
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu
Dobrý večer prosím o kontrolu logu, přítelkyni se poslední dobou zpomalil cpt a včera se jí ani nezapli widows a spustila se obnova syst.
Děkuji
LOG:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Gabča at 2013-12-14 21:59:38
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 41 GB (14%) free of 291 GB
Total RAM: 2812 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:59:48, on 14.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16750)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\SiteRanker\SiteRankTray.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\trend micro\Gabča.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60040
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
R3 - URLSearchHook: Harmony Hollow Software Toolbar - {3806B089-6759-411D-B2C3-B7995A9F34D7} - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~2\SITERA~1\SiteRank.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Harmony Hollow Software Toolbar - {3806b089-6759-411d-b2c3-b7995a9f34d7} - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O3 - Toolbar: Harmony Hollow Software Toolbar - {3806b089-6759-411d-b2c3-b7995a9f34d7} - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SiteRanker] "C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Samsung Auto Backup Guage.lnk = ?
O4 - Startup: Samsung Auto Backup Real-Time Daemon.lnk = ?
O4 - Startup: Samsung Auto Backup Scheduler.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.2.0\ViProtocol.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater17.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14097 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
"C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\Windows\system32\conhost.exe "3604823351067466491-1528218753-1247064105-921698411-1098017733-13281767641599949133
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
atieclxx
"taskhost.exe"
taskeng.exe {0C330200-DF30-424A-BD8C-5480683D0E59}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe"
"C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe"
"C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Hp\QuickPlay\QPService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe" /Start
"C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
"C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
"C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" /logon
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\splwow64.exe 8192
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe" -Embedding
"C:\Windows\system32\wuauclt.exe"
taskhost.exe $(Arg0)
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Gabča\Desktop\Programs\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default
prefs.js - "browser.startup.homepage" - "http://www.searchnu.com/406"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:2.5.6.0, {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6"
prefs.js - "keyword.URL" - "http://dts.search-results.com/sr?src=ff ... PN10645&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.2.0\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\SysWOW64\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
AskSearch.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files (x86)\Mozilla Firefox\plugins\
npnul32.dll
NPOFF12.DLL
nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
avg-secure-search.xml
crawlersrch.xml
google.xml
jyxo-cz.xml
mall-cz.xml
Search_Results.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\
conduit.xml
icqplugin.xml
Search_Results.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09 6270336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-05 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
C:\PROGRA~2\SITERA~1\SiteRank.dll [2013-10-10 1574584]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14 175776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3806b089-6759-411d-b2c3-b7995a9f34d7}]
Harmony Hollow Software Toolbar - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll [2009-03-10 2079256]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-09-20 329712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}]
Ask Search Assistant BHO
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-09-20 59376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}]
Ask Toolbar BHO
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{3806b089-6759-411d-b2c3-b7995a9f34d7} - Harmony Hollow Software Toolbar - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll [2009-03-10 2079256]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14 4372120]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-15 1815848]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2009-07-22 450048]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2009-08-20 2363392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-02 98304]
"QPService"=C:\Program Files (x86)\HP\QuickPlay\QPService.exe [2009-06-23 468264]
"UCam_Menu"=C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2009-02-17 218408]
"QlbCtrl.exe"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-06-24 320056]
"UpdatePRCShortCut"=C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
""= []
"WirelessAssistant"=C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-07-23 498744]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"SiteRanker"=C:\Program Files (x86)\SiteRanker\SiteRankTray.exe [2013-09-29 1059328]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2013-12-09 2471448]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Samsung Auto Backup Guage.lnk - C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
Samsung Auto Backup Real-Time Daemon.lnk - C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
Samsung Auto Backup Scheduler.lnk - C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BsScanner]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"WallpaperStyle"=2
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-12-14 21:59:41 ----D---- C:\Program Files\trend micro
2013-12-14 21:59:38 ----D---- C:\rsit
2013-12-14 19:13:44 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-14 19:13:43 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-14 19:13:43 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-14 19:13:41 ----A---- C:\Windows\system32\wmp.dll
2013-12-14 19:08:00 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-12-14 19:04:39 ----D---- C:\Windows\Migration
2013-12-14 18:42:50 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-14 18:42:49 ----A---- C:\Windows\system32\ieui.dll
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 18:42:48 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\iesetup.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\iernonce.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-14 18:42:47 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-14 18:42:46 ----A---- C:\Windows\system32\iertutil.dll
2013-12-14 18:42:45 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-14 18:42:45 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-14 18:42:45 ----A---- C:\Windows\system32\jscript.dll
2013-12-14 18:42:44 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-14 18:42:44 ----A---- C:\Windows\system32\jscript9.dll
2013-12-14 18:42:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-14 18:42:42 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-14 18:42:42 ----A---- C:\Windows\system32\urlmon.dll
2013-12-14 18:42:40 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-14 18:42:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-14 18:42:40 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-14 18:42:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-14 18:42:39 ----A---- C:\Windows\system32\wininet.dll
2013-12-14 18:42:37 ----A---- C:\Windows\system32\ieframe.dll
2013-12-14 18:42:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-14 18:42:33 ----A---- C:\Windows\system32\mshtml.dll
2013-12-14 18:38:39 ----D---- C:\Program Files\Microsoft Silverlight
2013-12-14 18:38:39 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-12-14 18:36:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-14 18:36:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-14 18:36:33 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-14 18:36:31 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-12-14 18:36:31 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-12-14 18:36:26 ----A---- C:\Windows\system32\wksprtPS.dll
2013-12-14 18:36:26 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-14 18:36:26 ----A---- C:\Windows\system32\tsgqec.dll
2013-12-14 18:36:25 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\wksprt.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\rdpudd.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\rdpendp_winip.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\rdpcorets.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\mstsc.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\aaclient.dll
2013-12-14 18:36:24 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-12-14 18:36:24 ----A---- C:\Windows\system32\mstscax.dll
2013-12-14 18:33:07 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-14 18:33:07 ----A---- C:\Windows\system32\tzres.dll
2013-12-14 18:30:22 ----D---- C:\ProgramData\AVG Secure Search
2013-12-14 17:22:52 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-14 17:22:52 ----A---- C:\Windows\system32\msieftp.dll
2013-12-14 17:22:51 ----A---- C:\Windows\system32\win32k.sys
2013-12-14 17:22:49 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-14 17:22:49 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-14 17:22:42 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-14 17:22:42 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-13 21:37:18 ----D---- C:\Program Files (x86)\TuneUp Utilities 2010
2013-12-13 21:36:37 ----D---- C:\ProgramData\TuneUp Software
2013-12-11 22:40:00 ----D---- C:\ProgramData\ESET
2013-12-11 22:40:00 ----D---- C:\Program Files\ESET
2013-12-11 21:32:17 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2013-12-11 21:32:17 ----A---- C:\Windows\system32\qdvd.dll
2013-12-11 17:58:38 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-11 17:58:38 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-11 17:58:37 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 17:58:37 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 17:58:37 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-11 17:58:37 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 17:58:37 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 17:58:37 ----A---- C:\Windows\system32\cscript.exe
2013-12-10 15:54:37 ----A---- C:\Windows\system32\MRT.exe
2013-12-09 21:54:29 ----D---- C:\7de8edae6386dccbf7a34abb778b
2013-12-03 21:44:03 ----D---- C:\Windows\system32\MRT
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbport.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbohci.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbhub.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbehci.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbd.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2013-11-15 22:27:15 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-15 22:27:15 ----A---- C:\Windows\system32\crypt32.dll
2013-11-15 22:27:09 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-15 22:27:06 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-15 22:27:06 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-15 22:27:06 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-15 22:27:06 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 22:27:06 ----A---- C:\Windows\system32\credui.dll
2013-11-15 22:27:06 ----A---- C:\Windows\system32\authui.dll
2013-11-15 22:26:57 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-15 22:26:57 ----A---- C:\Windows\system32\schannel.dll
2013-11-15 22:26:57 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-15 22:26:57 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-15 22:26:57 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-15 22:26:57 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-15 22:26:55 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-15 22:26:55 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-15 22:26:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\sspicli.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\secur32.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\lsass.exe
2013-11-15 22:26:51 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-15 22:26:51 ----A---- C:\Windows\system32\gdi32.dll
2013-11-15 22:26:49 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-15 22:26:49 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-15 22:26:49 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-15 22:26:49 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-15 22:26:49 ----A---- C:\Windows\system32\FWPUCLNT.DLL
======List of files/folders modified in the last 1 month======
2013-12-15 05:16:13 ----D---- C:\Windows\SYSWOW64\migration
2013-12-15 05:16:13 ----D---- C:\Windows\system32\wfp
2013-12-15 05:16:13 ----D---- C:\Windows\system32\migration
2013-12-15 05:16:13 ----D---- C:\Windows\system32\catroot2
2013-12-15 05:16:13 ----AD---- C:\Windows
2013-12-15 05:16:01 ----D---- C:\Windows\Tasks
2013-12-15 05:16:00 ----SHD---- C:\Config.Msi
2013-12-15 05:16:00 ----D---- C:\Windows\system32\catroot
2013-12-15 05:16:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-12-15 05:15:35 ----D---- C:\Windows\registration
2013-12-15 05:14:02 ----D---- C:\Windows\Microsoft.NET
2013-12-15 05:10:09 ----D---- C:\ProgramData\Recovery
2013-12-14 21:59:43 ----D---- C:\Windows\Temp
2013-12-14 21:59:41 ----RD---- C:\Program Files
2013-12-14 21:59:36 ----AD---- C:\ProgramData\Temp
2013-12-14 21:55:32 ----SHD---- C:\System Volume Information
2013-12-14 21:55:28 ----A---- C:\ProgramData\hpqp.ini
2013-12-14 21:55:25 ----A---- C:\ProgramData\HPWALog.txt
2013-12-14 21:55:24 ----HD---- C:\ProgramData
2013-12-14 21:54:29 ----D---- C:\Windows\system32\DriverStore
2013-12-14 21:54:00 ----D---- C:\Windows\winsxs
2013-12-14 21:52:25 ----D---- C:\Windows\system32\config
2013-12-14 21:47:58 ----D---- C:\Windows\SysWOW64
2013-12-14 21:47:58 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-14 21:47:57 ----D---- C:\Windows\System32
2013-12-14 21:47:57 ----D---- C:\Program Files\Windows Media Player
2013-12-14 21:47:56 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-14 21:47:55 ----D---- C:\Program Files\Internet Explorer
2013-12-14 21:47:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-14 21:47:53 ----D---- C:\Windows\system32\cs-CZ
2013-12-14 21:47:52 ----D---- C:\Windows\SYSWOW64\wbem
2013-12-14 21:47:52 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-14 21:47:52 ----D---- C:\Windows\system32\wbem
2013-12-14 21:47:52 ----D---- C:\Windows\system32\en-US
2013-12-14 21:47:52 ----D---- C:\Windows\system32\drivers\en-US
2013-12-14 21:47:52 ----D---- C:\Windows\system32\drivers
2013-12-14 21:47:52 ----D---- C:\Windows\PolicyDefinitions
2013-12-14 21:47:48 ----D---- C:\Windows\inf
2013-12-14 19:40:46 ----D---- C:\Windows\Logs
2013-12-14 19:32:18 ----D---- C:\Users\Gabča\AppData\Roaming\AVG
2013-12-14 19:13:06 ----SHD---- C:\Windows\Installer
2013-12-14 19:10:45 ----RSD---- C:\Windows\assembly
2013-12-14 19:08:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-14 19:04:39 ----SD---- C:\ProgramData\Microsoft
2013-12-14 18:52:48 ----D---- C:\ProgramData\Microsoft Help
2013-12-14 18:38:39 ----D---- C:\Program Files (x86)
2013-12-14 17:50:47 ----D---- C:\Windows\Downloaded Program Files
2013-12-14 17:43:12 ----D---- C:\Windows\system32\Tasks
2013-12-14 17:42:48 ----D---- C:\Program Files (x86)\AVG
2013-12-14 17:11:06 ----D---- C:\Program Files (x86)\SiteRanker
2013-12-14 17:10:13 ----D---- C:\Program Files (x86)\Google
2013-12-14 17:08:10 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-14 17:05:02 ----D---- C:\ProgramData\Google
2013-12-14 08:27:44 ----D---- C:\Windows\system32\CodeIntegrity
2013-12-13 21:48:16 ----D---- C:\Users\Gabča\AppData\Roaming\ICQ
2013-12-13 21:38:10 ----D---- C:\Users\Gabča\AppData\Roaming\TuneUp Software
2013-12-11 22:08:37 ----D---- C:\ProgramData\MFAData
2013-12-11 21:57:17 ----D---- C:\ProgramData\AVG2013
2013-12-11 21:56:45 ----HD---- C:\$AVG
2013-12-11 21:43:32 ----D---- C:\Windows\system32\drivers\etc
2013-12-11 21:43:32 ----D---- C:\Program Files (x86)\Common Files
2013-12-11 18:35:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-10 18:46:42 ----D---- C:\Users\Gabča\AppData\Roaming\vlc
2013-12-10 02:12:26 ----D---- C:\Windows\system32\drivers\UMDF
2013-12-10 02:12:25 ----D---- C:\Users\Gabča\AppData\Roaming\dvdcss
2013-12-10 02:08:59 ----D---- C:\ProgramData\Adobe
2013-12-09 17:18:17 ----D---- C:\Program Files (x86)\AVG Secure Search
2013-12-03 22:17:35 ----D---- C:\ProgramData\CanonIJPLM
2013-12-03 21:44:02 ----D---- C:\Windows\debug
2013-11-22 17:11:00 ----D---- C:\Windows\rescache
2013-11-19 03:33:38 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 AFW;Agnitum Firewall Driver; C:\Windows\system32\DRIVERS\afw.sys [2012-11-20 40544]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2013-11-10 46368]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 afwcore;afwcore; C:\Windows\system32\DRIVERS\afwcore.sys [2012-11-20 464480]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-09-22 1484800]
R3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys [2009-06-05 114192]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-02 6036480]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 18432]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys [2009-07-22 487936]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-07-15 273456]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-03-09 36408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-17 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-07-17 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-07-17 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-17 21160]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2008-05-02 23552]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2008-05-02 18432]
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-09-16 82816]
S3 Prot6Flt;Prot6Flt; C:\Windows\system32\drivers\Prot6Flt.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-06-24 216576]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\drivers\RtsUIR.sys []
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2008-05-02 8704]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\drivers\USBCCID.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 usbser;Nokia USB Serial Port; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2008-05-02 8704]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-07-02 203264]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 864032]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2009-07-09 124928]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2009-01-21 247152]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [2009-07-22 240128]
R2 vToolbarUpdater17.2.0;vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [2013-12-09 1771544]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-28 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Děkuji
LOG:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Gabča at 2013-12-14 21:59:38
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 41 GB (14%) free of 291 GB
Total RAM: 2812 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:59:48, on 14.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16750)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\SiteRanker\SiteRankTray.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\trend micro\Gabča.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60040
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
R3 - URLSearchHook: Harmony Hollow Software Toolbar - {3806B089-6759-411D-B2C3-B7995A9F34D7} - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~2\SITERA~1\SiteRank.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Harmony Hollow Software Toolbar - {3806b089-6759-411d-b2c3-b7995a9f34d7} - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O3 - Toolbar: Harmony Hollow Software Toolbar - {3806b089-6759-411d-b2c3-b7995a9f34d7} - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SiteRanker] "C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Samsung Auto Backup Guage.lnk = ?
O4 - Startup: Samsung Auto Backup Real-Time Daemon.lnk = ?
O4 - Startup: Samsung Auto Backup Scheduler.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.2.0\ViProtocol.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater17.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14097 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
"C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe"
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\Windows\system32\conhost.exe "3604823351067466491-1528218753-1247064105-921698411-1098017733-13281767641599949133
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
atieclxx
"taskhost.exe"
taskeng.exe {0C330200-DF30-424A-BD8C-5480683D0E59}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe"
"C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe"
"C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Hp\QuickPlay\QPService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe" /Start
"C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
"C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
"C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" /logon
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\splwow64.exe 8192
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe" -Embedding
"C:\Windows\system32\wuauclt.exe"
taskhost.exe $(Arg0)
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Gabča\Desktop\Programs\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default
prefs.js - "browser.startup.homepage" - "http://www.searchnu.com/406"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:2.5.6.0, {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6"
prefs.js - "keyword.URL" - "http://dts.search-results.com/sr?src=ff ... PN10645&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.2.0\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35]
"Description"=
"Path"=C:\Windows\SysWOW64\npdeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
AskSearch.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files (x86)\Mozilla Firefox\plugins\
npnul32.dll
NPOFF12.DLL
nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
avg-secure-search.xml
crawlersrch.xml
google.xml
jyxo-cz.xml
mall-cz.xml
Search_Results.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\
conduit.xml
icqplugin.xml
Search_Results.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09 6270336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-05 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
C:\PROGRA~2\SITERA~1\SiteRank.dll [2013-10-10 1574584]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14 175776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3806b089-6759-411d-b2c3-b7995a9f34d7}]
Harmony Hollow Software Toolbar - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll [2009-03-10 2079256]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-09-20 329712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}]
Ask Search Assistant BHO
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-09-20 59376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}]
Ask Toolbar BHO
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{3806b089-6759-411d-b2c3-b7995a9f34d7} - Harmony Hollow Software Toolbar - C:\Program Files (x86)\Harmony_Hollow_Software\tbHarm.dll [2009-03-10 2079256]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14 4372120]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-15 1815848]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2009-07-22 450048]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2009-08-20 2363392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-02 98304]
"QPService"=C:\Program Files (x86)\HP\QuickPlay\QPService.exe [2009-06-23 468264]
"UCam_Menu"=C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2009-02-17 218408]
"QlbCtrl.exe"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-06-24 320056]
"UpdatePRCShortCut"=C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
""= []
"WirelessAssistant"=C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-07-23 498744]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"SiteRanker"=C:\Program Files (x86)\SiteRanker\SiteRankTray.exe [2013-09-29 1059328]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2013-12-09 2471448]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Samsung Auto Backup Guage.lnk - C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
Samsung Auto Backup Real-Time Daemon.lnk - C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
Samsung Auto Backup Scheduler.lnk - C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BsScanner]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"WallpaperStyle"=2
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-12-14 21:59:41 ----D---- C:\Program Files\trend micro
2013-12-14 21:59:38 ----D---- C:\rsit
2013-12-14 19:13:44 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-14 19:13:43 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-14 19:13:43 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-14 19:13:41 ----A---- C:\Windows\system32\wmp.dll
2013-12-14 19:08:00 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-12-14 19:04:39 ----D---- C:\Windows\Migration
2013-12-14 18:42:50 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-14 18:42:49 ----A---- C:\Windows\system32\ieui.dll
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-14 18:42:48 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 18:42:48 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\iesetup.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\iernonce.dll
2013-12-14 18:42:48 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-14 18:42:47 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-14 18:42:46 ----A---- C:\Windows\system32\iertutil.dll
2013-12-14 18:42:45 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-14 18:42:45 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-14 18:42:45 ----A---- C:\Windows\system32\jscript.dll
2013-12-14 18:42:44 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-14 18:42:44 ----A---- C:\Windows\system32\jscript9.dll
2013-12-14 18:42:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-14 18:42:42 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-14 18:42:42 ----A---- C:\Windows\system32\urlmon.dll
2013-12-14 18:42:40 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-14 18:42:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-14 18:42:40 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-14 18:42:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-14 18:42:39 ----A---- C:\Windows\system32\wininet.dll
2013-12-14 18:42:37 ----A---- C:\Windows\system32\ieframe.dll
2013-12-14 18:42:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-14 18:42:33 ----A---- C:\Windows\system32\mshtml.dll
2013-12-14 18:38:39 ----D---- C:\Program Files\Microsoft Silverlight
2013-12-14 18:38:39 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-12-14 18:36:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-14 18:36:33 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-14 18:36:33 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-14 18:36:31 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-12-14 18:36:31 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-12-14 18:36:26 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-12-14 18:36:26 ----A---- C:\Windows\system32\wksprtPS.dll
2013-12-14 18:36:26 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-14 18:36:26 ----A---- C:\Windows\system32\tsgqec.dll
2013-12-14 18:36:25 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\wksprt.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\rdpudd.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\rdpendp_winip.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\rdpcorets.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\mstsc.exe
2013-12-14 18:36:25 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-12-14 18:36:25 ----A---- C:\Windows\system32\aaclient.dll
2013-12-14 18:36:24 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-12-14 18:36:24 ----A---- C:\Windows\system32\mstscax.dll
2013-12-14 18:33:07 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-14 18:33:07 ----A---- C:\Windows\system32\tzres.dll
2013-12-14 18:30:22 ----D---- C:\ProgramData\AVG Secure Search
2013-12-14 17:22:52 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-14 17:22:52 ----A---- C:\Windows\system32\msieftp.dll
2013-12-14 17:22:51 ----A---- C:\Windows\system32\win32k.sys
2013-12-14 17:22:49 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-14 17:22:49 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-14 17:22:42 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-14 17:22:42 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-13 21:37:18 ----D---- C:\Program Files (x86)\TuneUp Utilities 2010
2013-12-13 21:36:37 ----D---- C:\ProgramData\TuneUp Software
2013-12-11 22:40:00 ----D---- C:\ProgramData\ESET
2013-12-11 22:40:00 ----D---- C:\Program Files\ESET
2013-12-11 21:32:17 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2013-12-11 21:32:17 ----A---- C:\Windows\system32\qdvd.dll
2013-12-11 17:58:38 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-11 17:58:38 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-11 17:58:37 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 17:58:37 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 17:58:37 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-11 17:58:37 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 17:58:37 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 17:58:37 ----A---- C:\Windows\system32\cscript.exe
2013-12-10 15:54:37 ----A---- C:\Windows\system32\MRT.exe
2013-12-09 21:54:29 ----D---- C:\7de8edae6386dccbf7a34abb778b
2013-12-03 21:44:03 ----D---- C:\Windows\system32\MRT
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbport.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbohci.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbhub.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbehci.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbd.sys
2013-11-28 17:34:20 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2013-11-15 22:27:15 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-11-15 22:27:15 ----A---- C:\Windows\system32\crypt32.dll
2013-11-15 22:27:09 ----A---- C:\Windows\system32\drivers\afd.sys
2013-11-15 22:27:06 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2013-11-15 22:27:06 ----A---- C:\Windows\SYSWOW64\credui.dll
2013-11-15 22:27:06 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-11-15 22:27:06 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 22:27:06 ----A---- C:\Windows\system32\credui.dll
2013-11-15 22:27:06 ----A---- C:\Windows\system32\authui.dll
2013-11-15 22:26:57 ----A---- C:\Windows\SYSWOW64\schannel.dll
2013-11-15 22:26:57 ----A---- C:\Windows\system32\schannel.dll
2013-11-15 22:26:57 ----A---- C:\Windows\system32\lsasrv.dll
2013-11-15 22:26:57 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2013-11-15 22:26:57 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2013-11-15 22:26:57 ----A---- C:\Windows\system32\drivers\cng.sys
2013-11-15 22:26:55 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2013-11-15 22:26:55 ----A---- C:\Windows\SYSWOW64\secur32.dll
2013-11-15 22:26:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\sspisrv.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\sspicli.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\secur32.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\ncrypt.dll
2013-11-15 22:26:55 ----A---- C:\Windows\system32\lsass.exe
2013-11-15 22:26:51 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2013-11-15 22:26:51 ----A---- C:\Windows\system32\gdi32.dll
2013-11-15 22:26:49 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2013-11-15 22:26:49 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2013-11-15 22:26:49 ----A---- C:\Windows\system32\nshwfp.dll
2013-11-15 22:26:49 ----A---- C:\Windows\system32\IKEEXT.DLL
2013-11-15 22:26:49 ----A---- C:\Windows\system32\FWPUCLNT.DLL
======List of files/folders modified in the last 1 month======
2013-12-15 05:16:13 ----D---- C:\Windows\SYSWOW64\migration
2013-12-15 05:16:13 ----D---- C:\Windows\system32\wfp
2013-12-15 05:16:13 ----D---- C:\Windows\system32\migration
2013-12-15 05:16:13 ----D---- C:\Windows\system32\catroot2
2013-12-15 05:16:13 ----AD---- C:\Windows
2013-12-15 05:16:01 ----D---- C:\Windows\Tasks
2013-12-15 05:16:00 ----SHD---- C:\Config.Msi
2013-12-15 05:16:00 ----D---- C:\Windows\system32\catroot
2013-12-15 05:16:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-12-15 05:15:35 ----D---- C:\Windows\registration
2013-12-15 05:14:02 ----D---- C:\Windows\Microsoft.NET
2013-12-15 05:10:09 ----D---- C:\ProgramData\Recovery
2013-12-14 21:59:43 ----D---- C:\Windows\Temp
2013-12-14 21:59:41 ----RD---- C:\Program Files
2013-12-14 21:59:36 ----AD---- C:\ProgramData\Temp
2013-12-14 21:55:32 ----SHD---- C:\System Volume Information
2013-12-14 21:55:28 ----A---- C:\ProgramData\hpqp.ini
2013-12-14 21:55:25 ----A---- C:\ProgramData\HPWALog.txt
2013-12-14 21:55:24 ----HD---- C:\ProgramData
2013-12-14 21:54:29 ----D---- C:\Windows\system32\DriverStore
2013-12-14 21:54:00 ----D---- C:\Windows\winsxs
2013-12-14 21:52:25 ----D---- C:\Windows\system32\config
2013-12-14 21:47:58 ----D---- C:\Windows\SysWOW64
2013-12-14 21:47:58 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-14 21:47:57 ----D---- C:\Windows\System32
2013-12-14 21:47:57 ----D---- C:\Program Files\Windows Media Player
2013-12-14 21:47:56 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-14 21:47:55 ----D---- C:\Program Files\Internet Explorer
2013-12-14 21:47:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-14 21:47:53 ----D---- C:\Windows\system32\cs-CZ
2013-12-14 21:47:52 ----D---- C:\Windows\SYSWOW64\wbem
2013-12-14 21:47:52 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-14 21:47:52 ----D---- C:\Windows\system32\wbem
2013-12-14 21:47:52 ----D---- C:\Windows\system32\en-US
2013-12-14 21:47:52 ----D---- C:\Windows\system32\drivers\en-US
2013-12-14 21:47:52 ----D---- C:\Windows\system32\drivers
2013-12-14 21:47:52 ----D---- C:\Windows\PolicyDefinitions
2013-12-14 21:47:48 ----D---- C:\Windows\inf
2013-12-14 19:40:46 ----D---- C:\Windows\Logs
2013-12-14 19:32:18 ----D---- C:\Users\Gabča\AppData\Roaming\AVG
2013-12-14 19:13:06 ----SHD---- C:\Windows\Installer
2013-12-14 19:10:45 ----RSD---- C:\Windows\assembly
2013-12-14 19:08:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-14 19:04:39 ----SD---- C:\ProgramData\Microsoft
2013-12-14 18:52:48 ----D---- C:\ProgramData\Microsoft Help
2013-12-14 18:38:39 ----D---- C:\Program Files (x86)
2013-12-14 17:50:47 ----D---- C:\Windows\Downloaded Program Files
2013-12-14 17:43:12 ----D---- C:\Windows\system32\Tasks
2013-12-14 17:42:48 ----D---- C:\Program Files (x86)\AVG
2013-12-14 17:11:06 ----D---- C:\Program Files (x86)\SiteRanker
2013-12-14 17:10:13 ----D---- C:\Program Files (x86)\Google
2013-12-14 17:08:10 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-14 17:05:02 ----D---- C:\ProgramData\Google
2013-12-14 08:27:44 ----D---- C:\Windows\system32\CodeIntegrity
2013-12-13 21:48:16 ----D---- C:\Users\Gabča\AppData\Roaming\ICQ
2013-12-13 21:38:10 ----D---- C:\Users\Gabča\AppData\Roaming\TuneUp Software
2013-12-11 22:08:37 ----D---- C:\ProgramData\MFAData
2013-12-11 21:57:17 ----D---- C:\ProgramData\AVG2013
2013-12-11 21:56:45 ----HD---- C:\$AVG
2013-12-11 21:43:32 ----D---- C:\Windows\system32\drivers\etc
2013-12-11 21:43:32 ----D---- C:\Program Files (x86)\Common Files
2013-12-11 18:35:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-10 18:46:42 ----D---- C:\Users\Gabča\AppData\Roaming\vlc
2013-12-10 02:12:26 ----D---- C:\Windows\system32\drivers\UMDF
2013-12-10 02:12:25 ----D---- C:\Users\Gabča\AppData\Roaming\dvdcss
2013-12-10 02:08:59 ----D---- C:\ProgramData\Adobe
2013-12-09 17:18:17 ----D---- C:\Program Files (x86)\AVG Secure Search
2013-12-03 22:17:35 ----D---- C:\ProgramData\CanonIJPLM
2013-12-03 21:44:02 ----D---- C:\Windows\debug
2013-11-22 17:11:00 ----D---- C:\Windows\rescache
2013-11-19 03:33:38 ----N---- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 AFW;Agnitum Firewall Driver; C:\Windows\system32\DRIVERS\afw.sys [2012-11-20 40544]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2013-11-10 46368]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 afwcore;afwcore; C:\Windows\system32\DRIVERS\afwcore.sys [2012-11-20 464480]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-09-22 1484800]
R3 AtiHdmiService;ATI Service for HD Audio Codec; C:\Windows\system32\drivers\AtiHdmi.sys [2009-06-05 114192]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-02 6036480]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 18432]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys [2009-07-22 487936]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-07-15 273456]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-03-09 36408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-17 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-07-17 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-07-17 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-17 21160]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2008-05-02 23552]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2008-05-02 18432]
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-09-16 82816]
S3 Prot6Flt;Prot6Flt; C:\Windows\system32\drivers\Prot6Flt.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-06-24 216576]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\drivers\RtsUIR.sys []
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2008-05-02 8704]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\drivers\USBCCID.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 usbser;Nokia USB Serial Port; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2008-05-02 8704]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-03-02 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-07-02 203264]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 864032]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2009-07-09 124928]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2009-01-21 247152]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [2009-07-22 240128]
R2 vToolbarUpdater17.2.0;vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [2013-12-09 1771544]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-28 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: Prosím o kontrolu
Zdravim a pekny vecer preji
Stahnete Shortcut Cleaner http://www.bleepingcomputer.com/downloa ... t-cleaner/
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner


- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Spustte tradicne dvouklikem
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v miste spusteni jako sc-cleaner.txt, ten sem vlozte

- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Prosím o kontrolu
Znovu dobrý večer šli mi spustili jen dva progr. Ten "JRT" mi nejde spustit , píše mi to něco že není vytvořená složka a že byl přístup odepřen ...
Jinak zde jsou logy SC-CLEANER :
Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/
Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 12/15/2013 12:08:18 AM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Gabča\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
Searching C:\Users\Public\Desktop\
Searching C:\Users\Gabča\Desktop
0 bad shortcuts found.
Program finished at: 12/15/2013 12:08:21 AM
Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s)
ADW CLEANER :
# AdwCleaner v3.015 - Report created 15/12/2013 at 00:10:50
# Updated 10/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Gabča - GABČA-PC
# Running from : C:\Users\Gabča\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiteRanker
Folder Deleted : C:\Program Files (x86)\AskTBar
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\SiteRanker
Folder Deleted : C:\Program Files (x86)\Harmony_Hollow_Software
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Gabča\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Gabča\AppData\Local\Conduit
Folder Deleted : C:\Users\Gabča\AppData\Local\torch
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\searchresultstb
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\SiteRanker
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\Harmony_Hollow_Software
Folder Deleted : C:\Users\Gabča\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\Gabča\AppData\Roaming\iWin
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Conduit
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\ICQToolbarData
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\CT2475029
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
Folder Deleted : C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
File Deleted : C:\Windows\SysWOW64\conduitEngine.tmp
File Deleted : C:\Program Files (x86)\Mozilla Firefox\Components\AskSearch.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\Conduit.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\crawlersrch.xml
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\Search_Results.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\CToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\CToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2475029
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0DE3308-5D5A-470D-81B9-634FC078393B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9CB65206-89C4-402C-BA80-02D8C59F9B1D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\SiteRanker
Key Deleted : HKCU\Software\torch
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Harmony_Hollow_Software
Key Deleted : HKLM\Software\AskTBar
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\torch
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\Harmony_Hollow_Software
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Harmony_Hollow_Software Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16750
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
-\\ Mozilla Firefox v3.5.6 (cs)
[ File : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\prefs.js ]
Line Deleted : user_pref("CT2475029.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2475029.CT2481020.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481024.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481025.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481029.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481031.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481032.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481033.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481034.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481035.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481037.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CTID", "ct2475029");
Line Deleted : user_pref("CT2475029.CommunitiesChangesLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CurrentServerDate", "5-1-2013");
Line Deleted : user_pref("CT2475029.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2475029.DownloadDomainsCheckInterval", "168");
Line Deleted : user_pref("CT2475029.DownloadDomainsListLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Deleted : user_pref("CT2475029.EMailNotifierPollDate", "Sat Jan 05 2013 18:41:14 GMT+0100");
Line Deleted : user_pref("CT2475029.ExternalComponentPollDate129078508355624514", "Sun Apr 01 2012 02:54:13 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedLastCount129133095456874337", 0);
Line Deleted : user_pref("CT2475029.FeedLastCount6244576562585401993", 0);
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029379", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029381", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029382", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129133095459686870", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129133095459686871", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687146", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687147", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687148", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602500", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602506", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602512", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602518", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602524", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602530", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603404", "Sat Mar 10 2012 23:53:31 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603410", "Sat Mar 10 2012 23:53:31 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603416", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603422", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603428", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603434", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603440", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603446", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603452", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603458", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603464", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603470", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603476", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603482", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603488", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603494", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758786", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758792", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758798", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758804", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758810", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758816", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758822", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758828", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758834", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758840", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758846", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758852", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758858", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758864", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758870", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758876", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758882", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758888", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758894", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758900", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758906", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758912", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758918", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758924", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758930", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758936", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758942", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758948", "Sat Mar 10 2012 23:53:37 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758954", "Sat Mar 10 2012 23:53:37 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758960", "Sat Mar 10 2012 23:53:37 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029379", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029381", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029382", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129133095459686870", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129133095459686871", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687146", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687147", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687148", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602500", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602512", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602518", 5);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602524", 5);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603416", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603428", 60);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603434", 10);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603482", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603488", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603494", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758786", 5);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758798", 30);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758804", 30);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758810", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758828", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758840", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758846", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758852", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758870", 1440);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758900", 10);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758918", 5);
Line Deleted : user_pref("CT2475029.FirstServerDate", "19-11-2010");
Line Deleted : user_pref("CT2475029.FirstTime", true);
Line Deleted : user_pref("CT2475029.FirstTimeFF3", true);
Line Deleted : user_pref("CT2475029.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2475029.GroupingLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2475029.GroupingLastResponse", true);
Line Deleted : user_pref("CT2475029.GroupingLastServerUpdateTime", "130018550160600000");
Line Deleted : user_pref("CT2475029.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2475029.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2475029.Initialize", true);
Line Deleted : user_pref("CT2475029.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2475029.InstalledDate", "Fri Nov 19 2010 19:21:03 GMT+0100");
Line Deleted : user_pref("CT2475029.IsGrouping", true);
Line Deleted : user_pref("CT2475029.IsMulticommunity", true);
Line Deleted : user_pref("CT2475029.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2475029.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2475029.LanguagePackLastCheckTime", "Fri Nov 19 2010 19:21:06 GMT+0100");
Line Deleted : user_pref("CT2475029.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2475029.LastLogin_2.5.6.0", "Sat Jan 05 2013 18:41:12 GMT+0100");
Line Deleted : user_pref("CT2475029.LatestVersion", "3.16.0.3");
Line Deleted : user_pref("CT2475029.Locale", "en");
Line Deleted : user_pref("CT2475029.LoginCache", 4);
Line Deleted : user_pref("CT2475029.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2475029.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2475029.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2475029.RadioIsPodcast", false);
Line Deleted : user_pref("CT2475029.RadioMediaID", "13098944");
Line Deleted : user_pref("CT2475029.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2475029.RadioMenuSelectedID", "EBRadioMenu_CT247502913098944");
Line Deleted : user_pref("CT2475029.RadioStationName", "Mellesleg%20-%20Rapp");
Line Deleted : user_pref("CT2475029.RadioStationURL", "hxxp://195.228.254.168:8060/");
Line Deleted : user_pref("CT2475029.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2475029.SavedHomepage", "hxxp://start.icq.com/");
Line Deleted : user_pref("CT2475029.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2475029&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2475029.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2475029.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=");
Line Deleted : user_pref("CT2475029.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2475029.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2475029.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2475029.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2475029.SettingsLastCheckTime", "Fri Nov 19 2010 19:21:01 GMT+0100");
Line Deleted : user_pref("CT2475029.SettingsLastUpdate", "1289996232");
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsLastCheck", "Fri Nov 19 2010 19:21:00 GMT+0100");
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsLastUpdate", "1246790578");
Line Deleted : user_pref("CT2475029.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2475029.UserID", "UN19634744872441667");
Line Deleted : user_pref("CT2475029.ValidationData_Toolbar", 0);
Line Deleted : user_pref("CT2475029.WeatherNetwork", "");
Line Deleted : user_pref("CT2475029.WeatherPollDate", "Sat Jan 05 2013 18:41:14 GMT+0100");
Line Deleted : user_pref("CT2475029.WeatherUnit", "C");
Line Deleted : user_pref("CT2475029.clientLogIsEnabled", false);
Line Deleted : user_pref("CT2475029.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2475029.ct2475029.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2475029.ct2475029.FeedLastCount129133095456874337", 400);
Line Deleted : user_pref("CT2475029.ct2475029.FeedLastCount6244576562585401993", 2109);
Line Deleted : user_pref("CT2475029.ct2475029.GroupingInvalidateCache", false);
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastResponse", true);
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastServerUpdateTime", "130018550160600000");
Line Deleted : user_pref("CT2475029.ct2475029.InvalidateCache", false);
Line Deleted : user_pref("CT2475029.ct2475029.LanguagePackLastCheckTime", "Sat Jan 05 2013 18:41:12 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.Locale", "en");
Line Deleted : user_pref("CT2475029.ct2475029.RadioLastCheckTime", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2475029.ct2475029.RadioLastUpdateServer", "129054397178370000");
Line Deleted : user_pref("CT2475029.ct2475029.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2475029&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2475029.ct2475029.SearchInNewTabLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2475029.ct2475029.SettingsLastCheckTime", "Sat Jan 05 2013 18:41:10 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.SettingsLastUpdate", "1328797653");
Line Deleted : user_pref("CT2475029.ct2475029.ThirdPartyComponentsLastCheck", "Sat Jan 05 2013 18:41:10 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.ThirdPartyComponentsLastUpdate", "1331805997");
Line Deleted : user_pref("CT2475029.myStuffEnabled", true);
Line Deleted : user_pref("CT2475029.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2475029.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2475029.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2475029.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Apr 01 2012 02:54:14 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Sat Jan 05 2013 18:41:12 GMT+0100");
Line Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\11.1.0.12");
Line Deleted : user_pref("avg.install.userHPSettings", "hxxp://www.crawler.com/homepage.aspx?tbid=60040");
Line Deleted : user_pref("browser.search.defaultenginename", "Search Results");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("browser.search.order.1", "Search Results");
Line Deleted : user_pref("browser.search.selectedEngine", "Search Results");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/406");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", true);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1375546458);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "sella%20ronda||dolomity%20superski||student%20agency||caprese");
Line Deleted : user_pref("icqtoolbar.icqgeo", 0);
Line Deleted : user_pref("icqtoolbar.installTime", "1331420000");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "3.5.6");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "126279007212627900721264706185793");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1375546463);
Line Deleted : user_pref("icqtoolbar.version", "1.1.9");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Deleted : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=435&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=6615437572664541&o=APN10645&q=");
Line Deleted : user_pref("startup.homepage_override_url", "hxxp://www.ask.com/?o=13166&l=dis");
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : search_url
*************************
AdwCleaner[R0].txt - [36767 octets] - [15/12/2013 00:10:01]
AdwCleaner[S0].txt - [36461 octets] - [15/12/2013 00:10:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [36522 octets] ##########
Jinak zde jsou logy SC-CLEANER :
Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/
Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 12/15/2013 12:08:18 AM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Gabča\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
Searching C:\Users\Public\Desktop\
Searching C:\Users\Gabča\Desktop
0 bad shortcuts found.
Program finished at: 12/15/2013 12:08:21 AM
Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s)
ADW CLEANER :
# AdwCleaner v3.015 - Report created 15/12/2013 at 00:10:50
# Updated 10/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Gabča - GABČA-PC
# Running from : C:\Users\Gabča\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiteRanker
Folder Deleted : C:\Program Files (x86)\AskTBar
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\SiteRanker
Folder Deleted : C:\Program Files (x86)\Harmony_Hollow_Software
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Gabča\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Gabča\AppData\Local\Conduit
Folder Deleted : C:\Users\Gabča\AppData\Local\torch
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\searchresultstb
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\SiteRanker
Folder Deleted : C:\Users\Gabča\AppData\LocalLow\Harmony_Hollow_Software
Folder Deleted : C:\Users\Gabča\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\Gabča\AppData\Roaming\iWin
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Conduit
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\ICQToolbarData
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\CT2475029
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Folder Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
Folder Deleted : C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
File Deleted : C:\Windows\SysWOW64\conduitEngine.tmp
File Deleted : C:\Program Files (x86)\Mozilla Firefox\Components\AskSearch.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\Conduit.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\crawlersrch.xml
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\searchplugins\Search_Results.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\CToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\CToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2475029
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0DE3308-5D5A-470D-81B9-634FC078393B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3806B089-6759-411D-B2C3-B7995A9F34D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9CB65206-89C4-402C-BA80-02D8C59F9B1D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{3806B089-6759-411D-B2C3-B7995A9F34D7}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\SiteRanker
Key Deleted : HKCU\Software\torch
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Harmony_Hollow_Software
Key Deleted : HKLM\Software\AskTBar
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\torch
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\Harmony_Hollow_Software
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Harmony_Hollow_Software Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16750
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
-\\ Mozilla Firefox v3.5.6 (cs)
[ File : C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default\prefs.js ]
Line Deleted : user_pref("CT2475029.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2475029.CT2481020.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481024.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481025.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481029.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481031.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481032.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481033.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481034.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481035.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481037.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CTID", "ct2475029");
Line Deleted : user_pref("CT2475029.CommunitiesChangesLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CurrentServerDate", "5-1-2013");
Line Deleted : user_pref("CT2475029.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2475029.DownloadDomainsCheckInterval", "168");
Line Deleted : user_pref("CT2475029.DownloadDomainsListLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Deleted : user_pref("CT2475029.EMailNotifierPollDate", "Sat Jan 05 2013 18:41:14 GMT+0100");
Line Deleted : user_pref("CT2475029.ExternalComponentPollDate129078508355624514", "Sun Apr 01 2012 02:54:13 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedLastCount129133095456874337", 0);
Line Deleted : user_pref("CT2475029.FeedLastCount6244576562585401993", 0);
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029379", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029381", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029382", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129133095459686870", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129133095459686871", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687146", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687147", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687148", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602500", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602506", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602512", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602518", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602524", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214602530", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603404", "Sat Mar 10 2012 23:53:31 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603410", "Sat Mar 10 2012 23:53:31 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603416", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603422", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603428", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603434", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603440", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603446", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603452", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603458", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603464", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603470", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603476", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603482", "Sat Mar 10 2012 23:53:32 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603488", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214603494", "Sat Mar 10 2012 23:53:33 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758786", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758792", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758798", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758804", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758810", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758816", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758822", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758828", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758834", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758840", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758846", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758852", "Sat Mar 10 2012 23:53:34 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758858", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758864", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758870", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758876", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758882", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758888", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758894", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758900", "Sat Mar 10 2012 23:53:35 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758906", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758912", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758918", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758924", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758930", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758936", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758942", "Sat Mar 10 2012 23:53:36 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758948", "Sat Mar 10 2012 23:53:37 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758954", "Sat Mar 10 2012 23:53:37 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedPollDate129255180214758960", "Sat Mar 10 2012 23:53:37 GMT+0100");
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029379", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029381", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029382", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129133095459686870", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129133095459686871", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687146", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687147", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687148", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602500", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602512", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602518", 5);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214602524", 5);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603416", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603428", 60);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603434", 10);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603482", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603488", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214603494", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758786", 5);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758798", 30);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758804", 30);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758810", 2);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758828", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758840", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758846", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758852", 15);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758870", 1440);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758900", 10);
Line Deleted : user_pref("CT2475029.FeedTTL129255180214758918", 5);
Line Deleted : user_pref("CT2475029.FirstServerDate", "19-11-2010");
Line Deleted : user_pref("CT2475029.FirstTime", true);
Line Deleted : user_pref("CT2475029.FirstTimeFF3", true);
Line Deleted : user_pref("CT2475029.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2475029.GroupingLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2475029.GroupingLastResponse", true);
Line Deleted : user_pref("CT2475029.GroupingLastServerUpdateTime", "130018550160600000");
Line Deleted : user_pref("CT2475029.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2475029.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2475029.Initialize", true);
Line Deleted : user_pref("CT2475029.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2475029.InstalledDate", "Fri Nov 19 2010 19:21:03 GMT+0100");
Line Deleted : user_pref("CT2475029.IsGrouping", true);
Line Deleted : user_pref("CT2475029.IsMulticommunity", true);
Line Deleted : user_pref("CT2475029.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2475029.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2475029.LanguagePackLastCheckTime", "Fri Nov 19 2010 19:21:06 GMT+0100");
Line Deleted : user_pref("CT2475029.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2475029.LastLogin_2.5.6.0", "Sat Jan 05 2013 18:41:12 GMT+0100");
Line Deleted : user_pref("CT2475029.LatestVersion", "3.16.0.3");
Line Deleted : user_pref("CT2475029.Locale", "en");
Line Deleted : user_pref("CT2475029.LoginCache", 4);
Line Deleted : user_pref("CT2475029.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2475029.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2475029.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2475029.RadioIsPodcast", false);
Line Deleted : user_pref("CT2475029.RadioMediaID", "13098944");
Line Deleted : user_pref("CT2475029.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2475029.RadioMenuSelectedID", "EBRadioMenu_CT247502913098944");
Line Deleted : user_pref("CT2475029.RadioStationName", "Mellesleg%20-%20Rapp");
Line Deleted : user_pref("CT2475029.RadioStationURL", "hxxp://195.228.254.168:8060/");
Line Deleted : user_pref("CT2475029.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2475029.SavedHomepage", "hxxp://start.icq.com/");
Line Deleted : user_pref("CT2475029.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2475029&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2475029.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2475029.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=");
Line Deleted : user_pref("CT2475029.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2475029.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2475029.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2475029.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2475029.SettingsLastCheckTime", "Fri Nov 19 2010 19:21:01 GMT+0100");
Line Deleted : user_pref("CT2475029.SettingsLastUpdate", "1289996232");
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsLastCheck", "Fri Nov 19 2010 19:21:00 GMT+0100");
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsLastUpdate", "1246790578");
Line Deleted : user_pref("CT2475029.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2475029.UserID", "UN19634744872441667");
Line Deleted : user_pref("CT2475029.ValidationData_Toolbar", 0);
Line Deleted : user_pref("CT2475029.WeatherNetwork", "");
Line Deleted : user_pref("CT2475029.WeatherPollDate", "Sat Jan 05 2013 18:41:14 GMT+0100");
Line Deleted : user_pref("CT2475029.WeatherUnit", "C");
Line Deleted : user_pref("CT2475029.clientLogIsEnabled", false);
Line Deleted : user_pref("CT2475029.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2475029.ct2475029.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2475029.ct2475029.FeedLastCount129133095456874337", 400);
Line Deleted : user_pref("CT2475029.ct2475029.FeedLastCount6244576562585401993", 2109);
Line Deleted : user_pref("CT2475029.ct2475029.GroupingInvalidateCache", false);
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastResponse", true);
Line Deleted : user_pref("CT2475029.ct2475029.GroupingLastServerUpdateTime", "130018550160600000");
Line Deleted : user_pref("CT2475029.ct2475029.InvalidateCache", false);
Line Deleted : user_pref("CT2475029.ct2475029.LanguagePackLastCheckTime", "Sat Jan 05 2013 18:41:12 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.Locale", "en");
Line Deleted : user_pref("CT2475029.ct2475029.RadioLastCheckTime", "Sat Jan 05 2013 18:41:13 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2475029.ct2475029.RadioLastUpdateServer", "129054397178370000");
Line Deleted : user_pref("CT2475029.ct2475029.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2475029&octid=EB_ORIGINAL_CTID&SearchSource=1");
Line Deleted : user_pref("CT2475029.ct2475029.SearchInNewTabLastCheckTime", "Sat Jan 05 2013 18:41:11 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.SettingsCheckIntervalMin", 120);
Line Deleted : user_pref("CT2475029.ct2475029.SettingsLastCheckTime", "Sat Jan 05 2013 18:41:10 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.SettingsLastUpdate", "1328797653");
Line Deleted : user_pref("CT2475029.ct2475029.ThirdPartyComponentsLastCheck", "Sat Jan 05 2013 18:41:10 GMT+0100");
Line Deleted : user_pref("CT2475029.ct2475029.ThirdPartyComponentsLastUpdate", "1331805997");
Line Deleted : user_pref("CT2475029.myStuffEnabled", true);
Line Deleted : user_pref("CT2475029.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2475029.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2475029.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2475029.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Apr 01 2012 02:54:14 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Sat Jan 05 2013 18:41:12 GMT+0100");
Line Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\11.1.0.12");
Line Deleted : user_pref("avg.install.userHPSettings", "hxxp://www.crawler.com/homepage.aspx?tbid=60040");
Line Deleted : user_pref("browser.search.defaultenginename", "Search Results");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("browser.search.order.1", "Search Results");
Line Deleted : user_pref("browser.search.selectedEngine", "Search Results");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/406");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.engineVerified", true);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1375546458);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "sella%20ronda||dolomity%20superski||student%20agency||caprese");
Line Deleted : user_pref("icqtoolbar.icqgeo", 0);
Line Deleted : user_pref("icqtoolbar.installTime", "1331420000");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "3.5.6");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "126279007212627900721264706185793");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1375546463);
Line Deleted : user_pref("icqtoolbar.version", "1.1.9");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Deleted : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=435&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=6615437572664541&o=APN10645&q=");
Line Deleted : user_pref("startup.homepage_override_url", "hxxp://www.ask.com/?o=13166&l=dis");
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : search_url
*************************
AdwCleaner[R0].txt - [36767 octets] - [15/12/2013 00:10:01]
AdwCleaner[S0].txt - [36461 octets] - [15/12/2013 00:10:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [36522 octets] ##########
Re: Prosím o kontrolu
Poprosim nyni o log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100
Re: Prosím o kontrolu
Zde je log :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-12-2013 01
Ran by Gabča (administrator) on GABČA-PC on 15-12-2013 10:23:04
Running from C:\Users\Gabča\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Gabča\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-22] (IDT, Inc.)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5618456 2013-09-12] (ESET)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
HKCU\...\Policies\system: [WallpaperStyle] 2
MountPoints2: {295bd853-b9f0-11e1-b39a-002713375b1a} - F:\Setup.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QPService] - C:\Program Files (x86)\Hp\QuickPlay\QPService.exe [468264 2009-06-23] (CyberLink Corp.)
HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-17] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [320056 2009-06-24] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SiteRanker] - "C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-15] (Hewlett-Packard)
HKU\Default\...\Policies\system: [WallpaperStyle] 2
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-15] (Hewlett-Packard)
HKU\Default User\...\Policies\system: [WallpaperStyle] 2
Startup: C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Guage.lnk
ShortcutTarget: Samsung Auto Backup Guage.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe (Clarus, Inc.)
Startup: C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Real-Time Daemon.lnk
ShortcutTarget: Samsung Auto Backup Real-Time Daemon.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe (Clarus, Inc.)
Startup: C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Scheduler.lnk
ShortcutTarget: Samsung Auto Backup Scheduler.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe (Clarus, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
SearchScopes: HKLM-x32 - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
SearchScopes: HKCU - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/Cl ... wsdc32.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_35 - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Gabča\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files (x86)\SiteRanker\firefox\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: https://www.google.cz/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchKeyword: r
CHR DefaultSearchProvider: Search Results
CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Gears 0.5.33.0) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gears.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.230.5) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U23) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll No File
CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll No File
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (Skype Click to Call) - C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.13.0.13771_0
CHR Extension: (Google Wallet) - C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-01-21] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [240128 2009-07-22] (IDT, Inc.)
S2 vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AFW; C:\Windows\System32\DRIVERS\afw.sys [40544 2012-11-20] (Agnitum Ltd.)
R3 afwcore; C:\Windows\System32\DRIVERS\afwcore.sys [464480 2012-11-20] (Agnitum Ltd.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-11-10] (AVG Technologies)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET)
S3 nmwcdcx64; C:\Windows\System32\drivers\ccdcmbox64.sys [23552 2008-05-02] (Nokia)
S3 nmwcdx64; C:\Windows\System32\drivers\ccdcmbx64.sys [18432 2008-05-02] (Nokia)
S3 Prot6Flt; No ImagePath
S3 RtsUIR; No ImagePath
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [8704 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
S3 USBCCID; No ImagePath
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltx64j.sys [8704 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
U4 VSSERV;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-15 10:23 - 2013-12-15 10:24 - 00018325 _____ C:\Users\Gabča\Desktop\FRST.txt
2013-12-15 10:22 - 2013-12-15 10:22 - 00000000 ____D C:\FRST
2013-12-15 10:21 - 2013-12-15 10:21 - 00112640 _____ (forum.viry.cz) C:\Users\Gabča\Desktop\FRSTLauncher.exe
2013-12-15 10:18 - 2013-12-15 10:18 - 01927796 _____ (Farbar) C:\Users\Gabča\Desktop\FRST64.exe
2013-12-15 00:27 - 2013-12-15 00:28 - 00000000 ___RD C:\Users\Gabča\Desktop\Čištění pc nepoužívat
2013-12-15 00:09 - 2013-12-15 00:11 - 00000000 ____D C:\AdwCleaner
2013-12-15 00:08 - 2013-12-15 00:08 - 00001796 _____ C:\sc-cleaner.txt
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\rsit
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\Program Files\trend micro
2013-12-14 19:13 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-14 19:13 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-14 19:13 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-14 19:13 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-14 19:08 - 2013-12-14 19:08 - 01563404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-12-14 18:42 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-14 18:42 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-14 18:42 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-14 18:42 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-14 18:42 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-14 18:42 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-14 18:42 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-14 18:42 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-14 18:42 - 2013-10-25 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-14 18:42 - 2013-10-25 04:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-14 18:42 - 2013-10-25 04:17 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 18:42 - 2013-10-25 03:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-14 18:38 - 2013-12-15 10:10 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-14 18:38 - 2013-12-15 10:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-12-14 18:36 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-12-14 18:36 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-12-14 18:36 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-12-14 18:36 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-12-14 18:36 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-12-14 18:36 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-14 18:36 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-14 18:36 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-14 18:36 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-12-14 18:36 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-12-14 18:36 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-12-14 18:36 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-14 18:36 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-12-14 18:36 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-12-14 18:36 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-12-14 18:36 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-12-14 18:36 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-12-14 18:36 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-12-14 18:36 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-12-14 18:36 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-12-14 18:36 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-12-14 18:36 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-12-14 18:36 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-12-14 18:36 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-12-14 18:33 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-14 18:33 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-14 18:01 - 2013-12-14 18:01 - 00000000 ____D C:\Users\Gabča\Desktop\TuneUp-Utilities-2012-CZ-+-návod-(plná-verze)
2013-12-14 17:43 - 2013-12-14 17:43 - 00001102 _____ C:\Users\Gabča\Desktop\AVG PC Tuneup.lnk
2013-12-14 17:43 - 2013-12-14 17:43 - 00000000 ____D C:\Windows\System32\Tasks\AVG
2013-12-14 17:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-14 17:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-14 17:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-14 17:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-14 17:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-14 17:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-14 17:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-13 21:37 - 2013-12-14 08:27 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2010
2013-12-13 21:36 - 2013-12-13 21:37 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\ProgramData\ESET
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\Program Files\ESET
2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean
2013-12-11 21:43 - 2013-12-15 00:14 - 00013538 _____ C:\Windows\PFRO.log
2013-12-11 21:33 - 2013-12-11 21:33 - 00000359 _____ C:\Users\Gabča\Desktop\Počítač – zástupce.lnk
2013-12-11 21:32 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-12-11 21:32 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-12-11 17:58 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 17:58 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 17:58 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 17:58 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 17:58 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 17:58 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 17:58 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 17:58 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 17:58 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 17:58 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 15:54 - 2013-12-11 21:40 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-09 21:54 - 2013-12-10 15:54 - 00000000 ____D C:\7de8edae6386dccbf7a34abb778b
2013-12-03 21:51 - 2013-12-14 18:57 - 00000134 _____ C:\Users\Gabča\Desktop\Internet Explorer Troubleshooting.url
2013-12-03 21:44 - 2013-12-11 21:40 - 00000000 ____D C:\Windows\system32\MRT
2013-11-28 18:17 - 2013-12-15 00:49 - 00023749 _____ C:\Windows\IE11_main.log
2013-11-28 17:34 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-15 22:27 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-15 22:27 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-15 22:27 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 22:27 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-15 22:27 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-15 22:27 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-15 22:27 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-15 22:27 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-15 22:27 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-15 22:26 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-15 22:26 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-15 22:26 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-15 22:26 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-15 22:26 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-15 22:26 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-15 22:26 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-15 22:26 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-15 22:26 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-15 22:26 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-15 22:26 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-15 22:26 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-15 22:26 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-15 22:26 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-15 22:26 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-15 22:26 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-15 22:26 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-15 22:26 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-15 22:26 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-15 22:26 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-15 22:26 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
==================== One Month Modified Files and Folders =======
2013-12-15 10:24 - 2013-12-15 10:23 - 00018325 _____ C:\Users\Gabča\Desktop\FRST.txt
2013-12-15 10:22 - 2013-12-15 10:22 - 00000000 ____D C:\FRST
2013-12-15 10:21 - 2013-12-15 10:21 - 00112640 _____ (forum.viry.cz) C:\Users\Gabča\Desktop\FRSTLauncher.exe
2013-12-15 10:18 - 2013-12-15 10:18 - 01927796 _____ (Farbar) C:\Users\Gabča\Desktop\FRST64.exe
2013-12-15 10:18 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-15 10:18 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-15 10:14 - 2009-10-11 00:14 - 01919858 _____ C:\Windows\WindowsUpdate.log
2013-12-15 10:11 - 2009-10-11 00:51 - 00004566 _____ C:\ProgramData\hpqp.ini
2013-12-15 10:10 - 2013-12-14 18:38 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-15 10:10 - 2013-12-14 18:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-12-15 10:10 - 2013-11-02 09:50 - 00002856 _____ C:\Windows\setupact.log
2013-12-15 10:10 - 2010-02-10 17:59 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-15 10:10 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-15 05:16 - 2009-12-22 22:31 - 00000000 ____D C:\Users\Gabča
2013-12-15 05:16 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 05:15 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-15 05:10 - 2010-05-18 21:27 - 00000000 ____D C:\ProgramData\Recovery
2013-12-15 00:49 - 2013-11-28 18:17 - 00023749 _____ C:\Windows\IE11_main.log
2013-12-15 00:34 - 2012-10-11 19:06 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-15 00:28 - 2013-12-15 00:27 - 00000000 ___RD C:\Users\Gabča\Desktop\Čištění pc nepoužívat
2013-12-15 00:14 - 2013-12-11 21:43 - 00013538 _____ C:\Windows\PFRO.log
2013-12-15 00:11 - 2013-12-15 00:09 - 00000000 ____D C:\AdwCleaner
2013-12-15 00:10 - 2010-01-06 17:27 - 00000000 ____D C:\ProgramData\ICQ
2013-12-15 00:08 - 2013-12-15 00:08 - 00001796 _____ C:\sc-cleaner.txt
2013-12-14 23:52 - 2010-02-10 17:59 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-14 23:51 - 2013-08-20 09:16 - 00000000 ____D C:\Windows\rescache
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\rsit
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\Program Files\trend micro
2013-12-14 21:59 - 2012-12-21 18:54 - 00000928 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job
2013-12-14 21:55 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-14 21:52 - 2009-07-14 05:45 - 00440680 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-14 21:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-14 19:32 - 2013-06-30 17:07 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\AVG
2013-12-14 19:08 - 2013-12-14 19:08 - 01563404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-12-14 19:08 - 2009-09-06 02:59 - 00672752 _____ C:\Windows\system32\perfh005.dat
2013-12-14 19:08 - 2009-09-06 02:59 - 00143500 _____ C:\Windows\system32\perfc005.dat
2013-12-14 19:08 - 2009-07-14 06:13 - 01614640 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-14 18:59 - 2012-12-21 18:54 - 00000906 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job
2013-12-14 18:57 - 2013-12-03 21:51 - 00000134 _____ C:\Users\Gabča\Desktop\Internet Explorer Troubleshooting.url
2013-12-14 18:52 - 2009-12-22 22:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-14 18:01 - 2013-12-14 18:01 - 00000000 ____D C:\Users\Gabča\Desktop\TuneUp-Utilities-2012-CZ-+-návod-(plná-verze)
2013-12-14 17:46 - 2010-01-06 17:32 - 00000000 ____D C:\Users\Gabča\Desktop\komunikace
2013-12-14 17:43 - 2013-12-14 17:43 - 00001102 _____ C:\Users\Gabča\Desktop\AVG PC Tuneup.lnk
2013-12-14 17:43 - 2013-12-14 17:43 - 00000000 ____D C:\Windows\System32\Tasks\AVG
2013-12-14 17:42 - 2012-03-30 12:03 - 00000000 ____D C:\Program Files (x86)\AVG
2013-12-14 17:10 - 2010-02-10 17:59 - 00000000 ____D C:\Program Files\Google
2013-12-14 17:10 - 2010-02-10 17:59 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-14 17:08 - 2009-12-23 23:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-14 17:05 - 2010-02-10 17:59 - 00000000 ____D C:\Users\Gabča\AppData\Local\Google
2013-12-14 17:05 - 2010-02-10 17:59 - 00000000 ____D C:\ProgramData\Google
2013-12-14 08:27 - 2013-12-13 21:37 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2010
2013-12-14 08:27 - 2009-12-23 23:07 - 00000000 ____D C:\Users\Gabča\AppData\Local\QuickPlay
2013-12-13 23:13 - 2009-07-14 03:34 - 77070336 _____ C:\Windows\system32\config\SOFTWARE_tureg_old
2013-12-13 23:13 - 2009-07-14 03:34 - 18612224 _____ C:\Windows\system32\config\SYSTEM_tureg_old
2013-12-13 23:13 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\SECURITY_tureg_old
2013-12-13 23:00 - 2009-07-14 03:34 - 51642368 _____ C:\Windows\system32\config\COMPONENTS_tureg_old
2013-12-13 23:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\SAM_tureg_old
2013-12-13 23:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\DEFAULT_tureg_old
2013-12-13 21:48 - 2010-01-06 17:26 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\ICQ
2013-12-13 21:38 - 2013-06-30 16:26 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\TuneUp Software
2013-12-13 21:37 - 2013-12-13 21:36 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\ProgramData\ESET
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\Program Files\ESET
2013-12-11 22:08 - 2012-03-30 11:59 - 00000000 ____D C:\ProgramData\MFAData
2013-12-11 21:57 - 2013-06-30 16:25 - 00000000 ____D C:\ProgramData\AVG2013
2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean
2013-12-11 21:56 - 2012-03-30 12:04 - 00000000 ___HD C:\$AVG
2013-12-11 21:40 - 2013-12-10 15:54 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 21:40 - 2013-12-03 21:44 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 21:33 - 2013-12-11 21:33 - 00000359 _____ C:\Users\Gabča\Desktop\Počítač – zástupce.lnk
2013-12-11 18:35 - 2012-10-11 19:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 18:35 - 2012-10-11 19:06 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 18:35 - 2011-11-04 17:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-10 18:47 - 2010-02-10 17:59 - 00003946 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-10 18:47 - 2010-02-10 17:59 - 00003694 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-10 18:46 - 2009-12-24 01:32 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\vlc
2013-12-10 15:54 - 2013-12-09 21:54 - 00000000 ____D C:\7de8edae6386dccbf7a34abb778b
2013-12-10 02:12 - 2010-01-19 21:56 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\dvdcss
2013-12-10 02:08 - 2009-12-22 22:33 - 00000000 ____D C:\ProgramData\Adobe
2013-12-09 18:07 - 2010-07-01 18:21 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-03 22:17 - 2012-02-09 18:58 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-11-23 19:26 - 2013-12-14 17:22 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 18:47 - 2013-12-14 17:22 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-19 03:33 - 2010-02-22 18:51 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Files to move or delete:
====================
C:\Users\Gabča\AdbeRdr940_cs_CZ.exe
C:\Users\Gabča\setup_av_free.exe
Some content of TEMP:
====================
C:\Users\Gabča\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-11 21:23
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:284.62 GB) (Free:39.33 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:13.17 GB) (Free:2.14 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Available physical RAM: 1604.19 MB
Total physical RAM: 2812.2 MB
Percentage of memory in use: 42%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 298 GB) (Disk ID: 302DB4F8)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=285 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows:8AA4CA1CF5E9407C
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
==================== Security Center ==================
AV: ESET NOD32 Antivirus 7.0 (Disabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 7.0 (Disabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Gab�a\Desktop" je 8341 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-12-2013 01
Ran by Gabča (administrator) on GABČA-PC on 15-12-2013 10:23:04
Running from C:\Users\Gabča\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Gabča\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-22] (IDT, Inc.)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5618456 2013-09-12] (ESET)
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-08-20] (Hewlett-Packard Company)
HKCU\...\Policies\system: [WallpaperStyle] 2
MountPoints2: {295bd853-b9f0-11e1-b39a-002713375b1a} - F:\Setup.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QPService] - C:\Program Files (x86)\Hp\QuickPlay\QPService.exe [468264 2009-06-23] (CyberLink Corp.)
HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-17] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [320056 2009-06-24] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [498744 2009-07-23] (Hewlett-Packard)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SiteRanker] - "C:\Program Files (x86)\SiteRanker\SiteRankTray.exe"
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-15] (Hewlett-Packard)
HKU\Default\...\Policies\system: [WallpaperStyle] 2
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1668664 2009-07-15] (Hewlett-Packard)
HKU\Default User\...\Policies\system: [WallpaperStyle] 2
Startup: C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Guage.lnk
ShortcutTarget: Samsung Auto Backup Guage.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe (Clarus, Inc.)
Startup: C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Real-Time Daemon.lnk
ShortcutTarget: Samsung Auto Backup Real-Time Daemon.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe (Clarus, Inc.)
Startup: C:\Users\Gabča\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Scheduler.lnk
ShortcutTarget: Samsung Auto Backup Scheduler.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe (Clarus, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
SearchScopes: HKLM-x32 - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
SearchScopes: HKCU - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/Cl ... wsdc32.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Gabča\AppData\Roaming\Mozilla\Firefox\Profiles\e74s1i27.default
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_35 - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Gabča\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [siteranker@siteranker.com] - C:\Program Files (x86)\SiteRanker\firefox\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: https://www.google.cz/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchKeyword: r
CHR DefaultSearchProvider: Search Results
CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Gears 0.5.33.0) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gears.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.230.5) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U23) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll No File
CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll No File
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Extension: (Skype Click to Call) - C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.13.0.13771_0
CHR Extension: (Google Wallet) - C:\Users\Gabča\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
==================== Services (Whitelisted) =================
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-01-21] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [240128 2009-07-22] (IDT, Inc.)
S2 vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AFW; C:\Windows\System32\DRIVERS\afw.sys [40544 2012-11-20] (Agnitum Ltd.)
R3 afwcore; C:\Windows\System32\DRIVERS\afwcore.sys [464480 2012-11-20] (Agnitum Ltd.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-11-10] (AVG Technologies)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET)
S3 nmwcdcx64; C:\Windows\System32\drivers\ccdcmbox64.sys [23552 2008-05-02] (Nokia)
S3 nmwcdx64; C:\Windows\System32\drivers\ccdcmbx64.sys [18432 2008-05-02] (Nokia)
S3 Prot6Flt; No ImagePath
S3 RtsUIR; No ImagePath
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [8704 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
S3 USBCCID; No ImagePath
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltx64j.sys [8704 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
U4 VSSERV;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-15 10:23 - 2013-12-15 10:24 - 00018325 _____ C:\Users\Gabča\Desktop\FRST.txt
2013-12-15 10:22 - 2013-12-15 10:22 - 00000000 ____D C:\FRST
2013-12-15 10:21 - 2013-12-15 10:21 - 00112640 _____ (forum.viry.cz) C:\Users\Gabča\Desktop\FRSTLauncher.exe
2013-12-15 10:18 - 2013-12-15 10:18 - 01927796 _____ (Farbar) C:\Users\Gabča\Desktop\FRST64.exe
2013-12-15 00:27 - 2013-12-15 00:28 - 00000000 ___RD C:\Users\Gabča\Desktop\Čištění pc nepoužívat

2013-12-15 00:09 - 2013-12-15 00:11 - 00000000 ____D C:\AdwCleaner
2013-12-15 00:08 - 2013-12-15 00:08 - 00001796 _____ C:\sc-cleaner.txt
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\rsit
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\Program Files\trend micro
2013-12-14 19:13 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-14 19:13 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-14 19:13 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-14 19:13 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-14 19:08 - 2013-12-14 19:08 - 01563404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-12-14 18:42 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-14 18:42 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-14 18:42 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-14 18:42 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-14 18:42 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-14 18:42 - 2013-10-25 07:17 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-14 18:42 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-14 18:42 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-14 18:42 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-14 18:42 - 2013-10-25 05:43 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-14 18:42 - 2013-10-25 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-14 18:42 - 2013-10-25 04:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-14 18:42 - 2013-10-25 04:17 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 18:42 - 2013-10-25 03:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-14 18:38 - 2013-12-15 10:10 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-14 18:38 - 2013-12-15 10:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-12-14 18:36 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-12-14 18:36 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-12-14 18:36 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-12-14 18:36 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-12-14 18:36 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-12-14 18:36 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-14 18:36 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-14 18:36 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-14 18:36 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-12-14 18:36 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-12-14 18:36 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-12-14 18:36 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-14 18:36 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-12-14 18:36 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-12-14 18:36 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-12-14 18:36 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-12-14 18:36 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-12-14 18:36 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-12-14 18:36 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-12-14 18:36 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-12-14 18:36 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-12-14 18:36 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-12-14 18:36 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-12-14 18:36 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-12-14 18:33 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-14 18:33 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-14 18:01 - 2013-12-14 18:01 - 00000000 ____D C:\Users\Gabča\Desktop\TuneUp-Utilities-2012-CZ-+-návod-(plná-verze)
2013-12-14 17:43 - 2013-12-14 17:43 - 00001102 _____ C:\Users\Gabča\Desktop\AVG PC Tuneup.lnk
2013-12-14 17:43 - 2013-12-14 17:43 - 00000000 ____D C:\Windows\System32\Tasks\AVG
2013-12-14 17:22 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-14 17:22 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-14 17:22 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-14 17:22 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-14 17:22 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-14 17:22 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-14 17:22 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-13 21:37 - 2013-12-14 08:27 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2010
2013-12-13 21:36 - 2013-12-13 21:37 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\ProgramData\ESET
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\Program Files\ESET
2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean
2013-12-11 21:43 - 2013-12-15 00:14 - 00013538 _____ C:\Windows\PFRO.log
2013-12-11 21:33 - 2013-12-11 21:33 - 00000359 _____ C:\Users\Gabča\Desktop\Počítač – zástupce.lnk
2013-12-11 21:32 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-12-11 21:32 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-12-11 17:58 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 17:58 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 17:58 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 17:58 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 17:58 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 17:58 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 17:58 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 17:58 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 17:58 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 17:58 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 15:54 - 2013-12-11 21:40 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-09 21:54 - 2013-12-10 15:54 - 00000000 ____D C:\7de8edae6386dccbf7a34abb778b
2013-12-03 21:51 - 2013-12-14 18:57 - 00000134 _____ C:\Users\Gabča\Desktop\Internet Explorer Troubleshooting.url
2013-12-03 21:44 - 2013-12-11 21:40 - 00000000 ____D C:\Windows\system32\MRT
2013-11-28 18:17 - 2013-12-15 00:49 - 00023749 _____ C:\Windows\IE11_main.log
2013-11-28 17:34 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-28 17:34 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-15 22:27 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-15 22:27 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-15 22:27 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-15 22:27 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-15 22:27 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-15 22:27 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-15 22:27 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-15 22:27 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-15 22:27 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-15 22:26 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-15 22:26 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-15 22:26 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-15 22:26 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-15 22:26 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-15 22:26 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-15 22:26 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-15 22:26 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-15 22:26 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-15 22:26 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-15 22:26 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-15 22:26 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-15 22:26 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-15 22:26 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-15 22:26 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-15 22:26 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-15 22:26 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-15 22:26 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-15 22:26 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-15 22:26 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-15 22:26 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
==================== One Month Modified Files and Folders =======
2013-12-15 10:24 - 2013-12-15 10:23 - 00018325 _____ C:\Users\Gabča\Desktop\FRST.txt
2013-12-15 10:22 - 2013-12-15 10:22 - 00000000 ____D C:\FRST
2013-12-15 10:21 - 2013-12-15 10:21 - 00112640 _____ (forum.viry.cz) C:\Users\Gabča\Desktop\FRSTLauncher.exe
2013-12-15 10:18 - 2013-12-15 10:18 - 01927796 _____ (Farbar) C:\Users\Gabča\Desktop\FRST64.exe
2013-12-15 10:18 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-15 10:18 - 2009-07-14 05:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-15 10:14 - 2009-10-11 00:14 - 01919858 _____ C:\Windows\WindowsUpdate.log
2013-12-15 10:11 - 2009-10-11 00:51 - 00004566 _____ C:\ProgramData\hpqp.ini
2013-12-15 10:10 - 2013-12-14 18:38 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-15 10:10 - 2013-12-14 18:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-12-15 10:10 - 2013-11-02 09:50 - 00002856 _____ C:\Windows\setupact.log
2013-12-15 10:10 - 2010-02-10 17:59 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-15 10:10 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-15 05:16 - 2009-12-22 22:31 - 00000000 ____D C:\Users\Gabča
2013-12-15 05:16 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-15 05:15 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-15 05:10 - 2010-05-18 21:27 - 00000000 ____D C:\ProgramData\Recovery
2013-12-15 00:49 - 2013-11-28 18:17 - 00023749 _____ C:\Windows\IE11_main.log
2013-12-15 00:34 - 2012-10-11 19:06 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-15 00:28 - 2013-12-15 00:27 - 00000000 ___RD C:\Users\Gabča\Desktop\Čištění pc nepoužívat

2013-12-15 00:14 - 2013-12-11 21:43 - 00013538 _____ C:\Windows\PFRO.log
2013-12-15 00:11 - 2013-12-15 00:09 - 00000000 ____D C:\AdwCleaner
2013-12-15 00:10 - 2010-01-06 17:27 - 00000000 ____D C:\ProgramData\ICQ
2013-12-15 00:08 - 2013-12-15 00:08 - 00001796 _____ C:\sc-cleaner.txt
2013-12-14 23:52 - 2010-02-10 17:59 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-14 23:51 - 2013-08-20 09:16 - 00000000 ____D C:\Windows\rescache
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\rsit
2013-12-14 21:59 - 2013-12-14 21:59 - 00000000 ____D C:\Program Files\trend micro
2013-12-14 21:59 - 2012-12-21 18:54 - 00000928 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job
2013-12-14 21:55 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-14 21:52 - 2009-07-14 05:45 - 00440680 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-14 21:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-14 19:32 - 2013-06-30 17:07 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\AVG
2013-12-14 19:08 - 2013-12-14 19:08 - 01563404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-12-14 19:08 - 2009-09-06 02:59 - 00672752 _____ C:\Windows\system32\perfh005.dat
2013-12-14 19:08 - 2009-09-06 02:59 - 00143500 _____ C:\Windows\system32\perfc005.dat
2013-12-14 19:08 - 2009-07-14 06:13 - 01614640 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-14 18:59 - 2012-12-21 18:54 - 00000906 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job
2013-12-14 18:57 - 2013-12-03 21:51 - 00000134 _____ C:\Users\Gabča\Desktop\Internet Explorer Troubleshooting.url
2013-12-14 18:52 - 2009-12-22 22:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-14 18:01 - 2013-12-14 18:01 - 00000000 ____D C:\Users\Gabča\Desktop\TuneUp-Utilities-2012-CZ-+-návod-(plná-verze)
2013-12-14 17:46 - 2010-01-06 17:32 - 00000000 ____D C:\Users\Gabča\Desktop\komunikace
2013-12-14 17:43 - 2013-12-14 17:43 - 00001102 _____ C:\Users\Gabča\Desktop\AVG PC Tuneup.lnk
2013-12-14 17:43 - 2013-12-14 17:43 - 00000000 ____D C:\Windows\System32\Tasks\AVG
2013-12-14 17:42 - 2012-03-30 12:03 - 00000000 ____D C:\Program Files (x86)\AVG
2013-12-14 17:10 - 2010-02-10 17:59 - 00000000 ____D C:\Program Files\Google
2013-12-14 17:10 - 2010-02-10 17:59 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-14 17:08 - 2009-12-23 23:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-14 17:05 - 2010-02-10 17:59 - 00000000 ____D C:\Users\Gabča\AppData\Local\Google
2013-12-14 17:05 - 2010-02-10 17:59 - 00000000 ____D C:\ProgramData\Google
2013-12-14 08:27 - 2013-12-13 21:37 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2010
2013-12-14 08:27 - 2009-12-23 23:07 - 00000000 ____D C:\Users\Gabča\AppData\Local\QuickPlay
2013-12-13 23:13 - 2009-07-14 03:34 - 77070336 _____ C:\Windows\system32\config\SOFTWARE_tureg_old
2013-12-13 23:13 - 2009-07-14 03:34 - 18612224 _____ C:\Windows\system32\config\SYSTEM_tureg_old
2013-12-13 23:13 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\SECURITY_tureg_old
2013-12-13 23:00 - 2009-07-14 03:34 - 51642368 _____ C:\Windows\system32\config\COMPONENTS_tureg_old
2013-12-13 23:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\SAM_tureg_old
2013-12-13 23:00 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\DEFAULT_tureg_old
2013-12-13 21:48 - 2010-01-06 17:26 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\ICQ
2013-12-13 21:38 - 2013-06-30 16:26 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\TuneUp Software
2013-12-13 21:37 - 2013-12-13 21:36 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\ProgramData\ESET
2013-12-11 22:40 - 2013-12-11 22:40 - 00000000 ____D C:\Program Files\ESET
2013-12-11 22:08 - 2012-03-30 11:59 - 00000000 ____D C:\ProgramData\MFAData
2013-12-11 21:57 - 2013-06-30 16:25 - 00000000 ____D C:\ProgramData\AVG2013
2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean
2013-12-11 21:56 - 2012-03-30 12:04 - 00000000 ___HD C:\$AVG
2013-12-11 21:40 - 2013-12-10 15:54 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 21:40 - 2013-12-03 21:44 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 21:33 - 2013-12-11 21:33 - 00000359 _____ C:\Users\Gabča\Desktop\Počítač – zástupce.lnk
2013-12-11 18:35 - 2012-10-11 19:06 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 18:35 - 2012-10-11 19:06 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 18:35 - 2011-11-04 17:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-10 18:47 - 2010-02-10 17:59 - 00003946 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-10 18:47 - 2010-02-10 17:59 - 00003694 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-10 18:46 - 2009-12-24 01:32 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\vlc
2013-12-10 15:54 - 2013-12-09 21:54 - 00000000 ____D C:\7de8edae6386dccbf7a34abb778b
2013-12-10 02:12 - 2010-01-19 21:56 - 00000000 ____D C:\Users\Gabča\AppData\Roaming\dvdcss
2013-12-10 02:08 - 2009-12-22 22:33 - 00000000 ____D C:\ProgramData\Adobe
2013-12-09 18:07 - 2010-07-01 18:21 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-03 22:17 - 2012-02-09 18:58 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-11-23 19:26 - 2013-12-14 17:22 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 18:47 - 2013-12-14 17:22 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-19 03:33 - 2010-02-22 18:51 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Files to move or delete:
====================
C:\Users\Gabča\AdbeRdr940_cs_CZ.exe
C:\Users\Gabča\setup_av_free.exe
Some content of TEMP:
====================
C:\Users\Gabča\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-11 21:23
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:284.62 GB) (Free:39.33 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:13.17 GB) (Free:2.14 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Available physical RAM: 1604.19 MB
Total physical RAM: 2812.2 MB
Percentage of memory in use: 42%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 298 GB) (Disk ID: 302DB4F8)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=285 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows:8AA4CA1CF5E9407C
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
==================== Security Center ==================
AV: ESET NOD32 Antivirus 7.0 (Disabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 7.0 (Disabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Gab�a\Desktop" je 8341 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001
==================== End Of Log ==============================
- Přílohy
-
- Addition.rar
- (6.65 KiB) Staženo 35 x
Re: Prosím o kontrolu



- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [] - [x] HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz SearchScopes: HKLM-x32 - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz SearchScopes: HKCU - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz CHR DefaultSearchKeyword: r CHR DefaultSearchProvider: Search Results CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... 2664541&q={searchTerms} CHR DefaultNewTabURL: S2 vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x] S3 Prot6Flt; No ImagePath S3 RtsUIR; No ImagePath S3 USBCCID; No ImagePath U4 VSSERV; 2013-12-11 22:08 - 2012-03-30 11:59 - 00000000 ____D C:\ProgramData\MFAData 2013-12-11 21:57 - 2013-06-30 16:25 - 00000000 ____D C:\ProgramData\AVG2013 2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean 2013-12-11 21:56 - 2012-03-30 12:04 - 00000000 ___HD C:\$AVG C:\Users\Gabča\AdbeRdr940_cs_CZ.exe C:\Users\Gabča\setup_av_free.exe C:\Program Files (x86)\AVG C:\Program Files (x86)\Common Files\AVG Secure Search Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => C:\Users\Gab a\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => C:\Users\Gab a\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe AlternateDataStreams: C:\Windows:8AA4CA1CF5E9407C AlternateDataStreams: C:\ProgramData\Temp:0B4227B4 Hosts: CMD: shutdown /r /f /t 2 End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: Prosím o kontrolu
Zdravím programy jsou odinstalovány a zde je log :
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2013 01
Ran by Gabča at 2013-12-15 19:05:32 Run:1
Running from C:\Users\Gabča\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [] - [x]
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
SearchScopes: HKLM-x32 - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
SearchScopes: HKCU - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
CHR DefaultSearchKeyword: r
CHR DefaultSearchProvider: Search Results
CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... 2664541&q={searchTerms}
CHR DefaultNewTabURL:
S2 vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x]
S3 Prot6Flt; No ImagePath
S3 RtsUIR; No ImagePath
S3 USBCCID; No ImagePath
U4 VSSERV;
2013-12-11 22:08 - 2012-03-30 11:59 - 00000000 ____D C:\ProgramData\MFAData
2013-12-11 21:57 - 2013-06-30 16:25 - 00000000 ____D C:\ProgramData\AVG2013
2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean
2013-12-11 21:56 - 2012-03-30 12:04 - 00000000 ___HD C:\$AVG
C:\Users\Gabča\AdbeRdr940_cs_CZ.exe
C:\Users\Gabča\setup_av_free.exe
C:\Program Files (x86)\AVG
C:\Program Files (x86)\Common Files\AVG Secure Search
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\Windows:8AA4CA1CF5E9407C
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdatePRCShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\CustomizeSearch => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\SearchAssistant => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key deleted successfully.
HKCR\CLSID\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key deleted successfully.
HKCR\CLSID\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key not found.
CHR DefaultSearchKeyword: r ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchProvider: Search Results ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... 2664541&q={searchTerms} ==> The Chrome "Settings" can be used to fix the entry.
vToolbarUpdater17.2.0 => Service deleted successfully.
Prot6Flt => Service deleted successfully.
RtsUIR => Service deleted successfully.
USBCCID => Service deleted successfully.
VSSERV => Service deleted successfully.
C:\ProgramData\MFAData => Moved successfully.
C:\ProgramData\AVG2013 => Moved successfully.
C:\Users\Gabča\Desktop\Speclean => Moved successfully.
C:\$AVG => Moved successfully.
C:\Users\Gabča\AdbeRdr940_cs_CZ.exe => Moved successfully.
C:\Users\Gabča\setup_av_free.exe => Moved successfully.
C:\Program Files (x86)\AVG => Moved successfully.
"C:\Program Files (x86)\Common Files\AVG Secure Search" => File/Directory not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows => ":8AA4CA1CF5E9407C" ADS removed successfully.
C:\ProgramData\Temp => ":0B4227B4" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2013 01
Ran by Gabča at 2013-12-15 19:05:32 Run:1
Running from C:\Users\Gabča\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [UpdatePRCShortCut] - C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [] - [x]
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
SearchScopes: HKLM-x32 - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
SearchScopes: HKCU - {C1CB7F29-25A2-4CB6-B694-28FCF819E402} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
CHR DefaultSearchKeyword: r
CHR DefaultSearchProvider: Search Results
CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... 2664541&q={searchTerms}
CHR DefaultNewTabURL:
S2 vToolbarUpdater17.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe [x]
S3 Prot6Flt; No ImagePath
S3 RtsUIR; No ImagePath
S3 USBCCID; No ImagePath
U4 VSSERV;
2013-12-11 22:08 - 2012-03-30 11:59 - 00000000 ____D C:\ProgramData\MFAData
2013-12-11 21:57 - 2013-06-30 16:25 - 00000000 ____D C:\ProgramData\AVG2013
2013-12-11 21:56 - 2013-12-11 21:56 - 00000000 ____D C:\Users\Gabča\Desktop\Speclean
2013-12-11 21:56 - 2012-03-30 12:04 - 00000000 ___HD C:\$AVG
C:\Users\Gabča\AdbeRdr940_cs_CZ.exe
C:\Users\Gabča\setup_av_free.exe
C:\Program Files (x86)\AVG
C:\Program Files (x86)\Common Files\AVG Secure Search
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => C:\Users\Gab
a\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\Windows:8AA4CA1CF5E9407C
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdatePRCShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\CustomizeSearch => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\SearchAssistant => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key deleted successfully.
HKCR\CLSID\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key deleted successfully.
HKCR\CLSID\{C1CB7F29-25A2-4CB6-B694-28FCF819E402} => Key not found.
CHR DefaultSearchKeyword: r ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchProvider: Search Results ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchURL: http://dts.search-results.com/sr?src=cr ... 2664541&q={searchTerms} ==> The Chrome "Settings" can be used to fix the entry.
vToolbarUpdater17.2.0 => Service deleted successfully.
Prot6Flt => Service deleted successfully.
RtsUIR => Service deleted successfully.
USBCCID => Service deleted successfully.
VSSERV => Service deleted successfully.
C:\ProgramData\MFAData => Moved successfully.
C:\ProgramData\AVG2013 => Moved successfully.
C:\Users\Gabča\Desktop\Speclean => Moved successfully.
C:\$AVG => Moved successfully.
C:\Users\Gabča\AdbeRdr940_cs_CZ.exe => Moved successfully.
C:\Users\Gabča\setup_av_free.exe => Moved successfully.
C:\Program Files (x86)\AVG => Moved successfully.
"C:\Program Files (x86)\Common Files\AVG Secure Search" => File/Directory not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1305378287-1200049395-268641518-1000UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows => ":8AA4CA1CF5E9407C" ADS removed successfully.
C:\ProgramData\Temp => ":0B4227B4" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Re: Prosím o kontrolu
Jak se chova PC 

Re: Prosím o kontrolu
Nyní již je to mnohem lepší a stabilnější děkuji
ale jen když se mrknu na využití paměti ramek tak se pohybuje okolo 900mb je to v pořádku?

Re: Prosím o kontrolu
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
vyuziti je odpovidajici danemu systemu a bezicich programu
A pokud nejsou problemy ci dotazy, je to z me strany vse 


- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy



Re: Prosím o kontrolu
Perfektní děkuji za Váš čas.