2016-11-13 12:38:10 ----D---- C:\WINDOWS\system32\config
2016-11-13 12:33:44 ----D---- C:\WINDOWS\CbsTemp
2016-11-13 11:18:20 ----D---- C:\WINDOWS\system32\DriverStore
2016-11-13 11:18:14 ----D---- C:\WINDOWS\WinSxS
2016-11-13 11:14:24 ----D---- C:\WINDOWS\Microsoft.NET
2016-11-13 09:31:07 ----D---- C:\WINDOWS\system32\wbem
2016-11-13 09:31:07 ----D---- C:\WINDOWS\system32\oobe
2016-11-13 09:31:04 ----SD---- C:\WINDOWS\system32\F12
2016-11-13 09:31:04 ----SD---- C:\WINDOWS\system32\DiagSvcs
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\migwiz
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\migration
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\Dism
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\cs-CZ
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\Boot
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\appraiser
2016-11-13 09:31:04 ----D---- C:\WINDOWS\system32\AdvancedInstallers
2016-11-13 09:31:01 ----RSD---- C:\WINDOWS\Fonts
2016-11-13 09:31:01 ----RD---- C:\WINDOWS\PurchaseDialog
2016-11-13 09:31:01 ----RD---- C:\WINDOWS\PrintDialog
2016-11-13 09:31:01 ----RD---- C:\WINDOWS\MiracastView
2016-11-13 09:31:01 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-11-13 09:31:01 ----RD---- C:\WINDOWS\DevicesFlow
2016-11-13 09:31:01 ----D---- C:\WINDOWS\apppatch
2016-11-13 09:31:01 ----D---- C:\Program Files\Windows Portable Devices
2016-11-13 09:31:01 ----D---- C:\Program Files\Windows Photo Viewer
2016-11-13 09:31:01 ----D---- C:\Program Files\Windows Multimedia Platform
2016-11-13 09:31:01 ----D---- C:\Program Files\Windows Media Player
2016-11-13 09:31:01 ----D---- C:\Program Files\Windows Mail
2016-11-13 09:31:01 ----D---- C:\Program Files\Windows Defender
2016-11-13 09:31:01 ----D---- C:\Program Files\Internet Explorer
2016-11-13 08:59:02 ----D---- C:\WINDOWS\rescache
2016-11-12 12:08:31 ----SHD---- C:\System Volume Information
2016-11-11 21:17:08 ----HD---- C:\ProgramData
2016-11-11 18:11:58 ----D---- C:\WINDOWS\system32\MRT
2016-11-11 17:56:27 ----AC---- C:\WINDOWS\system32\MRT.exe
2016-11-09 19:08:01 ----D---- C:\WINDOWS\system32\catroot2
2016-11-07 17:47:44 ----D---- C:\Program Files\Steam
2016-11-07 17:32:13 ----D---- C:\Program Files\Common Files\Steam
2016-11-07 16:22:26 ----D---- C:\WarThunder
2016-11-07 10:50:56 ----D---- C:\WINDOWS\Tasks
2016-11-07 10:50:56 ----D---- C:\WINDOWS\system32\Tasks
2016-11-07 10:38:18 ----SHD---- C:\WINDOWS\Installer
2016-11-07 10:38:17 ----D---- C:\Program Files\7-Zip
2016-11-07 10:37:14 ----D---- C:\Users\Marek\AppData\Roaming\Seznam.cz
2016-11-07 10:37:07 ----D---- C:\Program Files\Seznam.cz
2016-11-05 10:42:09 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-10-30 16:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
2016-10-28 22:06:08 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2016-10-27 17:26:32 ----RSD---- C:\WINDOWS\assembly
2016-10-26 21:38:24 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2016-10-26 21:38:18 ----DC---- C:\WINDOWS\Panther
2016-10-26 21:07:59 ----D---- C:\Users\Marek\AppData\Roaming\Skype
2016-10-26 21:05:11 ----D---- C:\ProgramData\Skype
2016-10-26 21:05:03 ----RD---- C:\Program Files\Skype
2016-10-26 21:05:01 ----D---- C:\Program Files\Common Files
2016-10-26 18:10:17 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-10-26 17:29:27 ----D---- C:\WINDOWS\Minidump

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-05-12 58776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-10-26 224616]
R0 pe3apc6b;Death to Spies Environment Driver (pe3apc6b); C:\WINDOWS\system32\drivers\pe3apc6b.sys [2007-11-15 64640]
R0 ps7apc6b;Death to Spies Synchronization Driver (ps7apc6b); C:\WINDOWS\system32\drivers\ps7apc6b.sys [2007-11-15 68744]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2016-05-12 35096]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-05-12 91232]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-05-12 815792]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-05-12 449640]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-07-10 74240]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-12-01 7680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-05-12 32792]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-05-12 91168]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-05-12 124808]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-07-10 37376]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2013-11-26 5120]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-07-10 52736]
R3 ADIHdAudAddService;@oem4.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-01-03 370688]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-01-13 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-01-13 290304]
R3 AtcL001;@netl160x.inf,%AtcL001.Service.DispName%;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\WINDOWS\System32\drivers\l160x86.sys [2015-07-10 55808]
R3 AtiHDAudioService;@oem3.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdW73.sys [2012-05-14 86656]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2015-08-06 130048]
R3 MTsensor;@oem2.inf,%ASACPI.DisplayName%;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-07-10 88928]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-07-10 83296]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-07-10 51040]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-07-10 51552]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-07-10 33632]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-09-17 26112]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-07-10 96768]
S3 dg_ssudbus;@oem8.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2015-11-15 88576]
S3 fcvsc;fcvsc; C:\WINDOWS\System32\drivers\fcvsc.sys [2015-07-10 24064]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-07-10 17408]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2015-07-10 22016]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-07-10 37728]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2015-07-10 61936]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-07-10 23040]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-07-10 45056]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-08-06 32768]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-07-10 31744]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-07-10 190816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-07-10 73568]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-07-10 100704]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-07-10 42848]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-07-10 21856]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-07-10 21856]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\WINDOWS\System32\drivers\usbser.sys [2015-08-06 48128]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2015-07-10 184832]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AEADIFilters;@oem4.inf,%AEADISRV.SvcDesc%;Andrea ADI Filters Service; C:\WINDOWS\system32\AEADISRV.EXE [2007-10-19 86016]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-01-13 217088]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-05-12 243296]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
R2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2016-09-29 2272904]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2015-08-06 24576]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-07-10 135848]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-07-10 135848]
R2 OneSyncSvc_Session1;Hostitel synchronizace_Session1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
R2 SamsungUPDUtilSvc;Samsung UPD Utility Service; C:\Windows\system32\SecUPDUtilSvc.exe [2014-11-26 118576]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1034584]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-07-10 135848]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S2 OneSyncSvc_Session6;Hostitel synchronizace_Session6; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S2 pr2apc6b;Death to Spies Drivers Auto Removal (pr2apc6b); C:\WINDOWS\system32\pr2apc6b.exe [2007-11-15 411008]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 23040]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2015-05-29 43696]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-05 172488]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\lsass.exe [2015-07-10 41864]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 PimIndexMaintenanceSvc_Session1;Data kontaktů_Session1; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 PimIndexMaintenanceSvc_Session6;Data kontaktů_Session6; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-08-06 669696]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-07-10 35176]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2016-10-13 1459488]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 UnistoreSvc_Session1;Úložiště uživatelských dat_Session1; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S3 UnistoreSvc_Session6;Úložiště uživatelských dat_Session6; C:\WINDOWS\System32\svchost.exe [2015-07-10 35176]
S4 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-07-10 45240]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118249
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#2 Příspěvek od Rudy »

Zdravím!
Potřebuji log FRST: http://forum.viry.cz/viewtopic.php?f=24&t=132509 , abych mohl mazat. Mazání z RSIT pomocí OTM může poškodit systém.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

morar
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 212
Registrován: 01 kvě 2007 16:35
Bydliště: Bzenec

Re: Prosím o kontrolu.

#3 Příspěvek od morar »

Log z FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-11-2016
Ran by Marek (administrator) on MAREK-PC (15-11-2016 21:31:08)
Running from C:\Users\Marek\Desktop
Loaded Profiles: Marek (Available Profiles: Marek & DefaultAppPool)
Platform: Microsoft Windows 10 Pro (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
(Comodo) C:\Program Files\Comodo\Dragon\dragon_updater.exe
() C:\Windows\System32\SecUPDUtilSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SoundMAX.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1302528 2008-01-02] (Analog Devices, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7408312 2016-10-26] (AVAST Software)
HKLM\...\Run: [SoundMAX] => C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [3637248 2007-12-06] (Analog Devices, Inc.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] ()
HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [159456 2011-08-05] (Microsoft Corporation)
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [3576664 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7048408 2016-11-07] (Piriform Ltd)
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\MountPoints2: {e46e1849-6234-11e5-93d6-001bfc8c3dfd} - "E:\Lenovo_Suite.exe"
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\MountPoints2: {e46e1872-6234-11e5-93d6-001bfc8c3dfd} - "E:\Lenovo_Suite.exe"
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [792064 2015-07-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-05-12] (AVAST Software)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-3817569863-3399223854-3555965538-1001] => 127.0.0.1:8118
AutoConfigURL: [S-1-5-21-3817569863-3399223854-3555965538-1001] => 127.0.0.1:8118
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a8d5e23d-43ab-4c7f-8c01-0c2bf04ea6de}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
SearchScopes: HKLM -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3817569863-3399223854-3555965538-1001 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3817569863-3399223854-3555965538-1001 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}

FireFox:
========
FF DefaultProfile: j9igrqbx.default
FF ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\j9igrqbx.default [2016-11-15]
FF Extension: (ImTranslator) - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\j9igrqbx.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2016-11-15]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-12]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-05-12]
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [No File]

Chrome:
=======
CHR DefaultProfile: Default
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-05-12]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-05-12]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

Opera:
=======
OPR StartupUrls: "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggQcAwLUV8SRxgRclsNTA0TQA0OIV9bBBRDGARGJgsLVw8XFFEFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA=="
OPR Extension: (Wander Burst) - C:\Users\Marek\AppData\Roaming\Opera Software\Opera Stable\Extensions\ddnjmpkgmjldeegiggfnicgfmkdcmkfk [2015-08-02]
OPR Extension: (Opera Bookmarks Share Portal) - C:\Users\Marek\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi [2015-09-29]
OPR Extension: (Adblock Plus) - C:\Users\Marek\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-03-13]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-12] (AVAST Software)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1034584 2015-06-18] (Disc Soft Ltd)
R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2272904 2016-09-29] (Comodo)
S2 pr2apc6b; C:\WINDOWS\system32\pr2apc6b.exe [411008 2007-11-15] (Cenega Czech)
R2 SamsungUPDUtilSvc; C:\Windows\system32\SecUPDUtilSvc.exe [118576 2014-11-26] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [277760 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23264 2015-07-10] (Microsoft Corporation)
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [32792 2016-05-12] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [35096 2016-05-12] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [91168 2016-05-12] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [91232 2016-05-12] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [58776 2016-05-12] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [815792 2016-05-12] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449640 2016-05-12] (AVAST Software)
S2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [124808 2016-05-12] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [224616 2016-10-26] (AVAST Software)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R0 pe3apc6b; C:\WINDOWS\System32\drivers\pe3apc6b.sys [64640 2007-11-15] (Cenega Czech)
R0 ps7apc6b; C:\WINDOWS\System32\drivers\ps7apc6b.sys [68744 2007-11-15] (Cenega Czech)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2013-11-26] (Samsung Electronics) [File not signed]
S3 UdeCx; C:\WINDOWS\System32\drivers\udecx.sys [31744 2015-07-10] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37400 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [245600 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [97632 2015-07-10] (Microsoft Corporation)
R3 WUDFWpdMtp; C:\WINDOWS\System32\drivers\WUDFRd.sys [161792 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-15 21:31 - 2016-11-15 21:31 - 00010910 _____ C:\Users\Marek\Desktop\FRST.txt
2016-11-15 21:30 - 2016-11-15 21:31 - 00000000 ____D C:\FRST
2016-11-15 21:26 - 2016-11-15 21:29 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2016-11-15 21:25 - 2016-11-15 21:25 - 01760768 _____ (Farbar) C:\Users\Marek\Desktop\FRST.exe
2016-11-15 21:14 - 2016-11-15 21:14 - 00016148 _____ C:\WINDOWS\system32\MAREK-PC_Marek_HistoryPrediction.bin
2016-11-15 19:17 - 2016-11-15 19:17 - 00000000 ____D C:\Users\Marek\AppData\Local\ElevatedDiagnostics
2016-11-15 18:21 - 2016-11-15 18:22 - 00000000 ____D C:\rsit
2016-11-15 18:21 - 2016-11-15 18:22 - 00000000 ____D C:\Program Files\trend micro
2016-11-15 18:21 - 2016-11-15 18:21 - 01107968 _____ C:\Users\Marek\Downloads\RSIT.exe
2016-11-15 18:03 - 2016-11-15 18:03 - 08580928 _____ (Piriform Ltd) C:\Users\Marek\Downloads\ccsetup524.exe
2016-11-07 10:50 - 2016-11-15 18:15 - 00000958 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-11-07 10:50 - 2016-11-07 10:50 - 20477632 _____ (Adobe Systems Incorporated) C:\Users\Marek\Downloads\install_flash_player_ppapi.exe
2016-11-07 10:43 - 2016-11-07 10:46 - 08270712 _____ (Piriform Ltd) C:\Users\Marek\Downloads\ccsetup523.exe
2016-11-06 08:50 - 2016-11-06 08:50 - 00000000 ____D C:\Users\Marek\AppData\Roaming\Easeware
2016-11-06 08:49 - 2016-11-06 08:53 - 00604928 _____ (Reimage) C:\Users\Marek\Downloads\ReimageRepair.exe
2016-11-06 08:48 - 2016-11-06 08:50 - 02210840 _____ (Easeware ) C:\Users\Marek\Downloads\DriverNavigator_Setup.exe
2016-11-05 21:34 - 2016-11-05 21:34 - 00000017 _____ C:\Users\Marek\AppData\Local\resmon.resmoncfg
2016-11-05 10:27 - 2016-11-05 10:27 - 00002133 _____ C:\Users\Public\Desktop\Comodo Dragon.lnk
2016-11-05 10:27 - 2016-11-05 10:27 - 00000000 ____D C:\Users\Marek\AppData\Local\Chromium
2016-11-05 10:27 - 2016-11-05 10:27 - 00000000 ____D C:\Users\Marek\AppData\Local\Comodo
2016-11-05 10:27 - 2016-11-05 10:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2016-11-05 10:27 - 2016-11-05 10:27 - 00000000 ____D C:\Program Files\Comodo
2016-11-05 10:26 - 2016-11-05 10:26 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc71.dll
2016-11-05 10:26 - 2016-11-05 10:26 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr71.dll
2016-11-05 09:53 - 2016-11-05 09:53 - 00000000 ____D C:\Users\Marek\AppData\Local\Macromedia
2016-10-31 19:16 - 2016-10-31 19:16 - 00002275 _____ C:\Users\Public\Desktop\SmartShare.lnk
2016-10-30 16:37 - 2016-10-30 16:37 - 00000000 ____D C:\WINDOWS\system32\SSFilter
2016-10-30 16:37 - 2016-10-30 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG Software
2016-10-30 16:37 - 2016-10-30 16:37 - 00000000 ____D C:\ProgramData\LG Software
2016-10-30 16:37 - 2016-10-30 16:37 - 00000000 ____D C:\Program Files\LG Software
2016-10-30 16:37 - 2011-08-10 14:00 - 00378880 _____ C:\WINDOWS\system32\av_dll.dll
2016-10-30 16:37 - 2011-08-10 14:00 - 00020992 _____ C:\WINDOWS\system32\av_proxy.dll
2016-10-30 16:36 - 2016-10-30 16:36 - 00000000 ____D C:\ProgramData\Package Cache
2016-10-30 16:31 - 2016-10-30 16:32 - 191087726 _____ C:\Users\Marek\Downloads\LG_SmartShare_WAL_33_2.3.1511.1201.zip
2016-10-26 21:43 - 2016-10-26 21:43 - 03910208 _____ C:\Users\Marek\Desktop\adwcleaner_6.030.exe
2016-10-26 21:05 - 2016-10-26 21:05 - 00000000 ____D C:\Program Files\Common Files\Skype
2016-10-26 21:01 - 2016-10-26 21:01 - 00000000 ____D C:\Users\Marek\Documents\My Games
2016-10-26 21:01 - 2016-10-26 21:01 - 00000000 ____D C:\ProgramData\Gaijin
2016-10-26 18:43 - 2016-11-05 08:53 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-10-26 18:00 - 2016-10-26 18:02 - 00000000 ___HD C:\$WINDOWS.~BT

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-15 21:14 - 2015-07-10 09:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-11-15 21:09 - 2014-12-21 13:10 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-15 20:56 - 2014-12-21 13:10 - 00000956 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-15 20:29 - 2015-08-06 16:48 - 01986934 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-15 20:29 - 2015-07-10 14:19 - 00824684 _____ C:\WINDOWS\system32\perfh005.dat
2016-11-15 20:29 - 2015-07-10 14:19 - 00183806 _____ C:\WINDOWS\system32\perfc005.dat
2016-11-15 20:29 - 2015-07-10 09:27 - 00000000 ____D C:\WINDOWS\INF
2016-11-15 20:25 - 2015-07-10 10:55 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-15 20:25 - 2015-07-10 10:53 - 00215192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-11-15 20:24 - 2015-07-10 07:59 - 00131072 ___SH C:\WINDOWS\system32\config\BBI
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-11-15 20:21 - 2015-07-10 09:28 - 00000000 ____D C:\Program Files\Windows Defender
2016-11-15 20:21 - 2015-07-10 08:01 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2016-11-15 20:21 - 2015-07-10 07:59 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-11-15 19:25 - 2015-08-06 17:42 - 00000000 ___DC C:\WINDOWS\Panther
2016-11-15 18:14 - 2015-11-17 20:32 - 00000000 ____D C:\AdwCleaner
2016-11-15 18:03 - 2015-11-17 11:09 - 00001038 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-11-15 17:12 - 2014-12-21 13:03 - 00000000 ____D C:\Users\Marek\AppData\Local\Adobe
2016-11-15 17:11 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-11-15 13:02 - 2015-07-10 09:28 - 00000000 ___HD C:\Program Files\WindowsApps
2016-11-15 13:02 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-11-13 08:59 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\rescache
2016-11-11 18:11 - 2014-12-21 13:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-11-11 17:56 - 2014-12-21 13:46 - 138444440 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-11-07 17:47 - 2016-03-08 20:35 - 00000000 ____D C:\Program Files\Steam
2016-11-07 17:32 - 2016-03-08 20:35 - 00000000 ____D C:\Program Files\Common Files\Steam
2016-11-07 16:22 - 2016-03-29 16:25 - 00000000 ____D C:\WarThunder
2016-11-07 10:38 - 2015-09-22 10:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-11-07 10:38 - 2015-09-22 10:58 - 00000000 ____D C:\Program Files\7-Zip
2016-11-07 10:37 - 2015-09-29 18:26 - 00000000 ____D C:\Program Files\Seznam.cz
2016-11-07 10:37 - 2015-09-22 10:57 - 00000000 ____D C:\Users\Marek\AppData\Roaming\Seznam.cz
2016-11-05 18:42 - 2015-08-06 16:50 - 00000000 ____D C:\Users\Marek
2016-11-05 10:42 - 2016-01-05 13:05 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-11-05 10:20 - 2015-03-01 14:25 - 00000000 ____D C:\Users\Marek\AppData\LocalLow\Temp
2016-10-30 16:37 - 2014-12-21 14:14 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-10-28 22:06 - 2016-04-14 16:00 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-10-28 22:06 - 2016-04-14 16:00 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-10-28 02:22 - 2014-12-21 12:21 - 00407720 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-10-26 21:38 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2016-10-26 21:07 - 2015-05-08 15:40 - 00000000 ____D C:\Users\Marek\AppData\Roaming\Skype
2016-10-26 21:05 - 2015-05-08 15:39 - 00000000 ___RD C:\Program Files\Skype
2016-10-26 21:05 - 2015-05-08 15:39 - 00000000 ____D C:\ProgramData\Skype
2016-10-26 18:10 - 2015-07-10 09:28 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-10-26 17:29 - 2016-01-06 00:13 - 00000000 ____D C:\WINDOWS\Minidump
2016-10-26 17:23 - 2014-12-21 13:13 - 00224616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys
2016-10-26 17:17 - 2015-08-06 19:09 - 00002429 _____ C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-10-26 17:17 - 2015-08-06 19:09 - 00000000 ___RD C:\Users\Marek\OneDrive

==================== Files in the root of some directories =======

2016-11-05 21:34 - 2016-11-05 21:34 - 0000017 _____ () C:\Users\Marek\AppData\Local\resmon.resmoncfg
2015-09-01 17:19 - 2015-09-01 17:19 - 0000000 _____ () C:\ProgramData\temp

Some files in TEMP:
====================
C:\Users\Marek\AppData\Local\Temp\libeay32.dll
C:\Users\Marek\AppData\Local\Temp\msvcr120.dll
C:\Users\Marek\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================

ShortcutWithArgument: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online\Imperia Online.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://www.imperiaonline.org/?ref_ad=src123 --app-window-size=1920,1080
ShortcutWithArgument: C:\Users\Marek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Imperia Online.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxp://www.imperiaonline.org/?ref_ad=src123 --app-window-size=1920,1080

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Marek\Desktop" je 5 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118249
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#4 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\MountPoints2: {e46e1849-6234-11e5-93d6-001bfc8c3dfd} - "E:\Lenovo_Suite.exe"
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\MountPoints2: {e46e1872-6234-11e5-93d6-001bfc8c3dfd} - "E:\Lenovo_Suite.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [No File]
OPR StartupUrls: "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggQcAwLUV8SRxgRclsNTA0TQA0OIV9bBBRDGARGJgsLVw8XFFEFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA=="
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\ProgramData\temp
C:\Users\Marek\AppData\Local\Temp

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

morar
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 212
Registrován: 01 kvě 2007 16:35
Bydliště: Bzenec

Re: Prosím o kontrolu.

#5 Příspěvek od morar »

Tady je log po fixu:

Fix result of Farbar Recovery Scan Tool (x86) Version: 12-11-2016
Ran by Marek (15-11-2016 22:46:30) Run:1
Running from C:\Users\Marek\Desktop
Loaded Profiles: Marek (Available Profiles: Marek & DefaultAppPool)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\MountPoints2: {e46e1849-6234-11e5-93d6-001bfc8c3dfd} - "E:\Lenovo_Suite.exe"
HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\...\MountPoints2: {e46e1872-6234-11e5-93d6-001bfc8c3dfd} - "E:\Lenovo_Suite.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [No File]
OPR StartupUrls: "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggQcAwLUV8SRxgRclsNTA0TQA0OIV9bBBRDGARGJgsLVw8XFFEFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA=="
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\ProgramData\temp
C:\Users\Marek\AppData\Local\Temp

EmptyTemp:
End
*****************

"HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e46e1849-6234-11e5-93d6-001bfc8c3dfd}" => key removed successfully.
HKCR\CLSID\{e46e1849-6234-11e5-93d6-001bfc8c3dfd} => key not found.
"HKU\S-1-5-21-3817569863-3399223854-3555965538-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e46e1872-6234-11e5-93d6-001bfc8c3dfd}" => key removed successfully.
HKCR\CLSID\{e46e1872-6234-11e5-93d6-001bfc8c3dfd} => key not found.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
"HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3" => key removed successfully.
"HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9" => key removed successfully.
OPR StartupUrls: "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggQcAwLUV8SRxgRclsNTA0TQA0OIV9bBBRDGARGJgsLVw8XFFEFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA==" => removed successfully.
idsvc => service removed successfully.
wpcsvc => service removed successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\ProgramData\temp => moved successfully
C:\Users\Marek\AppData\Local\Temp => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 583648 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 16232212 B
Java, Flash, Steam htmlcache => 29222741 B
Windows/system/drivers => 368042 B
Edge => 91 B
Chrome => 399360 B
Firefox => 48963398 B
Opera => 14169824 B

Temp, IE cache, history, cookies, recent:
Default => 87004 B
ProgramData => 0 B
Public => 0 B
systemprofile => 5304326 B
LocalService => 4930 B
NetworkService => 28900 B
Marek => 9506697 B
DefaultAppPool => 72372 B

RecycleBin => 0 B
EmptyTemp: => 119.2 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 22:46:46 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118249
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#6 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

morar
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 212
Registrován: 01 kvě 2007 16:35
Bydliště: Bzenec

Re: Prosím o kontrolu.

#7 Příspěvek od morar »

Počítač se zrychlil. Vypadá to dobře.
Kdyby něco tak se ještě ozvu. Dík

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118249
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#8 Příspěvek od Rudy »

OK a nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno