
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu na vir
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu na vir
PC se zasekává a zase odsekává (nelze hýbat ničím jiným než kursorem)
Nelze pracovat s programy. Po chvilce se to většinou spraví a zase jede.
A pak zase jakoby zatuhne.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-11-2013
Ran by Martin (administrator) on MARTIN-PC on 29-11-2013 22:44:42
Running from D:\AMD
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) D:\VPNCisco\cvpnd.exe
(Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamgui.exe
(DT Soft Ltd) D:\DAEMON Tools Lite\DTLite.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Valve Corporation) D:\Steam\Steam.exe
(SkypEmoticons) C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe
(CMedia) C:\Program Files\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe
() C:\Program Files\ASUS Xonar DX Audio\Customapp\MXmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\bin\msmdsrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Mozilla Corporation) D:\Firefox_W_7\firefox.exe
(Mozilla Corporation) D:\Firefox_W_7\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.cpl,CMICtrlWnd
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKCU\...\Run: [Steam] - D:\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [se] - C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe [5827488 2013-10-13] (SkypEmoticons)
MountPoints2: {b3aa83fd-deba-11df-920a-4061868e83bf} - H:\setup.exe
HKLM-x32\...\Run: [] - [x]
AppInit_DLLs-x32: c:\progra~2\ss-hel~1\psupport.dll [ ] ()
==================== Internet (Whitelisted) ====================
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur-esult.info/?l=1&q= ... g=EN&cc=CZ
SearchScopes: HKCU - DefaultScope {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={search ... 9&tsp=5007
SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur-esult.info/?l=1&q= ... g=EN&cc=CZ
SearchScopes: HKCU - {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Office2007\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - F:\Visual Studio 2012\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\AdobeReader\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\AdobeReader\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\Programy\No1 Video Converter\msdxm.ocx (Microsoft Corporation)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Office2007\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler-x32: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - D:\Programy\No1 Video Converter\msdxm.ocx (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default
FF user.js: detected! => C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\user.js
FF NewTab: hxxp://www.google.com
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch");
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.cz/
FF Keyword.URL: hxxp://websearch.pur-esult.info/?pid=726&r=2013/10/13&hid=2097324813789929082&lg=EN&cc=CZ&l=1&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - D:\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Martin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Martin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\searchplugins\WebSearch.xml
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\Extensions\cs@dictionaries.addons.mozilla.org
FF Extension: Flashblock - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF Extension: prefs - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi
FF StartMenuInternet: FIREFOX.EXE - D:\Firefox_W_7\firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - http://www.google.cz/search?q={searchTe ... {startPage}
CHR DefaultSuggestURL: (Google) - "suggest_url": "",
CHR Extension: (Google Wallet) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
==================== Services (Whitelisted) =================
R2 CVPND; D:\VPNCisco\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation)
R2 MBAMScheduler; D:\Programy\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; D:\Programy\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 Microsoft Office Groove Audit Service; F:\Office2007\Office12\GrooveAuditService.exe [65824 2006-10-26] (Microsoft Corporation)
R2 MsDtsServer100; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [214040 2008-07-10] (Microsoft Corporation)
R2 msgsvr; D:\AVOX\ManagerENG\SMS_MMS Manager\msgsvr\msgsvr.exe [748032 2011-05-17] (Gemfor s.r.o.)
R2 MSSQL$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
R2 MSSQLSERVER; D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [57820696 2008-07-10] (Microsoft Corporation)
R2 MSSQLServerOLAPService; D:\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\bin\msmdsrv.exe [43709464 2008-07-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-07] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-09-08] ()
R2 ReportServer; D:\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2045464 2008-07-10] (Microsoft Corporation)
S3 SQLSERVERAGENT; D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [430616 2008-07-10] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation)
R3 MSSQLFDLauncher; "D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER [x]
==================== Drivers (Whitelisted) ====================
S3 adiusbaw; C:\Windows\System32\DRIVERS\adiusbawx64.sys [169496 2007-02-07] (Analog Devices Inc.)
R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [1197568 2008-01-18] (C-Media Inc)
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
R1 DNE; C:\Windows\System32\DRIVERS\dnelwf64.sys [132184 2011-08-04] (Citrix Systems, Inc.)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [67024 2013-03-12] (Fuzhou Rockchip Electronics Co,Ltd.)
S3 rt70x64; C:\Windows\System32\DRIVERS\netr7064.sys [388448 2010-04-27] (Ralink Technology Corp.)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-10-23] ()
S3 VSPerfDrv110; F:\Visual Studio 2012\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
U3 aeaf5bbo; C:\Windows\System32\Drivers\aeaf5bbo.sys [0 ] (Microsoft Corporation)
S3 MSICDSetup; \??\G:\CDriver64.sys [x]
S4 NVHDA; system32\drivers\nvhda64v.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-29 22:44 - 2013-11-29 22:44 - 00000000 ____D C:\FRST
2013-11-29 22:19 - 2013-11-29 22:19 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA Corporation
2013-11-23 09:53 - 2013-11-23 09:53 - 00474128 _____ C:\Windows\Minidump\112313-47627-01.dmp
2013-11-11 18:47 - 2013-11-11 18:47 - 00262144 _____ C:\Windows\Minidump\111113-50091-01.dmp
2013-11-10 15:00 - 2013-11-10 15:00 - 00000000 ___SH C:\Users\Martin\AppData\Local\LumaEmu
2013-11-10 13:01 - 2013-11-10 14:32 - 00000531 _____ C:\Users\Public\Desktop\Call of Duty Ghosts.lnk
2013-11-06 18:04 - 2013-11-08 21:47 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-06 18:04 - 2013-11-08 21:47 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-06 18:03 - 2013-11-06 18:03 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-06 18:02 - 2013-11-29 22:30 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-06 18:02 - 2013-11-29 22:30 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-06 18:02 - 2013-11-06 18:02 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Šablony
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Soubory cookie
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Poslední
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní tiskárny
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní síť
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Nabídka Start
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Dokumenty
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Obrázky
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Hudba
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Filmy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Data aplikací
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Data aplikací
2013-11-06 18:02 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-06 18:02 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-06 18:00 - 2013-10-23 11:30 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-06 18:00 - 2013-10-23 11:30 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-11-06 18:00 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-11-06 18:00 - 2013-09-28 00:01 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-11-06 18:00 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-11-06 17:57 - 2013-11-29 22:16 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA
2013-11-03 16:22 - 2013-11-03 16:22 - 00000000 ____D C:\ProgramData\EA Core
2013-11-03 08:18 - 2013-11-29 22:37 - 00008290 _____ C:\Windows\setupact.log
2013-11-03 08:18 - 2013-11-03 08:18 - 00000000 _____ C:\Windows\setuperr.log
2013-11-03 08:17 - 2013-11-03 08:17 - 00002282 _____ C:\Windows\PFRO.log
2013-11-02 19:16 - 2013-11-02 19:16 - 00017551 _____ C:\Windows\DirectX.log
2013-11-02 12:25 - 2013-11-02 12:28 - 00000000 ____D C:\Users\Martin\Documents\Battlefield 4
2013-11-02 12:24 - 2013-11-02 12:41 - 00000473 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2013-11-02 10:13 - 2013-11-02 10:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Sniper Elite Nazi Zombie Army 2
2013-11-02 10:12 - 2013-11-02 10:12 - 00000000 ____D C:\ProgramData\ALI213
==================== One Month Modified Files and Folders =======
2013-11-29 22:44 - 2013-11-29 22:44 - 00000000 ____D C:\FRST
2013-11-29 22:42 - 2010-10-23 12:31 - 01656192 _____ C:\Windows\WindowsUpdate.log
2013-11-29 22:42 - 2009-07-14 16:18 - 00823598 _____ C:\Windows\system32\perfh005.dat
2013-11-29 22:42 - 2009-07-14 16:18 - 00202814 _____ C:\Windows\system32\perfc005.dat
2013-11-29 22:42 - 2009-07-14 06:13 - 02026878 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-29 22:37 - 2013-11-03 08:18 - 00008290 _____ C:\Windows\setupact.log
2013-11-29 22:36 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-29 22:30 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-29 22:30 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-29 22:30 - 2012-08-03 17:13 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-11-29 22:30 - 2011-03-11 19:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-29 22:19 - 2013-11-29 22:19 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA Corporation
2013-11-29 22:16 - 2013-11-06 17:57 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA
2013-11-29 22:16 - 2012-02-09 22:30 - 00000966 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job
2013-11-29 20:34 - 2009-07-14 05:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-29 20:34 - 2009-07-14 05:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-23 10:16 - 2010-10-23 13:11 - 00000000 ____D C:\TrillianCZ
2013-11-23 09:53 - 2013-11-23 09:53 - 00474128 _____ C:\Windows\Minidump\112313-47627-01.dmp
2013-11-23 09:53 - 2012-01-11 20:05 - 00000000 ____D C:\Windows\Minidump
2013-11-22 17:16 - 2012-02-09 22:30 - 00000914 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job
2013-11-20 18:47 - 2013-07-11 19:46 - 00000000 ____D C:\Users\Martin\Documents\Visual Studio 2012
2013-11-18 18:32 - 2010-10-23 13:02 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla
2013-11-17 11:23 - 2012-02-09 22:31 - 00002378 _____ C:\Users\Martin\Desktop\Google Chrome.lnk
2013-11-11 18:47 - 2013-11-11 18:47 - 00262144 _____ C:\Windows\Minidump\111113-50091-01.dmp
2013-11-10 16:20 - 2010-10-23 19:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype
2013-11-10 15:00 - 2013-11-10 15:00 - 00000000 ___SH C:\Users\Martin\AppData\Local\LumaEmu
2013-11-10 14:32 - 2013-11-10 13:01 - 00000531 _____ C:\Users\Public\Desktop\Call of Duty Ghosts.lnk
2013-11-08 21:47 - 2013-11-06 18:04 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-08 21:47 - 2013-11-06 18:04 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-06 18:03 - 2013-11-06 18:03 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-06 18:02 - 2013-11-06 18:02 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Šablony
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Soubory cookie
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Poslední
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní tiskárny
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní síť
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Nabídka Start
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Dokumenty
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Obrázky
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Hudba
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Filmy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Data aplikací
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Data aplikací
2013-11-06 18:02 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help
2013-11-03 17:34 - 2013-09-08 16:49 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-11-03 17:34 - 2012-06-22 10:46 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-11-03 17:12 - 2012-06-22 10:33 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-11-03 16:22 - 2013-11-03 16:22 - 00000000 ____D C:\ProgramData\EA Core
2013-11-03 13:31 - 2013-09-08 16:53 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-03 12:33 - 2013-08-26 08:52 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Origin
2013-11-03 08:18 - 2013-11-03 08:18 - 00000000 _____ C:\Windows\setuperr.log
2013-11-03 08:17 - 2013-11-03 08:17 - 00002282 _____ C:\Windows\PFRO.log
2013-11-02 19:16 - 2013-11-02 19:16 - 00017551 _____ C:\Windows\DirectX.log
2013-11-02 19:16 - 2013-07-11 19:21 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-02 12:41 - 2013-11-02 12:24 - 00000473 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2013-11-02 12:28 - 2013-11-02 12:25 - 00000000 ____D C:\Users\Martin\Documents\Battlefield 4
2013-11-02 10:13 - 2013-11-02 10:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Sniper Elite Nazi Zombie Army 2
2013-11-02 10:12 - 2013-11-02 10:12 - 00000000 ____D C:\ProgramData\ALI213
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
Some content of TEMP:
====================
C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Martin\AppData\Local\Temp\nvStInst.exe
C:\Users\Martin\AppData\Local\Temp\sonarinst.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-21 18:41
==================== End Of Log ============================
Nelze pracovat s programy. Po chvilce se to většinou spraví a zase jede.
A pak zase jakoby zatuhne.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-11-2013
Ran by Martin (administrator) on MARTIN-PC on 29-11-2013 22:44:42
Running from D:\AMD
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) D:\VPNCisco\cvpnd.exe
(Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Malwarebytes Corporation) D:\Programy\Malwarebytes' Anti-Malware\mbamgui.exe
(DT Soft Ltd) D:\DAEMON Tools Lite\DTLite.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Valve Corporation) D:\Steam\Steam.exe
(SkypEmoticons) C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe
(CMedia) C:\Program Files\ASUS Xonar DX Audio\Customapp\AsusAudioCenter.exe
() C:\Program Files\ASUS Xonar DX Audio\Customapp\MXmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\bin\msmdsrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Mozilla Corporation) D:\Firefox_W_7\firefox.exe
(Mozilla Corporation) D:\Firefox_W_7\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.cpl,CMICtrlWnd
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKCU\...\Run: [Steam] - D:\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [se] - C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe [5827488 2013-10-13] (SkypEmoticons)
MountPoints2: {b3aa83fd-deba-11df-920a-4061868e83bf} - H:\setup.exe
HKLM-x32\...\Run: [] - [x]
AppInit_DLLs-x32: c:\progra~2\ss-hel~1\psupport.dll [ ] ()
==================== Internet (Whitelisted) ====================
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur-esult.info/?l=1&q= ... g=EN&cc=CZ
SearchScopes: HKCU - DefaultScope {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={search ... 9&tsp=5007
SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur-esult.info/?l=1&q= ... g=EN&cc=CZ
SearchScopes: HKCU - {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Office2007\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - F:\Visual Studio 2012\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\AdobeReader\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\AdobeReader\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\Programy\No1 Video Converter\msdxm.ocx (Microsoft Corporation)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Office2007\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler-x32: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - D:\Programy\No1 Video Converter\msdxm.ocx (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default
FF user.js: detected! => C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\user.js
FF NewTab: hxxp://www.google.com
FF SearchEngineOrder.1: WebSearch
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "WebSearch");: user_pref("browser.search.order.1,S", "WebSearch");
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.cz/
FF Keyword.URL: hxxp://websearch.pur-esult.info/?pid=726&r=2013/10/13&hid=2097324813789929082&lg=EN&cc=CZ&l=1&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - D:\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Martin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Martin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\searchplugins\WebSearch.xml
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\Extensions\cs@dictionaries.addons.mozilla.org
FF Extension: Flashblock - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF Extension: prefs - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi
FF StartMenuInternet: FIREFOX.EXE - D:\Firefox_W_7\firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - http://www.google.cz/search?q={searchTe ... {startPage}
CHR DefaultSuggestURL: (Google) - "suggest_url": "",
CHR Extension: (Google Wallet) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
==================== Services (Whitelisted) =================
R2 CVPND; D:\VPNCisco\cvpnd.exe [1528616 2010-03-23] (Cisco Systems, Inc.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation)
R2 MBAMScheduler; D:\Programy\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; D:\Programy\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 Microsoft Office Groove Audit Service; F:\Office2007\Office12\GrooveAuditService.exe [65824 2006-10-26] (Microsoft Corporation)
R2 MsDtsServer100; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [214040 2008-07-10] (Microsoft Corporation)
R2 msgsvr; D:\AVOX\ManagerENG\SMS_MMS Manager\msgsvr\msgsvr.exe [748032 2011-05-17] (Gemfor s.r.o.)
R2 MSSQL$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
R2 MSSQLSERVER; D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [57820696 2008-07-10] (Microsoft Corporation)
R2 MSSQLServerOLAPService; D:\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\bin\msmdsrv.exe [43709464 2008-07-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-07] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-09-08] ()
R2 ReportServer; D:\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2045464 2008-07-10] (Microsoft Corporation)
S3 SQLSERVERAGENT; D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [430616 2008-07-10] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation)
R3 MSSQLFDLauncher; "D:\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER [x]
==================== Drivers (Whitelisted) ====================
S3 adiusbaw; C:\Windows\System32\DRIVERS\adiusbawx64.sys [169496 2007-02-07] (Analog Devices Inc.)
R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [1197568 2008-01-18] (C-Media Inc)
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
R1 DNE; C:\Windows\System32\DRIVERS\dnelwf64.sys [132184 2011-08-04] (Citrix Systems, Inc.)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [67024 2013-03-12] (Fuzhou Rockchip Electronics Co,Ltd.)
S3 rt70x64; C:\Windows\System32\DRIVERS\netr7064.sys [388448 2010-04-27] (Ralink Technology Corp.)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-10-23] ()
S3 VSPerfDrv110; F:\Visual Studio 2012\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
U3 aeaf5bbo; C:\Windows\System32\Drivers\aeaf5bbo.sys [0 ] (Microsoft Corporation)
S3 MSICDSetup; \??\G:\CDriver64.sys [x]
S4 NVHDA; system32\drivers\nvhda64v.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-29 22:44 - 2013-11-29 22:44 - 00000000 ____D C:\FRST
2013-11-29 22:19 - 2013-11-29 22:19 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA Corporation
2013-11-23 09:53 - 2013-11-23 09:53 - 00474128 _____ C:\Windows\Minidump\112313-47627-01.dmp
2013-11-11 18:47 - 2013-11-11 18:47 - 00262144 _____ C:\Windows\Minidump\111113-50091-01.dmp
2013-11-10 15:00 - 2013-11-10 15:00 - 00000000 ___SH C:\Users\Martin\AppData\Local\LumaEmu
2013-11-10 13:01 - 2013-11-10 14:32 - 00000531 _____ C:\Users\Public\Desktop\Call of Duty Ghosts.lnk
2013-11-06 18:04 - 2013-11-08 21:47 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-06 18:04 - 2013-11-08 21:47 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-06 18:03 - 2013-11-06 18:03 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-06 18:02 - 2013-11-29 22:30 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-06 18:02 - 2013-11-29 22:30 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-06 18:02 - 2013-11-06 18:02 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Šablony
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Soubory cookie
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Poslední
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní tiskárny
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní síť
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Nabídka Start
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Dokumenty
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Obrázky
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Hudba
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Filmy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Data aplikací
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Data aplikací
2013-11-06 18:02 - 2009-07-14 05:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-06 18:02 - 2009-07-14 05:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-06 18:00 - 2013-10-23 11:30 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-06 18:00 - 2013-10-23 11:30 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-11-06 18:00 - 2013-10-23 11:30 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-11-06 18:00 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-11-06 18:00 - 2013-09-28 00:01 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-11-06 18:00 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-11-06 17:57 - 2013-11-29 22:16 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA
2013-11-03 16:22 - 2013-11-03 16:22 - 00000000 ____D C:\ProgramData\EA Core
2013-11-03 08:18 - 2013-11-29 22:37 - 00008290 _____ C:\Windows\setupact.log
2013-11-03 08:18 - 2013-11-03 08:18 - 00000000 _____ C:\Windows\setuperr.log
2013-11-03 08:17 - 2013-11-03 08:17 - 00002282 _____ C:\Windows\PFRO.log
2013-11-02 19:16 - 2013-11-02 19:16 - 00017551 _____ C:\Windows\DirectX.log
2013-11-02 12:25 - 2013-11-02 12:28 - 00000000 ____D C:\Users\Martin\Documents\Battlefield 4
2013-11-02 12:24 - 2013-11-02 12:41 - 00000473 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2013-11-02 10:13 - 2013-11-02 10:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Sniper Elite Nazi Zombie Army 2
2013-11-02 10:12 - 2013-11-02 10:12 - 00000000 ____D C:\ProgramData\ALI213
==================== One Month Modified Files and Folders =======
2013-11-29 22:44 - 2013-11-29 22:44 - 00000000 ____D C:\FRST
2013-11-29 22:42 - 2010-10-23 12:31 - 01656192 _____ C:\Windows\WindowsUpdate.log
2013-11-29 22:42 - 2009-07-14 16:18 - 00823598 _____ C:\Windows\system32\perfh005.dat
2013-11-29 22:42 - 2009-07-14 16:18 - 00202814 _____ C:\Windows\system32\perfc005.dat
2013-11-29 22:42 - 2009-07-14 06:13 - 02026878 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-29 22:37 - 2013-11-03 08:18 - 00008290 _____ C:\Windows\setupact.log
2013-11-29 22:36 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-29 22:30 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-29 22:30 - 2013-11-06 18:02 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-29 22:30 - 2012-08-03 17:13 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-11-29 22:30 - 2011-03-11 19:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-29 22:19 - 2013-11-29 22:19 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA Corporation
2013-11-29 22:16 - 2013-11-06 17:57 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA
2013-11-29 22:16 - 2012-02-09 22:30 - 00000966 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job
2013-11-29 20:34 - 2009-07-14 05:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-29 20:34 - 2009-07-14 05:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-23 10:16 - 2010-10-23 13:11 - 00000000 ____D C:\TrillianCZ
2013-11-23 09:53 - 2013-11-23 09:53 - 00474128 _____ C:\Windows\Minidump\112313-47627-01.dmp
2013-11-23 09:53 - 2012-01-11 20:05 - 00000000 ____D C:\Windows\Minidump
2013-11-22 17:16 - 2012-02-09 22:30 - 00000914 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job
2013-11-20 18:47 - 2013-07-11 19:46 - 00000000 ____D C:\Users\Martin\Documents\Visual Studio 2012
2013-11-18 18:32 - 2010-10-23 13:02 - 00000000 ____D C:\Users\Martin\AppData\Local\Mozilla
2013-11-17 11:23 - 2012-02-09 22:31 - 00002378 _____ C:\Users\Martin\Desktop\Google Chrome.lnk
2013-11-11 18:47 - 2013-11-11 18:47 - 00262144 _____ C:\Windows\Minidump\111113-50091-01.dmp
2013-11-10 16:20 - 2010-10-23 19:26 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype
2013-11-10 15:00 - 2013-11-10 15:00 - 00000000 ___SH C:\Users\Martin\AppData\Local\LumaEmu
2013-11-10 14:32 - 2013-11-10 13:01 - 00000531 _____ C:\Users\Public\Desktop\Call of Duty Ghosts.lnk
2013-11-08 21:47 - 2013-11-06 18:04 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-08 21:47 - 2013-11-06 18:04 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-06 18:03 - 2013-11-06 18:03 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-11-06 18:02 - 2013-11-06 18:02 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Šablony
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Soubory cookie
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Poslední
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní tiskárny
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní síť
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Nabídka Start
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Dokumenty
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Obrázky
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Hudba
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Filmy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\Data aplikací
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2013-11-06 18:02 - 2013-11-06 18:02 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Data aplikací
2013-11-06 18:02 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help
2013-11-03 17:34 - 2013-09-08 16:49 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-11-03 17:34 - 2012-06-22 10:46 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-11-03 17:12 - 2012-06-22 10:33 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-11-03 16:22 - 2013-11-03 16:22 - 00000000 ____D C:\ProgramData\EA Core
2013-11-03 13:31 - 2013-09-08 16:53 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-03 12:33 - 2013-08-26 08:52 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Origin
2013-11-03 08:18 - 2013-11-03 08:18 - 00000000 _____ C:\Windows\setuperr.log
2013-11-03 08:17 - 2013-11-03 08:17 - 00002282 _____ C:\Windows\PFRO.log
2013-11-02 19:16 - 2013-11-02 19:16 - 00017551 _____ C:\Windows\DirectX.log
2013-11-02 19:16 - 2013-07-11 19:21 - 00000000 ____D C:\ProgramData\Package Cache
2013-11-02 12:41 - 2013-11-02 12:24 - 00000473 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2013-11-02 12:28 - 2013-11-02 12:25 - 00000000 ____D C:\Users\Martin\Documents\Battlefield 4
2013-11-02 10:13 - 2013-11-02 10:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Sniper Elite Nazi Zombie Army 2
2013-11-02 10:12 - 2013-11-02 10:12 - 00000000 ____D C:\ProgramData\ALI213
Files to move or delete:
====================
C:\Windows\Tasks\At1.job
Some content of TEMP:
====================
C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Martin\AppData\Local\Temp\nvStInst.exe
C:\Users\Martin\AppData\Local\Temp\sonarinst.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-21 18:41
==================== End Of Log ============================
Re: Prosím o kontrolu logu na vir
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner


- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Prosím o kontrolu logu na vir
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Professional x64
Ran by Martin on so 30.11.2013 at 8:46:57,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\optprostart_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\optprostart_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sp global
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sprotector
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\websearch"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 30.11.2013 at 8:52:49,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Professional x64
Ran by Martin on so 30.11.2013 at 8:46:57,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\optprostart_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\optprostart_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sp global
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sprotector
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\websearch"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 30.11.2013 at 8:52:49,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Prosím o kontrolu logu na vir
# AdwCleaner v3.013 - Report created 30/11/2013 at 08:56:14
# Updated 24/11/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Martin - MARTIN-PC
# Running from : D:\AMD\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\DDownLoad kueePer
Folder Deleted : C:\ProgramData\SeArch--NewTTab
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
Folder Deleted : C:\Users\Martin\AppData\Roaming\SkypEmoticons
File Deleted : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\searchplugins\WebSearch.xml
File Deleted : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_289822ec
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKCU\Software\Pokki
Key Deleted : HKLM\Software\OptimizerPro
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v14.0.1 (cs)
[ File : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\prefs.js ]
Line Deleted : user_pref("aol_toolbar.default.homepage.check", false);
Line Deleted : user_pref("aol_toolbar.default.search.check", false);
Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.pur-esult.info/?pid=726&r=2013/10/13&hid=2097324813789929082&lg=EN&cc=CZ&l=1&q=");
Line Deleted : user_pref("browser.search.order.1", "WebSearch");
Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Line Deleted : user_pref("extensions.DQADa3.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self==window.top){var script=document.createElement(\"script\");script.[...]
Line Deleted : user_pref("extensions.Jvsk31ng.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.hostname.indexOf('mail.')==-1)\r\n{try{for(i=0;i<5;i++)[...]
Line Deleted : user_pref("keyword.URL", "hxxp://websearch.pur-esult.info/?pid=726&r=2013/10/13&hid=2097324813789929082&lg=EN&cc=CZ&l=1&q=");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", "");
-\\ Google Chrome v
[ File : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3814 octets] - [30/11/2013 08:55:15]
AdwCleaner[S0].txt - [3719 octets] - [30/11/2013 08:56:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3779 octets] ##########
# Updated 24/11/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Martin - MARTIN-PC
# Running from : D:\AMD\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\DDownLoad kueePer
Folder Deleted : C:\ProgramData\SeArch--NewTTab
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
Folder Deleted : C:\Users\Martin\AppData\Roaming\SkypEmoticons
File Deleted : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\searchplugins\WebSearch.xml
File Deleted : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_289822ec
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKCU\Software\Pokki
Key Deleted : HKLM\Software\OptimizerPro
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v14.0.1 (cs)
[ File : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\kqynkvy4.default\prefs.js ]
Line Deleted : user_pref("aol_toolbar.default.homepage.check", false);
Line Deleted : user_pref("aol_toolbar.default.search.check", false);
Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.pur-esult.info/?pid=726&r=2013/10/13&hid=2097324813789929082&lg=EN&cc=CZ&l=1&q=");
Line Deleted : user_pref("browser.search.order.1", "WebSearch");
Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Line Deleted : user_pref("extensions.DQADa3.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self==window.top){var script=document.createElement(\"script\");script.[...]
Line Deleted : user_pref("extensions.Jvsk31ng.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.hostname.indexOf('mail.')==-1)\r\n{try{for(i=0;i<5;i++)[...]
Line Deleted : user_pref("keyword.URL", "hxxp://websearch.pur-esult.info/?pid=726&r=2013/10/13&hid=2097324813789929082&lg=EN&cc=CZ&l=1&q=");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
Line Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", "");
-\\ Google Chrome v
[ File : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3814 octets] - [30/11/2013 08:55:15]
AdwCleaner[S0].txt - [3719 octets] - [30/11/2013 08:56:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3779 octets] ##########
Re: Prosím o kontrolu logu na vir
Poprosim o log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100
Re: Prosím o kontrolu logu na vir
Zde přikládám všechny logy, kopírováno do jednoho txt souboru v zipu.vyosek píše:Poprosim o log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100
Díky.
- Přílohy
-
- vsechny_logy_text.zip
- (20.36 KiB) Staženo 22 x
Re: Prosím o kontrolu logu na vir

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd) HKCU\...\Run: [Steam] - D:\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKCU\...\Run: [se] - "C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe" /minimized MountPoints2: {b3aa83fd-deba-11df-920a-4061868e83bf} - H:\setup.exe HKLM-x32\...\Run: [] - [x] AppInit_DLLs-x32: c:\progra~2\ss-hel~1\psupport.dll [ ] () SearchScopes: HKCU - DefaultScope {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/GENUINE - disabled No File CHR DefaultSuggestURL: (Google) - "suggest_url": "", U3 a17wjj65; C:\Windows\System32\Drivers\a17wjj65.sys [0 ] (Microsoft Corporation) S3 MSICDSetup; \??\G:\CDriver64.sys [x] S4 NVHDA; system32\drivers\nvhda64v.sys [x] S3 vpnva; system32\DRIVERS\vpnva64.sys [x] 2013-12-01 13:09 - 2013-12-01 13:09 - 00029696 _____ C:\Users\Martin\AppData\Local\MSGBOX.EXE 2013-12-01 13:09 - 2013-12-01 13:09 - 00015327 _____ C:\Users\Martin\Desktop\LM.bat 2013-12-01 13:09 - 2013-12-01 13:09 - 00014640 _____ C:\Users\Martin\Desktop\FRST.txt 2013-11-30 10:49 - 2013-11-30 10:49 - 00000065 _____ C:\Windows\SysWOW64\debug.log 2013-11-30 08:54 - 2013-11-30 08:56 - 00000000 ____D C:\AdwCleaner 2013-11-30 08:52 - 2013-11-30 08:52 - 00002070 _____ C:\Users\Martin\Desktop\JRT.txt C:\Windows\Tasks\At1.job C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Martin\AppData\Local\Temp\nvStInst.exe C:\Users\Martin\AppData\Local\Temp\Quarantine.exe C:\Users\Martin\AppData\Local\Temp\sonarinst.exe C:\Windows\inf\ntvdm.vbe Task: C:\Windows\Tasks\At1.job => C:\Users\Martin\AppData\Local\Temp\ installer_r.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio8788GX" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk" /f Hosts: CMD: shutdown /r /f /t 2 End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: Prosím o kontrolu logu na vir
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-12-2013
Ran by Martin at 2013-12-01 21:06:22 Run:1
Running from C:\Users\Martin\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKCU\...\Run: [Steam] - D:\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [se] - "C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
MountPoints2: {b3aa83fd-deba-11df-920a-4061868e83bf} - H:\setup.exe
HKLM-x32\...\Run: [] - [x]
AppInit_DLLs-x32: c:\progra~2\ss-hel~1\psupport.dll [ ] ()
SearchScopes: HKCU - DefaultScope {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
CHR DefaultSuggestURL: (Google) - "suggest_url": "",
U3 a17wjj65; C:\Windows\System32\Drivers\a17wjj65.sys [0 ] (Microsoft Corporation)
S3 MSICDSetup; \??\G:\CDriver64.sys [x]
S4 NVHDA; system32\drivers\nvhda64v.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]
2013-12-01 13:09 - 2013-12-01 13:09 - 00029696 _____ C:\Users\Martin\AppData\Local\MSGBOX.EXE
2013-12-01 13:09 - 2013-12-01 13:09 - 00015327 _____ C:\Users\Martin\Desktop\LM.bat
2013-12-01 13:09 - 2013-12-01 13:09 - 00014640 _____ C:\Users\Martin\Desktop\FRST.txt
2013-11-30 10:49 - 2013-11-30 10:49 - 00000065 _____ C:\Windows\SysWOW64\debug.log
2013-11-30 08:54 - 2013-11-30 08:56 - 00000000 ____D C:\AdwCleaner
2013-11-30 08:52 - 2013-11-30 08:52 - 00002070 _____ C:\Users\Martin\Desktop\JRT.txt
C:\Windows\Tasks\At1.job
C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Martin\AppData\Local\Temp\nvStInst.exe
C:\Users\Martin\AppData\Local\Temp\Quarantine.exe
C:\Users\Martin\AppData\Local\Temp\sonarinst.exe
C:\Windows\inf\ntvdm.vbe
Task: C:\Windows\Tasks\At1.job => C:\Users\Martin\AppData\Local\Temp\ installer_r.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio8788GX" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk" /f
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Nvtmru => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Steam => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\se => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3aa83fd-deba-11df-920a-4061868e83bf} => Key deleted successfully.
HKCR\CLSID\{b3aa83fd-deba-11df-920a-4061868e83bf} => Key not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DEFDE33C-70D1-4803-A6AD-950338167DFF} => Key deleted successfully.
HKCR\CLSID\{DEFDE33C-70D1-4803-A6AD-950338167DFF} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Value deleted successfully.
HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Key not found.
HKCR\PROTOCOLS\Handler\vnd.ms.radio => Key deleted successfully.
HKCR\CLSID\{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} => Key not found.
HKLM\Software\MozillaPlugins\FF Plugin: @microsoft.com/GENUINE - disabled No File => Key not found.
"FF Plugin: @microsoft.com/GENUINE - disabled No File" => not found.
HKLM\Software\Wow6432Node\MozillaPlugins\FF Plugin-x32: @microsoft.com/GENUINE - disabled No File => Key not found.
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File not found.
CHR DefaultSuggestURL: (Google) - "suggest_url": "", ==> The Chrome "Settings" can be used to fix the entry.
a17wjj65 => Service not found.
MSICDSetup => Service deleted successfully.
NVHDA => Service deleted successfully.
vpnva => Service deleted successfully.
C:\Users\Martin\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\Martin\Desktop\LM.bat => Moved successfully.
"C:\Users\Martin\Desktop\FRST.txt" => File/Directory not found.
C:\Windows\SysWOW64\debug.log => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Martin\Desktop\JRT.txt => Moved successfully.
C:\Windows\Tasks\At1.job => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nvStInst.exe => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\sonarinst.exe => Moved successfully.
"C:\Windows\inf\ntvdm.vbe" => File/Directory not found.
C:\Windows\Tasks\At1.job not found.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio8788GX" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Ran by Martin at 2013-12-01 21:06:22 Run:1
Running from C:\Users\Martin\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKCU\...\Run: [Steam] - D:\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [se] - "C:\Users\Martin\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
MountPoints2: {b3aa83fd-deba-11df-920a-4061868e83bf} - H:\setup.exe
HKLM-x32\...\Run: [] - [x]
AppInit_DLLs-x32: c:\progra~2\ss-hel~1\psupport.dll [ ] ()
SearchScopes: HKCU - DefaultScope {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
SearchScopes: HKCU - {DEFDE33C-70D1-4803-A6AD-950338167DFF} URL = http://www.google.cz/search?q={searchTe ... {startPage}
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
CHR DefaultSuggestURL: (Google) - "suggest_url": "",
U3 a17wjj65; C:\Windows\System32\Drivers\a17wjj65.sys [0 ] (Microsoft Corporation)
S3 MSICDSetup; \??\G:\CDriver64.sys [x]
S4 NVHDA; system32\drivers\nvhda64v.sys [x]
S3 vpnva; system32\DRIVERS\vpnva64.sys [x]
2013-12-01 13:09 - 2013-12-01 13:09 - 00029696 _____ C:\Users\Martin\AppData\Local\MSGBOX.EXE
2013-12-01 13:09 - 2013-12-01 13:09 - 00015327 _____ C:\Users\Martin\Desktop\LM.bat
2013-12-01 13:09 - 2013-12-01 13:09 - 00014640 _____ C:\Users\Martin\Desktop\FRST.txt
2013-11-30 10:49 - 2013-11-30 10:49 - 00000065 _____ C:\Windows\SysWOW64\debug.log
2013-11-30 08:54 - 2013-11-30 08:56 - 00000000 ____D C:\AdwCleaner
2013-11-30 08:52 - 2013-11-30 08:52 - 00002070 _____ C:\Users\Martin\Desktop\JRT.txt
C:\Windows\Tasks\At1.job
C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Martin\AppData\Local\Temp\nvStInst.exe
C:\Users\Martin\AppData\Local\Temp\Quarantine.exe
C:\Users\Martin\AppData\Local\Temp\sonarinst.exe
C:\Windows\inf\ntvdm.vbe
Task: C:\Windows\Tasks\At1.job => C:\Users\Martin\AppData\Local\Temp\ installer_r.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio8788GX" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk" /f
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Nvtmru => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Steam => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\se => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b3aa83fd-deba-11df-920a-4061868e83bf} => Key deleted successfully.
HKCR\CLSID\{b3aa83fd-deba-11df-920a-4061868e83bf} => Key not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DEFDE33C-70D1-4803-A6AD-950338167DFF} => Key deleted successfully.
HKCR\CLSID\{DEFDE33C-70D1-4803-A6AD-950338167DFF} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Value deleted successfully.
HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Key not found.
HKCR\PROTOCOLS\Handler\vnd.ms.radio => Key deleted successfully.
HKCR\CLSID\{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} => Key not found.
HKLM\Software\MozillaPlugins\FF Plugin: @microsoft.com/GENUINE - disabled No File => Key not found.
"FF Plugin: @microsoft.com/GENUINE - disabled No File" => not found.
HKLM\Software\Wow6432Node\MozillaPlugins\FF Plugin-x32: @microsoft.com/GENUINE - disabled No File => Key not found.
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File not found.
CHR DefaultSuggestURL: (Google) - "suggest_url": "", ==> The Chrome "Settings" can be used to fix the entry.
a17wjj65 => Service not found.
MSICDSetup => Service deleted successfully.
NVHDA => Service deleted successfully.
vpnva => Service deleted successfully.
C:\Users\Martin\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\Martin\Desktop\LM.bat => Moved successfully.
"C:\Users\Martin\Desktop\FRST.txt" => File/Directory not found.
C:\Windows\SysWOW64\debug.log => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Martin\Desktop\JRT.txt => Moved successfully.
C:\Windows\Tasks\At1.job => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nv3DVStreaming.dll => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nvStereoApiI.dll => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\nvStInst.exe => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Martin\AppData\Local\Temp\sonarinst.exe => Moved successfully.
"C:\Windows\inf\ntvdm.vbe" => File/Directory not found.
C:\Windows\Tasks\At1.job not found.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1979353130-4083666961-470471326-1000UA.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCEPServiceManager" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio8788GX" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Data Sync.lnk" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Re: Prosím o kontrolu logu na vir
Jak se chova PC 

Re: Prosím o kontrolu logu na vir
Moc děkuji, zatím od této doby se ani jednou nekouslo.vyosek píše:Jak se chova PC
Vlastně od prvního spuštění FRST64 spadlo jen jednou - natrvalo.
Nyní po provedení skriptu zcela stabilní !
Rád bych podpořil virovou poradnu, kde se dozvím patřičné konto?
// EDIT 23:09
Tak teď se to kouslo. Natrvalo. Musel jsem resetovat.
Ale může to být také nějaká hardwarová závada.

Re: Prosím o kontrolu logu na vir
Tak jeste uklidime
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
Zpusoby podpory fora jsou zde http://forum.viry.cz/viewtopic.php?f=7&t=78175
A pokud nejsou problemy ci dotazy, je to z me strany vse 


- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy


